Power system access control method and device, electronic equipment and medium
Through the access control method based on zero-trust architecture, combined with deep learning and large language models, fine-grained access control policies are generated in real time, and the security and real-time nature of power system access control are solved, achieving the improvement of flexibility and real-time response capabilities.
Patent Information
- Application Number
- CN202510558453.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, power system access control has the problem of high security protection requirements, high complexity and inability to control in real time. Especially when there are many types of low-voltage distribution side equipment and limited computing capabilities, it is difficult to improve flexibility and real-time response capabilities.
The access control method based on the zero-trust architecture is adopted to collect the evaluation data of devices, systems and networks in real time, use deep learning and large language models to dynamically generate access control policies, and combine trusted agents for access control to realize device trust assessment, system resource environment assessment and network trust assessment, and generate fine-grained access control policies.
It realizes the flexibility, security and real-time response capabilities of access control, and can adjust permissions in real time according to the operating status of the power grid and the safety of the equipment to ensure the safety of the system without affecting normal operation.
Smart Images

Figure CN120342723A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system access security control, and in particular to a power system access control method, device, electronic device and medium. Background Art
[0002] The core objective of power system access control is to ensure the safe and stable operation of the power grid and prevent unauthorized access from causing system crashes, data leaks or malicious attacks. With the development of smart grids, the number of connected terminal devices has increased significantly, including substation control systems, smart meters, Supervisory Control And Data Acquisition (SCADA) systems, distribution automation terminals, and low-voltage control-related business devices (such as distributed energy control, charging piles, microgrid management systems, etc.). Traditional Role-Base Access Control (RBAC) is difficult to meet the access management requirements of large-scale, dynamic, and cross-regional scenarios. Especially on the low-voltage distribution side, where there are a wide variety of device types and complex communication environments, the security protection requirements are more stringent.
[0003] Compared with ordinary IT systems, power system access control requires higher real-time performance, supports hierarchical control among different users, devices, and dispatching centers, and at the same time adapts to the needs of remote operation and maintenance, emergency response, and network security protection. In low-voltage control-related business scenarios, terminal devices are mostly low-power embedded systems with limited computing capabilities, making it difficult to run complex identity authentication and encryption protocols. Therefore, the access control mechanism must balance security and lightweight.
[0004] Because the power grid operating environment is complex and constantly changing, involving multiple links such as dispatching, operation and maintenance, and security protection, static permission management is difficult to meet the actual needs. In emergency situations such as fault repair, natural disasters, and cyberattacks, it is necessary to temporarily elevate the permissions of maintenance personnel and dispatchers to quickly troubleshoot problems and restore the system, while tightening or revoking the access permissions of suspicious users to prevent misoperations or malicious damage. In addition, smart grid devices are widely distributed, and the demand for remote operation and maintenance increases. External experts or third-party teams need to temporarily obtain access permissions under specific times and conditions to ensure efficient maintenance, while avoiding security risks brought by long-term open permissions. Grid dispatching has multi-level permission management requirements. From the national level to the provincial and municipal levels, permissions must be adjusted according to dispatching strategies to ensure that personnel at different positions can access the correct system at the correct time without overstepping their authority or affecting the operation of other regions. In the face of increasingly complex cyberattacks, access control also needs to be combined with real-time security monitoring, and permissions are dynamically adjusted through means such as behavior analysis and anomaly detection. For example, when detecting abnormal logins, abnormal device status, or high-risk operations, permissions are automatically tightened or a secondary authentication mechanism is triggered. In addition, the permissions for business scenarios such as power market transactions and load adjustment also need to change according to factors such as trading cycles and dispatching plans to prevent unauthorized users from accessing sensitive data or controlling devices at the wrong time. Compared with other industries, the dynamic access control of the power system faces higher real-time requirements, and it is necessary to ensure that permission adjustments can take effect in milliseconds to avoid affecting dispatching and device control. At the same time, it is also necessary to address the problem of limited computing power of devices, because many embedded terminals (such as smart meters and relay protection devices) cannot run complex dynamic permission management solutions and must adopt lightweight control mechanisms. In addition, a balance needs to be achieved between security and reliability, avoiding that overly strict permission management leads to inability to access critical devices in emergency situations, and also preventing overly loose policies from bringing security risks, and ensuring that access control can seamlessly cooperate between heterogeneous subsystems. Summary of the Invention
[0005] The present invention provides a power system access control method, device, electronic device and medium, which are used to solve the defects in the prior art of high security protection requirements, high complexity and inability to control in real time for power system access control, and realize the improvement of the flexibility, security and real-time response ability of access control.
[0006] The present invention provides a power system access control method, including: Real-time collecting device evaluation data of a target access device, system evaluation data of a target power system, and network risk assessment data, wherein the target access device is a device to access the target power system; Perform device trust evaluation on the target access device based on the device evaluation data, perform system resource environment evaluation on the target power system based on the system evaluation data, and perform network trust evaluation on the security status of the currently accessed network based on the network risk evaluation data; Generate a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result; Perform access control on the target access device based on the target access control policy.
[0007] In a possible implementation, the method further includes: During the process of the target access device accessing the target power system, perform device trust evaluation, system resource environment evaluation, and network trust evaluation in real time; Dynamically adjust the target access policy based on the evaluation results of the real-time device trust evaluation, system resource environment evaluation, and network trust evaluation; Perform access control on the target access device in real time based on the dynamically adjusted target access control policy.
[0008] In a possible implementation, the method further includes: Input the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result into an access control policy generation model to obtain multiple candidate access control policies output by the access control policy generation model; Score the multiple candidate access control policies based on a random forest model, and use the access control policy with the highest score as the target access control policy.
[0009] In a possible implementation, the method further includes: Allocate a trusted proxy for the target access device based on the target access control policy; Control the target access device to access system resources of the target power system based on the trusted proxy.
[0010] In a possible implementation, the method further includes: The access control policy generation model is trained through the following steps: Obtain sample device trust evaluation results, sample system resource environment evaluation results, and sample network trust evaluation results; Fuse the features of the sample device trust evaluation result, the sample system resource environment evaluation result, and the sample network trust evaluation result; Train a large language model according to the feature fusion data, and when the accuracy of the output result of the large language model is greater than or equal to a threshold, obtain the access control policy generation model.
[0011] In a possible implementation, the method further includes: Inputting the device evaluation data into a device trust evaluation model to obtain the device trust evaluation result; Inputting the system evaluation data into a system resource environment evaluation model to obtain the system resource environment evaluation result; Inputting the network risk evaluation data into a network trust evaluation model to obtain the network trust evaluation result.
[0012] The present invention also provides a power system access control device, including the following modules: A data acquisition module, configured to collect in real time the device evaluation data of a target access device, the system evaluation data of a target power system, and network risk evaluation data, where the target access device is a device to access the target power system; An evaluation module, configured to perform device trust evaluation on the target access device based on the device evaluation data, perform system resource environment evaluation on the target power system based on the system evaluation data, and perform network trust evaluation on the security status of the currently accessed network based on the network risk evaluation data; A policy generation module, configured to generate a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result; An access control module, configured to perform access control on the target access device based on the target access control policy.
[0013] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, the power system access control method as described in any one of the above is implemented.
[0014] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the power system access control method as described in any one of the above is implemented.
[0015] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the power system access control method as described in any one of the above is implemented.
[0016] The power system access control method, device, electronic device and medium provided by the present invention collect device evaluation data of a target access device, system evaluation data of a target power system and network risk evaluation data in real time, where the target access device is a device to access the target power system; perform device trust evaluation on the target access device based on the device evaluation data, perform system resource environment evaluation on the target power system based on the system evaluation data, and perform network trust evaluation on the security state of the current access network based on the network risk evaluation data; generate a target access control policy based on the device trust evaluation result, the system resource environment evaluation result and the network trust evaluation result; and perform access control on the target access device based on the target access control policy. Compared with the defects in the prior art of high security protection requirements, high complexity and inability to perform real-time control for power system access control. By this solution, access control based on attributes and risks and a zero-trust architecture are adopted to ensure that access permissions can be adjusted in real time according to the power grid operation state, device security status and user behavior, which not only guarantees system security but also does not affect the normal operation of the power grid, and improves the flexibility, security and real-time response ability of access control. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0018] Figure 1 It is an architecture diagram of the power system access control method provided by the present invention.
[0019] Figure 2 It is one of the schematic flowcharts of the power system access control method provided by the present invention.
[0020] Figure 3 It is the second schematic flowchart of the power system access control method provided by the present invention.
[0021] Figure 4 It is a flowchart of the training method of the device trust evaluation model provided by the present invention.
[0022] Figure 5 It is a flowchart of the training method of the network trust evaluation model provided by the present invention.
[0023] Figure 6 It is a flowchart of the training method of the system resource environment evaluation model provided by the present invention.
[0024] Figure 7It is a flowchart of the training method for the access control policy generation model provided by the present invention.
[0025] Figure 8 It is a schematic structural diagram of the power system access control device provided by the present invention.
[0026] Figure 9 It is a schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners
[0027] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.
[0028] To facilitate the understanding of the embodiments of the present invention, the following will further explain with specific embodiments with reference to the accompanying drawings. The embodiments do not constitute a limitation to the embodiments of the present invention.
[0029] Figure 1 It is an architecture diagram of the power system access control method provided by the present invention. As Figure 1 shown, this method is based on the zero-trust architecture, combines deep learning and large language model (LLM) to dynamically adjust the access control policy to ensure network and system security. The architecture is divided into a control plane and a data plane. Among them, the control plane evaluates the device, network risk, and system resource environment through a trusted evaluation engine, and uses LLM to dynamically generate fine-grained access control policies. The data plane executes the policy through a trusted proxy to isolate untrusted devices. Deep learning is used for device behavior prediction, intrusion detection, and resource security evaluation to ensure the accuracy of the evaluation. This system can be widely applied to the low-voltage control-related business scenarios of the power system to improve security and flexibility.
[0030] The control plane is mainly responsible for evaluating the security of the access subject and the environment, and generating dynamic access control policies, including a trusted evaluation engine and a dynamic access control engine. Among them, the trusted evaluation engine uses a deep learning model to comprehensively evaluate the device, network risk, and system resource environment. Its evaluation result is provided as input to the dynamic access control engine. The dynamic access control engine uses LLM plus a decision tree model to generate attribute-based access control policies.
[0031] The data plane takes the trusted agent as the executor of access control and is responsible for: receiving the access control policies generated by the control plane; filtering access requests according to the policies to restrict access behaviors that do not conform to the policies; allocating trusted agents with specified access permissions to different devices to achieve resource isolation at different access levels; and proxying device access to system resources to ensure secure data transmission.
[0032] Figure 2 It is one of the flow diagrams of the power system access control method provided by the present invention. As Figure 2 shown, the method includes the following: S21. Real-time collect the device evaluation data of the target access device, the system evaluation data of the target power system, and the network risk evaluation data.
[0033] In the embodiments of the present invention, first, it is necessary to determine whether the target access device of the power system to be accessed meets the security requirements to decide whether to allow the device to continue accessing; evaluate the security status of the current access network; and analyze the system resource load and security status. Therefore, it is necessary to collect the device evaluation data of the target access device, the system evaluation data of the target power system, and the network risk evaluation data.
[0034] Among them, the device evaluation data includes device fingerprint, firmware integrity, operating system security, malware detection results, device behavior logs, geographical location, and historical trust level, etc. The system evaluation data includes multi-dimensional operating state data, such as resource load, user access permissions, resource sensitivity, system vulnerability status, and access behavior logs, etc. The network risk evaluation data includes network source, traffic encryption situation, port exposure, distributed denial of service attack behavior (Distributed Denial of Service, DDoS), IP reputation (Internet Protocol reputation), Wi-Fi security, and geographical location, etc.
[0035] S22. Perform device trust evaluation on the target access device based on the device evaluation data, perform system resource environment evaluation on the target power system based on the system evaluation data, and perform network trust evaluation on the security status of the current access network based on the network risk evaluation data.
[0036] Input the device evaluation data into the device trust evaluation model to obtain the device trust evaluation result; input the system evaluation data into the system resource environment evaluation model to obtain the system resource environment evaluation result; input the network risk evaluation data into the network trust evaluation model to obtain the network trust evaluation result.
[0037] S23. Generate a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result.
[0038] Input the device trust evaluation result, system resource environment evaluation result, and network trust evaluation result into the access control policy generation model to obtain multiple candidate access control policies output by the access control policy generation model.
[0039] Furthermore, a decision tree model can be used to quickly verify the candidate access control policies to determine the target access control policy. Since the decision tree model has strong interpretability, the generated access control policy is convenient for security auditing and manual policy adjustment.
[0040] S24. Perform access control on the target access device based on the target access control policy.
[0041] Optionally, during the process of the target access device accessing the target power system, device trust evaluation, system resource environment evaluation, and network trust evaluation are performed in real time; the target access policy is dynamically adjusted based on the evaluation results of the device trust evaluation, system resource environment evaluation, and network trust evaluation performed in real time; and access control on the target access device is performed in real time based on the dynamically adjusted target access control policy.
[0042] The access control policy in the embodiment of the present invention needs to be fine-grained and supports the generation of policies based on parameters such as user identity, device status, access time, and network environment. When the device evaluation is unqualified, the device access is directly rejected.
[0043] The power system access control method provided by the present invention collects device evaluation data of the target access device, system evaluation data of the target power system, and network risk evaluation data in real time, where the target access device is a device to access the target power system; performs device trust evaluation on the target access device based on the device evaluation data, performs system resource environment evaluation on the target power system based on the system evaluation data, and performs network trust evaluation on the security status of the currently accessed network based on the network risk evaluation data; generates a target access control policy based on the device trust evaluation result, system resource environment evaluation result, and network trust evaluation result; and performs access control on the target access device based on the target access control policy. Compared with the defects in the prior art of high security protection requirements, high complexity, and inability to perform real-time control for power system access control. By this method, attribute-based and risk-based access control and zero-trust architecture are used to ensure that access permissions can be adjusted in real time according to the grid operation status, device security status, and user behavior, which not only ensures system security but also does not affect the normal operation of the power grid, and improves the flexibility, security, and real-time response ability of access control.
[0044] Figure 3 is the second flow schematic diagram of the power system access control method provided by the present invention, asFigure 3 As shown, the method includes the following: S31. Collect the device evaluation data of the target access device, the system evaluation data of the target power system, and the network risk assessment data in real time.
[0045] In the embodiments of the present invention, first, it is necessary to determine whether the target access device of the power system to be accessed meets the security requirements and decide whether to allow the device to continue accessing; evaluate the security status of the current access network; and analyze the system resource load and security status. Therefore, it is necessary to collect the device evaluation data of the target access device, the system evaluation data of the target power system, and the network risk assessment data.
[0046] Among them, the device evaluation data includes device fingerprints, firmware integrity, operating system security, malware detection results, device behavior logs, geographical locations, and historical trust levels, etc. As shown in Table 1: Table 1 Device Evaluation Parameters
[0047] The system evaluation data includes multi-dimensional operating state data, such as resource load, user access permissions, resource sensitivity, system vulnerability status, and access behavior logs, etc. As shown in Table 2: Table 2 System Evaluation Parameters
[0048] The network risk assessment data includes network sources, traffic encryption, port exposure, distributed denial of service attacks (DDoS), IP reputation, Wi-Fi security, and geographical locations, etc. As shown in Table 3: Table 3 Network Risk Assessment Parameters
[0049] S32. Perform device trust evaluation on the target access device based on the device evaluation data, perform system resource environment evaluation on the target power system based on the system evaluation data, and perform network trust evaluation on the security status of the current access network based on the network risk assessment data.
[0050] In the embodiments of the present invention, it is necessary to pre-train a device trust evaluation model, a system resource environment evaluation model, and a network trust evaluation model.
[0051] Specifically, such as Figure 4As shown in the figure, the training process of the device trust evaluation model first collects raw data from multiple dimensions, including device fingerprints, firmware integrity, operating system security, malware detection results, device behavior logs, geographical locations, and historical trust levels. Next, these data are cleaned, standardized, and vectorized to construct a unified device feature representation. Subsequently, a deep learning model (Transformer) based on the self-attention mechanism and a long short-term memory network (LSTM) are used to model the security status and behavior patterns of the device, identifying high-risk features and trusted behavior features. After training, the model can generate a trust score based on the multi-dimensional features of the input device, serving as a key basis for the dynamic access control policy engine to achieve precise authorization and risk isolation based on the device status.
[0052] As Figure 5 shown in the figure, the network trust evaluation model first collects raw data from multiple dimensions, including network sources, traffic encryption, port exposure, DDoS attack behavior, IP reputation, Wi-Fi security, and geographical locations. Subsequently, the system maps network connections and sessions into a graph structure, representing the communication topology between different devices and hosts, and uses a graph neural network (GNN) to extract the structural features of network behavior. At the same time, CNN is used to perform spatial pattern analysis on the time series or session content of network traffic data. The feature vectors extracted by the two models are fused and input into a multi-task learning framework for training, thereby constructing a network trust evaluation model. The trust score output by this model can be used for dynamic access control policies to guide the system to adjust authorization permissions in real time according to the network status.
[0053] As Figure 6 shown in the figure, the system resource environment evaluation model adopts a semi-supervised learning strategy. First, it collects the current multi-dimensional operating state data of the system, such as resource load, user access permissions, resource sensitivity, system vulnerability status, and access behavior logs, and standardizes these data. Subsequently, a part of the high-quality labeled samples are extracted for supervised training to construct a system state classifier or scorer. At the same time, a contrast learning mechanism is introduced for the unlabeled data to construct positive and negative sample pairs. By optimizing the aggregation of similar states and the separation of different states in the representation space, the generalization and recognition ability of the model for abnormal system states is enhanced. Finally, the supervised path and the self-supervised path are fused, and the overall model training is completed through a unified embedding space, outputting a system trust score for use as a decision basis for dynamic access control policies.
[0054] Further, input the device evaluation data into the device trust evaluation model to obtain the device trust evaluation result; input the system evaluation data into the system resource environment evaluation model to obtain the system resource environment evaluation result; input the network risk evaluation data into the network trust evaluation model to obtain the network trust evaluation result.
[0055] S33. Input the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result into the access control policy generation model to obtain multiple candidate access control policies output by the access control policy generation model.
[0056] In the embodiment of the present invention, it is also necessary to pre-train the access control policy generation model. As Figure 7 shown, first obtain the sample device trust evaluation result, the sample system resource environment evaluation result, and the sample network trust evaluation result; perform feature fusion on the sample device trust evaluation result, the sample system resource environment evaluation result, and the sample network trust evaluation result; train a large language model according to the feature fusion data, and use the large language model to perform context understanding learning on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result. When the accuracy of the output result of the large language model is greater than or equal to the threshold, the access control policy generation model is obtained.
[0057] S34. Score the multiple candidate access control policies based on a random forest model, and use the access control policy with the highest score as the target access control policy.
[0058] Use a decision tree model (random forest model) to quickly verify the candidate access control policies and generate a formal access control policy. Since the decision tree model has strong interpretability, the generated access control policy is convenient for security auditing and manual adjustment of the policy.
[0059] S35. Allocate a trusted proxy for the target access device based on the target access control policy.
[0060] S36. Control the target access device to access the system resources of the target power system based on the trusted proxy.
[0061] Filter the access requests according to the target access control policy to restrict access behaviors that do not conform to the policy. Allocate trusted proxies with specified access permissions to different devices according to the target access control policy to achieve resource isolation at different access levels. The proxy device accesses the system resources to ensure data transmission security. The trusted proxy receives and executes the access control policy generated by the control plane. Filter the access requests according to the policy to ensure that only devices that meet the conditions can access the resources. Achieve resource isolation at different access levels and ensure data transmission security.
[0062] Optionally, during the process of the target access device accessing the target power system, device trust evaluation, system resource environment evaluation, and network trust evaluation are performed in real time; the target access policy is dynamically adjusted based on the evaluation results of the device trust evaluation, system resource environment evaluation, and network trust evaluation performed in real time; and access control over the target access device is performed in real time based on the dynamically adjusted target access control policy.
[0063] The access control policy in the embodiments of the present invention needs to be fine-grained and supports the generation of policies based on parameters such as user identity, device status, access time, and network environment. When the device evaluation is unqualified, the device access is directly rejected.
[0064] The beneficial effects of the power system access control method provided by the present invention include: Dynamic evaluation and adaptive adjustment: The comprehensive evaluation mechanism based on deep learning and large models can monitor the security status of devices, networks, and system resources in real time, automatically adjust the access control policy, enhance the protection ability of the system, and reduce security vulnerabilities and attack surfaces.
[0065] Reject access of untrusted devices: Through device evaluation, devices that do not meet the security requirements can be identified, and their access can be directly rejected to prevent potential security threats.
[0066] Fine-grained control: Supports the dynamic generation and adjustment of access control policies based on multiple parameters (such as device fingerprint, device status, network environment, access time, etc.), improving the accuracy and flexibility of access management.
[0067] Combination of deep learning and large models: Through intelligent analysis of data by deep learning models, an automated risk assessment and decision-making process is realized, reducing manual intervention and improving efficiency.
[0068] Trusted proxy mechanism: Ensures that devices that do not meet the security policy are isolated, while granting appropriate access permissions to devices that meet the requirements, effectively isolating resources at different access levels and avoiding data leakage and abuse.
[0069] The power system access control device provided by the present invention is described below. The power system access control device described below can be correspondingly referred to the power system access control method described above.
[0070] Figure 8 It is a schematic structural diagram of the power system access control device provided by the present invention, specifically including: The data acquisition module 801 is used to collect device evaluation data of the target access device, system evaluation data of the target power system, and network risk evaluation data in real time, where the target access device is a device to access the target power system. For detailed description, refer to the relevant description corresponding to the above method embodiment, which will not be elaborated here.
[0071] An evaluation module 802, configured to perform device trust evaluation on the target access device based on the device evaluation data of the device, perform system resource environment evaluation on the target power system based on the system evaluation data of the system, and perform network trust evaluation on the security status of the currently accessed network based on the network risk evaluation data. For detailed description, refer to the relevant description corresponding to the above method embodiments, which will not be elaborated here.
[0072] A policy generation module 803, configured to generate a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result. For detailed description, refer to the relevant description corresponding to the above method embodiments, which will not be elaborated here.
[0073] An access control module 804, configured to perform access control on the target access device based on the target access control policy. For detailed description, refer to the relevant description corresponding to the above method embodiments, which will not be elaborated here.
[0074] Figure 9 The schematic physical structure diagram of an electronic device is exemplified. As Figure 9 shown, the electronic device may include: a processor 910, a communication interface 920, a memory 930, and a communication bus 940. Among them, the processor 910, the communication interface 920, and the memory 930 complete communication with each other through the communication bus 940. The processor 910 may call the logical instructions in the memory 930 to execute the power system access control method, and the method includes: collecting in real time the device evaluation data of the target access device, the system evaluation data of the target power system, and the network risk evaluation data, where the target access device is the device to access the target power system; performing device trust evaluation on the target access device based on the device evaluation data, performing system resource environment evaluation on the target power system based on the system evaluation data, and performing network trust evaluation on the security status of the currently accessed network based on the network risk evaluation data; generating a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result; and performing access control on the target access device based on the target access control policy.
[0075] In addition, when the logical instructions in the above-mentioned memory 930 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs, Read-Only Memories), random access memories (RAMs, Random Access Memories), magnetic disks, or optical discs that can store program codes.
[0076] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the power system access control method provided by the above-mentioned various methods. The method includes: collecting in real time the device evaluation data of the target access device, the system evaluation data of the target power system, and the network risk evaluation data, where the target access device is the device to access the target power system; performing device trust evaluation on the target access device based on the device evaluation data, performing system resource environment evaluation on the target power system based on the system evaluation data, and performing network trust evaluation on the security state of the current access network based on the network risk evaluation data; generating a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result; and performing access control on the target access device based on the target access control policy.
[0077] In another aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a power system access control method provided by the above-mentioned various methods. The method includes: collecting in real time device evaluation data of a target access device, system evaluation data of a target power system, and network risk evaluation data, where the target access device is a device to access the target power system; performing device trust evaluation on the target access device based on the device evaluation data, performing system resource environment evaluation on the target power system based on the system evaluation data, and performing network trust evaluation on the security state of the current access network based on the network risk evaluation data; generating a target access control policy based on the device trust evaluation result, the system resource environment evaluation result, and the network trust evaluation result; and performing access control on the target access device based on the target access control policy.
[0078] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0079] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A power system access control method, characterized in that, Including: Real-time collecting device evaluation data of a target access device, system evaluation data of a target power system, and network risk assessment data, where the target access device is a device to access the target power system; Based on the device evaluation data, performing device trustworthiness evaluation on the target access device, based on the system evaluation data, performing system resource environment evaluation on the target power system, and based on the network risk assessment data, performing network trust evaluation on the security status of the current access network; Generating a target access control policy based on the device trustworthiness evaluation result, the system resource environment evaluation result, and the network trust evaluation result; Performing access control on the target access device based on the target access control policy.
2. The method according to claim 1, wherein The method further includes: During the process of the target access device accessing the target power system, performing device trustworthiness evaluation, system resource environment evaluation, and network trust evaluation in real time; Dynamically adjusting the target access policy based on the evaluation results of the real-time device trustworthiness evaluation, system resource environment evaluation, and network trust evaluation; Performing access control on the target access device in real time based on the dynamically adjusted target access control policy.
3. The method according to claim 1, wherein The generating the target access control policy based on the device trustworthiness evaluation result, the system resource environment evaluation result, and the network trust evaluation result includes: Inputting the device trustworthiness evaluation result, the system resource environment evaluation result, and the network trust evaluation result into an access control policy generation model to obtain multiple candidate access control policies output by the access control policy generation model; Scoring the multiple candidate access control policies based on a random forest model, and taking the access control policy with the highest score as the target access control policy.
4. The method according to claim 3, wherein The performing access control on the target access device based on the target access control policy includes: Allocating a trusted proxy for the target access device based on the target access control policy; Controlling the target access device to access system resources of the target power system based on the trusted proxy.
5. The method according to any one of claims 1 to 4, characterized in that, The access control policy generation model is obtained through the following steps of training: Obtaining sample device trustworthiness evaluation results, sample system resource environment evaluation results, and sample network trust evaluation results; Performing feature fusion on the sample device trustworthiness evaluation results, the sample system resource environment evaluation results, and the sample network trust evaluation results; Training a large language model according to the feature fusion data, and when the accuracy of the output result of the large language model is greater than or equal to a threshold, obtaining the access control policy generation model.
6. The method according to claim 1, wherein The performing device trustworthiness evaluation on the target access device based on the device evaluation data, performing system resource environment evaluation on the target power system based on the system evaluation data, and performing network trust evaluation on the security status of the current access network based on the network risk assessment data includes: Inputting the device evaluation data into a device trustworthiness evaluation model to obtain the device trustworthiness evaluation result; Inputting the system evaluation data into a system resource environment evaluation model to obtain the system resource environment evaluation result; Input the network risk assessment data into a network trust assessment model to obtain the network trust assessment result.
7. An access control device for a power system, characterized in that, It includes: A data collection module, configured to collect in real time the device assessment data of a target access device, the system assessment data of a target power system, and network risk assessment data, where the target access device is a device to access the target power system; An assessment module, configured to perform device trust assessment on the target access device based on the device assessment data, perform system resource environment assessment on the target power system based on the system assessment data, and perform network trust assessment on the security status of the currently accessed network based on the network risk assessment data; A policy generation module, configured to generate a target access control policy based on the device trust assessment result, the system resource environment assessment result, and the network trust assessment result; An access control module, configured to perform access control on the target access device based on the target access control policy.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, wherein, When the processor executes the computer program, it implements the power system access control method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the power system access control method according to any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the power system access control method according to any one of claims 1 to 6.
Citation Information
Cited By
Access control method and device of power system, equipment, storage medium and program product
CN121000420A
Access control method and device, electronic equipment and computer readable storage medium
CN121603256A