Data security guarantee method and device based on virtual power plant
By collecting and processing data traffic and log information of virtual power plants, and using the security event identification model to dynamically adjust the strategy, the rigid policy problems in the existing technology are solved, and the flexibility and robustness of data security are improved.
Patent Information
- Application Number
- CN202411691192.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-08-01
AI Technical Summary
The existing technology cannot flexibly adjust the data security and network security policies of virtual power plants based on real-time generated log files and other data, resulting in rigid and unsupported policies.
Collect data flow information and information system log information of virtual power plants, summarize and process it, input it into the security event identification model as a hidden layer, and select the security adjustment strategy for adjustment through the security judgment result.
It realizes dynamic adjustment of security policies based on real-time data, improving the flexibility and robustness of data security guarantees.
Smart Images

Figure CN120408651A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security assurance, and in particular, to a data security assurance method and device based on a virtual power plant. Background Art
[0002] With the continuous development of intelligent technology, intelligent devices are increasingly used in people's life, work and study. Using intelligent technology means has improved the quality of people's life and increased the efficiency of people's study and work.
[0003] Currently, for data security assurance of the data generated during the operation and operation and maintenance of a virtual power plant, the existing technology only executes different deployment ideas and strategies through the deployment of data security policies, but cannot flexibly adjust data security and network security policies according to data such as real-time generated log files, resulting in rigid and non-robust data security assurance policies.
[0004] For the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of the present invention provide a data security assurance method and device based on a virtual power plant to at least solve the technical problem that the existing technology only executes different deployment ideas and strategies through the deployment of data security policies, but cannot flexibly adjust data security and network security policies according to data such as real-time generated log files, resulting in rigid and non-robust data security assurance policies.
[0006] According to one aspect of the embodiments of the present invention, a data security assurance method based on a virtual power plant is provided, including: collecting data traffic information and information system log information of the virtual power plant; aggregating and processing the data traffic information and the information system log information to obtain a data security matrix; inputting the data security matrix as a hidden layer into a security event recognition model to obtain a security judgment result; and selecting a security adjustment strategy for adjustment according to the security judgment result.
[0007] Optionally, the aggregating and processing the data traffic information and the information system log information to obtain a data security matrix includes: inputting the data traffic information and the information system log information into a matrix
[0008]
[0009] to obtain the data security matrix including the data traffic information and the information system log information, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements.
[0010] Optionally, before inputting the data security matrix into the security event recognition model as a hidden layer to obtain a security judgment result, the method further includes: constructing the security event recognition model according to historical data.
[0011] Optionally, the selecting a security adjustment policy for adjustment according to the security judgment result includes: analyzing the security judgment result to obtain security problem data; calling the database of the security adjustment policy according to the security problem data to obtain a target policy; and performing a security configuration adjustment operation according to the target policy.
[0012] According to another aspect of the embodiments of the present invention, there is also provided a data security guarantee device based on a virtual power plant, including: a collection module, configured to collect data traffic information and information system log information of the virtual power plant; a summarization module, configured to perform a summarization process on the data traffic information and the information system log information to obtain a data security matrix; an identification module, configured to input the data security matrix into a security event recognition model as a hidden layer to obtain a security judgment result; and an adjustment module, configured to select a security adjustment policy for adjustment according to the security judgment result.
[0013] Optionally, the summarization module includes: an input unit, configured to input the data traffic information and the information system log information into a matrix
[0014]
[0015] to obtain the data security matrix including the data traffic information and the information system log information, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements.
[0016] Optionally, the device further includes: a construction module, configured to construct the security event recognition model according to historical data.
[0017] Optionally, the adjustment module includes: an analysis unit, configured to analyze the security judgment result to obtain security problem data; a calling unit, configured to call the database of the security adjustment policy according to the security problem data to obtain a target policy; and an execution unit, configured to perform a security configuration adjustment operation according to the target policy.
[0018] According to another aspect of the embodiments of the present invention, there is also provided a non-volatile storage medium, where the non-volatile storage medium includes a stored program, and when the program runs, it controls a device where the non-volatile storage medium is located to execute a data security guarantee method based on a virtual power plant.
[0019] According to another aspect of the embodiments of the present invention, an electronic device is further provided, which includes a processor and a memory; computer-readable instructions are stored in the memory, and the processor is used to run the computer-readable instructions, wherein when the computer-readable instructions run, a data security guarantee method based on a virtual power plant is executed.
[0020] In the embodiments of the present invention, by collecting the data traffic information and information system log information of the virtual power plant; aggregating and processing the data traffic information and the information system log information to obtain a data security matrix; inputting the data security matrix as a hidden layer into a security event recognition model to obtain a security judgment result; and selecting a security adjustment strategy according to the security judgment result for adjustment, the technical problem in the prior art that only different deployment ideas and strategies are executed through the deployment of data security policies, but the data security and network security policies cannot be flexibly adjusted according to data such as real-time generated log files, resulting in rigid and non-robust data security guarantee policies is solved. Description of the Drawings
[0021] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0022] Figure 1 is a flowchart of a data security guarantee method based on a virtual power plant according to an embodiment of the present invention;
[0023] Figure 2 is a structural block diagram of a data security guarantee device based on a virtual power plant according to an embodiment of the present invention;
[0024] Figure 3 is a block diagram of a terminal device for executing the method according to the present invention according to an embodiment of the present invention;
[0025] Figure 4 is a storage unit for holding or carrying program code for implementing the method according to the present invention according to an embodiment of the present invention. Detailed Embodiments
[0026] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0027] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0028] According to an embodiment of the present invention, there is provided a method embodiment of a data security guarantee method based on a virtual power plant. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0029] Embodiment 1
[0030] Figure 1 is a flowchart of a data security guarantee method based on a virtual power plant according to an embodiment of the present invention. As Figure 1 shown, the method includes the following steps:
[0031] Step S102, collect the data traffic information and information system log information of the virtual power plant.
[0032] Step S104, summarize and process the data traffic information and the information system log information to obtain a data security matrix.
[0033] Step S106, input the data security matrix into a security event recognition model as a hidden layer to obtain a security judgment result.
[0034] Step S108, select a security adjustment strategy for adjustment according to the security judgment result.
[0035] Optionally, the summarizing and processing the data traffic information and the information system log information to obtain a data security matrix includes: inputting the data traffic information and the information system log information into a matrix
[0036]
[0037] Among them, the data security matrix including the data traffic information and the information system log information is obtained, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements.
[0038] Optionally, before inputting the data security matrix as a hidden layer into the security event recognition model to obtain a security judgment result, the method further includes: constructing the security event recognition model according to historical data.
[0039] Optionally, the selecting a security adjustment strategy for adjustment according to the security judgment result includes: analyzing the security judgment result to obtain security problem data; calling the database of the security adjustment strategy according to the security problem data to obtain a target strategy; and performing a security configuration adjustment operation according to the target strategy.
[0040] Through the above embodiments, the technical problem in the prior art that only different deployment ideas and strategies are executed through the deployment of data security policies, but the data security and network security policies cannot be flexibly adjusted according to data such as real-time generated log files, resulting in rigid and non-robust data security guarantee policies is solved.
[0041] Embodiment 2
[0042] Figure 2 It is a structural block diagram of a data security guarantee device based on a virtual power plant according to an embodiment of the present invention. As Figure 2 shown, the device includes:
[0043] An acquisition module 20, configured to acquire data traffic information and information system log information of a virtual power plant.
[0044] A summarization module 22, configured to perform a summarization process on the data traffic information and the information system log information to obtain a data security matrix.
[0045] An identification module 24, configured to input the data security matrix as a hidden layer into a security event recognition model to obtain a security judgment result.
[0046] An adjustment module 26, configured to select a security adjustment strategy for adjustment according to the security judgment result.
[0047] Optionally, the summarization module includes: an input unit, configured to input the data traffic information and the information system log information into a matrix
[0048]
[0049] In it, the data security matrix including the data traffic information and the information system log information is obtained, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements.
[0050] Optionally, the device further includes: a construction module for constructing the security event recognition model according to historical data.
[0051] Optionally, the adjustment module includes: an analysis unit for analyzing the security judgment result to obtain security problem data; a call unit for calling the database of the security adjustment policy according to the security problem data to obtain a target policy; an execution unit for performing a security configuration adjustment operation according to the target policy.
[0052] Through the above embodiments, the technical problem in the prior art that only different deployment ideas and strategies are executed through the deployment of data security policies, but the data security and network security policies cannot be flexibly adjusted according to data such as real-time generated log files, resulting in rigid and non-robust data security guarantee policies is solved.
[0053] According to another aspect of the embodiments of the present invention, a non-volatile storage medium is further provided. The non-volatile storage medium includes a stored program, where the program, when running, controls the device where the non-volatile storage medium is located to execute a data security guarantee method based on a virtual power plant.
[0054] Specifically, the above method includes: collecting the data traffic information and the information system log information of the virtual power plant; performing a summary process on the data traffic information and the information system log information to obtain a data security matrix; inputting the data security matrix as a hidden layer into the security event recognition model to obtain a security judgment result; and selecting a security adjustment policy according to the security judgment result for adjustment. Optionally, the performing a summary process on the data traffic information and the information system log information to obtain a data security matrix includes: inputting the data traffic information and the information system log information into a matrix
[0055]
[0056] Among them, the data security matrix including the data traffic information and the information system log information is obtained, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements. Optionally, before inputting the data security matrix into the security event recognition model as the hidden layer to obtain a security judgment result, the method further includes: constructing the security event recognition model according to historical data. Optionally, the selecting a security adjustment strategy for adjustment according to the security judgment result includes: analyzing the security judgment result to obtain security problem data; calling the database of the security adjustment strategy according to the security problem data to obtain a target strategy; and performing a security configuration adjustment operation according to the target strategy.
[0057] According to another aspect of the embodiments of the present invention, an electronic device is further provided, including a processor and a memory; computer-readable instructions are stored in the memory, and the processor is configured to run the computer-readable instructions, where the computer-readable instructions perform a data security guarantee method based on a virtual power plant when running.
[0058] Specifically, the above method includes: collecting data traffic information and information system log information of a virtual power plant; aggregating and processing the data traffic information and the information system log information to obtain a data security matrix; inputting the data security matrix into a security event recognition model as a hidden layer to obtain a security judgment result; and selecting a security adjustment strategy for adjustment according to the security judgment result. Optionally, the aggregating and processing the data traffic information and the information system log information to obtain a data security matrix includes: inputting the data traffic information and the information system log information into a matrix
[0059]
[0060] Among them, the data security matrix including the data traffic information and the information system log information is obtained, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements. Optionally, before inputting the data security matrix into the security event recognition model as the hidden layer to obtain a security judgment result, the method further includes: constructing the security event recognition model according to historical data. Optionally, the selecting a security adjustment strategy for adjustment according to the security judgment result includes: analyzing the security judgment result to obtain security problem data; calling the database of the security adjustment strategy according to the security problem data to obtain a target strategy; and performing a security configuration adjustment operation according to the target strategy.
[0061] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.
[0062] In the above embodiments of the present invention, the descriptions of the various embodiments have their respective emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0063] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0064] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0065] In addition, Figure 3 is a schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application. As Figure 3 shown, the terminal device may include an input device 30, a processor 31, an output device 32, a memory 33, and at least one communication bus 34. The communication bus 34 is used to implement communication connections between components. The memory 33 may include high-speed RAM memory and may also include non-volatile storage NVM, such as at least one disk memory. Various programs can be stored in the memory 33 to complete various processing functions and implement the method steps of this embodiment.
[0066] Optionally, the above-mentioned processor 31 can be implemented, for example, by a central processing unit (CPU), an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a controller, a microcontroller, a microprocessor, or other electronic components. The processor 31 is coupled to the above-mentioned input device 30 and output device 32 through a wired or wireless connection.
[0067] Optionally, the above input device 30 may include various input devices, such as at least one of a user interface facing the user, a device interface facing the device, a programmable interface of software, a camera, and a sensor. Optionally, the device interface facing the device may be a wired interface for data transmission between devices, or may also be a hardware insertion interface for data transmission between devices (such as a USB interface, a serial port, etc.); Optionally, the user interface facing the user may be, for example, a control button facing the user, a voice input device for receiving voice input, and a touch sensing device for receiving user touch input (such as a touch screen with touch sensing function, a touch pad, etc.); Optionally, the above programmable interface of software may be, for example, an entry for the user to edit or modify the program, such as an input pin interface or an input interface of a chip, etc.; Optionally, the above transceiver may be a radio frequency transceiver chip with communication function, a baseband processing chip, and a transceiver antenna, etc. Audio input devices such as microphones can receive voice data. The output device 32 may include output devices such as a display and a speaker.
[0068] In this embodiment, the processor of the terminal device includes functions for executing each module of the data processing device in each device. For the specific functions and technical effects, reference may be made to the above embodiments, and details are not described herein again.
[0069] Figure 4 FIG. [X] is a schematic diagram of the hardware structure of a terminal device provided in another embodiment of the present application. Figure 4 is a Figure 3 specific embodiment in the implementation process. As Figure 4 shown, the terminal device of this embodiment includes a processor 41 and a memory 42.
[0070] The processor 41 executes the computer program code stored in the memory 42 to implement the method in the above embodiment.
[0071] The memory 42 is configured to store various types of data to support the operation of the terminal device. Examples of these data include instructions for any application or method operating on the terminal device, such as messages, pictures, videos, etc. The memory 42 may include a random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory.
[0072] Optionally, the processor 41 is disposed in the processing component 40. The terminal device may further include: a communication component 43, a power supply component 44, a multimedia component 45, an audio component 46, an input / output interface 47, and / or a sensor component 48. The specific components included in the terminal device are set according to actual requirements, and this embodiment does not limit this.
[0073] The processing component 40 generally controls the overall operation of the terminal device. The processing component 40 may include one or more processors 41 to execute instructions to complete all or part of the steps of the above method. In addition, the processing component 40 may include one or more modules to facilitate the interaction between the processing component 40 and other components. For example, the processing component 40 may include a multimedia module to facilitate the interaction between the multimedia component 45 and the processing component 40.
[0074] The power supply component 44 provides power for various components of the terminal device. The power supply component 44 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the terminal device.
[0075] The multimedia component 45 includes a display screen that provides an output interface between the terminal device and the user. In some embodiments, the display screen may include a liquid crystal display (LCD) and a touch panel (TP). If the display screen includes a touch panel, the display screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of the touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operation.
[0076] The audio component 46 is configured to output and / or input audio signals. For example, the audio component 46 includes a microphone (MIC). When the terminal device is in an operating mode, such as a voice recognition mode, the microphone is configured to receive external audio signals. The received audio signals may be further stored in the memory 42 or sent via the communication component 43. In some embodiments, the audio component 46 further includes a speaker for outputting audio signals.
[0077] The input / output interface 47 provides an interface between the processing component 40 and a peripheral interface module, and the above peripheral interface module may be a click wheel, a button, etc. These buttons may include, but are not limited to: volume buttons, start buttons, and lock buttons.
[0078] The sensor assembly 48 includes one or more sensors for providing a status assessment of various aspects of the terminal device. For example, the sensor assembly 48 can detect the on / off state of the terminal device, the relative positioning of components, and the presence or absence of user contact with the terminal device. The sensor assembly 48 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact, including detecting the distance between the user and the terminal device. In some embodiments, the sensor assembly 48 can also include a camera, etc.
[0079] The communication component 43 is configured to facilitate communication between the terminal device and other devices in a wired or wireless manner. The terminal device can access a wireless network based on communication standards, such as WiFi, 2G, or 3G, or a combination thereof. In one embodiment, the terminal device can include a SIM card slot for inserting a SIM card, enabling the terminal device to log in to the GPRS network and establish communication with the server through the Internet.
[0080] As can be seen from the above, in Figure 4 the embodiments, the communication component 43, the audio component 46, and the input / output interface 47, and the sensor assembly 48 can all be used as Figure 3 implementation manners of the input device in the embodiments.
[0081] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of units or modules can be in an electrical or other form.
[0082] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0083] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0084] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0085] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A data security guarantee method based on a virtual power plant, characterized in that Including: Collecting the data traffic information and information system log information of the virtual power plant; Summarizing and processing the data traffic information and the information system log information to obtain a data security matrix; Inputting the data security matrix as a hidden layer into a security event recognition model to obtain a security judgment result; Selecting a security adjustment strategy according to the security judgment result for adjustment.
2. The method according to claim 1, characterized in that The summarizing and processing the data traffic information and the information system log information to obtain a data security matrix includes: Inputting the data traffic information and the information system log information into a matrix to obtain the data security matrix including the data traffic information and the information system log information, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements.
3. The method according to claim 1, characterized in that, Before inputting the data security matrix as a hidden layer into a security event recognition model to obtain a security judgment result, the method further includes: Constructing the security event recognition model according to historical data.
4. The method according to claim 1, characterized in that, The selecting a security adjustment strategy according to the security judgment result for adjustment includes: Analyzing the security judgment result to obtain security problem data; Invoking the database of the security adjustment strategy according to the security problem data to obtain a target strategy; Performing a security configuration adjustment operation according to the target strategy.
5. A data security guarantee device based on a virtual power plant, characterized in that, Including: A collection module for collecting the data traffic information and information system log information of the virtual power plant; A summarization module for summarizing and processing the data traffic information and the information system log information to obtain a data security matrix; An identification module for inputting the data security matrix as a hidden layer into a security event recognition model to obtain a security judgment result; An adjustment module for selecting a security adjustment strategy according to the security judgment result for adjustment.
6. The device according to claim 5, characterized in that, The summarization module includes: An input unit for inputting the data traffic information and the information system log information into a matrix to obtain the data security matrix including the data traffic information and the information system log information, where D1 to Dn represent n data traffic information elements, and T1 to Tn represent n information system log information elements.
7. The device according to claim 5, characterized in that, The device further includes: A construction module for constructing the security event recognition model according to historical data.
8. The device according to claim 5, characterized in that, The adjustment module includes: An analysis unit for analyzing the security judgment result to obtain security problem data; An invocation unit for invoking the database of the security adjustment strategy according to the security problem data to obtain a target strategy; An execution unit for performing a security configuration adjustment operation according to the target strategy.
9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, where the program controls the device where the non-volatile storage medium is located to execute the method according to any one of claims 1 to 4 when running.
10. An electronic device, characterized in that, Including a processor and a memory; computer-readable instructions are stored in the memory, and the processor is used to run the computer-readable instructions, where the computer-readable instructions execute the method according to any one of claims 1 to 4 when running.