Security and privacy protection method for data service of regional power marketing management information platform

Through dynamic noise anonymization, multi-party secure computing and fragmented reorganization transmission, combined with the operating status of the power system, the shortcomings of existing technologies that cannot adjust privacy protection strength and transmission mechanism in real time are solved, dynamic security protection of power data is achieved, and the data security and privacy protection of the power system are enhanced.

CN120597322APending Publication Date: 2025-09-05INNER MONGOLIA POWER (GROUP) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510696459.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing data security protection methods are unable to adjust the privacy protection strength in real time, cannot identify potential risk requests, and the transmission process does not fully consider the physical characteristics of the power system, resulting in data exposing user behavior characteristics in high-load and high-risk scenarios, and are difficult to resist attacks from cross-regional joint nodes.

Method used

Combined with the operating status of the power system, dynamic noise anonymization, multi-party secure computing-driven access policy generation and shard dynamic reorganization transmission are adopted. Through a trusted execution environment, multi-party secure computing node clusters and blockchain smart contracts, dynamic access control and transmission reorganization are achieved to ensure data security and privacy protection.

Benefits of technology

It realizes the adaptive adjustment of data disturbance and transmission mechanism to the operation status of the power grid, enhances the ability to resist traffic timing analysis and fragmentation restoration attacks, effectively resists the collusion tampering and deceptive access strategies of cross-regional joint nodes, and improves the ability to prevent the reverse inference of individual information in the data environment of the power industry.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597322A_ABST
    Figure CN120597322A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security protection, in particular to a security and privacy protection method for data service of a regional power marketing management information platform, which comprises the following steps of: inputting original data of a power user into a trusted execution environment, adding dynamic noise to the data in the trusted execution environment and generating irreversible anonymous variation data; generating a dynamic access strategy based on the consensus verification result of each computing node, wherein the dynamic access strategy comprises a data access permission threshold value and an abnormal access consensus mark; and segmenting the anonymous variation data into a plurality of dynamic fragments, adding a unique recombination verification code to each fragment, and transmitting the fragments to a target terminal through an independent communication link. According to the invention, the risk of cross-regional joint node collusion tampering or cheating access strategies is effectively resisted; and furthermore, an abnormal access consensus result is used for driving an authority threshold index to decay, so that fine-grained and dynamic access control is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security protection technology, and in particular to a method for protecting the security and privacy of data services on a regional power marketing management information platform. Background Art

[0002] With the advancement of electricity market reform and the continuous construction of regional electricity sales platforms, electricity users' transaction information, electricity consumption behavior, identity attributes and other data are widely collected, centrally managed, and interactively circulated between different systems. In order to support differentiated electricity price strategies, precise marketing services and auxiliary scheduling analysis, the power sales and management information platform needs to frequently call user-level data, resulting in data transmission and processing between multiple nodes and multiple systems, forming a highly sensitive, dynamically changing and physically widely distributed data chain.

[0003] Existing data security protection methods mainly focus on static storage encryption, fixed differential privacy perturbations, role-based access control, etc. These methods have the following shortcomings:

[0004] There is a lack of protection mechanisms linked to the operating status of the power system. Traditional differential privacy methods use fixed noise intensity parameters and cannot adjust the privacy protection intensity in real time according to the current load status or frequency fluctuations of the power grid. This makes it easy to expose user behavior characteristics in high-load and high-risk scenarios.

[0005] Access policy generation is decoupled from actual access behavior, and potential risk requests cannot be identified. The current system generally judges user permissions based on preset rules, and cannot combine dynamic characteristics such as real-time access frequency and cross-regional behavior for risk perception and permission adjustment, making it difficult to resist progressive abuse or collusion-based access attacks.

[0006] The data transmission process is decoupled from the physical environment and lacks a verifiable and controllable secure path. Traditional encrypted transmission or sharding strategies do not fully consider the physical characteristics of the power system, making it difficult to build a transmission mechanism that is bound to the real-time operating environment, resulting in the risk of sharded data being restored and reorganized. Summary of the Invention

[0007] The present invention provides a security and privacy protection method for data services of a regional power marketing management information platform. By combining the power system operation status with a privacy protection method having dynamic adaptability and physical binding characteristics, a full-link trusted protection mechanism from data disturbance, access control to transmission reorganization is realized to meet the new data security requirements of the regional power sales and management platform.

[0008] The security and privacy protection method of the regional power marketing management information platform data service includes the following steps:

[0009] S1, dynamic data mutation anonymization:

[0010] The original data of electricity users is input into a trusted execution environment (TEE), where dynamic noise is added to the data to generate irreversible anonymous variant data. The generation parameters of the dynamic noise (noise addition intensity coefficient) are bound to the real-time load status and data sensitivity level of the electricity sales platform.

[0011] S2, access policy generation driven by multi-party secure computation:

[0012] The anonymous mutation data is input into a multi-party secure computing node cluster, and a dynamic access policy is generated based on the consensus verification results of each computing node. The dynamic access policy includes a data access permission threshold and an abnormal access consensus mark, which is a global signal to determine whether the current data access has a security risk;

[0013] S3, dynamic fragment reassembly and transmission:

[0014] According to the data access permission threshold of the dynamic access policy, the anonymous mutated data is divided into several dynamic shards, each shard is attached with a unique reorganization verification code, and transmitted to the target terminal through an independent communication link. The shard reorganization is triggered only after the target terminal satisfies the consensus verification of the multi-party computing node.

[0015] Optionally, the S1 is executed in a trusted execution environment:

[0016] S11, obtaining load status parameters of the power sales platform, including regional power grid frequency fluctuation value and peak power consumption ratio in the current period;

[0017] S12: Based on the data sensitivity classification rules, user identity information and electricity usage behavior characteristics in the original data are classified into sensitivity levels to generate sensitivity level labels;

[0018] S13, calculating a noise addition intensity coefficient based on the load state parameter and the sensitivity level label, wherein the higher the sensitivity level and the more unstable the load state, the greater the noise intensity coefficient;

[0019] S14 adopts the differential privacy mechanism to inject dynamic noise that conforms to the Laplace distribution into the original data according to the noise intensity coefficient, generates irreversible anonymous mutation data, and destroys the association log between the original data and the noise parameters.

[0020] Optionally, the sensitivity level is set to three levels of sensitivity, wherein the highly sensitive field includes the user address, identity information and electricity usage period, which can directly or indirectly identify the user identity and is set to level 3; the medium sensitive field includes the electricity price package and electricity usage mode and is set to level 2; the low sensitive field includes the average power consumption of the area and is set to level 1;

[0021] In a trusted execution environment, field types are identified and assigned default sensitivity levels based on their categories. A joint identification mechanism is introduced, and when a high-risk field combination appears, the sensitivity level of the field group is automatically increased.

[0022] Optionally, the noise addition intensity coefficient is calculated as:

[0023]

[0024] Where K is the noise addition intensity coefficient, Δf is the absolute value of the fluctuation of the regional power grid frequency relative to the reference frequency, f0 is the reference frequency, S is the data sensitivity level, S∈{1,2,3}, α is the load state sensitivity weight, and β is the sensitivity level weight.

[0025] Optionally, in S2, the anonymous variant data is split into several data subsets according to the preset regional power grid load distribution, and distributed to different computing nodes in the multi-party secure computing node cluster, wherein the selection of the computing nodes meets the preset selection conditions.

[0026] Optionally, the preset selection condition includes:

[0027] a. The physical location of the computing node matches the electricity sales region corresponding to the data subset;

[0028] b. The computing node has a trusted execution environment and passes hardware fingerprint bidirectional authentication.

[0029] Optionally, in S2, each computing node executes:

[0030] S21, analyze abnormal access patterns of the data subset within the trusted execution environment and extract features of access frequency and cross-region correlation access count;

[0031] S22, based on the access frequency and cross-region associated access count features, calculate the abnormal probability value of each data subset using a pre-trained anomaly detection model, and submit the calculation result to the consensus network;

[0032] S23, the consensus network uses the Byzantine fault-tolerant algorithm to verify the abnormal probability value submitted by each computing node. When more than half of the computing nodes pass the verification, a global abnormal access consensus mark is generated;

[0033] S24, calculating a data access permission threshold based on the global abnormal access consensus mark and the real-time status of the regional power grid load, wherein the access permission threshold is negatively correlated with the regional load and has an exponential decay relationship with the abnormality probability value;

[0034] S25, encapsulates the access permission threshold and abnormal access consensus mark into a dynamic access policy and writes it into the blockchain smart contract.

[0035] Optionally, the S3 specifically includes:

[0036] S31, dynamic shard generation: The anonymous variant data is divided into a number of shards according to the permission threshold, where the number of shards is positively correlated with the access permission threshold, and the size of each shard is dynamically adjusted according to the real-time fluctuation of the regional power grid load. The greater the load fluctuation, the smaller the shard granularity;

[0037] S32, Reorganization Verification Code Binding: Generate a unique reorganization verification code for each shard. The verification code is calculated by concatenating the consensus result hash value of the multi-party secure computing node cluster, the shard index number, and the current grid frequency value, and the verification code is encrypted using a sealed key in the trusted execution environment.

[0038] S33, independent link transmission: assign each fragment to an independent communication link;

[0039] S34, reorganization condition triggering: After receiving the shard, the target terminal submits a shard verification request to the consensus network.

[0040] Optionally, the selection rule of the communication link in S33 is:

[0041] Shards with high access rights thresholds are preferentially transmitted through the power-dedicated optical fiber network;

[0042] The low access threshold slices are transmitted through the 5G slicing network, and a random delay is added to the transmission interval of each communication link. The delay duration of the random delay is determined by the load status of the power grid.

[0043] Optionally, in S34, the consensus network verifies the validity of the reorganization verification code based on the shard index number and the current grid status parameters. When more than 2 / 3 of the nodes confirm that the verification code is legal and the grid status is consistent with when the shard was generated, the shard reorganization is triggered and the transmission link log is destroyed.

[0044] Beneficial effects of the present invention:

[0045] This invention introduces regional power grid frequency fluctuations and electricity sales load status into the privacy protection system, dynamically adjusts the differential privacy noise intensity and sharding granularity, and realizes adaptive adjustment of data disturbance and transmission mechanism to the power grid operation status. It overcomes the problem that static parameters in traditional privacy protection methods cannot cope with real-time security risks, and effectively improves the ability to prevent individual information from being reversed in the data environment of the power industry.

[0046] The present invention forcibly binds the physical deployment location of multi-party secure computing nodes to the electricity sales area, introduces an improved Byzantine fault-tolerant algorithm, and dynamically adjusts the consensus verification threshold based on the power grid load level. While ensuring data integrity, it effectively resists the risk of cross-regional joint nodes colluding to tamper with or deceive access policies; further, it drives the exponential decay of the permission threshold through abnormal access consensus results to achieve fine-grained and dynamic access control.

[0047] The present invention proposes an encryption reassembly verification code mechanism based on the fusion generation of power grid operating parameters (frequency value, load rate). Reassembly can only be performed under the condition that the environmental state of the target terminal is consistent with that when the fragmentation is generated and passes the consensus verification. It realizes the deep binding of the data transmission path and the physical characteristics of the power system. Combined with dynamic fragmentation and link random delay design, it significantly enhances the ability to resist traffic timing analysis attacks and fragmentation restoration attacks, and builds a complete physical-logical collaborative security closed loop. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only for the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0049] Figure 1 Schematic diagram of a method flow in an embodiment of the present invention;

[0050] Figure 2 A schematic diagram of access policy generation driven by multi-party secure computing according to an embodiment of the present invention. DETAILED DESCRIPTION

[0051] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. Those skilled in the art may also implement some known technologies in other alternative ways. The accompanying drawings are only for describing the embodiments in more detail and are not intended to limit the present invention in any specific way.

[0052] like Figure 1-Figure 2 As shown in FIG, the security and privacy protection method of the regional power marketing management information platform data service includes the following steps:

[0053] S1, dynamic data mutation anonymization:

[0054] The original data of electricity users is input into the Trusted Execution Environment (TEE), where dynamic noise is added to the data to generate irreversible anonymous variant data. The generation parameters of the dynamic noise (noise addition intensity coefficient) are bound to the real-time load status and data sensitivity level of the electricity sales platform.

[0055] S2, access policy generation driven by multi-party secure computation:

[0056] The anonymous mutation data is input into a multi-party secure computing node cluster, and a dynamic access policy is generated based on the consensus verification results of each computing node. The dynamic access policy includes data access permission thresholds and abnormal access consensus marks, which are global signals to determine whether there is a security risk in the current data access.

[0057] S3, dynamic fragment reassembly and transmission:

[0058] According to the data access permission threshold of the dynamic access policy, the anonymous mutated data is divided into several dynamic shards. Each shard is attached with a unique reorganization verification code and transmitted to the target terminal through an independent communication link. The shard reorganization is triggered only after the target terminal meets the consensus verification of the multi-party computing nodes.

[0059] In S1, the original data of power users is input into the trusted execution environment through a secure data channel. The secure data channel adopts a hardware-level isolated input and output memory mapping mechanism. The following operations are performed within the TEE:

[0060] S11, real-time acquisition of load status parameters of the power sales platform, including: regional power grid frequency fluctuation value Δf, current period power peak ratio P peak .

[0061] S12, according to the data sensitivity level classification rules, the user identity information and electricity usage behavior characteristics in the original data are graded to generate a sensitivity level label S∈{1,2,3}, where a larger value indicates a higher sensitivity.

[0062] The various fields involved in the original data of electricity users are divided into three levels of sensitivity according to the risk level of possible privacy leakage. Table 1 below shows the specific rules.

[0063] Table 1 Data sensitivity level classification rules

[0064]

[0065] Field classification process: Within the TEE, sensitivity labels are generated for raw data fields through the following logical process:

[0066] 1. Identify field categories: According to the type of field in the data structure, it can be divided into:

[0067] Identity (such as name, address, ID card);

[0068] Behavioral (such as power consumption time period, current fluctuation graph);

[0069] Strategy (such as electricity price packages and payment methods);

[0070] Statistics (such as regional average power consumption and weather information).

[0071] 2. Risk label rule setting: Set risk feature labels for each type of field, as shown in Table 2 below.

[0072] Table 2 Risk label rule setting table

[0073]

[0074] 3. Joint identification and level upgrade mechanism: When any of the following conditions are met, the field sensitivity level is automatically upgraded by one level (up to a maximum of level 3):

[0075] The identity field and behavior field appear together (can indirectly identify user behavior);

[0076] Enterprise users + high-frequency energy consumption fluctuations (production rhythm can be inferred);

[0077] Electricity consumption characteristics that are highly correlated with statutory holidays and nighttime hours (which can be used to infer residential type and daily habits).

[0078] S13, based on the load state parameters and the sensitivity level label, dynamically calculate the noise addition intensity coefficient K, which is calculated as:

[0079]

[0080] Among them, K is the noise addition intensity coefficient, Δf is the absolute value of the fluctuation of the regional power grid frequency relative to the reference frequency (50 Hz), f0 is the reference frequency, which is set to 50 Hz, S is the data sensitivity level (1 is low sensitivity and 3 is high sensitivity), α is the load state sensitivity weight (platform preset), and β is the sensitivity level weight (platform preset).

[0081] α∈[0.5,2.0], based on the historical data of power grid operation, the sensitivity of frequency fluctuation to data anomaly rate is analyzed. Linear regression is used. During the testing phase, α can be adjusted through the simulation platform so that the anonymity processing error under high load fluctuation is controlled within the platform's tolerable threshold.

[0082] β∈[1.0,3.0] is set according to the risk assessment score of each level of sensitive data leakage. For example, the risk score of level 3 (user identity + industrial electricity use behavior) after leakage is 9 points, level 2 is 6 points, and level 1 is 3 points. The proportional coefficient is 3:2:1. Setting β=1.5 can make the risk difference more significant.

[0083] S14, using the differential privacy mechanism, injects Laplace distribution into the original data according to the noise intensity coefficient K. Dynamic noise generates irreversible anonymous mutation data:

[0084] in, is the anonymous variant data, D is the original user data, Δ is the query sensitivity (the maximum output difference range set for different fields), and Lap(·) represents the Laplace distribution generating function. Query sensitivity Δ is the upper bound used to control the output variation in differential privacy. It is defined as the maximum difference in the query function output between any two adjacent data sets. For numeric fields (such as electricity and time period), the maximum observable difference is set:

[0085] The power consumption field Δ = 100 kWh (assuming that the maximum difference for a single user in a cycle does not exceed 100 kWh);

[0086] The power consumption period field Δ=6 (if divided by hours, the difference is at most 6 hours).

[0087] For classification fields (such as package type), one-hot encoding is used to calculate the L1 distance, and Δ=1 is set.

[0088] After the anonymous mutation is completed, the associated logs of the original data and noise parameters are immediately destroyed to ensure the completeness of irreversibility and privacy protection.

[0089] The generation of anonymous variant data can be simply expressed as: anonymous variant data = original data + Laplace noise, where Laplace noise is obtained by the Laplace distribution generating function Lap(·). When processing the original data of electricity users for privacy protection, a "noise addition" method is adopted. This method artificially adds a set of random interference values ​​to the original data, making it impossible for others to restore the specific behavior of the real users even if they obtain the data.

[0090] But this set of "interference values" is not added randomly, but its strength is determined by two factors:

[0091] Whether the current operating status of the power system is stable (for example, whether the frequency fluctuates greatly);

[0092] The privacy sensitivity of the data itself (for example, whether it contains personal identity, production characteristics, etc.).

[0093] After combining the weights of these two factors, a "noise intensity coefficient" is obtained to control the size of the noise - the more sensitive the data and the more unstable the system state, the greater the superimposed noise will be, thereby improving the protection strength.

[0094] The Laplace distribution generating function does not randomly "create a number" and add it to the original data, but extracts noise values ​​from the probability model of the "Laplace distribution".

[0095] The Laplace distribution is a symmetric distribution centered at 0, with values ​​decreasing rapidly on both sides. The values ​​it generates are usually very close to 0, and may occasionally have large positive or negative numbers, but the probability of large numbers is much smaller than that of small numbers. Its "steepness" is determined by the "scale" parameter we set, that is, the Δ / K mentioned above. The smaller this ratio is, the more concentrated the noise is; the larger it is, the more dispersed the noise is and the stronger the disturbance effect is.

[0096] The noise values ​​are generated as follows:

[0097] The system first randomly generates a number between [-0.5, 0.5] (this is a completely random starting point);

[0098] Then, based on this random number, a standard transformation method is used to generate the value of the Laplace distribution;

[0099] This final value is used as the "interference added to the original data".

[0100] Specific scenario examples:

[0101] Assume that the original electricity consumption of a user is 300kWh;

[0102] The system determines that the sensitivity of the data is "high";

[0103] The current power grid fluctuations are also relatively large;

[0104] The system derived a noise intensity factor of 2.0;

[0105] The query sensitivity is set to 100kWh.

[0106] Then the noise amplitude will be larger. For example, the system finally adds a Laplace noise of -75kWh, and the anonymous data obtained is:

[0107] Anonymous value = 300-75 = 225kWh. The attacker only sees 225, but cannot accurately infer your real 300 because they don't know how much noise has been added to you, nor do they know the basis and parameters for generating the noise.

[0108] In this way, user privacy is protected, others cannot directly infer the user's true behavior, and the data structure is preserved. Although disturbed, the overall trend of the data can still be used for statistical analysis and adaptively adjust the protection strength instead of "one size fits all".

[0109] S2 specifically includes:

[0110] S21. In the multi-party secure computing node cluster deployed by the system, the nodes must meet the following conditions:

[0111] S211: The physical location of the node must strictly match the electricity sales region corresponding to the data subset it processes; prevent cross-regional data theft or coordinated attacks: If any node is allowed to process data from any region, attackers can control multiple cross-regional nodes to launch joint attacks or data leaks. The regional binding mechanism naturally isolates the attack surface and strengthens the security boundary. Adapting to the regional characteristics of the electricity sales scenario: The electricity sales region itself has strong geographical dependence, and the grid operation status, electricity price strategy, load peaks and valleys in different regions are different;

[0112] S212, the node has a trusted execution environment (TEE) and establishes communication trust through a two-way identity authentication mechanism based on hardware fingerprints; TEE is a "secure computing area" hard-isolated within the processor. Even if the main system is invaded, the internal data cannot be read from the outside; TEE is used to perform operations such as data sensitivity analysis and abnormal behavior detection to ensure that data is not stolen during the processing process, hardware fingerprint two-way authentication: the processing chip or device of each node has a unique hardware fingerprint; before communication is established, the hardware identity of the "party issuing the request" and the "party receiving the request" will be verified at the same time to prevent forged nodes from mixing into the system, ensuring that the nodes participating in consensus and analysis are safe and trustworthy, and preventing man-in-the-middle attacks, forged nodes from participating in data consensus or stealing data.

[0113] S22, each node performs the following operations within the TEE:

[0114] S221, performing abnormal access behavior analysis on the received data subset to extract the following behavior features:

[0115] Single user access frequency;

[0116] The number of cross-region association visits.

[0117] S222: Input the above features into the pre-trained anomaly detection model and calculate the anomaly probability value P of the data subset. abnormal ∈[0,1], and submit the result to the consensus network.

[0118] S223, consensus verification and global strategy generation: The consensus network uses the improved Byzantine Fault Tolerance (BFT) algorithm to verify the abnormal probability value, and sets the consensus passing criteria as:

[0119]

[0120] Among them, N agree Indicates the number of nodes participating in the consensus, N total Indicates the total number of participating nodes in the current consensus round, L current Indicates the current regional power grid load rate, L maxIt represents the maximum allowable load rate of the region. The algorithm dynamically adjusts the consensus threshold according to the grid load to improve the consensus efficiency under high load. After the abnormal probability value Pabnormal submitted by each node is verified by consensus, the confirmed data access behavior has potential abnormalities. The "consensus result" generated at this time is the abnormal access consensus mark.

[0121] S224, dynamic permission threshold calculation and packaging: When consensus is passed, the data access permission threshold T is dynamically calculated based on the abnormal probability value and the real-time grid load status. access , calculated as follows:

[0122]

[0123] Among them, T access Indicates the current effective data access permission threshold, T base represents the standard value of the basic access rights set, k is the exponential decay coefficient of the abnormal probability, P abnormal is the abnormal probability value of the data subset, It represents the regional load ratio and the current operating pressure of the power grid. The access permission threshold is exponentially decayed with the abnormal probability value and is inversely proportional to the power grid load rate, ensuring that data access is restricted under high-risk and high-load conditions.

[0124] S225, the generated access permission threshold T access The global abnormal access consensus mark is encapsulated into a dynamic access policy, written into the smart contract, and stored in the blockchain to ensure that the access control process cannot be tampered with and can be traced.

[0125] The pre-trained anomaly detection model is as follows:

[0126] 1. For the user access logs in each electricity sales area, construct the following features:

[0127] Single user access frequency (f u ):The number of requests a user makes to access platform data within a unit of time. Statistical method: Sliding window method (24 hours), counting the frequency of access events in the user request log.

[0128] Cross-region associated visits (c u ) : The number of times the user has recently accessed multiple data subsets that do not belong to their sales region. Judgment logic: If user A is from East China, but queries electricity consumption data in North China and South China at the same time, then one cross-region access is accumulated.

[0129] 2. Model Architecture (LSTM+Sigmoid): This model uses a time series-based anomaly detection model, whose input is the user behavior feature sequence and output is the abnormal probability of the current behavior. The model architecture is as follows:

[0130] Input structure: Each time step inputs a feature vector: x t =[f u (t),c u (t)], where t represents the time step, divided into hours.

[0131] Model structure:

[0132] The LSTM layer (1-2 layers, 64 hidden units) is used to capture the time-dependent trend of user access behavior;

[0133] The fully connected layer maps the LSTM output to a single neuron output;

[0134] The Sigmoid activation function maps the output to the [0,1] interval to generate abnormality probabilities:

[0135] P abnormal =σ(W·h T +b), where h T represents the hidden state of the last time step of LSTM, W and b are the parameters of the fully connected layer, and σ(·) is the Sigmoid function (i.e. ).

[0136] 3. Model training method:

[0137] Training data construction:

[0138] Normal samples: user's daily access behavior logs;

[0139] Abnormal samples: including simulated attacks (such as short-term high-frequency access, cross-region batch requests), historical intrusion data, or audit anomaly mark logs;

[0140] Label: binary classification, 0 is normal and 1 is abnormal.

[0141] The loss function used to train the model is the standard binary cross entropy loss function.

[0142] 4. Deployment and execution logic: Within the TEE, the node constructs a feature sequence for each user in the data subset within the recent period at every time window.

[0143] The sequence is input into the pre-trained LSTM model to obtain the abnormal probability Pabnormal at the current time point; if the local calculation result of the node is higher than the preset warning threshold (0.7), it is judged as a high-risk behavior and enters the consensus process.

[0144] The access characteristics of user A in the past 6 hours are shown in Table 3:

[0145] Table 3 User A's access characteristics in the past 6 hours

[0146]

[0147] Table 3 shows a clear trend:

[0148] The frequency of visits continues to increase (from 2 to 12);

[0149] The number of cross-region visits is also increasing (from 0 to 3);

[0150] There are characteristics of concurrent rise of "high frequency + cross-region".

[0151] In the behavioral sequence composed of these six time points, the model found that this behavioral sequence was highly similar to the behavioral patterns marked as "abnormal" in the training set. The LSTM model captured the sudden change from a stable state to a high-frequency and multi-region access behavior, and thus output an abnormal probability close to 1, outputting P. abnormal =0.87, where 0.87 is the probability result calculated by the neural network at the output layer of the Sigmoid activation function. It is between 0 and 1. The closer it is to 1, the more likely it is to be abnormal. This probability value will be submitted to the consensus node for global judgment.

[0152] S3 specifically includes:

[0153] S31, dynamic shard generation: divide the anonymous mutation data into several shards, the number of shards is N v With the access permission threshold T access At the same time, the sharding granularity (the size of each shard) is adjusted according to the grid frequency fluctuation. The calculation is:

[0154]

[0155] Among them, N v Indicates the total number of shards generated; T access is the current access permission threshold (output by S2), Δf is the deviation between the current grid frequency and the reference frequency, and f0 is the grid reference frequency, which is 50 Hz. The greater the frequency fluctuation, the more shards there are and the smaller the individual shards are, thus enhancing anti-attack capabilities.

[0156] Here and in S13, the utilization term is used: S13 protects privacy during the data "mutation" stage; here it prevents association restoration during the data "transmission" stage.

[0157] S32, Recombination verification code binding: Generate a unique recombination verification code V for each fragment i , which is hashed and encrypted by the following fields: V i =SM4 TEE (SM3(H cons ||IDi ||f cur ), where V i is the reorganization verification code of shard i, H cons The hash result output by the consensus network, ID i is the shard index number, f cur is the current grid frequency value; SM3() is the national secret hash function, SM4 TEE Cryptographic operations performed within the TEE with a sealed key.

[0158] S33, independent link transmission: Allocate each fragment to an independent communication link. The link selection rules are as follows:

[0159] If the shard access permission threshold is high, priority is given to using a dedicated power fiber optic network for transmission;

[0160] If the slice access permission threshold is low, it will be allocated to the 5G network slice channel and dynamic delay will be introduced.

[0161] The delay time is determined by the grid load status and is calculated as follows:

[0162] Among them, t delay is the delay time of the current link, t base is the basic transmission delay, L current is the current regional power grid load rate, L max The maximum safe load threshold of the region is taken as the 95th percentile load value that does not cause frequency fluctuation during the maximum continuous operation time. The statistical quantile method is used to count all the slices T in the initialization phase. access The median or 75% percentile is selected as the split point to distinguish between high access permission threshold and low access permission threshold.

[0163] S34, reorganization condition trigger: After receiving all shards, the target terminal initiates a shard reorganization verification request to the consensus network. The consensus network verifies the reorganization compliance based on the following two items:

[0164] S341, Recombined Verification Code Consistency: The verification code calculated by the consensus network node based on the shard index and the grid frequency matches the verification code bound within the shard;

[0165] S342, Grid Status Consistency: The current regional grid frequency value is consistent with the frequency value recorded when the shard was generated. When more than 2 / 3 of the nodes pass the verification, the reorganization operation is allowed:

[0166] Decrypt the shard;

[0167] Merge into complete data;

[0168] Destroy all link transmission logs to prevent the reassembled path from being leaked.

[0169] The present invention encompasses any alternatives, modifications, equivalents, and solutions that fall within the spirit and scope of the present invention. To provide a thorough understanding of the present invention, specific details are described in detail below in connection with the preferred embodiments of the present invention, but those skilled in the art will be able to fully understand the present invention without these detailed descriptions. Furthermore, to avoid unnecessary confusion regarding the essence of the present invention, well-known methods, processes, procedures, components, and circuits have not been described in detail.

[0170] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A security and privacy protection method for regional power marketing management information platform data services, characterized in that: The following steps are involved: S1, dynamic data mutation anonymization: The original data of power users is input into the trusted execution environment, and dynamic noise is added to the data within the trusted execution environment to generate irreversible anonymous variant data. The generation parameters of the dynamic noise are bound to the real-time load status and data sensitivity level of the power sales platform; S2, access policy generation driven by multi-party secure computation: The anonymous mutation data is input into a multi-party secure computing node cluster, and a dynamic access policy is generated based on the consensus verification results of each computing node. The dynamic access policy includes a data access permission threshold and an abnormal access consensus mark, which is a global signal to determine whether the current data access has a security risk; S3, dynamic fragment reassembly and transmission: According to the data access permission threshold of the dynamic access policy, the anonymous mutated data is divided into several dynamic shards, each shard is attached with a unique reorganization verification code, and transmitted to the target terminal through an independent communication link. The shard reorganization is triggered only after the target terminal satisfies the consensus verification of the multi-party computing node.

2. The security and privacy protection method for regional power marketing management information platform data services according to claim 1 is characterized in that: The S1 is executed in a trusted execution environment: S11, obtaining load status parameters of the power sales platform, including regional power grid frequency fluctuation value and peak power consumption ratio in the current period; S12: Based on the data sensitivity classification rules, user identity information and electricity usage behavior characteristics in the original data are classified into sensitivity levels to generate sensitivity level labels; S13, calculating a noise addition intensity coefficient based on the load state parameter and the sensitivity level label, wherein the higher the sensitivity level and the more unstable the load state, the greater the noise intensity coefficient; S14 adopts the differential privacy mechanism to inject dynamic noise that conforms to the Laplace distribution into the original data according to the noise intensity coefficient, generates irreversible anonymous mutation data, and destroys the association log between the original data and the noise parameters.

3. The security and privacy protection method for regional power marketing management information platform data services according to claim 2 is characterized in that: The sensitivity level is set to three levels of sensitivity, among which the highly sensitive fields include user address, identity information and electricity usage period, which can directly or indirectly identify the user identity and are set to level 3; the medium sensitive fields include electricity price packages and electricity usage patterns and are set to level 2; the low sensitive fields include regional average electricity consumption and are set to level 1; In a trusted execution environment, field types are identified and assigned default sensitivity levels based on their categories. A joint identification mechanism is introduced, and when a high-risk field combination appears, the sensitivity level of the field group is automatically increased.

4. The security and privacy protection method for regional power marketing management information platform data services according to claim 2 is characterized in that: The noise addition intensity coefficient is calculated as: Where K is the noise addition intensity coefficient, Δf is the absolute value of the fluctuation of the regional power grid frequency relative to the reference frequency, f0 is the reference frequency, S is the data sensitivity level, S∈{1,2,3}, α is the load state sensitivity weight, and β is the sensitivity level weight.

5. The security and privacy protection method for regional power marketing management information platform data services according to claim 1 is characterized in that: In S2, the anonymous variant data is split into several data subsets according to the preset regional power grid load distribution, and distributed to different computing nodes in the multi-party secure computing node cluster, wherein the selection of the computing nodes meets the preset selection conditions.

6. The security and privacy protection method for regional power marketing management information platform data services according to claim 5 is characterized in that: The preset selection conditions include: a. The physical location of the computing node matches the electricity sales region corresponding to the data subset; b. The computing node has a trusted execution environment and passes hardware fingerprint bidirectional authentication.

7. The security and privacy protection method for regional power marketing management information platform data services according to claim 5 is characterized in that: In S2, each computing node executes: S21, analyze abnormal access patterns of the data subset within the trusted execution environment and extract features of access frequency and cross-region correlation access count; S22, based on the access frequency and cross-region associated access count features, calculate the abnormal probability value of each data subset using a pre-trained anomaly detection model, and submit the calculation result to the consensus network; S23, the consensus network uses the Byzantine fault-tolerant algorithm to verify the abnormal probability value submitted by each computing node. When more than half of the computing nodes pass the verification, a global abnormal access consensus mark is generated; S24, calculating a data access permission threshold based on the global abnormal access consensus mark and the real-time status of the regional power grid load, wherein the access permission threshold is negatively correlated with the regional load and has an exponential decay relationship with the abnormality probability value; S25, encapsulates the access permission threshold and abnormal access consensus mark into a dynamic access policy and writes it into the blockchain smart contract.

8. The security and privacy protection method for regional power marketing management information platform data services according to claim 1 is characterized in that: The S3 specifically includes: S31, dynamic shard generation: The anonymous variant data is divided into a number of shards according to the permission threshold, where the number of shards is positively correlated with the access permission threshold, and the size of each shard is dynamically adjusted according to the real-time fluctuation of the regional power grid load. The greater the load fluctuation, the smaller the shard granularity; S32, Reorganization Verification Code Binding: Generate a unique reorganization verification code for each shard. The verification code is calculated by concatenating the consensus result hash value of the multi-party secure computing node cluster, the shard index number, and the current grid frequency value, and the verification code is encrypted using a sealed key in the trusted execution environment. S33, independent link transmission: assign each fragment to an independent communication link; S34, reorganization condition triggering: After receiving the shard, the target terminal submits a shard verification request to the consensus network.

9. The security and privacy protection method for regional power marketing management information platform data services according to claim 8 is characterized in that: The selection rule of the communication link in S33 is: Shards with high access rights thresholds are preferentially transmitted through the power-dedicated optical fiber network; The low access threshold slices are transmitted through the 5G slicing network, and a random delay is added to the transmission interval of each communication link. The delay duration of the random delay is determined by the load status of the power grid.

10. The method for protecting the security and privacy of data services of a regional power marketing management information platform according to claim 8, characterized in that: In S34, the consensus network verifies the validity of the reorganization verification code based on the shard index number and the current grid state parameters. When more than 2 / 3 of the nodes confirm that the verification code is legal and the grid state is consistent with that when the shard was generated, the shard reorganization is triggered and the transmission link log is destroyed.

Citation Information

Cited By

  • Data trusted processing method and system fusing trusted computing and block chain

    CN121144418A