Security label storage method and device applied to power grid data
By storing the mapping relationship between contact identifiers and safety tags in a pre-built database, the high cost problem caused by embedding safety tags into data carriers in the traditional model is solved, and the security and low-cost maintenance of cross-regional and cross-domain power grid data sharing are realized.
Patent Information
- Application Number
- CN202510848402.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-11-07
AI Technical Summary
In the traditional model, security tags are embedded in the power grid data carrier, which leads to increased data transmission redundancy and high maintenance costs for security tags, especially when sharing across regions and domains, the update costs are too high.
The contact identifier is embedded in the data carrier, and the mapping relationship between the contact identifier and the security tag is stored in the pre-set security tag database. The database manages the updates and maintenance of the security tags, avoiding direct modification of the data carrier.
This reduces the maintenance cost of security tags while ensuring the security of cross-regional and cross-domain power grid data sharing, and reduces data transmission pressure and redundancy.
Smart Images

Figure CN120910043A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cross-regional and cross-domain sharing of power grid data, and in particular to a method and device for storing security labels of power grid data. BACKGROUND
[0002] Cross-regional and cross-domain sharing of power grid data refers to breaking down barriers between different regions and different fields in the process of power system operation, management and service, and realizing interconnection, exchange and shared use of power grid data generated in power generation, power transmission, power transformation, power distribution and power utilization. This process integrates scattered data resources through information technology means, and provides strong support for optimized operation, collaborative management, business innovation and service improvement of the power system.
[0003] At present, in practical application, the traditional mode mainly uses security labels to be embedded in power grid data and flow with the data to protect the security of the whole life cycle of the data. The security label is a kind of "digital identity label" attached to the power grid data, and usually contains key information such as the sensitivity level of the data (such as public, internal, confidential), the use permission (such as viewing / editing / transmitting only), the flow rule (such as prohibited cross-regional transmission / need to be approved), the responsibility subject (such as the data provider / receiver) and the like. Thus, according to the different security labels carried by certain power grid data, corresponding restrictions are added to the cross-regional and cross-domain sharing of these power grid data, thereby ensuring the security of data access.
[0004] However, according to such a traditional mode, the security label is embedded in the data carrier, so that the security label follows the power grid data wherever the power grid data is transmitted. For example, the security label is attached to the power grid data, and the security label needs to be processed synchronously when the power grid data is copied, forwarded and the like. This not only increases data redundancy and increases data transmission pressure in the flow process of the power grid data, but also increases the update cost of the security label as the number of flow times of the power grid data increases. SUMMARY
[0005] The present application provides a method and device for storing security labels of power grid data, which mainly aims to replace the embedding of contact labels in data carriers and store the mapping relationship between the contact labels and the security labels in another special preset security label database. Thus, the security label can still provide restrictions for the sharing of data information in the data carrier, and even if the security label is updated, it can be processed by the preset security label database, without the need to modify the data information in the data carrier. Therefore, while ensuring the security of shared data in the cross-regional and cross-domain power grid business environment, the maintenance cost of the security label is reduced.
[0006] In order to achieve the above object, the present application mainly provides the following technical solutions:
[0007] The first aspect of the present application provides a method for storing security labels of power grid data, comprising:
[0008] determining a plurality of database tables corresponding to a plurality of power grid business systems respectively, wherein the plurality of power grid business systems correspond to different geographical areas and business fields covered;
[0009] According to the logical level contained in the data structure corresponding to the database table, the database table is converted into a tree structure of an XML document, wherein there is a path level between each element node in the tree structure, and the target data information associated with each element node comes from the database table;
[0010] According to the path level, determine the access path of each element node in the tree structure;
[0011] The access path is added to the target data information associated with the element node corresponding to the access path as a contact identifier, so that the corresponding contact identifier is carried in the target data information;
[0012] For each target data information associated with each element node, a security label is constructed, which is used to provide restriction rules for data sharing in the plurality of power grid business systems;
[0013] For the same target data information, a mapping relationship between the contact identifier and the security label is established and stored in a preset security label database.
[0014] The second aspect of the present application provides an apparatus for storing security labels of power grid data, comprising:
[0015] The first determining unit is configured to determine a plurality of database tables corresponding to a plurality of power grid business systems respectively, wherein the plurality of power grid business systems correspond to different geographical areas and business fields covered;
[0016] The conversion processing unit is configured to convert the database table into a tree structure of an XML document according to the logical level contained in the data structure corresponding to the database table, wherein there is a path level between each element node in the tree structure, and the target data information associated with each element node comes from the database table;
[0017] The second determining unit is configured to determine the access path of each element node in the tree structure according to the path level;
[0018] an adding unit, configured to add the access path as a contact identifier into the target data information associated with the element node corresponding to the access path, so that the target data information carries the corresponding contact identifier;
[0019] a constructing unit, configured to construct a security tag for the target data information associated with each of the element nodes, the security tag being used to provide a restriction rule for sharing of data in the plurality of power grid business systems;
[0020] a storing unit, configured to establish a mapping relationship between the contact identifier and the security tag for the same target data information, and store the mapping relationship into a preset security tag database.
[0021] The third aspect of the present application provides a computer readable storage medium, the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method for storing a security tag of power grid data.
[0022] The fourth aspect of the present application provides an electronic device, the device comprising at least one processor, and at least one memory connected with the processor, a bus;
[0023] The processor, the memory and the bus complete communication with each other;
[0024] The processor is configured to call program instructions in the memory to execute the method for storing a security tag of power grid data.
[0025] The technical solution provided by the present application has at least the following advantages:
[0026] The present application provides a method and device for storing a security tag of power grid data. For database tables of different power grid business systems in different regions and domains, the database tables are converted into a tree structure of an XML document according to logical levels contained in a data structure in the database tables. Since there are path levels between each element node in the tree structure, and the target data information associated with each element node is from the database table, it is equivalent to representing all data information in the database table according to the path levels. Then, the access path of each element node is determined according to the path levels, and the access path is added as a contact identifier into the target data information associated with the element node, so that the target data information carries the contact identifier. Furthermore, a security tag is constructed for each target data information, which is used to provide a restriction rule for sharing of the target data information in a cross-region and cross-domain environment. For the same target data information, a mapping relationship between the contact identifier and the security tag is established, and the mapping relationship is stored into a preset security tag database.
[0027] Compared with the technical problem of high security tag maintenance cost caused by embedding the security tag into the data carrier in the traditional mode, the application embeds the contact identifier into the data carrier, and stores the mapping relationship between the contact identifier and the security tag into another special preset security tag database, so that the security tag can still provide restriction for the sharing of data information in the data carrier, and even if the security tag is updated, as long as the preset security tag database is processed, the data information in the data carrier does not need to be modified, thereby reducing the maintenance cost of the security tag while ensuring the security of sharing data in the cross-regional cross-domain power grid business environment.
[0028] The above description is only a summary of the technical solutions of the application. In order to enable the technical means of the application to be more clearly understood and implemented according to the content of the specification, and in order to enable the above and other purposes, characteristics and advantages of the application to be more apparent and easy to understand, the following specific embodiments of the application are described. BRIEF DESCRIPTION OF DRAWINGS
[0029] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are included to provide a description of the preferred embodiments and are not meant to limit the present application. Moreover, the same reference numerals in the attached drawings indicate the same or similar components. In the drawings:
[0030] Figure 1 A method flow chart for storing a security tag applied to power grid data provided by an embodiment of the application;
[0031] Figure 2 A schematic diagram of a database table conversion expressed as an XML document structure provided by an embodiment of the application;
[0032] Figure 3 A method flow chart for sharing power grid data in a cross-regional business environment provided by an embodiment of the application;
[0033] Figure 4 A composition block diagram of a device for storing a security tag applied to power grid data provided by an embodiment of the application;
[0034] Figure 5 A composition block diagram of another device for storing a security tag applied to power grid data provided by an embodiment of the application. DETAILED DESCRIPTION
[0035] Exemplary embodiments of the present application will be described herein below with reference to the accompanying drawings. While exemplary embodiments of the present application are shown in the drawings, it is understood that the present application can be embodied in many forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the application to those skilled in the art.
[0036] As a complex infrastructure, the business systems of the power grid show significant differentiation in geographical coverage and functional orientation.
[0037] For example, the geographical coverage difference includes hierarchical management architecture and regional characteristic difference.
[0038] Hierarchical management architecture: different levels of systems such as national power grid, provincial power grid, and city / county power grid, are responsible for national backbone network, provincial transmission and distribution network, local power distribution and power service, respectively, with geographical coverage ranging from national to regional.
[0039] Regional characteristic difference: for example, the geographical division of the Southern Power Grid and the State Grid, or the structural difference of power grids in different provinces due to climate and terrain (such as mountainous areas and plains), resulting in different data collection focuses of regional systems (such as icing monitoring of mountainous power grids and typhoon warning data of coastal areas).
[0040] For example, the functional differentiation in business areas includes:
[0041] Full-chain segmentation of power generation, transmission, distribution, and consumption: the transmission system focuses on the operation status of high-voltage lines (such as line load and short-circuit fault data); the distribution system emphasizes voltage control of regional distribution networks and substation load balancing data; the consumption system focuses on user consumption behavior, metering data, and demand-side management information.
[0042] Independent operation of special business systems: for example, the dispatching automation system (SCADA), energy management system (EMS), power marketing system, and equipment asset management system (ERP), which serve vertical fields such as real-time dispatching, energy optimization, user service, and asset maintenance, respectively.
[0043] But in practical application, there is a sharing demand for cross-regional and cross-business data due to the need for cooperation caused by geographical regional differences, the need for data interconnection caused by business field intersection, and other reasons. The traditional mode mainly uses a security tag to embed power grid data and flow with the data to protect the security of the whole life cycle of the data. The security tag is a "digital identity tag" attached to the power grid data, which usually contains key information such as the sensitivity level of the data (such as public, internal, confidential), the use permission (such as viewing / editing / transmitting only), the flow rule (such as prohibited cross-regional transmission / need to be approved), the responsibility subject (such as data provider / receiver), etc. Thus, according to the different security tags carried by certain power grid data, appropriate restrictions are added to the cross-regional and cross-domain sharing of these power grid data, thereby ensuring the security of data access.
[0044] However, according to such a traditional mode, the security tag is embedded in the data carrier, so the security tag follows wherever the power grid data is transmitted, like being attached to the "power grid data". For example, the security tag needs to be processed synchronously when the power grid data is copied, forwarded, etc. This not only increases data redundancy and increases data transmission pressure during the flow of power grid data, but also the update cost of the security tag will be very high as the number of power grid data flow increases once the security tag expires.
[0045] Based on the above considerations, the embodiments of the present application provide a method for storing a security tag for power grid data, as shown in Figure 1 As shown in the following specific steps are provided by the embodiments of the present application:
[0046] 101, determine the database tables corresponding to each of the plurality of power grid business systems, and the plurality of power grid business systems correspond to different geographical areas and business fields.
[0047] The power grid business system provided by the embodiments of the present application can but not limited to include: a dispatching automation system (SCADA / EMS), the business field of which is: real-time monitoring of power grid, power flow calculation, fault scheduling, the geographical coverage of which is: national / provincial / city-level dispatching center, covering the whole network or regional backbone network; a transmission management system (TMS), the business field of which is: transmission line operation and maintenance, inspection, fault repair, the geographical coverage of which is: cross-provincial / in-provincial transmission corridor, focusing on high-voltage lines (220kV and above); a distribution management system (DMS), the business field of which is: distribution network operation, transformer area management, user power supply service, the geographical coverage of which is: city-level / county-level distribution network, focusing on 10kV and below lines.
[0048] As the geographical coverage range and business functions of the above power grid business systems are different, the database table design thereof needs to match the differentiated needs.
[0049] 102. According to the logical level contained in the data structure corresponding to the database table, the database table is converted into a tree structure of the XML document, and there is a path level between each element node in the tree structure, and the target data information associated with each element node comes from the database table.
[0050] The database table and the XML document are essentially representations of structured data, and the core of the conversion between the two is the mapping of the logical level. The following explains the mapping of the different logical levels between the two.
[0051] Database table: data is organized by rows (records) and columns (fields), and relationships between tables are established by primary keys and foreign keys, which embodies a two-dimensional flat structure; XML document: tree hierarchical structure is composed of element nodes and attributes, which embodies a vertical hierarchical relationship. Thus, this conversion is essentially converting a relational data model into a hierarchical data model, and the dimension conversion problem of the data structure needs to be solved.
[0052] Then, the conversion of the database table to the XML tree structure is essentially a semantic conversion of the data model, and the core steps are:
[0053] (1) Structure dimension conversion: from two-dimensional table structure to multi-dimensional tree structure;
[0054] (2) Relationship semantic conversion: from foreign key association relationship to node hierarchical relationship;
[0055] (3) Data representation conversion: from field value representation to node attribute / child element representation
[0056] Therefore, this conversion is not a simple format conversion, but requires a deep understanding of the logical structure of the database table, and through reasonable hierarchical design and node mapping, the data structure and semantic relationship of the database table are completely preserved in XML.
[0057] Moreover, after the conversion processing, there is a path level between each element node in the tree structure of the XML document, and the target data information associated with each element node comes from the database table.
[0058] 103. According to the path level, determine the access path of each element node in the tree structure.
[0059] 104. Add the access path as a contact identifier to the target data information associated with the element node corresponding to the access path, so that the target data information carries the corresponding contact identifier.
[0060] In this embodiment, the access path is used as a contact identifier, which is then added to the target data information associated with the element node corresponding to the access path. That is, the target data information carries the corresponding contact identifier. It can be seen that the contact identifier actually establishes a mapping relationship between the element node corresponding to the access path and the target data information.
[0061] It should be noted that compared to security tags, contact identifiers have a very small data size, and once generated, they are modified very infrequently. This ensures that the target data information embedded with the contact identifier will not incur costs from frequent modifications, and the contact identifier will not generate much redundant data during the sharing and circulation of the target data information.
[0062] 105. Construct security tags for the target data information associated with each element node. Security tags are used to provide restriction rules for data sharing in multiple power grid business systems.
[0063] Security tags are used to establish restrictions on data sharing across multiple power grid business systems. A security tag is a "digital identity" attached to power grid data, typically containing key information such as the data's sensitivity level (e.g., public, internal, confidential), usage permissions (e.g., viewing / editing / transfer only), flow rules (e.g., prohibiting cross-regional transmission / requiring approval), and responsible parties (e.g., data provider / recipient). Based on the different security tags carried by certain power grid data, corresponding restrictions are added to the cross-regional and cross-domain sharing of this data, thereby ensuring the security of data access.
[0064] In this embodiment of the application, a security label is constructed for the target data information based on the characteristics of the geographical region and business domain corresponding to the database table where the target data information is located, such as the access security level, whether it is allowed to be shared across regions and domains, etc., so as to restrict the sharing of the target data information across regions and domains.
[0065] 106. For the same target data information, establish a mapping relationship between contact identifiers and security tags, and store them in a pre-set security tag database.
[0066] Since the target data information carries a communication identifier, a mapping relationship between the communication identifier and the security label can be established based on the security label corresponding to the target data information. Furthermore, as can be seen from page 104, the communication identifier can represent the access path of an element node in the XML document data structure. Therefore, based on the communication identifier and the security label, the target data information on the element node corresponding to the access path can be further determined, and the corresponding restriction rules for data sharing in multiple power grid business systems can be established.
[0067] The embodiment of the application stores the contact identifier, the security label and the mapping relationship therebetween into a preset security label database, so that in the whole life cycle of power grid data, the security label is added, deleted or modified by maintaining the preset security label database, and the consistency of the security label of the same power grid data in the whole life cycle is ensured.
[0068] If the corresponding associated element node of the target data information changes, the maintenance operation on the preset security label database includes: determining a new element node associated with the target data information; determining a new access path of the new element node in the tree structure according to the path level; adding the new access path as a new contact identifier to the target data information and covering the original contact identifier; and covering the original contact identifier with the new contact identifier in the preset security label database to establish a mapping relationship with the corresponding security label. Thus, the timeliness and correctness of the association between the security label and the contact identifier are ensured, and the timeliness and correctness of the association between the security label and the target data information are indirectly ensured.
[0069] The above, the embodiment of the application provides a method for storing a security label applied to power grid data. Compared with the high maintenance cost of the security label caused by embedding the security label into the data carrier in the traditional mode, the embodiment of the application replaces the contact identifier embedded into the data carrier, and the mapping relationship between the contact identifier and the security label is stored into another special preset security label database. Thus, the security label can still provide restrictions for the sharing of data information in the data carrier, and even if the security label is updated, the preset security label database is processed, and the data information in the data carrier does not need to be modified. Therefore, while ensuring the security of shared data in the cross-regional and cross-domain power grid business environment, the maintenance cost of the security label is reduced.
[0070] In some alternative embodiments, for further refinement of 102, if the database table is in the format of an Excel file, the database table is converted into a tree structure of an XML document according to the logical level contained in the data structure corresponding to the database table, including steps A1-A5.
[0071] A1, if the database table is in the format of an Excel file, the database table is taken as a data unit corresponding to a root node;
[0072] A2, each worksheet contained in the database table is taken as a data unit corresponding to a secondary leaf node;
[0073] A3, each record information in the worksheet is taken as a data unit corresponding to a node at a next level of the secondary leaf node;
[0074] A4, store the data units corresponding to the root node, the data units corresponding to the second-level leaf node, and the data units corresponding to the next level nodes of the second-level leaf node of the database table in the format of a CSV file to obtain an intermediate media file;
[0075] A5, convert the intermediate media file into a tree structure of an XML document.
[0076] Exemplary explanations are given to A1-A5, and as shown in Figure 2 the schematic diagram of converting the database table into the XML document structure provided by the embodiments of the present application, Figure 2 provided is a worksheet in the database table, the worksheet is taken as the data unit corresponding to the second-level leaf node, and each record information in the worksheet is taken as the data unit corresponding to the next level nodes of the second-level leaf node, as shown in Figure 2 “row 1, row 2, row 3, row 4”, and iteration is performed to extend the path, and the column attribute in each row is taken as the next level data unit, as shown in Figure 2 “row 1” is taken as “field 1a” and “field 1b”, forming the object XML document as shown in Figure 2 and in each path level, some security rules can be formulated according to the security attribute information of the target data information (i.e. derived from the database table) on the element node to construct the security label corresponding to the target data information, as shown in Figure 2 the horizontal and vertical rectangles shown in the “XML document with security labels” shown in Figure 2 is for the convenience of showing which security label is associated with which element node in which path level, but does not mean that the security label is embedded into the target data information on the element node.
[0077] As shown in Figure 2 It can be seen that the embodiments of the present application store the data units corresponding to the root node, the data units corresponding to the second-level leaf node, and the data units corresponding to the next level nodes of the second-level leaf node of the database table in the format of a CSV file to obtain an intermediate media file, and convert the intermediate media file into a tree structure of an XML document.
[0078] In some modified embodiments, if the database table is text type data, the database table is converted into a tree structure of an XML document according to the logical levels contained in the data structure corresponding to the database table, including steps B1-B2.
[0079] B1, if the database table is text type data, the text type data is segmented and classified according to the logical architecture contained in the text type data, and a plurality of data units are extracted therefrom;
[0080] B2, convert the plurality of data units into a hierarchical tree structure as a tree structure of an XML document.
[0081] Exemplary explanation is made to B1-B5, although the text type data has no obvious storage structure, the data content therein has certain logical hierarchical relationship. The text type data is segmented and classified according to the logical architecture, the data unit is extracted, and the data is converted into hierarchical tree structure. Therefore, the correlation between the data can be obtained by using different levels of titles of the Word document, the Word document is logically segmented into several text blocks according to the logical relationship of the data content, such as parallelism, inclusion, etc., the tree structure conversion is performed, and thus the data is converted into XML document format.
[0082] In some changed embodiments, further refinement is made to 105, for the target data information associated on each element node, a security tag is constructed, including C1-C4.
[0083] C1, according to the path hierarchy existing between each element node in the tree structure of the XML document, the access order corresponding to each element node is determined;
[0084] C2, according to the access order, the security level of each element node is determined from low to high, and the security level rule is obtained;
[0085] C3, according to the access order, the relationship between the parent node and the child node in each element node is determined;
[0086] C4, the security tag is constructed for the target data information, at least including: according to the rule that the access permission of the child node is greater than that of the parent node, the security level rule.
[0087] In the embodiments of the present application, by organizing data units of different security levels and attributes, the database table is converted into a data tree with good logical structure, relatively independent node security attributes and inheritance relationship. After segmentation of the database table based on multiple attributes, the security level, the attribute information such as the belonging company and the belonging department are represented by using the security tag corresponding to the XML element, the access path is used as the contact identifier, and according to the mapping relationship between the contact identifier and the security tag, the indirect binding relationship between the target data information on the element node and the security tag is realized.
[0088] The order of accessing data is often from shallow to deep. For the hierarchical tree structure of the object XML document, when accessing specific data in the object, the path of the target element node must be obtained, which is composed of all nodes from the root node to the target element node. Therefore, in order to realize reasonable access permission setting, the security level of the outer node should be lower than that of the inner node. For the node without assigned security level, the security level of the parent node should be automatically inherited, that is, the access permission of the node is the same as that of the upper level, and the access subject with the access permission of the upper level can also access the next node, so as to realize the gradual deepening of the security level. In addition, the target data information and the security label of the element node realize the indirect binding relationship, so that the generated object XML document can support fine-grained access control of the original database table and meet the needs of different security levels.
[0089] Accordingly, the embodiments of the present application can but not limited to formulate the following binding rules of the security label:
[0090] Rule one: in the object XML security document, the security labels satisfy the principle of gradual deepening, if the subject has the permission to access the inner node, then it must have the permission to access all outer nodes on the path from the root node to the inner node.
[0091] Rule one description: the object XML security document stores data in the tree structure, and the access order is from the root node to the target leaf node. The security label of the child data node is equal to or higher than that of the parent data node.
[0092] Rule two: if the data node in the object XML security document does not directly bind the existing attribute label, it automatically inherits the security label of the upper node.
[0093] Rule two description: the data node in the object XML security document does not necessarily indirectly bind all security labels. For the data node without indirectly bound security label, the data node needs to implement inheritance, that is, to inherit the security label of the previous node, so as to realize the principle of gradual deepening from outside to inside.
[0094] Rule three: the root node of the object XML security document, that is, the document itself, if there is no specified security label, it is default to be accessible.
[0095] Rule three description: if the root node, that is, the data document, is not specified with a security label, the default security level label is U (Unclassified), and other access subjects can access it.
[0096] In the embodiment of the present application, the database table is converted into a tree structure of an XML document, and a security label is constructed for the target data information on the element nodes at each path level in the tree structure, so that fine-grained security management of the original database table is realized. For example, but not limited to, a security label is constructed for each element node according to the hierarchical relationship of the element nodes in the path level, which is equivalent to the security label of the target data information on the element node. Therefore, when constructing the security label for the target data information on the element node, not only the security rule is constructed for the target data information according to the data characteristics and requirements of the target data information, but also the security rule is constructed according to the position of the element node in the path level, so that the final security rule for the “target data information on the element node”, i.e., the security label, is obtained by comprehensively considering both factors.
[0097] In some modified embodiments, on the basis of storing the preset security label library, the present application provides a method for sharing power grid data in a cross-regional business environment, as shown in Figure 3 The embodiment of the present application provides the following specific steps:
[0098] 201, receiving a data acquisition request.
[0099] 202, determining the target database table of the target power grid business system and the to-be-acquired data content corresponding to the data acquisition request by analyzing the data acquisition request.
[0100] In the embodiment of the present application, the data acquisition request party does not know in which geographical region and business field of the power grid business system the to-be-acquired data content is, which is confidential to the data acquisition request party, so as to ensure the security of the power grid business system, but the data receiving party can identify the purpose of the data acquisition request party by analyzing the data acquisition request, so as to further determine which data information in the target database table of which power grid business system needs to be acquired.
[0101] 203, determining the target access path of the to-be-acquired data content in the tree structure according to the tree structure of the XML document converted and represented by the target database table.
[0102] In 101-106, each database table is converted into an XML document format for representation in the maintenance of the preset security label database, so that the target access path of the to-be-acquired data content can be directly determined in the tree structure of the XML document converted and represented by the target database table.
[0103] 204, determining the target security label corresponding to the target access path by querying the preset security label database.
[0104] If the mapping relationship between the contact identifier and the security label has been stored in the preset security label database as in 101-106, and the contact identifier is equivalent to the data information represented by the access path as in 104, then based on searching the preset security label database, the target security label corresponding to the target access path can be determined.
[0105] 205. Verify the permission of the data acquisition request according to the security rule information pre-stored in the target security label.
[0106] The security rule information in the security label, such as but not limited to the "digital identity" attached to the power grid data, usually contains key information such as the sensitivity level of the data (such as public, internal, confidential), usage permission (such as viewing / editing / transferring only), flow rule (such as prohibited cross-regional transmission / need to be approved), and responsible subject (such as data provider / receiver). Therefore, according to the different security labels carried by certain power grid data, corresponding restrictions are added to the cross-regional and cross-domain sharing of these power grid data, thereby ensuring the security of data access.
[0107] 206a, if the verification is passed, the data content to be acquired is authorized to be shared according to the security rule information in the security label in response to the data acquisition request.
[0108] 206b, if the verification is not passed, the data acquisition request is rejected.
[0109] Then, as in 206a and 206b, if the data receiver learns the security rule corresponding to the data content to be acquired according to the security label, it judges whether the data acquisition request party can share the corresponding data information. If yes, the verification is passed, otherwise the verification is not passed and the data acquisition request is rejected.
[0110] Further, as an implementation of the method shown in the above Figure 1 , Figure 3 The embodiment of the present application provides a device for storing a security label of power grid data. The device embodiment corresponds to the foregoing method embodiment, and for the sake of reading, the details of the foregoing method embodiment will not be described one by one, but it should be clear that the device in the present embodiment can correspondingly implement all the contents in the foregoing method embodiment. The device is applied to adding a security label to the cross-regional and cross-domain power grid data, and specifically as shown in Figure 4 The device comprises:
[0111] A first determination unit 31 is configured to determine a plurality of database tables corresponding to a plurality of power grid business systems respectively, wherein the plurality of power grid business systems correspond to different geographical areas and business fields covered.
[0112] The conversion processing unit 32 is configured to convert the database table into a tree structure of an XML document according to a logical level contained in a data structure corresponding to the database table, and a path level exists between each element node in the tree structure, and target data information associated with each element node is from the database table.
[0113] The second determination unit 33 is configured to determine an access path of each element node in the tree structure according to the path level.
[0114] The adding unit 34 is configured to add the access path as a contact identifier into the target data information associated with the element node corresponding to the access path, so that the target data information carries the corresponding contact identifier.
[0115] The construction unit 35 is configured to construct a security tag for the target data information associated with each element node, and the security tag is used to provide a restriction rule for sharing of data in the plurality of power grid business systems.
[0116] The storage unit 36 is configured to establish a mapping relationship between the contact identifier and the security tag for the same target data information, and store the mapping relationship into a preset security tag database.
[0117] Further, as shown in Figure 5 The apparatus further includes:
[0118] The receiving unit 37 is configured to receive a data acquisition request.
[0119] The parsing unit 38 is configured to determine a target database table and to-be-acquired data content of a target power grid business system corresponding to the data acquisition request by parsing the data acquisition request.
[0120] The third determination unit 39 is configured to determine a target access path of the to-be-acquired data content in the tree structure according to the tree structure of the XML document converted by the target database table.
[0121] The fourth determination unit 310 is configured to determine a target security tag corresponding to the target access path by querying the preset security tag database.
[0122] The verification unit 311 is configured to verify a permission of the data acquisition request according to security rule information pre-stored in the target security tag.
[0123] The verification unit 311 is further configured to, if the verification is passed, authorize sharing of the to-be-acquired data content according to the security rule information in the security tag in response to the data acquisition request.
[0124] Further, as shown in Figure 5 If the target data information corresponding associated element node changes, the device further comprises a maintenance unit 312, specifically used for:
[0125] Determining the new element node corresponding to the target data information associated with;
[0126] According to the path level, determine the new access path of the new element node in the tree structure;
[0127] The new access path is added to the target data information as a new contact identifier and covers the original contact identifier;
[0128] In the pre-set security tag database, the original contact identifier is covered with the new contact identifier, and a mapping relationship is established with the corresponding security tag.
[0129] Further, the conversion processing unit 32 is specifically used for:
[0130] If the database table is in the format of an Excel file, the database table is used as a data unit corresponding to the root node;
[0131] Each worksheet contained in the database table is used as a data unit corresponding to a secondary leaf node;
[0132] Each record information in the worksheet is used as a data unit corresponding to a node of the next level of the secondary leaf node;
[0133] In the format of a CSV file, the data unit corresponding to the root node, the data unit corresponding to the secondary leaf node and the data unit corresponding to the node of the next level of the secondary leaf node are stored, and an intermediate media file is obtained;
[0134] The intermediate media file is converted into a tree structure of an XML document.
[0135] Further, the conversion processing unit 32 is specifically used for:
[0136] If the database table is a text type data, the text type data is segmented and classified according to the logical architecture contained in the text type data, and a plurality of data units are extracted therefrom;
[0137] The plurality of data units are converted into a hierarchical tree structure as a tree structure of an XML document.
[0138] Further, the construction unit 35 is specifically used for:
[0139] According to a path level existing between each element node in a tree structure of the XML document, a visiting sequence corresponding to each element node is determined;
[0140] According to the visiting sequence, a security level of each element node is determined from low to high, and a security level rule is obtained;
[0141] According to the visiting sequence, a relationship between a parent node and a child node in each element node is determined;
[0142] A security tag is constructed for the target data information, and at least includes the security level rule and a rule that an access permission of a child node is greater than that of a parent node.
[0143] In summary, the device for storing a security tag of power grid data includes a processor and a memory, and the first determining unit, the conversion processing unit, the second determining unit, the adding unit, the constructing unit and the storing unit are all stored in the memory as program units, and the processor executes the program units stored in the memory to realize corresponding functions.
[0144] The processor includes a core, and the core calls corresponding program units from the memory. The core can be set as one or more, and by adjusting core parameters, the core replaces embedding a contact identifier into a data carrier, and stores a mapping relationship between the contact identifier and the security tag into another special preset security tag database, so that the security tag can still provide limitation for sharing of data information in the data carrier, and even if the security tag is updated, as long as the preset security tag database is processed, the data information in the data carrier does not need to be modified, so that the security of sharing data in a cross-regional and cross-domain power grid business environment is ensured, and the maintenance cost of the security tag is reduced.
[0145] The embodiment of the application provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the method for storing a security tag of power grid data.
[0146] The embodiment of the application provides an electronic device, which includes at least one processor, at least one memory connected with the processor, and a bus; the processor and the memory complete communication with each other through the bus; the processor is used for sharing program instructions in the memory to execute the method for storing a security tag of power grid data.
[0147] The application further provides a computer program product which, when executed on a data processing device, is adapted to execute a program initialized with the method steps for storing a security tag of power grid data.
[0148] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions specified in the flowchart block or blocks. Figure 1 The flowchart and / or block diagram in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments. In this regard, each block in the flowchart and / or block diagrams can represent a module, segment, or portion of code, which comprises one or more executable Figure 1 The flowchart and / or block diagram in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments. In this regard, each block in the flowchart and / or block diagrams can represent a module, segment, or portion of code, which comprises one or more executable
[0149] In one typical configuration, the device includes one or more processors (CPUs), memory, and a bus. The device can also include an input / output interface, a network interface, and the like.
[0150] The memory can include non-persistent memory and / or volatile memory, e.g., random access memory (RAM) comprising a number of memory locations that can be read and / or written on the fly. The memory can also include non-volatile memory, e.g., read-only memory (ROM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), flash memory (flash RAM), and the like. The memory includes at least one memory chip. The memory is an example of computer-readable media.
[0151] Computer-readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to computing devices. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0152] It is also to be noted that the terms "comprising", "including", and any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises a... " does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0153] Those skilled in the art will appreciate that embodiments of the present application can be devised for a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer-readable program code.
[0154] The embodiments of the present application are only illustrative and are not intended to limit the present application. Various changes and modifications can be made to the present application by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A method of applying a storage security tag to grid data, characterized by, The method comprises: determining a plurality of power grid business systems each corresponding to a database table, the plurality of power grid business systems corresponding to different geographical areas and business fields covered; according to a logical level contained in a data structure corresponding to the database table, converting the database table into a tree structure of an XML document, there being a path level between each element node in the tree structure, and the target data information associated with each element node coming from the database table; determining an access path of each element node in the tree structure according to the path level; adding the access path as a contact identifier to the target data information associated with the element node corresponding to the access path, so that the target data information carries the corresponding contact identifier; constructing a security tag for the target data information associated with each element node, the security tag being used to provide a restriction rule for data sharing in the plurality of power grid business systems; for the same target data information, establishing a mapping relationship between the contact identifier and the security tag, and storing it in a preset security tag database.
2. The method of claim 1, wherein, The method further comprises: receiving a data acquisition request; determining a target database table of a target power grid business system and to-be-acquired data content corresponding to the data acquisition request by analyzing the data acquisition request; determining a target access path of the to-be-acquired data content in the tree structure according to the tree structure of the XML document converted and represented by the target database table; determining a target security tag corresponding to the target access path by querying the preset security tag database; verifying the authority of the data acquisition request according to the security rule information pre-stored in the target security tag; if the verification is passed, authorizing the sharing of the to-be-acquired data content according to the security rule information in the security tag in response to the data acquisition request.
3. The method according to claim 1 or 2, characterized in that, If the element node corresponding to the target data information changes, the method further comprises: determining a new element node corresponding to the target data information; determining a new access path of the new element node in the tree structure according to the path level; adding the new access path as a new contact identifier to the target data information and covering the original contact identifier; in the preset security tag database, covering the original contact identifier with the new contact identifier to establish a mapping relationship with the corresponding security tag.
4. The method according to claim 1 or 2, characterized in that, The method of converting the database table into a tree structure of an XML document according to a logical level contained in a data structure corresponding to the database table comprises: if the database table is in the format of an Excel file, taking the database table as a data unit corresponding to a root node; taking each worksheet contained in the database table as a data unit corresponding to a secondary leaf node; taking each record information in the worksheet as a data unit corresponding to a node at a next level of the secondary leaf node; store the data units corresponding to the root node, the data units corresponding to the secondary leaf node, and the data units corresponding to the next level nodes of the secondary leaf node of the database table in the format of a CSV file to obtain an intermediate media file; convert the intermediate media file into a tree structure of an XML document.
5. The method according to claim 1 or 2, characterized in that, The conversion of the database table into a tree structure of an XML document according to the logical levels contained in the data structure corresponding to the database table comprises: if the database table is a text type data, segment and classify the text type data according to the logical architecture contained in the text type data to extract a plurality of data units; convert the plurality of data units into a hierarchical tree structure as a tree structure of an XML document.
6. The method of claim 1 or 2, wherein, construct a security tag for the target data information associated with each element node, which comprises: determine the access order of each element node according to the path level between the element nodes in the tree structure of the XML document; determine the security level of each element node from low to high according to the access order to obtain a security level rule; determine the relationship between the parent node and the child node in each element node according to the access order; construct a security tag for the target data information, which at least comprises the security level rule and the rule that the access permission of the child node is greater than that of the parent node.
7. A device for storing security tags for power grid data, characterized in that, The device comprises: a first determination unit configured to determine a plurality of database tables corresponding to a plurality of power grid business systems respectively, wherein the plurality of power grid business systems correspond to different geographical areas and business fields; a conversion processing unit configured to convert and represent the database tables into a tree structure of an XML document according to the logical levels contained in the data structure corresponding to the database tables, wherein a path level exists between the element nodes in the tree structure, and the target data information associated with each element node comes from the database table; a second determination unit configured to determine the access path of each element node in the tree structure according to the path level; an adding unit configured to add the access path as a contact identifier to the target data information associated with the element node corresponding to the access path, so that the target data information carries the corresponding contact identifier; a construction unit configured to construct a security tag for the target data information associated with each element node, wherein the security tag is used to provide a restriction rule for the sharing of data in the plurality of power grid business systems; a storage unit configured to establish a mapping relationship between the contact identifier and the security tag for the same target data information and store the mapping relationship in a preset security tag database.
8. The apparatus of claim 7, wherein, The device further comprises: a receiving unit configured to receive a data acquisition request; a parsing unit configured to determine the target database table of the target power grid business system and the to-be-acquired data content corresponding to the data acquisition request by parsing the data acquisition request. The third determining unit is configured to determine a target access path of the to-be-acquired data content in a tree structure of an XML document converted by the target database table according to the tree structure of the XML document converted by the target database table; The fourth determining unit is configured to determine a target security label corresponding to the target access path by querying the preset security label database; The verifying unit is configured to verify the permission of the data acquisition request according to security rule information pre-stored in the target security label. The verifying unit is further configured to, if the verification is passed, authorize sharing of the to-be-acquired data content according to the security rule information in the security label in response to the data acquisition request.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the method for applying a storage security label to power grid data according to any one of claims 1-6.
10. An electronic device, comprising: The device comprises at least one processor and at least one memory connected to the processor; The processor, the memory and the bus complete mutual communication through the bus; The processor is configured to call program instructions in the memory to execute the method for applying a storage security label to power grid data according to any one of claims 1-6.