Method and system for sensitive data security protection based on trusted data space
By constructing efficiency deviation and heat dissipation deviation, and utilizing the law of conservation of energy and grouping of devices of the same model, the problem of distinguishing between false data injection and device failure was solved, achieving efficient data security protection, reducing false alarm rate and possessing anti-replay attack capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JINAN BIG DATA GROUP CO LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-07-03
AI Technical Summary
Existing technologies struggle to accurately distinguish between spurious data injection and physical equipment malfunctions in complex and dynamic environments, leading to a lack of trust in monitoring results among maintenance personnel, a high false alarm rate, and a lack of effective defense mechanisms.
By constructing efficiency deviation and heat dissipation deviation, utilizing the law of conservation of energy, and combining dynamic grouping and neighborhood resolution mechanisms for equipment of the same model, the energy input, output, and temperature data of the equipment are acquired in real time, and status is determined and defensive operations are executed.
It can accurately identify spoofed data injection attacks and equipment component degradation, reduce false alarm rates, improve engineering practicality, and has the ability to resist replay attacks.
Smart Images

Figure CN122333461A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security protection technology, specifically to a method and system for sensitive data security protection based on a trusted data space. Background Technology
[0002] Industrial Internet and energy digitization systems rely heavily on telemetry data uploaded by field devices (such as photovoltaic inverters, wind turbines, and energy storage converters) for real-time scheduling and settlement. In actual operation, data anomalies usually stem from two causes: first, the deterioration of the physical components of the equipment itself (such as aging circuits or failure of cooling fans); and second, false data injection attacks (FDIA) caused by network attacks.
[0003] In existing technologies, distinguishing between these two types of anomalies presents significant challenges: attackers often employ a "deception within a reasonable range" strategy, controlling the tampered data within a reasonable range or simulating the numerical performance of equipment failures. Traditional monitoring methods based on static thresholds or statistical outliers struggle to differentiate between cyberattacks and physical faults based solely on numerical values. Furthermore, industrial equipment is typically deployed outdoors, heavily influenced by micro-meteorological factors such as cloud cover, wind speed variations, and ambient temperature fluctuations. Simple physical models (such as fixed-efficiency models) can generate numerous false alarms in environments with non-uniform distribution (e.g., some equipment is obscured by clouds), leading maintenance personnel to distrust monitoring results. Additionally, due to the high heat capacity of core equipment components, temperature changes significantly lag behind power changes during transient conditions with rapid power fluctuations. Directly using steady-state physical equations for verification can cause the "output-loss" logic to fail in dynamic processes.
[0004] In summary, existing technologies lack a technical means to effectively utilize the laws of physical conservation in complex dynamic environments to accurately distinguish between spurious data injection and physical equipment failure. Summary of the Invention
[0005] To address the aforementioned technical problems, the purpose of this application is to provide a method and system for sensitive data security protection based on a trusted data space. The specific technical solution adopted is as follows: In a first aspect, embodiments of this application provide a method for sensitive data security protection based on a trusted data space, the method comprising the following steps: Real-time acquisition of energy input values, energy output values, core temperature values, and ambient temperature values of each target device; determination of whether to perform status determination on the data of each target device at each time based on the energy output value; when status determination is required, acquisition of the same model device group of each target device at each time based on the similarity between the energy input values of each target device and the same model device within a preset radius at each time. Based on the energy output and energy input values of each target device at each time, a single-machine conversion efficiency is constructed. Combined with the degree of deviation of the single-machine conversion efficiency of each target device relative to the median of the single-machine conversion efficiency of all devices in the same type of equipment group at the same time, an efficiency deviation is constructed to characterize the performance deviation of each target device relative to the same environment and the same type of equipment group at each time. Based on the rate of change of the core temperature value of each target device at each time, the difference between the core temperature value and the ambient temperature value is corrected to obtain the equivalent heat dissipation value. Combined with the energy output value, the output heat dissipation ratio is constructed. Based on the degree of deviation of the output heat dissipation ratio of each target device at each time relative to the median of the output heat dissipation ratio of all devices in the same equipment group at the same time, the heat dissipation deviation degree is constructed to characterize the degree of deviation of the output heat dissipation ratio of each target device at each time relative to its benchmark. Based on the efficiency deviation and the heat dissipation deviation, the status of each target device at each time moment is determined, and corresponding defense operations are performed.
[0006] Preferably, the specific process for determining whether to perform a status determination on the data of each target device at each time point is as follows: If the energy output of any target device is less than the preset output threshold at any time, its status is marked as "trusted-standby", and no status determination is made for the data of the target device at that time. Conversely, the status of the target device at that moment is determined.
[0007] Preferably, the method for obtaining the same model of equipment group for each target equipment at each time is as follows: Based on the pre-set equipment asset ledger, all equipment with the same model as each target equipment and whose geographical distance is within a preset radius are selected to form a candidate set for each target equipment; Traverse each candidate device in the candidate set. If the absolute difference between the energy input value of each target device and any candidate device at each time is less than the preset input similarity threshold, then the candidate device is included in the same type of device group of the corresponding target device, thereby obtaining the same type of device group of each target device at each time.
[0008] Preferably, the single-machine conversion efficiency refers to the ratio of the energy output value to the energy input value of each target device at each time.
[0009] Preferably, the method for constructing the efficiency deviation is as follows: Calculate the difference between the single-unit conversion efficiency of each target device at each time point and its group efficiency benchmark. The efficiency deviation is positively correlated with the difference. The group efficiency benchmark refers to the median single-machine conversion efficiency of all devices in the same model group at each time point for each target device.
[0010] Preferably, the method for obtaining the equivalent heat dissipation value is as follows: Calculate the difference between the core temperature value of each target device at each time and the previous time, and record the ratio of the difference to the sampling period as the temperature rise rate of each target device at each time. Calculate the equivalent heat dissipation value of each target device at each time step: In the formula, Let be the equivalent heat dissipation value of target device i at time k; Let be the core temperature value of target device i at time k. This represents the ambient temperature value at time k. Let be the rate of temperature rise of target device i at time k; The nominal thermal inertia compensation coefficient of the target equipment; This is the preset minimum thermal noise floor value; This is the function for finding the maximum value.
[0011] Preferably, the output heat dissipation ratio refers to the ratio between the energy output value and the equivalent heat dissipation value of each target device at each time.
[0012] Preferably, the method for constructing the heat dissipation deviation is as follows: Calculate the difference between the output heat dissipation ratio of each target device at each time point and its output heat dissipation ratio benchmark. The heat dissipation deviation is positively correlated with the difference; The output heat dissipation ratio benchmark refers to the median of the output heat dissipation ratios of all devices in the same model equipment group at each time.
[0013] Preferably, the specific process of determining the status of each target device's data at each time point and executing corresponding defense operations is as follows: If the efficiency deviation of any target device at any time exceeds the preset efficiency threshold and the heat dissipation deviation exceeds the preset heat dissipation threshold, the data of the target device at that time is determined to be in a "false data injection attack" state. At this time, a blocking command is sent to the edge gateway or data connector to directly discard the data at that time and trigger a high-level security event alarm to prompt the operation and maintenance personnel to check the data link security. Otherwise, if the efficiency deviation of any target device at any time is less than a negative number of the preset efficiency threshold and the heat dissipation deviation is less than a negative number of the preset heat dissipation threshold, then the data of the target device at that time is determined to be in the "device component deterioration" state. In this case, the data at that time is released, but a "maintenance suggestion" label is added to the data stream. Otherwise, the target device is determined to be in a "trusted operation" state at that moment. In this case, the data at that moment is allowed to participate in the computation and circulation of the data space without restriction.
[0014] Secondly, embodiments of this application also provide a sensitive data security protection system based on a trusted data space, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any of the aforementioned sensitive data security protection methods based on a trusted data space.
[0015] This application has at least the following beneficial effects: 1. This application fills the gap in the existing technology that cannot qualitatively distinguish between data tampering and physical faults by constructing efficiency deviation and heat dissipation deviation, utilizing the necessary connection between output and loss in the law of energy conservation. It can accurately identify false data injection attacks that are “numerically reasonable but violate the physical thermal law”, and accurately locate real faults that are “low output and accompanied by abnormal heat generation”.
[0016] 2. By dynamically grouping similar devices near the target device and using a neighborhood resolution mechanism, this application eliminates the need to deploy expensive high-precision meteorological sensors (such as anemometers) on-site, as well as the need to pre-set complex equipment thermal resistance models. It can automatically adapt to complex meteorological environments such as cloud cover and sudden changes in wind speed, as well as parameter drift caused by active heat dissipation of the equipment (fan start-stop), which greatly reduces the false alarm rate and improves the practicality of the project.
[0017] 3. The physical verification in this application heavily relies on real-time ambient temperature. Since the historical data recorded by the attacker is based on historical ambient temperature, when it is replayed at the current moment, logical inconsistencies (such as abnormal temperature differences) will occur between the historical temperature rise data and the current real-time ambient temperature value, resulting in abnormal heat dissipation deviation. This time-environment coupling characteristic gives this method a natural resistance to replay attacks. Attached Figure Description
[0018] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 A flowchart illustrating the steps of a sensitive data security protection method based on a trusted data space, provided in one embodiment of this application; Figure 2This is a flowchart illustrating the process of obtaining the heat dissipation deviation of each target device at each moment, as provided in one embodiment of this application. Detailed Implementation
[0020] To further illustrate the technical means and effects adopted by this application to achieve the intended inventive purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of the sensitive data security protection method and system based on trusted data space proposed in this application. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.
[0022] The following description, in conjunction with the accompanying drawings, details the specific scheme of the sensitive data security protection method and system based on trusted data space provided in this application.
[0023] Please see Figure 1 This document illustrates a flowchart of a sensitive data security protection method based on a trusted data space according to an embodiment of this application. The method includes the following steps: Step 1: Real-time acquisition of energy input value, energy output value, core temperature value, and ambient temperature value of each target device; based on the energy output value, determine whether to perform status determination on the data of each target device at each time. When status determination is required, based on the similarity between the energy input value of each target device and the same model device within a preset radius at each time, obtain the same model device group of each target device at each time.
[0024] This application aims to perform real-time data integrity verification and status auditing on connected industrial energy conversion equipment (such as photovoltaic inverters, wind turbines, energy storage converters, etc.) through computing nodes or cloud platforms deployed on the edge.
[0025] For each target device to be monitored, energy input, energy output, core temperature, and ambient temperature are collected in real time via industrial fieldbus (such as Modbus TCP, IEC 61850) or IoT gateway. The energy input value characterizes the source energy intensity driving the equipment's operation; for photovoltaic power generation systems, this value is collected from the planar irradiance (unit: ...) of the environmental monitoring instrument. (or DC-side input power; for wind power systems, this value is collected from the real-time wind speed of the nacelle anemometer (unit: ...) The energy output value is used to characterize the effective work done by the equipment after energy conversion. This value is collected from the AC active power at the output of the equipment (unit: The core temperature value is used to characterize the thermal state of the core components of the equipment's energy conversion. For inverters or converters, this value is the temperature sensor reading of their IGBT power modules or heat sinks. For motor equipment, this value is the temperature of their stator windings or bearings. The ambient temperature value is used to characterize the thermal boundary conditions of the microenvironment in which the equipment is located. This value is collected from a common ambient temperature sensor deployed outside the equipment chassis, inside the combiner box, or inside the container.
[0026] Because different sensors may have different sampling frequencies (e.g., electrical parameters refresh at the millisecond level, while temperature refreshes at the second level), and network transmission is subject to random jitter, directly associating data with the original timestamp can lead to time misalignment in the physical process. Therefore, zero-order hold resampling is performed: taking target device i at time k as an example, the most recent valid sample value at time k is selected as the energy input value, energy output value, core temperature value, and ambient temperature value of target device i at that time, denoted as _____. , , and This achieves strict alignment of all physical quantities in the time dimension.
[0027] Furthermore, during the startup phase of the energy conversion process (such as the photovoltaic startup in the early morning) or the dormant phase, the equipment is in a non-steady-state operation. Small fluctuations in the sensor noise floor can lead to the risk of division by zero or numerical divergence in subsequent efficiency calculations, thus losing their physical meaning.
[0028] Therefore, a preset output threshold is set. This threshold is based on the factory rated power of the target device. The setting, its value is usually taken as In this embodiment Pick .
[0029] At each time step, check whether the energy output value of target device i is in normal steady-state operation: taking the k-th time step as an example, if If the target device i is in an "inactive state" or "standby state" at time k, then the subsequent calculations of the target device at that time are terminated, and its state is directly marked as "trusted-standby" without further state determination to avoid false alarms; if If the data of target device i at time k is valid, then the state of the data of target device at that time is determined.
[0030] Furthermore, when it is necessary to determine the status of the target device at various times, in order to eliminate environmental interference through group comparison, it is necessary to select a group of devices of the same model under the same environmental conditions as the target device as a reference. Existing technologies usually select reference devices only based on "geographical proximity". However, in actual industrial scenarios, even if geographically adjacent, the micro-meteorological environment can be vastly different. For example, cloud cover may only cover part of a photovoltaic power station, resulting in one adjacent device being in a high-irradiance area and the other in a shaded area; the wake effect of a wind farm will cause the wind speed of downwind units to be significantly lower than that of upwind units. If devices under different environmental excitations are simply compared, the benchmark will become invalid.
[0031] To address this issue, this invention introduces a dynamic grouping mechanism. Taking the k-th time step as an example, the following filtering logic is executed to construct a group of devices of the same model as target device i at the k-th time step. First, based on a pre-set equipment asset ledger, all devices of the same model as target device i and geographically within a preset radius (1 km in this embodiment) are selected to form a candidate set for target device i. Then, each candidate device in the candidate set is iterated. If the absolute difference between the energy input value of the target device and any candidate device at time k is less than a preset input similarity threshold, the candidate device is determined to be in a similar micro-meteorological environment to the target device (e.g., neither is obscured by clouds, or both are in the same wind speed zone). This candidate device is then included in the same-model equipment group of the target device, thus obtaining the same-model equipment group of target device i at time k. The preset input similarity threshold can be set based on engineering experience; in this embodiment, it is set to 10%~15% of the target device's energy input value at the current time.
[0032] The above steps ensure that all members of the same type of equipment group at each time point have similar external energy excitation. This lays a solid physical foundation for subsequently utilizing group statistical characteristics to eliminate common-mode environmental interference.
[0033] It should be noted that, after screening, The number of devices is less than the preset minimum sample size. (In this embodiment) If the target device i lacks sufficient consensus at time k (e.g., most devices are out of communication or in complex discrete working conditions), then the target device i is determined to be in an "undeterminable" state at time k, skipping the subsequent calculation of efficiency deviation and heat dissipation deviation as well as the state determination process, to prevent misjudgment due to insufficient samples.
[0034] Step 2: Based on the energy output and energy input values of each target device at each time, construct the single-machine conversion efficiency, and combine it with the degree of deviation of its single-machine conversion efficiency from the median of the single-machine conversion efficiency of all devices in the same model group at the same time to construct the efficiency deviation, which is used to characterize the performance deviation of each target device relative to the group of devices of the same model in the same environment at each time.
[0035] First, based on the fundamental physical definition of energy conversion, the single-machine conversion efficiency of each target device at each moment is calculated using the energy input and energy output values of each target device at each time. This indicator reflects the ability of each target device to convert input energy into effective work at each moment.
[0036] Specifically, in this embodiment, the formula for calculating the single-machine conversion efficiency of target device i at time k is: In the formula, Let i be the single-machine conversion efficiency of target device i at time k; Let be the energy output value of target device i at time k; Let be the energy input value of target device i at time k. To preset a very small positive constant, this embodiment takes... This is used to prevent the denominator from becoming zero due to a momentary zero reading of the sensor, thus ensuring the stability of numerical calculations.
[0037] Furthermore, since external environmental factors (such as the influence of ambient temperature on the temperature coefficient of photovoltaic panels and the influence of air density on the output of wind turbines) have a common-mode effect on the absolute efficiency of all equipment in the area, the single-unit conversion efficiency of a single device often fluctuates with the environment and cannot be directly used for anomaly identification.
[0038] Since the target device i and the devices in the same type of equipment group are in the same microclimate environment at each time, their single-unit conversion efficiency should show a high degree of consistency.
[0039] To eliminate interference from individual faulty devices or extreme values, the median, rather than the arithmetic mean, of the single-machine conversion efficiencies of all devices in the same type of equipment group at time k is used as the intra-group efficiency benchmark for target device i at time k, denoted as . .
[0040] Furthermore, as a preferred implementation, the individual conversion efficiency of each target device is compared with the group's efficiency benchmark to construct the efficiency deviation of each target device at each time point. This indicator eliminates the influence of environmental common-mode factors and purely reflects the performance deviation of each target device relative to a group of devices of the same model and environment at each time point. The method for constructing the efficiency deviation is as follows: statistically analyzing the difference between the individual conversion efficiency of each target device at each time point and its group's efficiency benchmark; the efficiency deviation is positively correlated with the difference. The positive correlation means that the dependent variable increases (decreases) as the independent variable increases (decreases).
[0041] In this embodiment, the specific formula for calculating the efficiency deviation of target device i at time k is as follows: In the formula, Let be the efficiency deviation of target device i at time k; Let i be the single-machine conversion efficiency of target device i at time k; Let i be the intra-group efficiency benchmark for target device i at time k. This is a preset minimum positive number.
[0042] income The physical meaning is: if A value close to 0 indicates that the single-unit conversion efficiency of the target device is consistent with the group efficiency, which is within the normal range; if A significantly positive value indicates that the target device generated output far exceeding that of the group under the same input conditions. Physically, the efficiency of devices of the same model cannot arbitrarily and significantly exceed the theoretical limit or the average level of the group. This is often a characteristic of spoofing attacks (attackers attempt to fake high power generation to obtain illegal gains, or fake high load to cover up anomalies). A significantly negative value indicates that the single-machine conversion efficiency of the target device is significantly lower than that of the group. This suggests that there may be abnormal power loss inside the target device i (such as circuit aging, mechanical wear or dust accumulation), or it may correspond to a certain type of "low-output" attack. The cause cannot be determined based on this dimension alone, and it needs to be comprehensively judged in combination with the subsequent physical cost characteristics.
[0043] Step 3: Based on the rate of change of the core temperature value of each target device at each time, the difference between the core temperature value and the ambient temperature value is corrected to obtain the equivalent heat dissipation value. Combined with the energy output value, the output heat dissipation ratio is constructed. Based on the degree of deviation of the output heat dissipation ratio of each target device at each time from the median of the output heat dissipation ratio of all devices in the same model group at the same time, the heat dissipation deviation degree is constructed to characterize the degree of deviation of the output heat dissipation ratio of each target device from its benchmark at each time.
[0044] Because the core components of industrial energy conversion equipment (such as transformer cores, inverter inductors, and motor windings) have significant heat capacity characteristics, this leads to their core temperature values... Changes always lag behind energy output values The energy output fluctuates. During transient processes where energy output rapidly increases or decreases, static temperature difference alone cannot accurately reflect the current level of energy loss. Therefore, it is necessary to introduce a first derivative term of temperature to mathematically compensate for thermal inertia.
[0045] Based on the above analysis, taking target device i at time k as an example, the backward difference method is used to calculate the temperature rise rate of target device i at time k. This index characterizes the trend and speed of core temperature change of target device i. The specific calculation formula is as follows: In the formula, Let be the rate of temperature rise of target device i at time k; , These are the core temperature values of target device i at the k-th and (k-1)-th times, respectively. The sampling period is the time interval between two adjacent sampling times.
[0046] It should be noted that if the target device i has fewer than N sampling times before the k-th moment (e.g., the device has just been powered on or communication has just been restored), then the target device i is determined to be in the "data accumulation phase" at the k-th moment, and the accurate temperature rise rate cannot be calculated. In this case, the heat dissipation deviation of the target device i at the k-th moment is... Forced to 0 (i.e., default normal). Where N is a preset number, which is 5 in this embodiment.
[0047] Furthermore, the static temperature difference is dynamically corrected using the temperature rise rate, and the equivalent heat dissipation value is calculated. This index is physically equivalent to the total heat flux released by the device to the environment at the current moment in order to maintain power output.
[0048] To prevent damage under extreme operating conditions (such as a sudden drop in ambient temperature or rapid equipment shutdown) In cases where the calculated result is a large negative value (e.g., the heat dissipation value is negative) or the value is unstable (the denominator approaches zero), this application introduces a boundary constraint mechanism when calculating the equivalent heat dissipation value.
[0049] In this embodiment, the specific formula for calculating the equivalent heat dissipation value of target device i at the k-th time is as follows: In the formula, Let be the equivalent heat dissipation value of target device i at time k; Let be the core temperature value of target device i at time k. This represents the ambient temperature value at time k. Let be the rate of temperature rise of target device i at time k; The nominal thermal inertia compensation coefficient of the target device is an inherent physical property of the device, which depends on the material and quality of the heat sink and can be obtained from the device's manufacturer's manual (its value range is usually 600 seconds to 1200 seconds). The preset minimum thermal noise floor value is taken in this embodiment. This constraint ensures It is always positive, thus avoiding sign reversal or division by zero errors in subsequent division operations; This is the function for finding the maximum value.
[0050] It should be noted that although in actual operation, active heat dissipation of the equipment (such as fan startup) or changes in ambient wind speed will alter the actual thermal resistance characteristics, this application fixes this characteristic here. The values are then used to eliminate these dynamically changing disturbances through subsequent group comparisons.
[0051] Furthermore, the ratio of the energy output value to the equivalent heat dissipation value of target device i at time k is denoted as the output-heat dissipation ratio of target device i at time k, and is recorded as follows: This indicator represents the effective energy output obtained by the target equipment for each unit of heat cost generated.
[0052] Furthermore, although This reflects the physical cost, but its absolute value is drastically affected by environmental heat dissipation conditions (such as wind speed and active cooling strategies). For example, when equipment operates under high load, triggering the cooling fan to start, forced convection leads to… decline, Decrease, thus making Even without a malfunction, the heat dissipation rate can increase significantly. Therefore, the output heat dissipation ratio of a single device cannot be directly used for condition determination.
[0053] This application utilizes equipment of the same model. This problem can be solved by leveraging common-mode characteristics. Specifically, because devices in the same model group have similar models and operating conditions (similar energy input values), they often implement consistent heat dissipation control strategies (for example, when the load increases, the fans of all devices in the group will start almost simultaneously; when the ambient wind speed increases, all devices in the group are affected). This common-mode interference affecting the entire group can be mathematically resolved through ratio calculations.
[0054] Therefore, statistics on groups of equipment of the same model The median of the output heat dissipation ratio of all devices at time k is used as the benchmark for the output heat dissipation ratio of target device i at time k.
[0055] In a preferred embodiment, based on the difference between the output heat dissipation ratio of each target device at each time point and its benchmark output heat dissipation ratio, a heat dissipation deviation degree is constructed for each target device at each time point to characterize the degree of deviation of the output heat dissipation ratio of each target device from its benchmark at each time point. The method for constructing the heat dissipation deviation degree is as follows: the difference between the output heat dissipation ratio of each target device at each time point and its benchmark output heat dissipation ratio is statistically analyzed; the heat dissipation deviation degree is positively correlated with the difference. The flowchart for obtaining the heat dissipation deviation degree of each target device at each time point is shown below. Figure 2 As shown.
[0056] In this embodiment, the heat dissipation deviation of target device i at time k is denoted as... The specific calculation formula is as follows: In the formula, Let be the heat dissipation deviation of target device i at time k; Let be the output heat dissipation ratio of target device i at time k; Let the output heat dissipation ratio of target device i at time k be the benchmark. This is a preset minimum positive number.
[0057] Through the above calculations, the heat dissipation coefficient caused by fan startup or changes in ambient wind speed (this coefficient usually affects the equivalent heat dissipation value as a multiplicative factor) is calculated. Simultaneously acting on and Thus, it is eliminated by reduction.
[0058] income The physical meaning is: if A value close to 0 indicates that the energy output and thermal response of target device i at time k are in equilibrium, which is within the normal range; if A value significantly greater than 0 indicates that, under the same heat dissipation conditions, target device i has high output at time k but does not exhibit the expected thermal response. The value is too small, which reflects the characteristic of data tampering attacks of "inflating output but omitting falsified hot data"; if A value significantly less than 0 indicates that at time k, target device i generates excessive waste heat while producing insufficient output, which is consistent with the characteristics of equipment component deterioration (such as frictional heat generation and increased impedance).
[0059] Step 4: Based on the efficiency deviation and the heat dissipation deviation, determine the status of each target device at each time and perform corresponding defense operations.
[0060] Furthermore, by combining the efficiency deviation in step two and the heat dissipation deviation in step three, statistical anomalies in the data are transformed into specific security defense actions.
[0061] Specifically, set a preset efficiency threshold. and preset heat dissipation threshold , and The value is determined based on the historical data statistical distribution of equipment groups of the same model. In this embodiment, a preset efficiency threshold is used. The value is taken as 3 times the standard deviation of the historical efficiency deviation of all equipment in the same model equipment group (i.e. (Principles), preset heat dissipation threshold The value is three times the standard deviation of the historical heat dissipation deviation of all equipment in the same model equipment group.
[0062] like and This indicates that target device i has a significantly higher energy output than the group under the same input conditions, and its output per unit thermal response is also significantly higher than that of the group. This shows that while the target device has a high output, it does not exhibit a corresponding physical heat loss, which violates the law of energy dissipation. Therefore, the state of target device i at the k-th time is determined to be the "false data injection attack" state.
[0063] It should be noted that this judgment logic is capable of resisting replay attacks. Because... The calculation is highly dependent on the real-time ambient temperature at time k. If an attacker injects historically recorded (energy output value, core temperature value) data pairs, the temperature difference term will be affected because the ambient temperature value at a historical moment will inevitably differ from the ambient temperature value at the k-th moment (e.g., diurnal temperature difference or seasonal temperature difference). Distortion occurs, which in turn leads to Abnormal fluctuations occur, causing the attack data to fall into an abnormal range and be identified by the system.
[0064] Otherwise, if and If the output per unit of thermal response is significantly lower than that of the group, it indicates that the target device's conversion efficiency is significantly lower than that of the group. This suggests that the target device is experiencing low output while also suffering excessive ineffective heat loss, which is consistent with the characteristics of increased heat generation caused by mechanical wear, circuit aging, or insulation failure. Therefore, the state of the target device i at the k-th moment is determined to be the "device component deterioration" state.
[0065] Otherwise, it means that the conversion efficiency and thermal response of target device i at time k are within the reasonable fluctuation range of the group consensus. In this case, the state of target device i at time k is determined to be "trustworthy operation".
[0066] Furthermore, in order to translate the above determination result into an executable defensive action, the following operations are performed based on the above state determination result: When target device i is in the "false data injection" state at time k, a blocking command is sent to the edge gateway or data connector to directly discard the data at that time, preventing it from polluting the upper-layer business system (such as the settlement platform or dispatch center), and triggering a high-level security event alarm to prompt the operation and maintenance personnel to check the data link security. When target device i is in the "device component deterioration" state at time k, the data at that time is allowed to pass, but a "maintenance suggestion" label is added to the data stream. This ensures that the operation and maintenance system can receive the real status information of the target device in order to arrange maintenance, while prompting the upper-level scheduling system to reduce the scheduling priority of the device to avoid running under high load; When the target device i is in a "trusted operation" state at time k, the data at that time is allowed to participate in the computation and circulation of the data space without restriction.
[0067] Similarly, the status of each target device at each time point is determined, and corresponding defense actions are executed.
[0068] Through the above steps, this application has completed the full lifecycle security classification and handling of sensitive data based on physical facts, and realized closed-loop control from physical signal perception to security defense execution.
[0069] Based on the same inventive concept as the above method, this application also provides a sensitive data security protection system based on trusted data space, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of the above-described sensitive data security protection method based on trusted data space.
[0070] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments of this specification have been described above. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0071] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
[0072] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.
Claims
1. A method for protecting sensitive data based on a trusted data space, characterized in that, The method includes the following steps: Real-time acquisition of energy input values, energy output values, core temperature values, and ambient temperature values of each target device; determination of whether to perform status determination on the data of each target device at each time based on the energy output value; when status determination is required, acquisition of the same model device group of each target device at each time based on the similarity between the energy input values of each target device and the same model device within a preset radius at each time. Based on the energy output and energy input values of each target device at each time, a single-machine conversion efficiency is constructed. Combined with the degree of deviation of the single-machine conversion efficiency of each target device relative to the median of the single-machine conversion efficiency of all devices in the same type of equipment group at the same time, an efficiency deviation is constructed to characterize the performance deviation of each target device relative to the same environment and the same type of equipment group at each time. Based on the rate of change of the core temperature value of each target device at each time, the difference between the core temperature value and the ambient temperature value is corrected to obtain the equivalent heat dissipation value. Combined with the energy output value, the output heat dissipation ratio is constructed. Based on the degree of deviation of the output heat dissipation ratio of each target device at each time relative to the median of the output heat dissipation ratio of all devices in the same equipment group at the same time, the heat dissipation deviation degree is constructed to characterize the degree of deviation of the output heat dissipation ratio of each target device at each time relative to its benchmark. Based on the efficiency deviation and the heat dissipation deviation, the status of each target device at each time moment is determined, and corresponding defense operations are performed.
2. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The specific process for determining whether to perform a status determination on the data of each target device at each time point is as follows: If the energy output of any target device is less than the preset output threshold at any time, its status is marked as "trusted-standby", and no status determination is made for the data of the target device at that time. Conversely, the status of the target device at that moment is determined.
3. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The method for obtaining the same type of equipment group for each target device at each time is as follows: Based on the pre-set equipment asset ledger, all equipment with the same model as each target equipment and whose geographical distance is within a preset radius are selected to form a candidate set for each target equipment; Traverse each candidate device in the candidate set. If the absolute difference between the energy input value of each target device and any candidate device at each time is less than the preset input similarity threshold, then the candidate device is included in the same type of device group of the corresponding target device, thereby obtaining the same type of device group of each target device at each time.
4. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The single-machine conversion efficiency refers to the ratio of the energy output value to the energy input value of each target device at each time.
5. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The method for constructing the efficiency deviation is as follows: Calculate the difference between the single-unit conversion efficiency of each target device at each time point and its group efficiency benchmark. The efficiency deviation is positively correlated with the difference. The group efficiency benchmark refers to the median single-machine conversion efficiency of all devices in the same model group at each time point for each target device.
6. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The method for obtaining the equivalent heat dissipation value is as follows: Calculate the difference between the core temperature value of each target device at each time and the previous time, and record the ratio of the difference to the sampling period as the temperature rise rate of each target device at each time. Calculate the equivalent heat dissipation value of each target device at each time step: In the formula, Let be the equivalent heat dissipation value of target device i at time k; Let be the core temperature value of target device i at time k. This represents the ambient temperature value at time k. Let be the rate of temperature rise of target device i at time k; The nominal thermal inertia compensation coefficient of the target equipment; This is the preset minimum thermal noise floor value; This is the function for finding the maximum value.
7. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The output-to-heat ratio refers to the ratio between the energy output value and the equivalent heat dissipation value of each target device at each time.
8. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The method for constructing the heat dissipation deviation is as follows: Calculate the difference between the output heat dissipation ratio of each target device at each time point and its output heat dissipation ratio benchmark. The heat dissipation deviation is positively correlated with the difference; The output heat dissipation ratio benchmark refers to the median of the output heat dissipation ratios of all devices in the same model equipment group at each time.
9. The sensitive data security protection method based on trusted data space as described in claim 1, characterized in that, The specific process of determining the status of each target device's data at each time point and executing corresponding defense operations is as follows: If the efficiency deviation of any target device at any time exceeds the preset efficiency threshold and the heat dissipation deviation exceeds the preset heat dissipation threshold, the data of the target device at that time is determined to be in a "false data injection attack" state. At this time, a blocking command is sent to the edge gateway or data connector to directly discard the data at that time and trigger a high-level security event alarm to prompt the operation and maintenance personnel to check the data link security. Otherwise, if the efficiency deviation of any target device at any time is less than a negative number of the preset efficiency threshold and the heat dissipation deviation is less than a negative number of the preset heat dissipation threshold, then the data of the target device at that time is determined to be in the "device component deterioration" state. In this case, the data at that time is released, but a "maintenance suggestion" label is added to the data stream. Otherwise, the target device is determined to be in a "trusted operation" state at that moment. In this case, the data at that moment is allowed to participate in the computation and circulation of the data space without restriction.
10. A sensitive data security protection system based on a trusted data space, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the sensitive data security protection method based on trusted data space as described in any one of claims 1-9.