A dual data security screening system based on edge computing
Through the data dual security screening system of edge computing, the dual screening mechanism of edge nodes and aggregation nodes is used to solve the problem of latency and stability of data security screening in smart grids, and efficient and accurate data security guarantees are achieved.
Patent Information
- Application Number
- CN202210344587.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-12-28
- Filing Date
- 2022-03-31
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-03-31
AI Technical Summary
In the prior art, the security screening time of smart grid data is long, and security risks cannot be discovered in time, and the security problems introduced by 5G edge computing lead to unstable data transmission.
The data dual security screening system based on edge computing is adopted to initially filter the security probability of data through edge nodes, and secondary screening is performed using a pre-trained discriminant network to ensure the security and authenticity of the data.
It reduces the delay in data screening, improves the accuracy and efficiency of data security screening, reduces the computing pressure of aggregation nodes, and ensures the security and authenticity of data.
Smart Images

Figure CN114980106B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent power grid service data processing, and particularly relates to a data double security screening system based on edge computing. Background Art
[0002] The deep integration of the energy Internet and 5G has promoted the digital development of the power grid and improved the intelligent level of the power grid. Due to the continuous increase in the number of underlying service terminals and the popularization of intelligent inspection robots, data transmission has been increasing. If all data is sent to the cloud for processing, it will lead to increased latency, untimely processing, and the inability to detect security risks in a timely manner. Based on the open feature of 5G capabilities, the edge computing local offloading and diversion technology based on the 5G user plane sinking can solve these problems. However, the opening of 5G capabilities also introduces security problems, and real power grid data may be subject to various frequent and diverse network attack means such as false data injection attacks. A false data injection attack is that an attacker premeditatedly modifies the business data of the power grid, causing the business master station system, etc. to make wrong judgments or maliciously increase the operation load of the network, thereby causing great harm to the intelligent power grid dispatching and stable operation.
[0003] In the face of the above security problems, from the perspective of reducing the computing power and storage resources of terminal devices, distributed computing is carried out by means of 5G edge computing, which is a network node with computing and storage functions. While collecting and calculating the data generated by power terminal devices, the 5G edge computing platform introduces a security mechanism to screen and process the injected false data, thereby ensuring the security of intelligent power grid data transmission. With the booming development of artificial intelligence, applying machine learning and deep learning to false data injection attack detection has become a trend. These methods can effectively cope with the increasing real-time power grid data volume and have obvious improvements compared with traditional detection methods. The algorithms and models of machine learning and deep learning are relatively complex, and intelligent computing services can currently mostly only be deployed in the cloud center. All the data collected by the intelligent power grid is processed and applied in the power grid data center of the cloud center. This computing and processing solution makes the communication and storage resource load larger and cannot meet the service requirements of some power systems that are more sensitive to latency. Summary of the Invention
[0004] Therefore, the technical problem to be solved by the present invention is to overcome the defect of long data security screening latency in the prior art, and thus provide a data double security screening system based on edge computing.
[0005] In the first aspect of the present invention, a data dual - security screening system based on edge computing is provided, including at least one data acquisition device, an edge node, and an aggregation node. The data acquisition device is used to collect data and upload the data to the edge node; the edge node is used to extract various attribute information of each data, calculate the first - level security probability of the data according to the security probabilities of the respective attribute information of the data, determine the data with the first - level security probability greater than a first preset value as the data to be second - level screened, and upload the data to be second - level screened to the aggregation node; the aggregation node is used to input the data to be second - level screened into a pre - trained discriminant network to obtain the second - level security probability of the data to be second - level screened, and determine the data to be second - level screened with the second - level security probability greater than a second preset value as real data.
[0006] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the data to be second - level screened with the first - level security probability less than or equal to the second preset value, or, the second - level security probability less than or equal to the second preset value is determined as false data.
[0007] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the security probability of the attribute information of the data is calculated by the following formula: where M z represents the proportion of the data with the z - th type of attribute information in all data, and M represents the set of attribute information.
[0008] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the first - level security probability of the data is calculated by the following formula: where b i represents the bias of the single - security probability of the z - th type of attribute information among all attribute information, and ω i represents the weight of the single - security probability of the z - th type of attribute information among all attribute information.
[0009] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the attribute information of the data is extracted by the following steps: extracting various data information parameters of the data; respectively performing standardization processing on each data information parameter to obtain the attribute information corresponding to each data information parameter.
[0010] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the edge node includes an edge platform layer and an edge service layer. The edge platform layer is used to extract various attribute information of each data; the edge service layer is used to calculate the first - level security probability of the data according to the security probabilities of the respective attribute information of the data.
[0011] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the edge node further includes an edge resource layer, and the edge resource layer is used to store the data to be double - screened.
[0012] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the aggregation node includes an aggregation resource layer and a platform service layer. The aggregation resource layer is used to store the data to be double - screened; the platform service layer is used to input the data to be double - screened into a pre - trained discriminant network to obtain the second - level security probability of the data to be double - screened.
[0013] Optionally, in the data dual - security screening system based on edge computing provided by the present invention, the aggregation node further includes a software service layer. The software service layer is used to process the real data according to the service requests of the data acquisition devices to obtain a data processing result, and send the data processing result to the data acquisition devices.
[0014] The technical solution of the present invention has the following advantages:
[0015] In the data dual - security screening system based on edge computing provided by the present invention, after the data acquisition device acquires data, the data is first input into the edge node. The edge node extracts the security - related attribute information in the data, and performs the first - level security screening on the data through the attribute information. After initially eliminating false data, the data to be double - screened with a higher security probability is uploaded to the aggregation node. The aggregation node has stronger computing power and storage capacity, and can perform further security screening on the data to be double - screened through a pre - trained discriminant network. The data dual - security screening system based on edge computing provided by the present invention ensures the accuracy of the screening result, and guarantees the security and authenticity of the data through the dual screening of the data. Moreover, the data dual - security screening system based on edge computing provided by the present invention first performs preliminary screening through the edge node, and then inputs the screened data into the aggregation node for secondary screening. On the basis of ensuring data security, it reduces the computing pressure on the aggregation node and improves the efficiency of data security screening. Description of the Drawings
[0016] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0017] Figure 1 It is the architecture diagram of a specific example of the data dual - security screening system based on edge computing in the embodiment of the present invention;
[0018] Figure 2 Schematic diagram of the training process of the discriminant network in the embodiment of the present invention;
[0019] Figure 3 Architecture diagram of a specific example of the data dual - security screening system based on edge computing in the embodiment of the present invention;
[0020] Figure 4 Principle block diagram of a specific example of a computer device in the embodiment of the present invention. Detailed implementation manners
[0021] The technical solutions of the present invention will be described clearly and completely below with reference to the accompanying drawings. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0022] In the description of the present invention, it should be noted that the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0023] In addition, the technical features involved in different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0024] The embodiment of the present invention provides a data dual - security screening system based on edge computing, as Figure 1 shown, including at least one data acquisition device, an edge node, and an aggregation node.
[0025] The data acquisition device is used to collect data and upload the data to the edge node.
[0026] In an optional embodiment, the data acquisition device includes intelligent devices such as unmanned aerial vehicles, inspection robots, high - definition monitoring cameras, etc.
[0027] In an optional embodiment, the data dual - security screening system includes one aggregation node, multiple edge nodes, and multiple data acquisition devices. One aggregation node is connected to multiple edge nodes, and one edge node is connected to multiple data acquisition devices. After the data acquisition device collects data, it sends the data to the nearest edge node.
[0028] The edge node is used to extract various attribute information of each data, calculate the first - level security probability of the data according to the security probabilities of the attribute information of the data, determine the data with the first - level security probability greater than the first preset value as the data to be second - level screened, and upload the data to be second - level screened to the aggregation node.
[0029] In an alternative embodiment, the attribute information of the data includes but is not limited to latency sensitivity, data packet size, data acquisition frequency, terminal device trust level, and computing resource occupancy.
[0030] In an alternative embodiment, if the first-level security probability of the data is less than or equal to the first preset value, the data is directly determined to be false data and is excluded; if the first-level security probability of the data is greater than the first preset value, it means that the data is determined to be secure data in the first-level security screening. However, for the reliability of the judgment result, the data needs to be uploaded to the aggregation node for a second-level security screening.
[0031] In an alternative embodiment, the first preset value can be set according to actual requirements. Exemplarily, the first preset value can be set to 95%.
[0032] The aggregation node is used to input the data to be secondarily screened into a pre-trained discriminant network to obtain the second-level security probability of the data to be secondarily screened, and determine the data to be secondarily screened with a second-level security probability greater than the second preset value as real data.
[0033] In an alternative embodiment, the discriminant network is obtained through generative adversarial training.
[0034] In an alternative embodiment, if the second-level security probability of the data to be secondarily screened is less than or equal to the second preset value, it is determined that the data to be secondarily screened is false data and is excluded.
[0035] In an alternative embodiment, the second preset value can be set according to actual requirements. Exemplarily, the second preset value can be set to 99.9%.
[0036] The data double security screening system based on edge computing provided by the embodiments of the present invention, after the data acquisition device acquires data, first inputs it to the edge node. The edge node extracts the security-related attribute information in the data and performs a first-level security screening on the data through the attribute information. After initially excluding false data, the data to be secondarily screened with a higher security probability is uploaded to the aggregation node. The aggregation node has stronger computing and storage capabilities and can perform further security screening on the data to be secondarily screened through a pre-trained discriminant network. The data double security screening system based on edge computing provided by the embodiments of the present invention ensures the accuracy of the screening result, guarantees the security and authenticity of the data through the double screening of the data, and first performs a preliminary screening through the edge node and then inputs the screened data to the aggregation node for secondary screening, reducing the computing pressure on the aggregation node and improving the efficiency of data security screening on the basis of ensuring data security.
[0037] In an alternative embodiment, the edge node extracts the attribute information of the data through the following steps:
[0038] First, extract various data information parameters of the data.
[0039] In the embodiment of the present invention, the extracted data information parameters refer to the data information parameters related to the security probability, such as the delay sensitivity τ, the data packet size δ, the data acquisition frequency f, the terminal device trust degree ξ, and the computing resource occupancy ζ, etc.
[0040] Then, perform standardization processing on each data information parameter respectively to obtain the attribute information corresponding to each data information parameter.
[0041] In an alternative embodiment, the data information parameters are standardized through the following formula:
[0042]
[0043] Where x i represents the data information parameter of each sample data, μ represents the mean of the data information parameter, σ represents the standard deviation of the sample, and is expressed as:
[0044]
[0045] Therefore, after standardization, each data information parameter is expressed as: Take as the attribute information.
[0046] In an alternative embodiment, for the convenience of representation, the five types of standardized attribute information obtained are represented by z, where 1 ≤ z ≤ 5. When z = 1, it is represented as When z = 2, it is represented as And so on.
[0047] Define a set M = {g1, g2,..., g3}. M represents the set of related attributes. The distribution of the attribute z in the set belongs to the polynomial distribution. Define the security probability calculation formula for a single attribute as follows:
[0048]
[0049] Where M z 's calculation represents the proportion of the data with the attribute z that needs to be screened among all the data.
[0050] Therefore, the total security probability calculation formula after further calculating all the attributes superimposed together is as follows:
[0051]
[0052] Where bi Represents the bias of the single security probability of attribute z among all attributes, ω i Represents the weight of the single security probability of attribute z among all attributes. The weight values of each attribute can be reasonably adjusted according to security requirements. Here And 0 ≤ b i ≤ 1.
[0053] In an alternative embodiment, the discriminant network is trained by a generative adversarial training method, as Figure 2 shown. The training process specifically includes the following steps:
[0054] Define the input and output in the generative adversarial network. The input is the real data a and the random noise signal b, and the output is still a value representing the data security probability
[0055] Build the generative adversarial network, including two parts: the generative network G and the discriminant network D. The optimization objective function is:
[0056]
[0057] where, a ~ P data (a) represents that the real data a collected by the aggregation server follows the distribution P data (a); b ~ P b (b) represents that the input b of the generator follows a certain distribution P b (b); The generative network tries to make the output G(b) of the generative network follow P data (a) to deceive the discriminant network; D(a) represents the estimation of the discriminant network for the real data; D(G(b)) represents the estimation of the discriminant network for the data generated by the generative network.
[0058] The discriminant network D tries to increase the value of V, and the generative network G tries to decrease the value of V. The two networks are in mutual adversarial competition.
[0059] First, fix G and train D:
[0060]
[0061] The purpose of training D is to make the value of this formula as large as possible. Real data is expected to be classified as 1 by D, and generated data is expected to be classified as 0. For the first term, if real data is misclassified as 0, then log(D(a)) << 0, and the expectation will become negative infinity. For the second term, if generated data is misclassified as 1, It will also be negative infinity. If a lot of data is misclassified, there will be a lot of negative infinities, and there is still a lot of room for optimization. The parameters can be corrected to increase the value of V. This can make the discriminative network D better distinguish between true and false data.
[0062] Then fix D and train G:
[0063]
[0064] The purpose of training G is to make the value of V as small as possible, so that D cannot screen out true and false data. Since the first term of the objective function does not contain G and is a constant and is not affected, it can be directly ignored. For G, it hopes that D can classify the data it sends as 1 (true data) when discriminating. In this way, D is deceived and the effect of passing off the false as the real is achieved. For the second term, the generative network hopes that D(b)=1, so the above formula can be expressed as:
[0065]
[0066] The generative network reduces the value of V by correcting the parameters. This can make the discriminative network D less likely to distinguish between true and false data.
[0067] Under the adversarial training of the generative network and the discriminative network, their generative and discriminative functions become more and more powerful. After multiple trainings, the ability of the discriminative network to distinguish false data and the ability of the generative network to generate false data are both optimized. At this time, the global optimal solution can be expressed as:
[0068]
[0069] Among them, P g (a) is a transformation of P b (b).
[0070] Therefore, after multiple trainings of the deep learning model with generative adversarial training, the hyperparameters of the model obtained by training the discriminative network are retained to construct a second-level security screening mechanism.
[0071] Take as the second-level security probability of the second-level security screening. When the second-level security probability is less than 99.9%, the aggregation node automatically screens and eliminates this data. The screened data is further processed at the aggregation node.
[0072] In an optional embodiment, as Figure 3 shown, in the data dual security screening system based on edge computing provided by the embodiments of the present invention, the edge node includes an edge platform layer and an edge service layer,
[0073] The edge platform layer is used to extract various attribute information of each data;
[0074] The edge service layer is used to calculate the first-level security probability of data according to the security probabilities of the respective attribute information of the data.
[0075] In an alternative embodiment, as Figure 3 shown, in the data dual security screening system based on edge computing provided by the embodiments of the present invention, the edge node further includes an edge resource layer, and the edge resource layer is used to store the data to be double-screened.
[0076] In an alternative embodiment, the edge resource layer is further used to store the data uploaded by the data acquisition device.
[0077] In an alternative embodiment, as Figure 3 shown, in the data dual security screening system based on edge computing provided by the embodiments of the present invention, the aggregation node includes an aggregation resource layer and a platform service layer.
[0078] The aggregation resource layer is used to store the data to be double-screened.
[0079] The platform service layer is used to input the data to be double-screened into a pre-trained discriminant network to obtain the second-level security probability of the data to be double-screened.
[0080] In an alternative embodiment, the platform service layer first extracts features from the data to be double-screened. If the data to be double-screened contains the topological features of the D network, the data to be double-screened is input into a pre-trained discriminant network to obtain the second-level security probability of the data to be double-screened. If the data to be double-screened does not contain the topological features of the D network, it is determined that the data to be double-screened is false data and the data is excluded.
[0081] In an alternative embodiment, as Figure 3 shown, the aggregation node further includes a software service layer, and the software service layer is used to perform data processing on the real data according to the service request of the data acquisition device, obtain a data processing result, and send the data processing result to the data acquisition device.
[0082] The embodiments of the present invention provide a computer device, as Figure 4 shown, the computer device mainly includes one or more processors 31 and a memory 32. Figure 4 Taking one processor 31 as an example.
[0083] The computer device may further include: an input device 33 and an output device 34.
[0084] The processor 31, the memory 32, the input device 33, and the output device 34 may be connected by a bus or other means. Figure 4 Taking connection by bus as an example.
[0085] The processor 31 may be a Central Processing Unit (CPU). The processor 31 may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., or a combination of the above types of chips. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The memory 32 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the edge-computing-based data dual security screening system. In addition, the memory 32 may include high-speed random access memory and may also include non-transitory memory, such as at least one magnetic disk storage device, flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 32 may optionally include a memory remotely disposed relative to the processor 31, and these remote memories may be connected to the edge-computing-based data dual security screening system through a network. The input device 33 may receive a calculation request (or other digital or character information) input by the user and generate a key signal input related to the edge-computing-based data dual security screening system. The output device 34 may include a display device such as a display screen for outputting calculation results.
[0086] An embodiment of the present invention provides a computer-readable storage medium. The computer-readable storage medium stores computer instructions. The computer storage medium stores computer-executable instructions, and the computer-executable instructions can execute the steps performed by the data acquisition device, edge node, and aggregation node in the edge-computing-based data dual security screening system in any of the above embodiments. Among them, the storage medium may be a magnetic disk, optical disk, Read-Only Memory (ROM), Random Access Memory (RAM), Flash Memory, Hard Disk Drive (HDD), or Solid-State Drive (SSD), etc.; the storage medium may also include a combination of the above types of memories.
[0087] Obviously, the above embodiments are merely examples given for clear illustration and are not limitations on the implementation manners. For those of ordinary skill in the art, other different forms of changes or alterations can be made based on the above description. It is not necessary and impossible to exhaustively list all implementation manners here. And the obvious changes or alterations derived therefrom still fall within the protection scope of the present invention.
Claims
1. A dual - security screening system for data based on edge computing, characterized in that, Comprising at least one data acquisition device, an edge node, and an aggregation node, The data acquisition device is used to acquire data and upload the data to the edge node; The edge node is used to extract various attribute information of each data, calculate the first-level security probability of the data according to the security probabilities of the respective attribute information of the data, determine the data with the first-level security probability greater than a first preset value as the data to be double-screened, and upload the data to be double-screened to the aggregation node; The aggregation node is used to input the data to be double-screened into a pre-trained discriminant network to obtain the second-level security probability of the data to be double-screened, and determine the data to be double-screened with the second-level security probability greater than a second preset value as real data; The edge node includes an edge platform layer and an edge service layer, The edge platform layer is used to extract various attribute information of each data; The edge service layer is used to calculate the first-level security probability of the data according to the security probabilities of the respective attribute information of the data.
2. The edge-computing-based data double-security screening system according to claim 1, wherein, The data to be double-screened with the first-level security probability less than or equal to the second preset value, or the second-level security probability less than or equal to the second preset value is determined as false data.
3. The data dual security screening system based on edge computing according to claim 1, characterized in that, The security probability of the attribute information of the data is calculated by the following formula: Among them, M z represents the proportion of data with the z-th type of attribute information in all data, and M represents the set of attribute information.
4. The data dual security screening system based on edge computing according to claim 1 or 3, characterized in that The first-level security probability of the data is calculated by the following formula: Among them, b i represents the bias of the single security probability of the z-th type of attribute information among all attribute information, and ω i represents the weight of the single security probability of the z-th type of attribute information among all attribute information.
5. The dual - security screening system for data based on edge computing according to claim 1, characterized in that, The attribute information of the data is extracted by the following steps: Extract various data information parameters of the data; Standardize each of the data information parameters to obtain the attribute information corresponding to each data information parameter.
6. The data dual security screening system based on edge computing according to claim 1, wherein The edge node further includes an edge resource layer, The edge resource layer is used to store the data to be double-screened.
7. The data dual security screening system based on edge computing according to claim 1, characterized in that, The aggregation node includes an aggregation resource layer and a platform service layer, The aggregation resource layer is used to store the data to be double-screened; The platform service layer is used to input the data to be double-screened into a pre-trained discriminant network to obtain the second-level security probability of the data to be double-screened.
8. The data dual security screening system based on edge computing according to claim 7, wherein The aggregation node further includes a software service layer, The software service layer is used to process the real data according to the service request of the data acquisition device to obtain a data processing result, and send the data processing result to the data acquisition device.
Citation Information
Patent Citations
Financial data behavior screening work method through cloud platform
CN112463853A
Transformer substation equipment intelligent analysis method and system based on edge calculation
CN113837526A