Data security transmission method based on network configuration management system
By limiting the node read/write rate and monitoring the rate curve in the distribution network management system, the problem of difficult monitoring of data leakage in the distribution communication network is solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202211294474.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2042-10-21
AI Technical Summary
Existing power distribution communication networks are difficult to effectively monitor data leakage in terms of data security, especially when actively transferring or leaking data, which consumes a lot of resources and is inefficient.
By establishing read/write rate limiting functions in the distribution network management system, the read/write rate of nodes is limited, and the rate curves between nodes are monitored. A third node is used to determine whether there are signs of data leakage, thus avoiding direct access to data content.
It improves the security of data transmission, reduces the risk of data leakage, lowers the consumption of monitoring resources, and does not interfere with normal data transmission.
Smart Images

Figure CN115664780B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data transmission, in particular to a data security transmission method based on a distribution network management system. BACKGROUND
[0002] At present, the power distribution communication network is constructed by using a passive optical network technology, and is used for transmitting monitoring data such as line voltage, line current, zero sequence current, device state and fault information. The number of user access points has reached a certain amount, and is predicted to increase explosively in the future. However, the control of data security in the prior art is often to defend against external attacks, and it is difficult to monitor the active transfer or data leakage, or the resources consumed by the monitoring are too large, and the efficiency is low. SUMMARY
[0003] In view of the problem that the data security of the prior art cannot be guaranteed, the present application provides a data security transmission method based on a distribution network management system, which improves the transmission mode, limits and monitors the read-write rate of each data, can judge the read-write trace of the data from the source to judge whether the data is leaked, and the monitored node does not need to master the data itself, further reducing the security risk.
[0004] The technical scheme of the present application is as follows.
[0005] The data security transmission method based on the distribution network management system comprises the following steps:
[0006] The registered nodes are counted, and for any data to be transmitted, the starting point of transmission is a first node, the end point of transmission is a second node, and the remaining nodes are third nodes;
[0007] A read-write speed limiting function is established to obtain a read-write speed limiting value according to the number of nodes, and the read-write speed limiting value is limited in the data transmission process in the system;
[0008] After the transmission is completed, the read-write rate curve of the first node and the second node is called and a specified third node is forwarded;
[0009] The third node obtains a characteristic paragraph related to the data transmission from the read-write rate curve of the first node and the second node according to the read-write speed limiting value;
[0010] The third node monitors the read-write rate curve of the first node and / or the second node according to a preset rule, and judges whether a suspicious paragraph with a similarity to the characteristic paragraph reaching a threshold value appears;
[0011] If it appears, the use record of the first node and / or the second node or the communication record of the network link is called to judge whether there is data leakage.
[0012] The application establishes a set of security protocols for data transmission between nodes, and the nodes need to be limited by read-write speed limit values during data transmission. Since any data theft method cannot be separated from reading and writing, by monitoring the read-write rate curve of the node, it can be directly observed whether there are relevant data reading and writing traces. Therefore, the application can monitor the security of the data without the data itself, without interfering with the monitoring behavior, and without additional security risks.
[0013] Preferably, the read-write speed limit function is established to obtain the read-write speed limit value according to the number of nodes, including:
[0014] The read-write speed limit function is established:
[0015]
[0016] Wherein, v is the read-write speed limit value, K is a data transmission coefficient with a value range of 0-1, a is the first node number, b is the second node number, V a is the read-write maximum speed of the first node, V b is the read-write maximum speed of the second node.
[0017] After calculating the read-write speed limit value, the corresponding read-write speed is limited according to the preset time interval.
[0018] Preferably, the corresponding read-write speed is limited according to the preset time interval, including:
[0019] The preset time interval T and the duration t, wherein T is greater than t, and during reading and writing, the read-write speed is limited to the read-write speed limit value every T time, and the process is repeated for t time, until the reading and writing are completed.
[0020] In the application, in order to balance the read-write efficiency and highlight the characteristics, the speed is periodically limited, so that the read-write speed can produce periodic rules, which is convenient for subsequent identification, and most of the time is still read and written at the highest speed.
[0021] Preferably, the forwarding of the specified third node includes:
[0022] Judging the network link set P1 of the second node, judging the network link set P2 of the third node;
[0023] Judging whether P1 and P2 have an intersection, if there is, randomly selecting a third node from the network link of the intersection as the specified third node, if there is not, randomly selecting the specified third node from all third nodes.
[0024] Preferably, the feature paragraph related to the current data transmission is obtained from the read-write rate curve of the first node and the second node according to the read-write speed limit value, including:
[0025] finding periodic read-write rate changes from the read-write rate curve;
[0026] If the period of a paragraph is T, further determine whether there is a read-write limiting value v in t time in each period, if yes, the paragraph is a feature paragraph.
[0027] As preferred, the monitoring the read-write rate curve of the first node and / or the second node according to the preset rule, determining whether there is a suspicious paragraph with a similarity to the feature paragraph reaching a threshold, comprises:
[0028] Setting a preset rule, triggering the monitoring when the read-write rate reaches a peak value, continuously recording the read-write rate curve in at least 3T time; marking the read-write rate curve recorded by the monitoring and the feature paragraph in the same coordinate, and adjusting the phase difference, determining whether there is a paragraph overlapping or partially overlapping with the feature paragraph, if yes, marking the bit as a suspicious paragraph.
[0029] The substantial effect of the present application comprises: limiting the read-write rate, and monitoring the rate, so as to supervise by other nodes, which reduces the contact of other nodes to data, and enhances the data security of the whole system, and prevents the data leakage in unawareness. BRIEF DESCRIPTION OF DRAWINGS
[0030] Figure 1 is the flow chart of the embodiment of the present application. DETAILED DESCRIPTION
[0031] To make the purpose, technical scheme and advantages of the embodiments of the present application more clear, the technical scheme will be described clearly and completely in combination with embodiments, obviously, the described embodiments are only part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.
[0032] It should be understood that in various embodiments of the present application, the size of the serial number of each process does not mean the execution order, the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0033] It should be understood that in the present application, "including" and "having" and any variants thereof are intended to cover non-exclusive inclusion, for example, the process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0034] It should be understood that in the present application, "a plurality of" means two or more. "And / or" is only a description of the relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. The character " / " generally represents that the associated objects before and after are in an "or" relationship. "Including A, B and C", "including A, B, C" means that A, B and C are all included, "including A, B or C" means that one of A, B and C is included, and "including A, B and / or C" means that any one or any two or three of A, B and C is included.
[0035] The technical solutions of the present application will be described in detail below with specific examples. The examples can be combined with each other, and the same or similar concepts or processes can not be described in some examples.
[0036] Embodiment:
[0037] The data security transmission method based on the network management system of the network management system includes the following steps, as shown in the figure: Figure 1 The registered nodes are counted, and for any data to be transmitted, the starting point of transmission is the first node, the end point of transmission is the second node, and the remaining nodes are the third nodes.
[0038] A read-write speed limiting function is established to obtain the read-write speed limiting value according to the node number, and the read-write speed limiting value is limited in the data transmission process of the system. It includes:
[0039] The read-write speed limiting function is established:
[0040]
[0041] Wherein, v is the read-write speed limiting value, K is the data transmission coefficient with a value range of 0~1, a is the first node number, b is the second node number, V a is the read-write speed of the first node, V b is the read-write speed of the second node;
[0042] After the read-write speed limiting value is calculated, the corresponding read-write speed is limited according to the preset time interval.
[0043]
[0044] Wherein, the corresponding read-write speed is limited according to the preset time interval, including:
[0045] The preset time interval T and the duration t, wherein T is greater than t, and every T time, the read-write speed is limited to the read-write speed limiting value, and the process is repeated for t time, until the read-write is completed.
[0046] In this embodiment, in order to balance the read-write efficiency and highlight the characteristics, the rate is periodically limited, so that the read-write rate can generate a periodic rule, which is convenient for subsequent identification, and the read-write rate is still at the highest rate most of the time.
[0047] After the transmission is completed, the read-write rate curve of the first node and the second node is called, and the specified third node is forwarded.
[0048] The forwarding of the specified third node comprises:
[0049] The network link set P1 of the second node is determined, and the network link set P2 of the third node is determined.
[0050] It is judged whether P1 and P2 have an intersection, if there is, a third node is randomly selected from the network link of the intersection as the specified third node, if not, the specified third node is randomly selected from all third nodes.
[0051] The third node obtains the characteristic paragraph related to the current data transmission from the read-write rate curve of the first node and the second node according to the read-write speed limit value, comprising:
[0052] The periodic read-write rate change is found from the read-write rate curve.
[0053] If the period of the paragraph is T, it is further judged whether there is a read-write speed limit value v of t time in each period, if there is, the paragraph is a characteristic paragraph.
[0054] The third node monitors the read-write rate curve of the first node and / or the second node according to the preset rule, and judges whether there is a suspicious paragraph with a similarity to the characteristic paragraph reaching a threshold, comprising:
[0055] The preset rule is set, the monitoring is triggered when the read-write rate reaches the peak, and the read-write rate curve is recorded for at least 3T time; the read-write rate curve recorded by the monitoring is marked in the same coordinate as the characteristic paragraph, and the phase difference is adjusted, it is judged whether there is a paragraph overlapping or partially overlapping with the characteristic paragraph, if there is, the marked bit is marked as a suspicious paragraph.
[0056] If there is, the use record of the first node and / or the second node or the communication record of the network link is called, and it is judged whether there is data leakage.
[0057] The embodiment establishes a set of security protocols for data transmission between nodes, and the nodes need to be limited by the read-write speed limit value during data transmission. Since any data stealing method cannot be separated from reading and writing, the read-write rate curve of the node can be directly observed to see whether there is a read-write trace of related data, so the application can monitor the security of the data without the data itself, which will not interfere with the monitoring behavior and will not cause additional security risks.
[0058] The substantial effect of the embodiment includes: by limiting the read-write rate and monitoring the rate, the other nodes are supervised by other nodes, which reduces the contact of the other nodes with the data, and the data transmission and non-transmission are known in the form of data itself, which can enhance the data security of the whole system and prevent data leakage in the unaware state.
[0059] Through the description of the above embodiments, those skilled in the art can understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the specific device is divided into different functional modules to complete all or part of the functions described above.
[0060] In the embodiments provided in the present application, it should be understood that the disclosed structures and methods can be implemented in other ways. For example, the above-described embodiments of the structure are only illustrative, for example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another structure, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, structures or units, which can be electrical, mechanical or other forms.
[0061] The units described as separate components can or can not be physically separated, and the components displayed as units can be one physical unit or multiple physical units, that is, they can be located in one place or distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0062] In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or in the form of software functional unit.
[0063] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The software product is stored in a storage medium, including a plurality of instructions to make a device (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the various embodiments of the method of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0064] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data security transmission method based on a power distribution network management system, characterized in that, Includes the following steps: The registered nodes are counted. For any data that needs to be transmitted, the starting point of the transmission is the first node, the ending point of the transmission is the second node, and the remaining nodes are the third nodes. Establish a read / write rate limiting function to obtain the read / write rate limit value based on the node's ID. Nodes within the system limit the read / write rate limit value during any data transmission process. Read / write rate limiting function: Where v is the read / write rate limit, K is the data transfer coefficient ranging from 0 to 1, a is the first node number, and b is the second node number. For the first node, read and write speeds are extremely fast. The maximum read / write speed for the second node; once the read / write speed limit is calculated, the corresponding read / write rate is limited according to a preset time interval; After the transmission is completed, retrieve the read / write rate curves of the first and second nodes, and forward the data to the designated third node; The third node obtains the characteristic segments related to this data transmission from the read and write rate curves of the first and second nodes based on the read and write rate limit values; The third node monitors the read and write rate curves of the first and / or second nodes according to preset rules to determine whether there are any suspicious paragraphs whose similarity to the feature paragraphs reaches a threshold. If this occurs, retrieve the usage records of the first and / or second nodes or the communication records of the network links they belong to to determine if there is a data leak.
2. The data security transmission method based on the distribution network management system according to claim 1, characterized in that, The step of limiting the corresponding read / write rate according to a preset time interval includes: The preset time interval T and duration t are used, where T is greater than t. During read and write operations, the read and write rate is limited to the read and write rate limit value every T time interval for a duration of t. This process is repeated until the read and write operations are completed.
3. The data security transmission method based on the distribution network management system according to claim 1, characterized in that, The forwarding designation of a third node includes: Determine the network link set P1 of the second node, and determine the network link set P2 of the third node; Determine whether P1 and P2 have an intersection. If they do, randomly select a third node from the network links of the intersection as the specified third node. If they do not, randomly select the specified third node from all third nodes.
4. The data security transmission method based on the distribution network management system according to claim 2, characterized in that, The step of obtaining the characteristic segment related to this data transmission from the read / write rate curves of the first and second nodes based on the read / write rate limit value includes: Identify periodic changes in read and write rates from the read and write rate curves; If a segment has a period of T, then it is further determined whether there is a read / write rate limit value v for time t in each segment. If so, the segment is a characteristic segment.
5. The data security transmission method based on the distribution network management system according to claim 4, characterized in that, The step of monitoring the read / write rate curves of the first and / or second nodes according to preset rules to determine whether a suspicious paragraph with a similarity to the feature paragraph reaches a threshold includes: Set preset rules to trigger monitoring when the read / write rate reaches its peak, and continuously record the read / write rate curve for at least 3T of time; The read / write rate curves of the monitoring records are plotted on the same coordinate system as the characteristic segments, and the phase difference is adjusted to determine whether there are segments that overlap or partially overlap with the characteristic segments. If so, the segments are marked as suspicious.
Citation Information
Patent Citations
Method and device for adjusting read-write speed limit of disk of virtual machine and computing equipment
CN112783441A
Data transfer node, method and system and computer readable storage medium
CN112800026A