A power edge cloud network and its security protection method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-24
- Publication Date
- 2026-08-14
AI Technical Summary
而现有的基于汇聚节点的自愈机制的异常节点只能对少数网络攻击的早期阶段进行检测,并且通常缺乏计算和存储资源对异常原因进行精确的诊断
[0034]本发明由于采取以上技术方案,其具有以下优点:本发明申请方案中,电路边缘云网络中包括汇聚节点和边缘云中心,通过汇聚节点中的监督汇聚节点对其周边的待评估汇聚节点进行行为特征采集,并基于预设的监督机制对待评估汇聚节点进行信任计算,以识别出待评估汇聚节点中的异常节点,再将获取的异常节点的处理数据传输至边缘云中心,以供边缘云中心基于深度学习算法对异常原因进行诊断,从而实现基于云边协作机制,通过边缘云网络的汇聚节点的相互监督,快速地检测出其中的异常节点,再由边缘云中心对异常原因进行精确地诊断,从而有助于快速实现异常节点地修复,保证电力边缘云网络的安全工作。
Smart Images

Figure CN116437352B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication technology, and in particular to a power edge cloud network and its security protection method. Background Technology
[0002] Currently, power (5G) edge cloud networks address the limitations of traditional cloud computing by expanding computing and storage resources at the network edge, thereby better enabling network services for power system businesses.
[0003] However, the inventors of this application discovered in their research that aggregation nodes in power edge cloud networks typically encounter two types of risks. One risk is that aggregation nodes are usually deployed in outdoor environments, making them susceptible to physical damage from natural factors such as wind and heavy rain, thus rendering them unable to function normally. The other risk is that aggregation nodes, due to lack of oversight, are vulnerable to cyberattacks, thus becoming malicious nodes in the network and reducing the security of the power edge cloud. Therefore, quickly identifying abnormal nodes in the power edge cloud network and diagnosing the causes of these abnormalities is a necessary step in rapidly repairing abnormal nodes and maintaining the normal and secure operation of the network. Existing self-healing mechanisms based on aggregation nodes can only detect abnormal nodes in the early stages of a few network attacks and typically lack the computational and storage resources for accurate diagnosis of the causes of abnormalities. Summary of the Invention
[0004] To address the aforementioned problems, the present invention aims to provide a power edge cloud network and its security protection method. Based on a cloud-edge collaboration mechanism, abnormal nodes are quickly detected through mutual supervision of the aggregation nodes of the edge cloud network. The edge cloud center then performs accurate diagnosis of the cause of the abnormality, thereby facilitating the rapid repair of abnormal nodes and ensuring the safe operation of the power edge cloud network.
[0005] To achieve the above objectives, the present invention adopts the following technical solution:
[0006] In a first aspect, this application provides a security protection method for a power edge cloud network, the power edge cloud network including sensors for collecting business data, aggregation nodes for aggregating and processing the business data, and an edge cloud center for managing and controlling the entire power edge cloud network;
[0007] The method includes:
[0008] The supervising aggregation node in the aggregation node collects the behavioral characteristics of the surrounding aggregation nodes to be evaluated, and performs trust calculation on the aggregation nodes to be evaluated based on a preset supervision mechanism in order to identify abnormal nodes in the aggregation nodes to be evaluated.
[0009] The processing data of the abnormal node is acquired and transmitted to the edge cloud center so that the edge cloud center can diagnose the cause of the abnormality based on a deep learning algorithm.
[0010] In one implementation of this application, the supervising aggregation node in the aggregation node collects behavioral characteristics of its surrounding aggregation nodes to be evaluated, including:
[0011] The monitoring aggregation node collects the data transmission rate, data reception rate, data tampering rate, and physical damage flag of the aggregation node to be evaluated in each data transmission cycle.
[0012] In one implementation of this application, the trust calculation of the aggregation node to be evaluated based on a preset supervision mechanism includes:
[0013] Calculate the corresponding first trust value change amount based on the data transmission rate in each data transmission cycle;
[0014] Calculate the corresponding second trust value change based on the data reception rate in each data transmission cycle;
[0015] Calculate the corresponding third trust value change amount based on the data tampering rate in each data transmission cycle;
[0016] Based on the calculated changes in the first trust value, the second trust value, and the third trust value, the historical trust value of the previous period for each data transmission period is updated to obtain the final trust value for each data transmission period.
[0017] In one implementation of this application, the step of calculating the corresponding first trust value change based on the data transmission rate in each data transmission cycle includes:
[0018] Based on the data transmission rate in each data transmission cycle, the corresponding first trust value change is calculated using a preset first exponential function;
[0019] The step of calculating the corresponding second trust value change based on the data reception rate in each data transmission cycle includes:
[0020] Based on the data reception rate in each data transmission cycle, the corresponding change in the second trust value is calculated using a preset second exponential function.
[0021] In one implementation of this application, both the first exponential function and the second exponential function are gaussmf functions.
[0022] In one implementation of this application, the step of calculating the corresponding third trust value change amount based on the data tampering rate in each data transmission cycle includes:
[0023] Based on the data tampering rate in each data transmission cycle, the corresponding change amount of the third trust value is calculated using a preset third linear function.
[0024] In one implementation of this application, the third linear function is specifically a negatively correlated linear function.
[0025] In one implementation of this application, the step of identifying abnormal nodes among the aggregation nodes to be evaluated includes:
[0026] Based on the final trust value of each data transmission cycle and the physical damage flag, it is determined whether the aggregation node to be evaluated is an abnormal node.
[0027] In one implementation of this application, the edge cloud center diagnoses the causes of anomalies based on a deep learning algorithm, including:
[0028] The edge cloud center acquires the data packet stream of the abnormal node and separates the abnormal data packets based on a machine learning classification algorithm;
[0029] The edge cloud center classifies the causes of anomalies in the input abnormal data packets based on a neural network model.
[0030] Secondly, this application provides a power edge cloud network, including sensors for collecting business data, aggregation nodes for processing the business data, and an edge cloud center for managing and controlling the entire power edge cloud network.
[0031] The aggregation nodes include monitoring aggregation nodes and aggregation nodes to be evaluated;
[0032] The monitoring aggregation node is used to collect behavioral characteristics of the surrounding aggregation nodes to be evaluated, and to perform trust calculation on the aggregation nodes to be evaluated based on a preset monitoring mechanism, so as to identify abnormal nodes in the aggregation nodes to be evaluated, and to transmit the processing data of the acquired abnormal nodes to the edge cloud center.
[0033] The edge cloud center is used to diagnose the causes of anomalies based on deep learning algorithms.
[0034] The present invention has the following advantages due to the adoption of the above technical solutions: In the solution of the present invention, the circuit edge cloud network includes a convergence node and an edge cloud center. The supervising convergence node in the convergence node collects the behavioral characteristics of the surrounding convergence nodes to be evaluated, and performs trust calculation on the convergence nodes to be evaluated based on a preset supervision mechanism to identify abnormal nodes in the convergence nodes to be evaluated. Then, the processing data of the acquired abnormal nodes is transmitted to the edge cloud center, so that the edge cloud center can diagnose the cause of the abnormality based on a deep learning algorithm. This realizes the rapid detection of abnormal nodes based on the cloud-edge collaboration mechanism through the mutual supervision of the convergence nodes of the edge cloud network. Then, the edge cloud center accurately diagnoses the cause of the abnormality, which helps to quickly repair abnormal nodes and ensure the safe operation of the power edge cloud network. Attached Figure Description
[0035] Figure 1 This is a schematic diagram of a power edge cloud network architecture provided in an embodiment of this application;
[0036] Figure 2 This is a flowchart illustrating a security protection method for a power edge cloud network provided in an embodiment of this application;
[0037] Figure 3 This is a schematic diagram of the change in trust value corresponding to the data reception / transmission rate in the embodiments of this application;
[0038] Figure 4 This is a schematic diagram of the curve representing the change in trust value corresponding to the data tampering rate in the embodiments of this application;
[0039] Figure 5 This is a schematic diagram of the data flow at the edge cloud center in an embodiment of this application. Detailed Implementation
[0040] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the described embodiments of the present invention are within the scope of protection of the present invention.
[0041] To address the technical problem that existing self-healing mechanisms for aggregation nodes can only detect a few early stages of network attacks and often lack the computational and storage resources for accurate diagnosis of anomalies, this application provides a power edge cloud network and its security protection method. The power edge cloud network includes sensors that collect service data, aggregation nodes that aggregate and process the service data, and an edge cloud center that manages and controls the entire power edge cloud network. The method includes: a supervisory aggregation node in the aggregation nodes collects behavioral characteristics of surrounding aggregation nodes to be evaluated, and performs trust calculations on the aggregation nodes to be evaluated based on a preset supervisory mechanism to identify abnormal nodes; the processing data of the abnormal nodes is then transmitted to the edge cloud center for diagnosis of the anomaly based on a deep learning algorithm. This application, based on a cloud-edge collaboration mechanism, rapidly detects abnormal nodes through mutual supervision of the aggregation nodes in the edge cloud network, and then the edge cloud center accurately diagnoses the cause of the anomaly, thereby facilitating rapid repair of abnormal nodes and ensuring the secure operation of the power edge cloud network.
[0042] See Figure 1 In one embodiment of this application, a network architecture for a power edge cloud is provided.
[0043] In the embodiments of this application, the power edge cloud network can be divided into three layers: a sensor layer, a aggregation node layer, and a cloud center layer. The bottom layer is the sensor layer, where sensors are responsible for collecting data for various services in the power 5G edge cloud and sending the collected data to their respective aggregation nodes for further processing. The second layer of the network architecture is the aggregation node layer, where each aggregation node evaluates the uploaded data from its assigned sensors and chooses to perform local computation or offload the data to other aggregation nodes. The top layer of the network architecture is the cloud center layer, where the edge cloud center has sufficient computing and storage resources to perform complex computational tasks offloaded by the aggregation nodes, and can also support various machine learning detection models with high storage requirements.
[0044] In the embodiments disclosed in this application, since the aggregation nodes in the second layer of the network architecture are at risk of physical damage or malicious attacks, hindering the normal operation of the power 5G edge cloud, it is necessary to design an abnormal node detection scheme at the aggregation node layer to quickly identify abnormal nodes and record them using blockchain to ensure the security and immutability of the detection results. Simultaneously, the abnormal data is sent to the edge cloud central layer to utilize a more accurate machine learning detection model for further anomaly identification.
[0045] Corresponding to Figure 1In this application, based on the network architecture, a security protection method for a power edge cloud network is provided, including:
[0046] S21, the supervising aggregation node in the aggregation node collects the behavioral characteristics of the surrounding aggregation nodes to be evaluated, and performs trust calculation on the aggregation nodes to be evaluated based on a preset supervision mechanism, so as to identify abnormal nodes in the aggregation nodes to be evaluated.
[0047] S22, the processing data of the abnormal node is acquired and transmitted to the edge cloud center so that the edge cloud center can diagnose the cause of the abnormality based on a deep learning algorithm.
[0048] In the above embodiments of this application, the circuit edge cloud network includes a convergence node and an edge cloud center. The supervising convergence node in the convergence node collects the behavioral characteristics of the surrounding convergence nodes to be evaluated, and performs trust calculation on the convergence nodes to be evaluated based on a preset supervision mechanism to identify abnormal nodes in the convergence nodes to be evaluated. Then, the processing data of the acquired abnormal nodes is transmitted to the edge cloud center, so that the edge cloud center can diagnose the cause of the abnormality based on a deep learning algorithm. This realizes that based on the cloud-edge collaboration mechanism, through the mutual supervision of the convergence nodes of the edge cloud network, abnormal nodes can be quickly detected, and the edge cloud center can accurately diagnose the cause of the abnormality, which helps to quickly repair abnormal nodes and ensure the safe operation of the power edge cloud network.
[0049] The workflow of the above method will be described below in a more detailed embodiment of this application with reference to more accompanying drawings, and the advantages of this application will be explained in conjunction with specific calculation parameters.
[0050] This application provides a security protection method for a power edge cloud network, including:
[0051] S21, the supervising aggregation node in the aggregation node collects the behavioral characteristics of the surrounding aggregation nodes to be evaluated, and performs trust calculation on the aggregation nodes to be evaluated based on a preset supervision mechanism, so as to identify abnormal nodes in the aggregation nodes to be evaluated.
[0052] Specifically, in this embodiment, the aggregation nodes in the power 5G edge cloud network can evaluate each other's communication service quality through communication interactions, achieving mutual supervision based on these evaluations. When one aggregation node evaluates the quality of another, the former is called the supervising aggregation node, and the latter is called the node to be evaluated. In this embodiment, because supervision is mutual, the node to be evaluated can also evaluate the supervising aggregation node; the principle is similar, and will not be repeated in detail here.
[0053] In one embodiment of this application, the supervising aggregation node in the aggregation node collects behavioral characteristics of its surrounding aggregation nodes to be evaluated, including:
[0054] The monitoring aggregation node collects the data transmission rate, data reception rate, data tampering rate, and physical damage flag of the aggregation node to be evaluated in each data transmission cycle.
[0055] The specific details of collecting the aforementioned behavioral characteristic data are as follows:
[0056] (1) Data transmission rate
[0057] Because the service data collected by each sensor in the power 5G edge cloud is relatively fixed, and the locations of the sensors and the aggregation node are also relatively fixed, the number of data packets sent by the aggregation node in each data transmission cycle will not fluctuate significantly. By monitoring the data transmission rate of an aggregation node, network intrusion behaviors such as Distributed Denial of Service (DDoS) attacks and replay attacks can be quickly detected.
[0058] At the end of each data transmission cycle, the aggregation node i records the data for this cycle t. n The number of data packets sent by the aggregation node to be evaluated that interacts with itself. Therefore, at the end of a data transmission cycle, aggregation node i can compare the number of data packets sent by aggregation node j in the same cycle t. n The number of data packets sent within the period t compared to the previous period t n-1 The number of data packets sent within the node is used to evaluate whether the data sending rate of the aggregation node j to be evaluated is normal. The Data Sending Rate (DSR) is defined as follows:
[0059]
[0060] DSR i,j (t n ) is in this period t nWithin, the evaluation result of the data transmission rate of aggregation node i to aggregation node j. S j (t n ) is in this period t n Within, the number of data packets sent from sink node j to sink node i. S j (t n-1 ) is the number of data packets that aggregation node j sent to aggregation node i during the previous data transmission cycle.
[0061] (2) Data reception rate
[0062] Similar to data transmission rate, the number of data packets received by aggregation nodes in the power 5G edge cloud is relatively fixed in each data transmission cycle due to their relatively fixed services and locations. The number of data packets received by the aggregation nodes to be evaluated can be counted using an Acknowledgement Character (ACK) mechanism. Whenever aggregation node i sends a data packet to node j to be evaluated, whether aggregation node j successfully received the data packet is determined by whether it received an ACK data packet. Monitoring the data reception rate of the aggregation nodes to be evaluated can quickly detect network intrusion behaviors such as packet loss attacks.
[0063] In each data transmission cycle, sink node i determines the number of data packets received from sink node j (to be evaluated) by the received ACK data packets, and performs a statistical analysis at the end of each transmission cycle. This is done by calculating the number of data packets received in cycle t. n The number of ACK packets received from the sink node j to be evaluated within the current period, compared with the previous period t. n-1 The number of ACK packets received from the aggregation node j to be evaluated is compared to determine whether the data reception rate of the aggregation node j is normal. The Data Received Rate (DRR) is defined as follows:
[0064]
[0065] DRR i,j (t n ) is in this period t n Within, the evaluation result of the data reception rate of aggregation node i to aggregation node j. R j (t n ) is in this period t n Within R, the number of ACK packets received by sink node i from sink node j. j (t n-1 ) is the number of ACK packets received by sink node i from sink node j during the previous data transmission cycle.
[0066] (3) Data tampering rate
[0067] During the operation of the power 5G edge cloud network, there is a possibility that aggregation nodes may be captured or attacked, thus becoming malicious nodes. To prevent malicious nodes from tampering with received data packets, anti-tampering supervision between aggregation nodes can be implemented through random data packet inspection. When a data packet passes through both the aggregation node to be evaluated and the supervising aggregation node, the supervising aggregation node can compare the content of the data packet to determine whether the aggregation node to be evaluated has engaged in malicious data packet tampering, thereby quickly detecting network attacks such as Man-in-the-Middle Attack (MITM).
[0068] In each transmission cycle t n In the process, every time aggregation node i receives a certain number m data packets from aggregation node j to be evaluated, it will send a data packet request signal to the upstream IoT node k of aggregation node j to request the (m+1)th data packet p from IoT node k. k and the data packet p k and the (m+1)th data packet p received from the aggregation node j to be evaluated j Compare, if data packet p k With p j If the discrepancy exceeds the normal error rate range, the aggregation node j under evaluation is considered to have tampered with data packets, and it will be continuously monitored for a period of time. The Data Tampering Rate (DTR) is defined as follows:
[0069]
[0070] DTR i,j (t n ) is in this period t n Within, the evaluation result of the data tampering rate of aggregation node i with respect to aggregation node j. In this period t n Within, the number of tampered data packets received by aggregation node i from aggregation node j. In this period t n Within, the total number of data packets received by aggregation node i from aggregation node j.
[0071] (4) Physical damage indicator
[0072] Because the aggregation nodes are deployed in outdoor environments, they are at risk of damage from external forces. Physical damage to the aggregation node can negatively impact the normal operation of the power 5G edge cloud. For example, if the aggregation node is physically damaged, other devices may experience prolonged periods of unresponsive service requests, or provide other nodes with significantly abnormal data. Upon detecting severe abnormal behavior in aggregation node i due to physical damage, surrounding nodes will directly reset its trust value to zero, as defined below:
[0073]
[0074] SAB i,j (t n ) represents the physical damage flag information of the node, SAB i,j (t n A value of 1 indicates that the node exhibits severe abnormal behavior due to physical damage. (SAB) i,j (t n A value of 0 indicates that the node is functioning normally.
[0075] Furthermore, in this embodiment, the supervisory aggregation node assesses the trust value of the aggregation node to be evaluated based on the collected behavioral characteristic data. To quickly detect abnormal nodes while reducing the false detection rate, a combination of historical and current trust values is used to screen abnormal nodes. If a node's trust value temporarily decreases due to short-term data volume fluctuations, it will gradually recover after the data transmission cycle returns to normal. If it is indeed an abnormal node with malicious behavior, its trust value will drop sharply after each transmission cycle, eventually triggering an alarm when it falls below a preset threshold.
[0076] The trust value assessment of the aggregation node is mainly based on the four dimensions described above: data reception rate, data transmission rate, data tampering rate, and physical damage flag. Specifically, in each data transmission cycle t... n The data reception rate and data transmission rate within the current period relative to the previous data transmission cycle t n-1 For this purpose, both excessively high and excessively low values are considered abnormal. Therefore, the gaussmf function is used to calculate the trust values of the data acceptance rate and data transmission rate of the aggregation node to be evaluated, as defined below:
[0077]
[0078]
[0079] TV receive (t n TV send (t n ) represent the transmission period t respectively nThe internal supervision aggregation node i evaluates the trust value of the aggregation node j to be evaluated regarding the data reception and transmission rates. C represents the mean in the Gaussian Method function, and σ represents the standard deviation in the Gaussian Method function. Figure 3 The diagram illustrates the recognition curve corresponding to the data transmission / reception rate of an exponential function with a specific parameter value.
[0080] The assessment of the data tampering rate of the aggregation node under evaluation is based on the comparison of two data packets received by the monitoring aggregation node. Generally, a difference of less than 10% is considered normal. If the difference between the two data packets exceeds 10%, the aggregation node under evaluation is suspected of tampering with data packets, and the trust value will decrease linearly, as defined below:
[0081] TV tamper(i,j) (t n )=1-2DTR i,j (t n (7)
[0082] TV tamper (t n ) represents the transmission period t n Within the framework, the trust value evaluation result of the monitoring aggregation node i for the data tampering rate of the aggregation node j to be evaluated is shown in the curve below. Figure 4 As shown.
[0083] The single-time trust value evaluation results of the data acceptance rate, data transmission rate, and data tampering rate of the node to be evaluated in each transmission cycle are combined with the historical evaluation results to obtain the final trust value evaluation results of the aggregation node to be evaluated this week for the three behavioral characteristic dimensions, defined as follows:
[0084]
[0085]
[0086]
[0087] in These represent the monitoring of aggregation node i and the evaluation of aggregation node j during transmission period t. n The final trust value evaluation result is based on the internal data acceptance rate, data transmission rate, and data tampering rate. If any of the three trust values is lower than 0.5, it indicates that the node is engaging in malicious behavior, triggering an alarm and isolating the node, as defined below:
[0088]
[0089]
[0090]
[0091] The three trust values are ultimately to be evaluated by the node during transmission period t. n Whether a node is considered abnormal is determined by the evaluation results of three trust values and the presence of serious abnormal behavior, as defined below:
[0092]
[0093] in This indicates that the monitoring aggregation node i is related to the aggregation node j to be evaluated during the transmission period t. n The final total trust rating within, if This indicates that the aggregation node j to be evaluated is a normal node; This indicates that the aggregation node j to be evaluated is an abnormal node.
[0094] S22, the processing data of the abnormal node is acquired and transmitted to the edge cloud center so that the edge cloud center can diagnose the cause of the abnormality based on a deep learning algorithm.
[0095] Specifically, in this embodiment, the aggregation node trust assessment at the aggregation node layer can quickly detect abnormal aggregation nodes. However, since this detection algorithm relies on a detection alarm threshold, it is prone to frequent false detections when the alarm threshold is too high and to missed detections when the threshold is too low, thus having certain limitations. Therefore, this application deploys an abnormal data stream detection algorithm based on machine learning and neural networks in the edge cloud center, where computing resources are more abundant, to further identify abnormal nodes detected by the aggregation node layer assessment algorithm, ensuring the accuracy of the system's anomaly detection.
[0096] After the trust evaluation algorithm determines that a certain aggregation node is suspected of being abnormal, surrounding nodes temporarily isolate it, no longer trusting its calculation results, command parameters, etc., and sending data packets received from the suspected abnormal node to the edge cloud center for anomaly detection via multi-hop transmission. Figure 5 As shown, for data packets received from suspected abnormal aggregation nodes, the edge cloud first uses the J48 machine learning algorithm to perform preliminary screening and classification, selecting abnormal data packets. After separating benign and abnormal data packets, the separated abnormal data packets are used to extract features from these abnormal data packets using a time-dimensional sliding window, and then the GRU neural network detection algorithm is used for fine detection to determine the cause of the abnormality of the abnormal node.
[0097] In summary, the method provided in this application embodiment includes a power edge cloud network comprising aggregation nodes and an edge cloud center. The aggregation nodes, through a supervisory aggregation node, collect behavioral characteristics of surrounding aggregation nodes to be evaluated. Based on a preset supervisory mechanism, trust calculations are performed on the aggregation nodes to be evaluated to identify abnormal nodes. The acquired processing data of the abnormal nodes is then transmitted to the edge cloud center, where it uses a deep learning algorithm to diagnose the cause of the anomaly. This achieves a cloud-edge collaboration mechanism, enabling rapid detection of abnormal nodes through mutual supervision of the aggregation nodes in the edge cloud network. The edge cloud center then accurately diagnoses the cause of the anomaly, facilitating rapid repair of abnormal nodes and ensuring the safe operation of the power edge cloud network.
[0098] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0099] In the embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units through some interfaces, and may be electrical, mechanical, or other forms.
[0100] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0101] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A security protection method for power edge cloud networks, characterized in that, The power edge cloud network includes sensors that collect service data, aggregation nodes that aggregate and process the service data, and an edge cloud center that manages and controls the entire power edge cloud network. The method includes: The supervising aggregation node in the aggregation node collects the behavioral characteristics of the surrounding aggregation nodes to be evaluated, and performs trust calculation on the aggregation nodes to be evaluated based on a preset supervision mechanism in order to identify abnormal nodes in the aggregation nodes to be evaluated. The processing data of the abnormal node is acquired and transmitted to the edge cloud center so that the edge cloud center can diagnose the cause of the abnormality based on a deep learning algorithm; The supervisory aggregation node in the aggregation node collects behavioral characteristics of the surrounding aggregation nodes to be evaluated, including: the supervisory aggregation node collects the data transmission rate, data reception rate, data tampering rate, and physical damage flag of the aggregation nodes to be evaluated in each data transmission cycle; The trust calculation of the aggregation node to be evaluated based on the preset supervision mechanism includes: calculating the corresponding first trust value change amount according to the data transmission rate in each data transmission cycle; calculating the corresponding second trust value change amount according to the data reception rate in each data transmission cycle; calculating the corresponding third trust value change amount according to the data tampering rate in each data transmission cycle; updating the historical trust value of the previous cycle of each data transmission cycle according to the calculated first trust value change amount, second trust value change amount, and third trust value change amount to obtain the final trust value of each data transmission cycle; The step of calculating the corresponding first trust value change based on the data transmission rate in each data transmission cycle includes: calculating the corresponding first trust value change based on the data transmission rate in each data transmission cycle using a preset first exponential function; The step of calculating the corresponding second trust value change based on the data reception rate in each data transmission cycle includes: calculating the corresponding second trust value change using a preset second exponential function based on the data reception rate in each data transmission cycle. Both the first exponential function and the second exponential function are Gaussmf functions; The step of calculating the corresponding third trust value change based on the data tampering rate in each data transmission cycle includes: calculating the corresponding third trust value change using a preset third linear function based on the data tampering rate in each data transmission cycle; the third linear function is specifically a negative correlation linear function; The step of identifying abnormal nodes among the aggregation nodes to be evaluated includes: determining whether the aggregation node to be evaluated is an abnormal node based on the final trust value of each data transmission cycle and the physical damage flag bit.
2. The security protection method for power edge cloud networks according to claim 1, characterized in that, The edge cloud center diagnoses the causes of anomalies based on deep learning algorithms, including: The edge cloud center acquires the data packet stream of the abnormal node and separates the abnormal data packets based on a machine learning classification algorithm; The edge cloud center classifies the causes of anomalies in the input abnormal data packets based on a neural network model.
3. A power edge cloud network, used to implement the security protection method for the power edge cloud network as described in any one of claims 1 to 2, characterized in that, It includes sensors that collect business data, aggregation nodes that aggregate and process the business data, and an edge cloud center that manages and controls the entire power edge cloud network. The aggregation nodes include monitoring aggregation nodes and aggregation nodes to be evaluated; The monitoring aggregation node is used to collect behavioral characteristics of the surrounding aggregation nodes to be evaluated, and to perform trust calculation on the aggregation nodes to be evaluated based on a preset monitoring mechanism, so as to identify abnormal nodes in the aggregation nodes to be evaluated, and to transmit the processing data of the acquired abnormal nodes to the edge cloud center. The edge cloud center is used to diagnose the causes of anomalies based on deep learning algorithms.