A blockchain-based virtual power plant data security protection method

CN116756772BActive Publication Date: 2026-09-29SHENZHEN POWER SUPPLY BUREAU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310776740.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-28
Publication Date
2026-09-29
Estimated Expiration
2043-06-28

AI Technical Summary

Technical Problem

在现有技术中主要采用密钥加密数据的方式保障数据的安全性,从而导致数据存在被非法入侵的可能

Benefits of technology

[0070]本发明提供的一种基于区块链的虚拟电厂数据安全防护方法,先通过混合加密策略对数据进行加密,既能够保障数据的隐私性,又能够保证数据的加密效率;其次通过构建边缘服务器与电网侧管理系统进行通信,可以利用边缘服务器的计算能力对数据进行预处理,可以有效地提高数据质量,并且不允许虚拟电厂节点或者其他用户直接访问电网侧管理系统,可以有效地降低被攻击的风险;然后在数据下发至虚拟电厂节点的过程中,获取防篡改数据以及泄密溯源数据,结合区块链不可篡改的特征,实现数据的防篡改以及泄密的溯源,从而进一步地保证了数据的安全性;最后,在电网侧管理系统进行通信的过程中,采用由融合优化算法训练的入侵分析模型进行入侵检测分析,可以避免非法设备伪装成边缘服务器进行非法操作,同时融合优化算法也能够使入侵分析模型训练效果更佳,从而具备较好的入侵检测分析能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116756772B_ABST
    Figure CN116756772B_ABST
Patent Text Reader

Abstract

The application discloses a kind of virtual power plant data security protection methods based on block chain, first by hybrid encryption strategy to the data encryption, both can guarantee the privacy of data, can also guarantee the encryption efficiency of data;Then in the process of data issuing to virtual power plant node, obtain tamper-proof data and leak trace data, in combination with the characteristics that block chain is inalterable, realize the trace of data tamper-proof and leak, to further guarantee the security of data;Finally, in the process of communication in grid side management system, using the intrusion analysis model trained by fusion optimization algorithm carries out intrusion detection analysis, can avoid illegal equipment disguised as edge server to carry out illegal operation, and fusion optimization algorithm can also make the training effect of intrusion analysis model better, to have better intrusion detection analysis ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of virtual power plant data security protection technology, specifically to a blockchain-based method for virtual power plant data security protection. Background Technology

[0002] Virtual power plants (VPPs) are a key technology for realizing smart distribution networks. They refer to the integration of dispersed clean energy sources, controllable loads, and energy storage systems within a distribution network into a single, specialized power plant, thus effectively reconciling the conflicts between smart grids and distributed energy resources and fully leveraging the value and benefits that distributed energy brings to the grid and users.

[0003] During the operation of a virtual power plant, it is often necessary to report electricity consumption data to the grid-side management system, access data from the grid-side management system, or receive instructions from the grid-side management system to the virtual power plant. All these processes involve data interaction. Current technologies primarily use key encryption to ensure data security, which leaves the data vulnerable to unauthorized intrusion. Furthermore, once data is illegally altered, the breach cannot be detected promptly; and when data is leaked, the user who leaked the data cannot be effectively traced, thus compromising data security. Summary of the Invention

[0004] The purpose of this invention is to provide a data security protection method for virtual power plants based on blockchain, which solves the problems existing in the prior art.

[0005] This invention is achieved through the following technical solution:

[0006] A blockchain-based method for protecting the data security of a virtual power plant is applied to a data security protection system for a virtual power plant, comprising virtual power plant nodes, edge servers, a blockchain, and a grid-side management system, including:

[0007] The encryption parameters are initialized through the grid-side management system and distributed to the virtual power plant nodes and edge servers to complete the system initialization. Based on the system initialization, the virtual power plant data on the virtual power plant nodes is transmitted to the edge servers through a hybrid encryption algorithm according to the encryption parameters.

[0008] The virtual power plant data is preprocessed by the edge server to obtain preprocessed virtual power plant data. The preprocessed virtual power plant data is then encrypted according to the encryption parameters to obtain encrypted virtual power plant data. The encrypted virtual power plant data is then transmitted to the grid-side management system for storage.

[0009] After the grid-side management system receives and stores the encrypted virtual power plant data, it receives the data response request sent by the virtual power plant node through the edge server, and requests the target data in the grid-side management system according to the data response request.

[0010] The power grid-side management system processes data response requests to obtain target data, user characteristic information corresponding to the target data, and anti-tampering data corresponding to the target data. Simultaneously, an intrusion detection analysis model trained by a fusion optimization algorithm is used to perform intrusion analysis and obtain intrusion analysis results, including whether the data has been intruded or not.

[0011] When the intrusion analysis result indicates that an intrusion has occurred, the transmission of the target data is stopped, and the data response process ends; when the intrusion analysis result indicates that no intrusion has occurred, the target data is transmitted to the edge server, and the tamper-proof data and the user characteristic information corresponding to the target data are published in the blockchain to prevent tampering and facilitate leakage tracing.

[0012] The target data is received by the edge server and forwarded to the virtual power plant node. At the same time, the virtual power plant node obtains tamper-proof data from the blockchain so that the virtual power plant node can verify and use the target data based on the tamper-proof data.

[0013] In one possible implementation, the encryption parameters are initialized through the grid-side management system and distributed to the virtual power plant nodes and edge servers to complete system initialization, including:

[0014] Initialize the first public key and the first private key corresponding to the virtual power plant node, initialize the second public key and the second private key corresponding to the edge server, initialize the third public key and the third private key corresponding to the power grid management system, and publish the first public key, the second public key and the third public key to the blockchain;

[0015] Initialize the symmetric key of the virtual power plant node, and update the symmetric key once every fixed period.

[0016] In one possible implementation, based on system initialization, and according to encryption parameters, the virtual power plant data on the virtual power plant node is transmitted to the edge server using a hybrid encryption algorithm, including:

[0017] Based on the system initialization, the virtual power plant data is encrypted using a virtual power plant node and a symmetric key to obtain the first encrypted data;

[0018] Obtain the second public key from the blockchain, use the second public key to encrypt the symmetric key to obtain the first encryption key, and transmit the first encrypted data and the first encryption key together to the edge server.

[0019] In one possible implementation, the virtual power plant data is preprocessed by an edge server to obtain preprocessed virtual power plant data. The preprocessed virtual power plant data is then encrypted according to the encryption parameters to obtain encrypted virtual power plant data. This encrypted virtual power plant data is then transmitted to the grid-side management system for storage, including:

[0020] The first encryption key is decrypted using the second private key in the edge server to obtain the symmetric key;

[0021] Based on the symmetric key, the first encrypted data is decrypted to obtain virtual power plant data;

[0022] The virtual power plant data is processed to remove duplicate values, missing values, and outliers, resulting in preprocessed virtual power plant data.

[0023] The preprocessed virtual power plant data is encrypted using a symmetric key to obtain encrypted virtual power plant data. A third public key is obtained from the blockchain and used to encrypt the symmetric key to obtain a second encryption key. The encrypted virtual power plant data and the second encryption key are then transmitted to the grid-side management system.

[0024] The second encryption key is decrypted using the grid-side management system and the third private key stored in the grid-side management system to obtain the symmetric key; the encrypted virtual power plant data is then decrypted using the symmetric key to obtain preprocessed virtual power plant data, and the preprocessed virtual power plant data is stored.

[0025] In one possible implementation, the data response request is processed by the power grid-side management system to obtain the target data, the user characteristic information corresponding to the target data, and the tamper-proof data corresponding to the target data, including:

[0026] The target data is obtained by identifying the data corresponding to the data response request from the stored virtual power plant data through the grid-side management system.

[0027] Add features to the target data to obtain the user feature information corresponding to the target data; encrypt the target data containing the user feature information using a symmetric key to obtain encrypted target data;

[0028] Obtain the hash value of the target data and encrypt the hash value using the first public key to obtain tamper-proof data.

[0029] In one possible implementation, an intrusion detection analysis model trained by a fusion optimization algorithm is used to obtain intrusion analysis results, including:

[0030] Historical traffic characteristic data and the corresponding intrusion analysis results are obtained, wherein the historical traffic characteristic data and the corresponding intrusion analysis results are pre-stored data;

[0031] An intrusion analysis model is constructed by using a convolutional neural network. Based on historical traffic feature data and the intrusion analysis results corresponding to the historical traffic feature data, the intrusion analysis model is trained using a fusion optimization algorithm to obtain the trained intrusion analysis model.

[0032] The system acquires real-time traffic data that processes data response requests and uses a trained intrusion analysis model to identify the real-time traffic data, thereby obtaining intrusion analysis results.

[0033] In one possible implementation, based on historical traffic characteristic data and the intrusion analysis results corresponding to the historical traffic characteristic data, and using a fusion optimization algorithm to train the intrusion analysis model, a trained intrusion analysis model is obtained, including:

[0034] A1. Set the iteration counter t = 1 and the maximum number of iterations to T. max Individual lower limit of parameter S min And the individual lower limit of parameter S max ;

[0035] A2. Use chaotic sequences or random generation of network parameters for the intrusion analysis model to obtain individual parameters, and obtain multiple individual parameters to form a population;

[0036] A3. Perform the first guiding update on each parameter individual in the population to obtain the first updated individual;

[0037] A4. Perform a second guided update on each parameter individual in the population to obtain the second updated individual;

[0038] A5. Determine whether the fitness value of the first updated individual is greater than the fitness value of the second updated individual. If yes, proceed to step A6; otherwise, proceed to step A7.

[0039] A6. Determine whether the fitness value of the parameter individual is greater than the fitness value of the first updated individual corresponding to the parameter individual. If yes, keep the parameter individual unchanged and proceed to step A8. Otherwise, replace the corresponding parameter individual with the first updated individual and proceed to step A9.

[0040] A7. Determine whether the fitness value of the parameter individual is greater than the fitness value of the second updated individual corresponding to the parameter individual. If yes, keep the parameter individual unchanged and proceed to step A8. Otherwise, replace the corresponding parameter individual with the second updated individual and proceed to step A9.

[0041] A8. Use a survival-of-the-fittest mechanism to perform spatial search and update the parameters of individuals in the population to obtain the updated population;

[0042] A9. Use an elite strategy to rapidly expand the updated population, and determine whether the number of parameter individuals in the updated population is greater than the lower limit S of parameter individuals. max If so, then generate [SS] max SS min The random number L in the population is used to eliminate the L individuals with the smallest fitness value in the population, where S represents the number of individuals with the parameter in the updated population;

[0043] A10. Determine whether the count value of the iteration counter t is greater than the maximum number of iterations, T. max Alternatively, if there is an individual in the updated population whose fitness value is greater than the preset fitness threshold, then the update ends and the individual with the largest fitness value is taken as the final network parameter of the intrusion detection model; otherwise, the iteration counter t is incremented by one and the process returns to step A3.

[0044] In one possible implementation, a first guided update is performed on each parameter individual in the population to obtain a first updated individual, including:

[0045]

[0046]

[0047]

[0048] in, Let i represent the i-th parameter individual in the population during the t-th training iteration, where i = 1, 2, ..., I, and I represents the total number of parameter individuals. Indicates the updated That is, the first updated individual; ζ1 represents the first intermediate parameter, n f Representation and parameter individuals The distance between two neighboring parameter individuals within a distance threshold. This represents individuals in the population excluding the parameter. Other individual parameters besides Indicates the center position among the neighboring parameter individuals. The fitness value represents the center position, and δ represents the decision factor. Represents individual parameters The fitness value, rand represents a random number between (0,1), and step t This represents the update step size during the t-th training iteration. This represents the individual with the highest fitness value in the current population, step.t-1 represents the update step size at the (t-1)th training iteration, and β represents the step size adjustment factor;

[0049] For each parameter individual in the population, a second guided update is performed to obtain the second updated individual, including:

[0050]

[0051]

[0052] Where ζ2 represents the second intermediate parameter, This represents the locally optimal individual with the highest fitness value among its neighboring individuals.

[0053] A survival-of-the-fittest mechanism is used to spatially search and update the parameters of individuals in the population, resulting in an updated population, including:

[0054] B1. Set the maximum number of space search updates to P;

[0055] B2. Perform a spatial search update on the parameter individuals in the population as follows:

[0056]

[0057]

[0058] Where ζ3 represents the third intermediate parameter, Representation and parameter individuals A random individual among all neighboring parameter individuals within a distance threshold. Represents individual parameters The next state,

[0059] B3. Determine whether the fitness value of the parameter individual after the spatial search update is greater than the fitness value before the spatial search update. If so, accept the spatial search update and update the entire parameter individual. Otherwise, proceed to step B4.

[0060] B4. Determine whether the number of searches has reached the maximum number of spatial search updates P. If so, randomly perturb the individual parameters and update the random perturbation using the roulette wheel algorithm and the set receiving probability. Otherwise, return to step B2.

[0061] B5. Update the parameters of individuals in the population according to the methods described in steps B2-B4 to obtain the updated population.

[0062] In one possible implementation, after publishing the tamper-proof data and the user characteristic information corresponding to the target data to the blockchain, the method further includes:

[0063] Acquire leaked data, which was generated by human-computer interaction;

[0064] Extract user feature information from the leaked data, and use this user feature information to match in the blockchain to obtain target user feature information, wherein the target user feature information is either empty or not empty;

[0065] When the target user feature information is not empty, the virtual power plant node corresponding to the target user feature information is used as the leakage node to complete the leakage tracing.

[0066] In one possible implementation, target data is received via an edge server and forwarded to a virtual power plant node. Simultaneously, the virtual power plant node retrieves tamper-proof data from the blockchain, enabling the virtual power plant node to verify and use the target data based on the tamper-proof data. This includes:

[0067] The target data is received through the edge server and forwarded to the virtual power plant node. At the same time, the tamper-proof data is obtained from the blockchain through the virtual power plant node.

[0068] The real-time hash value of the encrypted target data is obtained through the virtual power plant node, and the tamper-proof data is decrypted using the first private key to obtain the target hash value;

[0069] Determine whether the real-time hash value is the same as the target hash value. If they are the same, the encrypted target data has not been tampered with. Use the symmetric key to decrypt and use the encrypted target data. Otherwise, the encrypted target data has been tampered with. Discard the encrypted target data, generate an anomaly record, and upload the anomaly record to the blockchain.

[0070] This invention provides a blockchain-based method for protecting the data security of virtual power plants. First, it encrypts the data using a hybrid encryption strategy, ensuring both data privacy and encryption efficiency. Second, by constructing an edge server to communicate with the grid-side management system, the computing power of the edge server can be used to preprocess the data, effectively improving data quality and preventing direct access to the grid-side management system by virtual power plant nodes or other users, thus effectively reducing the risk of attacks. Then, during the data distribution to the virtual power plant nodes, tamper-proof data and leakage tracing data are acquired. Combined with the immutability of blockchain, this achieves data tamper-proofing and leakage tracing, further ensuring data security. Finally, during communication with the grid-side management system, an intrusion analysis model trained by a fusion optimization algorithm is used for intrusion detection analysis. This prevents illegal devices from masquerading as edge servers to perform illegal operations. The fusion optimization algorithm also improves the training effect of the intrusion analysis model, resulting in better intrusion detection and analysis capabilities. Attached Figure Description

[0071] To more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0072] Figure 1 A flowchart illustrating a blockchain-based method for protecting the data security of a virtual power plant, as provided in this embodiment of the invention. Detailed Implementation

[0073] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of this invention are only for explaining this invention and are not intended to limit this invention.

[0074] Example

[0075] like Figure 1 As shown, a blockchain-based method for protecting the data security of a virtual power plant is applied to a virtual power plant data security protection system comprising virtual power plant nodes, edge servers, blockchain, and a grid-side management system, including:

[0076] S1. Initialize the encryption parameters through the grid-side management system and distribute the encryption parameters to the virtual power plant nodes and edge servers to complete system initialization. Based on the system initialization, and according to the encryption parameters, transmit the virtual power plant data on the virtual power plant nodes to the edge servers using a hybrid encryption algorithm.

[0077] For example, the SM2 algorithm, or Elliptic Curve Public Key Cryptography, can be used to generate public and private keys for virtual power plant nodes, edge servers, and the grid-side management system. Once a connection is established, encryption can be performed using the public key. Using symmetric encryption algorithms alone leads to difficulties in key management and distribution, as well as lower security. Conversely, using asymmetric encryption algorithms alone results in long encryption / decryption times, slow speed, and suitability only for small amounts of data. Therefore, the hybrid encryption algorithm used in this invention first encrypts the plaintext using a symmetric encryption algorithm to obtain ciphertext, and then uses the public key of the asymmetric encryption algorithm to encrypt the key of the symmetric encryption algorithm to obtain the encrypted key ciphertext. For decryption, the private key of the asymmetric encryption algorithm is first used to decrypt the key ciphertext to obtain the symmetric encryption algorithm key, and then the symmetric encryption algorithm key is used to decrypt the ciphertext to obtain the plaintext. This invention successfully combines the advantages of low computational complexity and fast encryption speed of symmetric encryption algorithms with the high security of asymmetric encryption algorithms, while avoiding the disadvantages of both.

[0078] S2. The virtual power plant data is preprocessed by the edge server to obtain preprocessed virtual power plant data. The preprocessed virtual power plant data is then encrypted according to the encryption parameters to obtain encrypted virtual power plant data. The encrypted virtual power plant data is then transmitted to the grid-side management system for storage.

[0079] Optionally, the preprocessing of virtual power plant data may include data processing methods such as deduplication, outlier handling, and missing value handling. It is worth noting that, in addition to the above-mentioned data processing methods, other data processing methods can also be used to process virtual power plant data; this embodiment is merely an example.

[0080] S3. After the grid-side management system receives and stores the encrypted virtual power plant data, it receives the data response request sent by the virtual power plant node through the edge server, and requests the target data in the grid-side management system according to the data response request.

[0081] Optionally, the data response request may also include keywords or the name of the data to be retrieved, to facilitate the retrieval of the corresponding target data.

[0082] S4. Process the data response request through the power grid side management system, obtain the target data, the user feature information corresponding to the target data, and the anti-tampering data corresponding to the target data, and simultaneously use the intrusion analysis model trained by the fusion optimization algorithm to perform intrusion detection analysis and obtain the intrusion analysis result, which includes whether the data has been intruded or not.

[0083] Optionally, a neural network can be used as the intrusion analysis model. The intrusion analysis model can be trained by a fusion optimization algorithm so that it learns the traffic characteristics during an intrusion, thereby achieving intrusion analysis and ensuring data security.

[0084] S5. When the intrusion analysis result indicates an intrusion, stop the transmission of target data and end the data response process. When the intrusion analysis result indicates no intrusion, transmit the target data to the edge server and publish the tamper-proof data and the user characteristic information corresponding to the target data to the blockchain to prevent tampering and facilitate data leakage tracing. The user characteristic information can be associated with the unique identifier of the virtual power plant node and stored in the blockchain.

[0085] Once tamper-proof data is published to the blockchain, the blockchain's immutability allows virtual power plant nodes to verify the received data and check for tampering, thus ensuring data security. Simultaneously, the blockchain stores user characteristic information corresponding to the target data. Upon discovering leaked data, this user characteristic information can be retrieved and matched to identify which virtual power plant node leaked the data.

[0086] S6. Receive target data through the edge server and forward the target data to the virtual power plant node. At the same time, obtain tamper-proof data from the blockchain through the virtual power plant node so that the virtual power plant node can verify and use the target data based on the tamper-proof data.

[0087] In one possible implementation, the encryption parameters are initialized through the grid-side management system and distributed to the virtual power plant nodes and edge servers to complete system initialization. This includes: initializing the first public key and first private key corresponding to the virtual power plant nodes, initializing the second public key and second private key corresponding to the edge servers, initializing the third public key and third private key corresponding to the grid-side management system, and publishing the first, second, and third public keys to the blockchain. The symmetric key of the virtual power plant nodes is also initialized and updated at fixed intervals.

[0088] It is worth noting that after the virtual power plant node updates its symmetric key, it can synchronize the symmetric key to the grid-side management system to ensure normal data interaction.

[0089] In one possible implementation, based on system initialization, and according to encryption parameters, the virtual power plant data on the virtual power plant node is transmitted to the edge server using a hybrid encryption algorithm, including:

[0090] Based on the system initialization, the virtual power plant data is encrypted using a virtual power plant node and a symmetric key to obtain the first encrypted data.

[0091] Obtain the second public key from the blockchain, use the second public key to encrypt the symmetric key to obtain the first encryption key, and transmit the first encrypted data and the first encryption key together to the edge server.

[0092] Encrypting virtual power plant data using a hybrid encryption strategy can ensure both data security and encryption efficiency.

[0093] In one possible implementation, the virtual power plant data is preprocessed by an edge server to obtain preprocessed virtual power plant data. The preprocessed virtual power plant data is then encrypted according to the encryption parameters to obtain encrypted virtual power plant data. This encrypted virtual power plant data is then transmitted to the grid-side management system for storage, including:

[0094] The first encryption key is decrypted using the second private key in the edge server to obtain the symmetric key.

[0095] The first encrypted data is decrypted using the symmetric key to obtain virtual power plant data.

[0096] The virtual power plant data is processed to remove duplicate, missing, and outlier values, resulting in preprocessed virtual power plant data.

[0097] It is worth noting that other data processing methods can also be used to process the virtual power plant in order to improve data quality and reduce the amount of data processing required by the grid-side management system.

[0098] The preprocessed virtual power plant data is encrypted using a symmetric key to obtain encrypted virtual power plant data. A third public key is obtained from the blockchain and used to encrypt the symmetric key to obtain a second encryption key. The encrypted virtual power plant data and the second encryption key are then transmitted to the grid-side management system.

[0099] The second encryption key is decrypted using the grid-side management system and a third private key stored in the grid-side management system to obtain a symmetric key. Based on the symmetric key, the encrypted virtual power plant data is decrypted to obtain preprocessed virtual power plant data, which is then stored.

[0100] In one possible implementation, the data response request is processed by the power grid-side management system to obtain the target data, the user characteristic information corresponding to the target data, and the tamper-proof data corresponding to the target data, including:

[0101] The target data is obtained by identifying the data corresponding to the data response request from the stored virtual power plant data through the grid-side management system.

[0102] Add features to the target data to obtain the user feature information corresponding to the target data; encrypt the target data containing the user feature information using a symmetric key to obtain encrypted target data.

[0103] Obtain the hash value of the target data and encrypt the hash value using the first public key to obtain tamper-proof data.

[0104] Optionally, attributes or features can be added to the target data to imbue it with user characteristic information. The insertion position of the feature can only be determined by the grid-side management system, along with a data description. The data description, user characteristic information, and insertion position can be encrypted and stored together in the blockchain. For example, the data acquired by a virtual power plant node includes electricity consumption data for 20 days at various time points. Multiple data points can be fine-tuned to incorporate user characteristic information while maintaining the accuracy of the electricity consumption data.

[0105] Data descriptions can specify the data type and defined scope, such as the January electricity consumption data of a certain virtual power plant node.

[0106] When leaked data is discovered, relevant user characteristic information can be extracted and matched to pinpoint the location of the leak. For example, if the leaked data is from January, the operation records of those who accessed the January data can be extracted and matched with the leaked data to identify the leak location.

[0107] In one possible implementation, an intrusion detection analysis model trained by a fusion optimization algorithm is used to obtain intrusion analysis results, including:

[0108] Historical traffic characteristic data and the corresponding intrusion analysis results are obtained. The historical traffic characteristic data and the corresponding intrusion analysis results are both pre-stored data.

[0109] An intrusion analysis model is constructed using a convolutional neural network. Based on historical traffic feature data and the corresponding intrusion analysis results, a fusion optimization algorithm is used to train the intrusion analysis model, resulting in a trained intrusion analysis model.

[0110] It is worth noting that, in addition to using convolutional neural networks to build intrusion analysis models, other neural networks can also be used as intrusion analysis models.

[0111] The system acquires real-time traffic data that processes data response requests and uses a trained intrusion analysis model to identify the real-time traffic data, thereby obtaining intrusion analysis results.

[0112] Optionally, convolutional neural networks primarily process graph data, thus converting traffic data into graph data, which allows for better identification of features within the traffic data.

[0113] In one possible implementation, based on historical traffic characteristic data and the intrusion analysis results corresponding to the historical traffic characteristic data, and using a fusion optimization algorithm to train the intrusion analysis model, a trained intrusion analysis model is obtained, including:

[0114] A1. Set the iteration counter t = 1 and the maximum number of iterations to T. max Individual lower limit of parameter S min And the individual lower limit of parameter S max .

[0115] A2. Use chaotic sequences or random generation to generate network parameters for the intrusion analysis model, obtain individual parameters, and acquire multiple individual parameters to form a population. For example, randomly generate the weights and biases of the intrusion analysis model.

[0116] A3. Perform the first guiding update on each parameter individual in the population to obtain the first updated individual.

[0117] A4. Perform a second guided update on each parameter individual in the population to obtain the second updated individual.

[0118] A5. Determine whether the fitness value of the first updated individual is greater than the fitness value of the second updated individual. If yes, proceed to step A6; otherwise, proceed to step A7.

[0119] Optionally, an individual's fitness can be:

[0120]

[0121] Among them, F i Let i = 1, 2, ..., I, where I represents the total number of individuals; p = 1, 2, ..., P, where P represents the total number of historical traffic characteristic data; and k = 1, 2, ..., K, where K represents the total number of outputs of the intrusion analysis model. y' represents the k-th actual output when the p-th historical traffic feature data is input. pk This represents the expected output when the total number of historical traffic data for the p-th data point is input;

[0122] A6. Determine whether the fitness value of the parameter individual is greater than the fitness value of the first updated individual corresponding to the parameter individual. If yes, keep the parameter individual unchanged and proceed to step A8. Otherwise, replace the corresponding parameter individual with the first updated individual and proceed to step A9.

[0123] A7. Determine whether the fitness value of the parameter individual is greater than the fitness value of the second updated individual corresponding to the parameter individual. If yes, keep the parameter individual unchanged and proceed to step A8. Otherwise, replace the corresponding parameter individual with the second updated individual and proceed to step A9.

[0124] A8. Use a survival-of-the-fittest mechanism to perform spatial search and update the parameters of individuals in the population to obtain the updated population.

[0125] A9. Use an elite strategy to rapidly expand the updated population, and determine whether the number of parameter individuals in the updated population is greater than the lower limit S of parameter individuals. max If so, then generate [SS] max SS min The random number L in the population is used to eliminate the L individuals with the smallest fitness value in the population, where S represents the number of individuals with the parameter in the updated population.

[0126] A10. Determine whether the count value of the iteration counter t is greater than the maximum number of iterations, T. max Alternatively, if there is an individual in the updated population whose fitness value is greater than the preset fitness threshold, then the update ends and the individual with the largest fitness value is taken as the final network parameter of the intrusion detection model; otherwise, the iteration counter t is incremented by one and the process returns to step A3.

[0127] In one possible implementation, a first guided update is performed on each parameter individual in the population to obtain a first updated individual, including:

[0128]

[0129]

[0130]

[0131] in, Let i represent the i-th parameter individual in the population during the t-th training iteration, where i = 1, 2, ..., I, and I represents the total number of parameter individuals. Indicates the updated This refers to the first updated individual. ζ1 represents the first intermediate parameter, and n f Representation and parameter individuals The distance between two neighboring parameter individuals within a distance threshold. This represents individuals in the population excluding the parameter. Other individual parameters besides Indicates the center position among the neighboring parameter individuals. The fitness value represents the center position, and δ represents the decision factor. Represents individual parameters The fitness value, rand represents a random number between (0,1), and step t This represents the update step size during the t-th training iteration. This represents the individual with the highest fitness value in the current population, step. t-1 Let represent the update step size during the (t-1)th training iteration, and β represent the step size adjustment factor.

[0132] Optional, This represents the k-th neighboring parameter individual.

[0133] For each parameter individual in the population, a second guided update is performed to obtain the second updated individual, including:

[0134]

[0135]

[0136] Where ζ2 represents the second intermediate parameter, This represents the locally optimal individual with the highest fitness value among its neighboring individuals.

[0137] By employing both first and second guided updates, the algorithm can ensure both local and global search performance during training. Furthermore, a variable step size is implemented, allowing the algorithm to explore with a larger step size and broader field of view in the early stages, and a smaller step size and broader field of view in the later stages, thereby increasing convergence accuracy.

[0138] In this embodiment, after updating individual parameters, out-of-bounds processing can be performed to ensure that the data does not exceed the upper or lower limits.

[0139] A survival-of-the-fittest mechanism is used to spatially search and update the parameters of individuals in the population, resulting in an updated population, including:

[0140] B1. Set the maximum number of space search updates to P.

[0141] B2. Perform a spatial search update on the parameter individuals in the population as follows:

[0142]

[0143]

[0144] Where ζ3 represents the third intermediate parameter, Representation and parameter individuals A random individual among all neighboring parameter individuals within a distance threshold. Represents individual parameters The next state,

[0145] B3. Determine whether the fitness value of the parameter individual after the spatial search update is greater than the fitness value before the spatial search update. If so, accept the spatial search update and update the entire parameter individual. Otherwise, proceed to step B4.

[0146] B4. Determine whether the number of searches has reached the maximum number of spatial search updates P. If so, randomly perturb the individual parameters and update the random perturbation using the roulette wheel algorithm and the set receiving probability. Otherwise, return to step B2.

[0147] B5. Update the parameters of individuals in the population according to the methods described in steps B2-B4 to obtain the updated population.

[0148] Optionally, elite strategies may include: crossbreeding strategy, anti-elite strategy, and gene mutation strategy.

[0149] The crossbreeding strategy can be as follows: exchange some parameters of one parameter individual with those of another parameter individual to obtain two new parameter individuals, and then add the new parameter individuals to the population. In this embodiment, only the two individuals with the highest fitness values ​​are selected for crossbreeding.

[0150] Anti-elite strategy can be: Among them, top g The bottom represents the upper limit threshold of the g-th dimension parameter. g This represents the lower limit threshold of the g-th dimension parameter. express The g-th dimension parameter, g = 1, 2, ..., G, where G represents the total number of parameters.

[0151] Gene mutation strategies can include: adjusting one or more parameters in the top of an individual's genetic mutation list. g with bottom g The individuals are regenerated and replaced. In this embodiment, only the K individuals with the lowest fitness values ​​are selected for mutation.

[0152] This invention integrates the learning mechanism of the particle swarm optimization algorithm to further improve the convergence speed and ensure that all individuals tend towards the optimal solution. It also incorporates a genetic algorithm to further overcome the algorithm's tendency to get stuck in local optima and enhance its exploration capabilities. A reverse elitist strategy is introduced: in each iteration, an individual is generated that is the exact opposite of the elite individual. The reverse meaning is that the value in each dimension is the critical value of the solution space minus the value of the elite individual in that dimension.

[0153] In one possible implementation, after publishing the tamper-proof data and the user characteristic information corresponding to the target data to the blockchain, the method further includes:

[0154] The leaked data was obtained, which was generated by human-computer interaction.

[0155] Extract user feature information from the leaked data and use this user feature information to match it in the blockchain to obtain target user feature information, wherein the target user feature information is either empty or not empty.

[0156] When the target user feature information is not empty, the virtual power plant node corresponding to the target user feature information is used as the leakage node to complete the leakage tracing.

[0157] In one possible implementation, target data is received via an edge server and forwarded to a virtual power plant node. Simultaneously, the virtual power plant node retrieves tamper-proof data from the blockchain, enabling the virtual power plant node to verify and use the target data based on the tamper-proof data. This includes:

[0158] The target data is received by the edge server and forwarded to the virtual power plant node. At the same time, the tamper-proof data is obtained from the blockchain through the virtual power plant node.

[0159] The real-time hash value of the encrypted target data is obtained by using the virtual power plant node, and the tamper-proof data is decrypted using the first private key to obtain the target hash value.

[0160] By comparing the real-time hash value with the target hash value, it can be determined whether the target data has been tampered with. If they are the same, it indicates that the target data has not been tampered with and can be decrypted and used using a symmetric key. Conversely, if they are different, it means that the target data has been tampered with. In the case of tampered target data, the encrypted target data should be discarded, and an anomaly record should be generated. This anomaly record will be uploaded to the blockchain to ensure the integrity and immutability of the data. Through these measures, data tampering can be detected in a timely manner, and corresponding actions can be taken to ensure the security and reliability of the data.

[0161] This invention provides a blockchain-based method for protecting the data security of virtual power plants. First, it encrypts the data using a hybrid encryption strategy, ensuring both data privacy and encryption efficiency. Second, by constructing an edge server to communicate with the grid-side management system, the computing power of the edge server can be used to preprocess the data, effectively improving data quality and preventing direct access to the grid-side management system by virtual power plant nodes or other users, thus effectively reducing the risk of attacks. Then, during the data distribution to the virtual power plant nodes, tamper-proof data and leakage tracing data are acquired. Combined with the immutability of blockchain, this achieves data tamper-proofing and leakage tracing, further ensuring data security. Finally, during communication with the grid-side management system, an intrusion analysis model trained by a fusion optimization algorithm is used for intrusion detection analysis. This prevents illegal devices from masquerading as edge servers to perform illegal operations. The fusion optimization algorithm also improves the training effect of the intrusion analysis model, resulting in better intrusion detection and analysis capabilities.

[0162] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A blockchain-based method for protecting the data security of a virtual power plant, applied to a virtual power plant data security protection system comprising virtual power plant nodes, edge servers, blockchain, and a grid-side management system, characterized in that, include: The encryption parameters are initialized through the grid-side management system and distributed to the virtual power plant nodes and edge servers to complete the system initialization. Based on system initialization, and according to encryption parameters, the virtual power plant data on the virtual power plant node is transmitted to the edge server using a hybrid encryption algorithm. The virtual power plant data is preprocessed by the edge server to obtain preprocessed virtual power plant data. The preprocessed virtual power plant data is then encrypted according to the encryption parameters to obtain encrypted virtual power plant data. The encrypted virtual power plant data is then transmitted to the grid-side management system for storage. After the grid-side management system receives and stores the encrypted virtual power plant data, it receives the data response request sent by the virtual power plant node through the edge server, and requests the target data in the grid-side management system according to the data response request. The power grid-side management system processes data response requests to obtain target data, user characteristic information corresponding to the target data, and anti-tampering data corresponding to the target data. Simultaneously, an intrusion detection analysis model trained by a fusion optimization algorithm is used to perform intrusion analysis and obtain intrusion analysis results, including whether the data has been intruded or not. When the intrusion analysis result indicates that an intrusion has occurred, the transmission of target data is stopped, and the data response process ends. When the intrusion analysis result indicates that no intrusion has occurred, the target data is transmitted to the edge server, and the tamper-proof data and the user characteristic information corresponding to the target data are published in the blockchain to prevent tampering and facilitate leakage tracing. The target data is received by the edge server and forwarded to the virtual power plant node. At the same time, the virtual power plant node obtains tamper-proof data from the blockchain so that the virtual power plant node can verify and use the target data based on the tamper-proof data. An intrusion detection analysis model trained using a fusion optimization algorithm is used to perform intrusion analysis, yielding intrusion analysis results, including: Historical traffic characteristic data and the corresponding intrusion analysis results are obtained, wherein the historical traffic characteristic data and the corresponding intrusion analysis results are pre-stored data; An intrusion analysis model is constructed by using a convolutional neural network. Based on historical traffic feature data and the intrusion analysis results corresponding to the historical traffic feature data, the intrusion analysis model is trained using a fusion optimization algorithm to obtain the trained intrusion analysis model. The system acquires real-time traffic data that processes data response requests and uses a trained intrusion analysis model to identify the real-time traffic data, thereby obtaining intrusion analysis results. Based on historical traffic characteristic data and the corresponding intrusion analysis results, an intrusion analysis model is trained using a fusion optimization algorithm to obtain the trained intrusion analysis model, including: A1. Set the iteration counter t=1 and the maximum number of iterations to T. max Individual lower limit of parameter S min And the individual lower limit of parameter S max ; A2. Use chaotic sequences or random generation of network parameters for the intrusion analysis model to obtain individual parameters, and obtain multiple individual parameters to form a population; A3. Perform the first guiding update on each parameter individual in the population to obtain the first updated individual; A4. Perform a second guided update on each parameter individual in the population to obtain the second updated individual; A5. Determine whether the fitness value of the first updated individual is greater than the fitness value of the second updated individual. If yes, proceed to step A6; otherwise, proceed to step A7. A6. Determine whether the fitness value of the parameter individual is greater than the fitness value of the first updated individual corresponding to the parameter individual. If yes, keep the parameter individual unchanged and proceed to step A8. Otherwise, replace the corresponding parameter individual with the first updated individual and proceed to step A9. A7. Determine whether the fitness value of the parameter individual is greater than the fitness value of the second updated individual corresponding to the parameter individual. If yes, keep the parameter individual unchanged and proceed to step A8. Otherwise, replace the corresponding parameter individual with the second updated individual and proceed to step A9. A8. Use a survival-of-the-fittest mechanism to perform spatial search and update the parameters of individuals in the population to obtain the updated population; A9. Use an elite strategy to rapidly expand the updated population, and determine whether the number of parameter individuals in the updated population is greater than the lower limit S of parameter individuals. max If so, then generate [SS] max SS min The random number L in the population is used to eliminate the L individuals with the smallest fitness value in the population, where S represents the number of individuals with the parameter in the updated population; A10. Determine whether the count value of the iteration counter t is greater than the maximum number of iterations, T. max Alternatively, if there is an individual in the updated population whose fitness value is greater than the preset fitness threshold, then the update ends and the individual with the largest fitness value is taken as the final network parameter of the intrusion detection model; otherwise, the iteration counter t is incremented by one and the process returns to step A3.

2. The data security protection method for a blockchain-based virtual power plant according to claim 1, characterized in that, The system initialization is completed by initializing encryption parameters through the grid-side management system and distributing these parameters to virtual power plant nodes and edge servers. This includes: Initialize the first public key and the first private key corresponding to the virtual power plant node, initialize the second public key and the second private key corresponding to the edge server, initialize the third public key and the third private key corresponding to the power grid management system, and publish the first public key, the second public key and the third public key to the blockchain; Initialize the symmetric key of the virtual power plant node, and update the symmetric key once every fixed period.

3. The data security protection method for a blockchain-based virtual power plant according to claim 2, characterized in that, Based on system initialization, and according to encryption parameters, the virtual power plant data on the virtual power plant node is transmitted to the edge server using a hybrid encryption algorithm, including: Based on the system initialization, the virtual power plant data is encrypted using a virtual power plant node and a symmetric key to obtain the first encrypted data; Obtain the second public key from the blockchain, use the second public key to encrypt the symmetric key to obtain the first encryption key, and transmit the first encrypted data and the first encryption key together to the edge server.

4. The data security protection method for a blockchain-based virtual power plant according to claim 3, characterized in that, The virtual power plant data is preprocessed using an edge server to obtain preprocessed virtual power plant data. This preprocessed data is then encrypted according to the encryption parameters to obtain encrypted virtual power plant data. Finally, the encrypted virtual power plant data is transmitted to the grid-side management system for storage. The first encryption key is decrypted using the second private key in the edge server to obtain the symmetric key; Based on the symmetric key, the first encrypted data is decrypted to obtain virtual power plant data; The virtual power plant data is processed to remove duplicate, missing, and outlier values, resulting in preprocessed virtual power plant data. The preprocessed virtual power plant data is encrypted using a symmetric key to obtain encrypted virtual power plant data. A third public key is obtained from the blockchain and used to encrypt the symmetric key to obtain a second encryption key. The encrypted virtual power plant data and the second encryption key are then transmitted to the grid-side management system. The second encryption key is decrypted using the grid-side management system and the third private key stored in the grid-side management system to obtain the symmetric key; the encrypted virtual power plant data is then decrypted using the symmetric key to obtain preprocessed virtual power plant data, and the preprocessed virtual power plant data is stored.

5. The data security protection method for a blockchain-based virtual power plant according to claim 4, characterized in that, The data response request is processed through the power grid-side management system to obtain the target data, the user characteristic information corresponding to the target data, and the tamper-proof data corresponding to the target data, including: The target data is obtained by identifying the data corresponding to the data response request from the stored virtual power plant data through the grid-side management system. Add features to the target data to obtain the user feature information corresponding to the target data; encrypt the target data containing the user feature information using a symmetric key to obtain encrypted target data; Obtain the hash value of the target data and encrypt the hash value using the first public key to obtain tamper-proof data.

6. The data security protection method for a blockchain-based virtual power plant according to claim 5, characterized in that, Perform a first guide update on each parameter individual in the population to obtain the first updated individual, including: ; ; ; in, Let i represent the i-th parameter individual in the population during the t-th training iteration, where i = 1, 2, ..., I, and I represents the total number of parameter individuals. Indicates the updated That is, the first updated individual; Indicates the first intermediate parameter. Representation and parameter individuals The distance between two neighboring parameter individuals within a distance threshold. , This represents individuals in the population excluding the parameter. Other individual parameters besides Indicates the center position among the neighboring parameter individuals. The fitness value representing the center position. Indicates the judgment factor. Represents individual parameters fitness value, Represents a random number between (0,1). This represents the update step size during the t-th training iteration. This represents the individual with the highest fitness value in the current population. This represents the update step size during the (t-1)th training iteration. Indicates the step size adjustment factor; For each parameter individual in the population, a second guided update is performed to obtain the second updated individual, including: ; ; in, This indicates the second intermediate parameter. This represents the locally optimal individual with the highest fitness value among its neighboring individuals. A survival-of-the-fittest mechanism is used to spatially search and update the parameters of individuals in the population, resulting in an updated population, including: B1. Set the maximum number of space search updates to P; B2. Perform a spatial search update on the parameter individuals in the population as follows: ; ; in, This represents the third intermediate parameter. Representation and parameter individuals A random individual among all neighboring parameter individuals within a distance threshold. Represents individual parameters The next state, ; B3. Determine whether the fitness value of the parameter individual after the spatial search update is greater than the fitness value before the spatial search update. If so, accept the spatial search update and update the entire parameter individual. Otherwise, proceed to step B4. B4. Determine whether the number of searches has reached the maximum number of spatial search updates P. If so, randomly perturb the individual parameters and update the random perturbation using the roulette wheel algorithm and the set receiving probability. Otherwise, return to step B2. B5. Update the parameters of individuals in the population according to the methods described in steps B2-B4 to obtain the updated population.

7. The data security protection method for a blockchain-based virtual power plant according to claim 5, characterized in that, After publishing the tamper-proof data and the user feature information corresponding to the target data to the blockchain, the process also includes: Acquire leaked data, which was generated by human-computer interaction; Extract user feature information from the leaked data, and use this user feature information to match in the blockchain to obtain target user feature information, wherein the target user feature information is either empty or not empty; When the target user feature information is not empty, the virtual power plant node corresponding to the target user feature information is used as the leakage node to complete the leakage tracing.

8. The data security protection method for a blockchain-based virtual power plant according to claim 5, characterized in that, The target data is received through an edge server and forwarded to a virtual power plant node. Simultaneously, the virtual power plant node retrieves tamper-proof data from the blockchain, enabling the virtual power plant node to verify and use the target data based on this tamper-proof data. This includes: The target data is received through the edge server and forwarded to the virtual power plant node. At the same time, the tamper-proof data is obtained from the blockchain through the virtual power plant node. The real-time hash value of the encrypted target data is obtained through the virtual power plant node, and the tamper-proof data is decrypted using the first private key to obtain the target hash value; Determine whether the real-time hash value is the same as the target hash value. If they are the same, the encrypted target data has not been tampered with. Use the symmetric key to decrypt and use the encrypted target data. Otherwise, the encrypted target data has been tampered with. Discard the encrypted target data, generate an anomaly record, and upload the anomaly record to the blockchain.