A method and related equipment for protecting network security of microgrid system

Through real-time monitoring and evaluation in the micronet system, dynamically set download priority and duration, and dynamic key encryption transmission is used to solve the problem of insufficient network security protection in the existing technology, and the orderliness and security of data downloads are achieved.

CN119011274BActive Publication Date: 2025-05-13LEYAN TECHNOLOGY (SUZHOU) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411246666.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2025-05-13
Estimated Expiration
2044-09-06

AI Technical Summary

Technical Problem

Inadequate network security protection measures in existing micronet systems lead to the risk of internal networks being easily attacked and the risk of data leakage or malicious device manipulation is high.

Method used

Through real-time monitoring and evaluation, dynamically set download priority and duration, optimize resource allocation, and use preset download strategies and dynamic key encryption transmission to ensure the orderly and security of data downloads.

Benefits of technology

It improves the system's dynamic assessment and timely response capabilities for network security risks, enhances its ability to respond to threats, and ensures the security and priority management of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011274B_ABST
    Figure CN119011274B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method and related equipment for protecting the network security of a microgrid system, and relates to the field of communication technology. The present application is connected to a download terminal based on a preset processing rule; the attribute information of the data to be downloaded, the access information of the target application, and the biometric information of the target user sent by the download terminal are obtained; the biometric information of the target user is processed to generate the identity attribute information of the target user; the preset decryption rule is generated for the identity attribute information of the target user and the attribute information of the data to be downloaded; the encrypted data to be downloaded is processed based on the preset decryption rule to generate the decrypted data to be downloaded; the decrypted data to be downloaded is processed to generate the security level information of the download terminal of the data to be downloaded; the download priority information of the data to be downloaded and the target download duration of the data to be downloaded are generated; the decrypted data to be downloaded is processed based on the target download strategy to generate the download data information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a method for protecting the network security of a microgrid system and related equipment. Background Art

[0002] With the integration of informatization and industrialization, the security issues of microgrid systems have become increasingly prominent. Once a security vulnerability occurs in a microgrid system, the possibility of the microgrid system being attacked by viruses, Trojans and other threats increases, which in turn makes the industrial generation control process face security threats. At present, the security protection measures taken in the microgrid system are generally to deploy a firewall between the enterprise management layer of the microgrid system and the external network. Due to the lack of protection measures, once the firewall between the enterprise management layer and the external network is breached by the attacker, the internal network of the microgrid system can be easily controlled, so that the production data and other data in the microgrid system can be stolen, or the field equipment can be maliciously manipulated, affecting the normal industrial control. In addition, the microgrid system deploys a large number of intelligent fusion terminals, which are monitored and controlled by the microgrid energy controller. It has the characteristics of large amount of data transmission, diverse data acquisition methods, and high real-time data interaction. It is urgent to improve the network security protection of the microgrid system.

[0003] In the prior art, file sharing is mainly performed in two ways. In the first way, the microgrid system can generate a download link for the user's file. When other users want to download the file, they need to log in to the microgrid system first and then download the file. For some users who want to download the file in a non-logged-in state, they cannot download the file in this way. These users can download files in the second way. In this way, after the microgrid system generates a download link for the user's file, other users can download the file in a non-logged-in state, and the download link is permanently valid. However, this method has a greater data security risk.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0005] The purpose of the present disclosure is to provide a method and related equipment for protecting the network security of a microgrid system, which at least to a certain extent overcomes the problems existing in the prior art, dynamically sets download priority and duration through real-time monitoring and evaluation, optimizes resource allocation, processes download priority, target download duration and user data usage information according to a preset download strategy, forms a target download strategy, ensures the orderliness of data download, adopts dynamic key encryption transmission, improves the security of data transmission, realizes dynamic evaluation and timely response to network security risks, and improves the system's ability to respond to threats.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0007] According to one aspect of the present application, a method for protecting the network security of a microgrid system is provided, comprising: connecting to a download terminal based on a preset processing rule; obtaining attribute information of the data to be downloaded, access information of a target application, and biometric information of a target user sent by the download terminal; processing the biometric information of the target user to generate identity attribute information of the target user, wherein the identity attribute information of the target user includes the identity information of the target user and information on the purpose of the data to be downloaded by the target user; generating a preset decryption rule for the identity attribute information of the target user and the attribute information of the data to be downloaded, wherein the preset decryption rule is used to decrypt the encrypted data to be downloaded sent by the target server; decrypting the encrypted data based on the preset decryption rule; The method comprises the steps of: processing the decrypted data to be downloaded to generate decrypted data to be downloaded; processing the decrypted data to be downloaded to generate security level information of a downloading terminal of the data to be downloaded; processing the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the downloading terminal of the data to be downloaded and the access information of the target application to generate download priority information of the data to be downloaded and a target download duration of the data to be downloaded; processing the download priority information of the data to be downloaded, the target download duration of the data to be downloaded and the data usage information of the target user based on a preset download strategy to generate a target download strategy; processing the decrypted data to be downloaded based on the target download strategy to generate download data information.

[0008] In one embodiment of the present application, connecting with a download terminal based on a preset processing rule includes: obtaining digital certificate information, download terminal unique identification information, download terminal random number, download terminal key-share information, data processing level information of the download terminal and security level information of the download terminal sent by the download terminal; obtaining a target server random number and target server key-share information; generating a pre-master key based on the download terminal key-share information and the target server key-share information; generating a temporary session key based on the download terminal random number, the target server random number and the pre-master key; processing the digital certificate information and the download terminal unique identification information based on a preset pairing rule to generate a processing result; if the processing result is to allow the target server to pair with the download terminal, then obtaining configuration information, the configuration information including a domain name certificate and other target server parameters required to complete a connection establishment process with the download terminal; encrypting the configuration information based on the temporary session key to generate encrypted configuration information; processing the data processing level information of the download terminal and the security level information of the download terminal to generate a connection priority of the download terminal; sending the encrypted configuration information to the download terminal based on the connection priority of the download terminal to complete the connection establishment process.

[0009] In one embodiment of the present application, the data processing level information of the download terminal and the security level information of the download terminal are processed to generate a connection priority of the download terminal, including: obtaining real-time load balancing information of the target server and data connection task information within a preset period; processing the target server based on the data connection task information within the preset period to generate preset connection progress information of the target server; processing the data processing level information of the download terminal and the security level information of the download terminal to generate target processing progress information, wherein the target processing progress information includes the processing time and connection time of the download terminal; processing the preset connection progress information based on the target processing progress information to generate the connection priority of the download terminal.

[0010] In one embodiment of the present application, the biometric information of the target user is processed to generate the identity attribute information of the target user, including: processing the biometric information of the target user to generate initial facial image information and the identity information of the target user, wherein the initial facial image information is the facial information of the target user within a preset time period; processing the initial facial image information to generate the expression feature influencing factors of the target user; processing the expression feature influencing factors of the target user based on a preset emotion recognition model to generate target facial image information, wherein the target facial image information includes the expression change information of the target user; processing the target facial image information to generate the emotion information of the target user; processing the identity information of the target user and the emotion information of the target user to generate the identity attribute information of the target user.

[0011] In one embodiment of the present application, preset decryption rules are generated for the identity attribute information of the target user and the attribute information of the data to be downloaded, including: obtaining a preset decryption mapping table, wherein the preset decryption mapping table includes data decryption information preset by several users; processing the identity attribute information of the target user based on the preset decryption mapping table to generate initial data decryption information, wherein the initial data decryption information includes several decryption rules set by the target user for different types of data to be downloaded; processing the initial data decryption information based on the attribute information of the data to be downloaded to generate target data decryption information.

[0012] In one embodiment of the present application, the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded, and the access information of the target application are processed to generate the download priority information of the data to be downloaded and the target download duration of the data to be downloaded, including: processing the attribute information of the data to be downloaded and the identity information of the target user to generate the download priority information of the data to be downloaded; processing the security level information of the download terminal of the data to be downloaded based on the download priority information of the data to be downloaded to generate the initial download duration of the data to be downloaded; processing the initial download duration of the data to be downloaded based on the access information of the target application to generate the target download duration of the data to be downloaded.

[0013] In one embodiment of the present application, the download priority information of the data to be downloaded, the target download duration of the data to be downloaded, and the usage information of the data to be downloaded of the target user are processed based on a preset download strategy to generate a target download strategy, including: obtaining real-time data download processing information and other downloaded data information of the target server; processing the usage information of the data to be downloaded based on the real-time data download processing information of the target server to generate download importance information of the data to be downloaded; processing the other downloaded data information based on the download importance information of the data to be downloaded to generate download data adjustment information, wherein the download data adjustment information is used to perform data deletion processing on the data to be downloaded or other downloaded data information; processing the download priority information of the data to be downloaded and the target download duration of the data to be downloaded based on the download data adjustment information to generate download information of the data to be downloaded, wherein the download information of the data to be downloaded is used to characterize the final download duration and download timing of the data to be downloaded.

[0014] Another aspect of the present application is a microgrid system network security protection device, characterized in that it includes: an acquisition module, used to acquire attribute information of the data to be downloaded, access information of the target application, and biometric information of the target user sent by the download terminal; a processing module, used to connect to the download terminal based on a preset processing rule; processing the biometric information of the target user to generate identity attribute information of the target user, wherein the identity attribute information of the target user includes the identity information of the target user and the usage information of the data to be downloaded by the target user; generating a preset decryption rule for the identity attribute information of the target user and the attribute information of the data to be downloaded, wherein the preset decryption rule is used to decrypt the encrypted data to be downloaded sent by the target server; based on the preset decryption rule, The method comprises the steps of: processing the encrypted data to be downloaded according to the encryption rule to generate decrypted data to be downloaded; processing the decrypted data to be downloaded to generate security level information of the downloading terminal of the data to be downloaded; processing the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the downloading terminal of the data to be downloaded and the access information of the target application to generate download priority information of the data to be downloaded and the target download duration of the data to be downloaded; processing the download priority information of the data to be downloaded, the target download duration of the data to be downloaded and the data usage information of the target user based on a preset download strategy to generate a target download strategy; processing the decrypted data to be downloaded based on the target download strategy to generate download data information.

[0015] According to another aspect of the present application, an electronic device is provided, characterized in that it comprises: a first processor; and a memory for storing executable instructions of the first processor; wherein the first processor is configured to execute the above-mentioned microgrid system network security protection method by executing the executable instructions.

[0016] According to another aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a second processor, the above-mentioned method for protecting the network security of the microgrid system is implemented.

[0017] According to another aspect of the present application, a computer program product is provided, including a computer program, characterized in that when the computer program is executed by a third processor, the computer program implements the above-mentioned microgrid system network security protection method.

[0018] The present application provides a method and related equipment for protecting the network security of a microgrid system. The target server and the download terminal establish a connection based on preset rules, collect the attributes of the data to be downloaded, application access and user biometric information sent by the target server, process the user biometric information, and generate identity attribute information including identity and data usage. Combined with the user identity attributes and the attributes of the data to be downloaded, a preset decryption rule is created to decrypt the encrypted data sent by the server, the decryption rule is applied to generate the decrypted data, and further processed to generate the security level information of the download terminal, and the user identity, data attributes, security level and application access information are combined to determine the download priority and target duration of the data. According to the preset download strategy, the download priority, target duration and user data usage are processed to form a target download strategy. According to the target download strategy, the decrypted data is finally processed to generate data information available for download, which ensures the security and priority management of the data during the download process, while taking into account the specific needs of the user and the security requirements of the system.

[0019] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0021] Figure 1 A flow chart showing a method for protecting network security of a microgrid system provided by an embodiment of the present application is shown;

[0022] Figure 2 A schematic diagram of the structure of a microgrid system network security protection device provided by an embodiment of the present application is shown;

[0023] Figure 3 A schematic diagram of the structure of an electronic device provided by an embodiment of the present application is shown;

[0024] Figure 4 A schematic diagram of a storage medium provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0025] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0026] Combine the following Figure 1 To describe the protection method of the microgrid system network security according to the exemplary embodiment of the present application. It should be noted that the following application scenarios are only shown to facilitate understanding of the spirit and principle of the present application, and the implementation of the present application is not limited in this regard. On the contrary, the implementation of the present application can be applied to any applicable scenario.

[0027] It should be noted that the download terminal and the target server can establish communication through a physical port, etc. One or more download terminals can be deployed in the network system architecture, and the same download terminal can be connected to multiple target servers, and the same target server can also be connected to multiple download terminals.

[0028] Among them, the download terminal and the target server are not definite hardware products for the entire network system architecture. The same hardware, such as a computer, a target server, etc., may be used as a download terminal in one situation and as a target server in another situation.

[0029] The division of download terminals and target servers in this application can represent the corresponding relationship in communication mode, for example, one target server can correspond to multiple download terminals; it can also represent different usage functions, for example, the download terminal is used for user use, and the target server is used for storage and transfer of certificates. In order to facilitate more accurate judgment, in this application, the functions and roles of the download terminal and the target server are not limited. Only the one that sends the connection request in the communication connection is regarded as the download terminal, and the one that receives the connection request or stores the certificate is regarded as the target server.

[0030] In one implementation, the present application also proposes a microgrid system network security protection method and related equipment. Figure 1The flowchart of a method for protecting the network security of a microgrid system according to an embodiment of the present application is schematically shown. Figure 1 As shown, the method is applied to a target server and includes:

[0031] S101, connecting with a download terminal based on a preset processing rule.

[0032] In one implementation, digital certificate information, unique identification information of the download terminal, random number of the download terminal, key-share information of the download terminal, data processing level information of the download terminal and security level information of the download terminal are obtained, random number of the target server and key-share information of the target server are obtained, and a pre-master key is generated based on the key-share information of the download terminal and the key-share information of the target server.

[0033] Among them, the download terminal random number can be 32 bytes generated by a secure random number generator, the download terminal unique identification information can be the MAC address of the download terminal, key_share is the public key corresponding to the elliptic curve type, and the specific presentation form of the key_share information is not repeated here. The key-share information includes but is not limited to preset parameters for calculating the pre-master key; for example: the download terminal sends a request (Client Hello), the extended part carries the supported elliptic curve type, and the download terminal public key (POINT) is calculated for each elliptic curve type supported by itself, and the download terminal public key is placed in the key-share information in the extended information; after the target server selects the elliptic curve parameter, it multiplies it by the basepoint of the elliptic curve to obtain the target server public key (POINT); then extract the corresponding download terminal public key in the key_share information in the Client Hello, and calculate the pre-master key; after the download terminal receives the target server public key (POINT) of the target server, it calculates the pre-master key.

[0034] The download terminal random number and download terminal key-share information are generated by the download terminal; the target server random number and target server key-share information are generated by the target server, and the specific generation method is not limited here. By using the pre-information of the session key transmitted by the download terminal and the target server during the handshake process (connection establishment process), the session key can be quickly determined without affecting the handshake process (connection establishment process), greatly shortening the time for communication between the two ends after the handshake (connection establishment).

[0035] A temporary session key is generated based on the random number of the download terminal, the random number of the target server and the pre-master key. Identity authentication is completed by combining the unique identification of the download device with the digital certificate. During the identity authentication process, a temporary session key negotiation is performed to meet the plug-and-play requirements of the terminal device. During registration, the sensor device identification, digital certificate and other information need to be uniquely bound. After registration is completed, when the session link is reestablished, two-way identity authentication is performed based on the digital certificate and the SM2 algorithm. The digital certificate information and the unique identification information of the download terminal are processed based on the preset pairing rules to generate a processing result. If the processing result is to allow the target server to pair with the download terminal, the configuration information is obtained, and the configuration information includes the domain name certificate and other target server parameters required to complete the connection establishment process with the download terminal. The configuration information is encrypted based on the temporary session key to generate the encrypted configuration information. The configuration information includes the domain name certificate and other target server parameters required to complete the connection establishment process with the download terminal. The target server detects whether the domain name certificate in the local storage area is in a valid state; if not, a certificate loading request is sent to the certificate center; the domain name certificate in an invalid state is replaced with the new domain name certificate received from the certificate center. The target server detects whether the domain name certificate in the local storage area is in a valid state. If not, the target server sends a certificate loading request to the certificate center, and replaces the invalid domain name certificate with the new domain name certificate received from the certificate center. In this way, the invalid domain name certificate is replaced before the handshake begins, so that the required domain name certificate can be directly loaded during the handshake process, reducing the handshake time. A certificate list can be set in the target server, and the domain name certificate in the local storage area is recorded in the certificate list. The certificate list is used to detect whether the domain name certificate is in a valid state. Among them, the local storage area can include a disk storage area and a memory storage area. Files stored in the disk storage area require I / O performance to read and write, and files stored in the memory storage area can be read directly.

[0036] The configuration information is encrypted / decrypted by the temporary session key. Specifically, when the download terminal sends data, the data is first encrypted by the SM4 algorithm based on the temporary session key and then sent to the target server. When the target server receives the encrypted data, the data is first decrypted by the SM4 algorithm based on the temporary session key to obtain the corresponding data; similarly, when the target server sends data, the data is first encrypted by the SM4 algorithm based on the temporary session key and then sent to the download terminal. When the download terminal receives the encrypted data, the data is first decrypted by the SM4 algorithm based on the temporary session key to obtain the corresponding data.

[0037] The data processing level information and security level information of the download terminal are processed to generate the connection priority of the download terminal, and the encrypted configuration information is sent to the download terminal based on the connection priority of the download terminal to complete the connection establishment process. The specific implementation process is expanded below and will not be repeated here.

[0038] In another embodiment, the data processing level information of the download terminal and the security level information of the download terminal are processed to generate a connection priority of the download terminal, specifically including: obtaining real-time load balancing information of the target server and data connection task information within a preset period; processing the target server based on the data connection task information within the preset period to generate preset connection progress information of the target server; processing the data processing level information of the download terminal and the security level information of the download terminal to generate target processing progress information, wherein the target processing progress information includes the processing time and connection time of the download terminal; processing the preset connection progress information based on the target processing progress information to generate a connection priority of the download terminal.

[0039] First, it is necessary to monitor the load of the target server in real time, which involves information such as the server's current operating status, processing capacity, and network traffic. Load balancing information helps determine how to allocate connection requests from download terminals to optimize resource usage and response time. Analyze the data connection tasks of the server within the preset period, including the frequency, duration, and data volume of the tasks. This helps predict the data connection needs of the server in the future and generate reasonable preset connection progress information for the download terminal. Based on the data connection task information within the preset period, the preset connection progress information of the target server can be generated, including the estimated connection establishment time, data processing time, and possible waiting time.

[0040] The data processing level of the download terminal determines its ability and speed to process data, while the security level involves the security of data transmission and storage. A comprehensive evaluation of these two levels is required to generate target processing progress information, which should include the processing time and connection time of the download terminal. This requires considering the data processing capabilities of the download terminal and the current security policy to ensure that data is transmitted safely and efficiently. According to the processing time and connection time of the download terminal, the preset connection progress information of the target server is adjusted. This helps to ensure that the download terminal can complete the download and processing of data within a reasonable time. Finally, the connection priority of the download terminal is generated by combining the target processing progress information and the preset connection progress information. The connection priority should reflect the data processing needs and security requirements of the download terminal, as well as the load and available resources of the target server. This solution will be carried out dynamically to adapt to changes in network conditions and server status, while ensuring data security and compliance with relevant network security level protection requirements.

[0041] S102, obtaining attribute information of the data to be downloaded, access information of the target application, and biometric information of the target user sent by the download terminal.

[0042] In one implementation, data security technology tools, such as a data asset management microgrid system and a data lineage management tool, can be used to track and manage the source, processing, and application docking of data. Application access control is a key security measure that ensures that only authorized users can access applications and their data. The identity and permission control microgrid system can be used to manage user access rights to applications, while ensuring the security of the application interface to prevent unauthorized access and data leakage. In addition, the access information of the target application is used to characterize whether the target user has the authority to upload the corresponding data in the target application, as well as the time period allowed for upload and the size of the uploaded data.

[0043] S103: Process the biometric information of the target user to generate identity attribute information of the target user.

[0044] In one embodiment, the biometric information of the target user is processed to generate initial facial image information and identity information of the target user, wherein the initial facial image information is the facial information of the target user within a preset time period; the initial facial image information is processed to generate factors affecting the expression characteristics of the target user; the factors affecting the expression characteristics of the target user are processed based on a preset emotion recognition model to generate target facial image information, wherein the target facial image information includes expression change information of the target user; the target facial image information is processed to generate emotional information of the target user; the identity information of the target user and the emotional information of the target user are processed to generate identity attribute information of the target user, wherein the identity attribute information of the target user includes the identity information of the target user and information on the purpose of the target user's data to be downloaded.

[0045] Specifically, the target user's biometric information (such as the target user's facial information or fingerprint information, etc.) is processed to generate initial facial image information and the target user's identity information, wherein the initial facial image information is the facial information of the target user within a preset time period, and the facial image data of the same person collected within a specific time period are used to create a facial template.

[0046] The initial facial image information is processed based on preset processing rules to generate the influencing factors of the target user's expression characteristics, extract key features in the image, such as changes in facial action units (AU), and then used for subsequent micro-expression recognition. The influencing factors of the target user's expression characteristics are processed based on a preset emotion recognition model to generate target facial image information, wherein the preset emotion recognition model uses deep learning technology, especially convolutional neural networks (CNNs), to recognize micro-expressions. These networks can learn and extract complex features from a large amount of facial expression data. The real-time captured facial image is input into a well-trained model, which will analyze the image and predict the emotional state. By continuously monitoring the slight changes in facial expressions, the dynamic change process of the user's emotions can be tracked. The target facial image information includes the expression change information of the target user, and the target facial image information is processed to generate the target user's emotional information, including outputting the results of the emotional change, which may include the type and intensity of the emotion.

[0047] Specifically, the collected images are preprocessed, including denoising, contrast adjustment, normalization, etc., to improve the image quality. A facial detection algorithm is used to determine the position of the face in the image and locate the key points of the face, such as the eyes, nose, mouth, etc. This solution does not limit the specific facial detection algorithm, and the applicant can choose according to actual needs. Among them, the facial detection algorithm includes but is not limited to the histogram of oriented gradients (HOG), local binary pattern (LBP), and Haar cascade classifier. Facial action units are the basic components of facial expressions. By analyzing the changes in these action units, different micro-expressions can be identified. For example, AU1 indicates the lifting of the inner side of the eyebrows, AU12 indicates the closure of the lips, etc., and key features in the image are extracted, such as changes in facial action units, changes in facial contours, etc. According to the extracted features, a machine learning algorithm is used to classify the expressions and identify different emotions or psychological states.

[0048] By processing the identity information of the target user, the real identity of the target user is obtained, and the data decryption information used to decrypt the encrypted data to be downloaded is obtained. The decryption information is set based on the user's personal habits, or a preset decryption rule method and information associated with the attribute type of the data to be downloaded. The purpose is to decrypt the encrypted data to be downloaded, and generate identity attribute information exclusive to the target user based on the identity information of the target user and the target user's emotional information. The identity attribute information of the target user includes the identity information of the target user and the target user's data usage information to be downloaded. The target user's data usage information to be downloaded will be explained in detail later and will not be repeated here.

[0049] S104: Generate a preset decryption rule based on the identity attribute information of the target user and the attribute information of the data to be downloaded.

[0050] In one implementation, a preset decryption mapping table is obtained, wherein the preset decryption mapping table includes data decryption information preset by a number of users, and the preset decryption rules are used to decrypt the encrypted data to be downloaded sent by the target server. The identity attribute information of the target user is processed based on the preset decryption mapping table to generate initial data decryption information, wherein the initial data decryption information includes a number of decryption rules set by the target user for different types of data to be downloaded; the initial data decryption information is processed based on the attribute information of the data to be downloaded to generate target data decryption information.

[0051] First, there needs to be a clear data security management system, which includes the classification and classification of data, as well as the specification of the acquisition, storage, transmission and processing activities of different categories of data. For example, personal privacy data and confidential data should have the highest level of protection measures, while the protection level of public data can be relatively low. In addition, data acquisition must be authorized, data storage should be safe and reliable, and key data should be backed up regularly. Secondly, the acquisition and use of preset decryption mapping tables should follow strict security measures. The mapping table contains the data decryption information pre-set by the user, which may include decryption keys, algorithm types, etc. During the decryption process, it is necessary to ensure that only authorized users can access and use this information. Decryption operations should be performed under authority management and security supervision to prevent data leakage or abuse.

[0052] Next, based on the preset decryption mapping table, the identity attribute information of the target user is processed to generate the initial data decryption information. The initial data decryption information should include the decryption rules set by the user for different types of data to be downloaded. These rules may involve different encryption algorithms, such as DES, 3DES, AES, etc., as well as corresponding key management. Finally, combined with the attribute information of the data to be downloaded, the initial data decryption information is further processed to generate the target data decryption information. This step requires the identification of data attributes and the application of corresponding decryption rules to ensure the security and integrity of the data during transmission and use.

[0053] S105: Process the encrypted data to be downloaded based on the preset decryption rule to generate decrypted data to be downloaded.

[0054] In one implementation, the encrypted data to be downloaded is decrypted based on the target data decryption information to obtain the decrypted data to be downloaded, that is, the original data to be downloaded, so that the download device can subsequently download the data.

[0055] S106, processing the decrypted data to be downloaded to generate security level information of the downloading terminal of the data to be downloaded.

[0056] In one implementation, for the decrypted data to be downloaded, the type and attributes of the data need to be identified first to determine its classification. For example, if the data contains personal information or trade secrets, it may be classified as data with a higher security level. Next, the sensitivity, importance, and potential risks of the data need to be assessed, including the degree of harm that data leakage, tampering, or damage may cause to national security, economic operation, social stability, public health, and safety.

[0057] After comprehensive analysis, data is classified as general data, important data, or core data based on the objects and degree of impact that the data may cause. Important data and core data must be handled with extra strictness to ensure data security. Ultimately, the security level of the download terminal should match the security level of the data to be downloaded to ensure that appropriate security measures are taken to protect the data.

[0058] S107, processing the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded, and the access information of the target application to generate the download priority information of the data to be downloaded and the target download duration of the data to be downloaded.

[0059] In one implementation, attribute information of the data to be downloaded and identity information of the target user are processed to generate download priority information of the data to be downloaded; based on the download priority information of the data to be downloaded, security level information of the download terminal of the data to be downloaded is processed to generate an initial download duration of the data to be downloaded; based on the access information of the target application, the initial download duration of the data to be downloaded is processed to generate a target download duration of the data to be downloaded.

[0060] Specifically, analyze the attributes of the data to be downloaded, including but not limited to the access frequency of the data, the timeliness of the data, the size of the data, etc. These attributes can help the applicant determine whether the data is hot data. For example, data with a high access frequency is more likely to be hot data and should be given a higher download priority. Secondly, evaluate the identity information of the target user. If the target user is a VIP user or their behavior has a greater impact on the business, the data they request should also have a higher download priority.

[0061] The judgment of hot data can be achieved through data statistics and analysis. For example, an asynchronous monitoring statistics service and a hot data service can be created to perform request statistics on the Key. After reaching a certain request level, the hot Key is pushed to the business system, and the download priority information of the data to be downloaded is generated by combining the results of data attribute analysis and user identity evaluation. Different priority levels can be set, such as L3 and L4 levels, where L3 may contain critical business data and L4 may contain very critical business data. According to the generated download priority information, the corresponding download strategy is implemented. For example, for high-priority data, a more active download strategy can be adopted, such as extending the download time, using download nodes closer to users, etc., and the download data is reviewed and adjusted regularly to ensure that the data being downloaded is the current hot data and serves important users. This may involve the elimination and updating of data to maintain the efficiency and relevance of the download.

[0062] Finally, based on the results of download priority and download data adjustment, the download information of the data to be downloaded is generated, including download duration and download timing. This will guide the actual download operation, ensure that the data is downloaded at the right time, and be updated or eliminated when necessary, ensuring that the download system efficiently serves important users while maintaining the popularity and timeliness of the data.

[0063] Based on the download priority information of the data to be downloaded, the security level information of the data to be downloaded is processed to generate the initial download time of the data to be downloaded. The initial download time is determined based on the security level of the data to be downloaded. For example, important data should not be kept for too long to avoid data leakage. Based on the access information of the target application, the initial download time of the data to be downloaded is processed to generate the target download time of the data to be downloaded. This is determined based on the security of the target application. If the target application is easily leaked by hackers, the download time of its data should not be too long.

[0064] S108: Process the download priority information of the data to be downloaded, the target download duration of the data to be downloaded, and the usage information of the data to be downloaded of the target user based on the preset download strategy to generate a target download strategy.

[0065] In one implementation, real-time data download processing information and other downloaded data information of a target server are obtained, usage information of data to be downloaded is processed based on the real-time data download processing information of the target server to generate download importance information of the data to be downloaded, other downloaded data information is processed based on the download importance information of the data to be downloaded to generate download data adjustment information, wherein the download data adjustment information is used to perform data deletion processing on the data to be downloaded or other downloaded data information, download priority information of the data to be downloaded and target download duration of the data to be downloaded are processed based on the download data adjustment information to generate download information of the data to be downloaded, wherein the download information of the data to be downloaded is used to characterize the final download duration and download timing of the data to be downloaded.

[0066] Specifically, obtain the real-time data download load information and other downloaded data information of the target server; wherein, to obtain the real-time data download load information of the server, a server monitoring tool can be used to obtain the current download load, including the used download space, download hit rate, access frequency, etc., and collect key performance indicators such as CPU usage, memory usage, network bandwidth, etc., to evaluate the overall performance of the server.

[0067] Based on the real-time data download load information of the target server, the purpose information of the data to be downloaded is processed to generate the download importance information of the data to be downloaded, and the data is classified according to its purpose and importance. For example, the data is divided into transaction data, user information, log records, etc., and the importance of each type of data is evaluated to determine their impact on business operations. Different weights are set for different categories of data to reflect their importance to the business, and the data is prioritized according to the weight to determine which data needs to be downloaded first.

[0068] Based on the download importance information of the data to be downloaded, other downloaded data information is processed to generate download data adjustment information, wherein the download data adjustment information is used to perform data deletion processing on the data to be downloaded or other downloaded data information; according to the importance and access frequency of the download, a data elimination strategy is formulated, such as LRU (least recently used) or LFU (least frequently used), and according to the elimination strategy, it is determined which data needs to be deleted from the download to free up space for more important data.

[0069] Based on the download data adjustment information, the download priority information of the data to be downloaded and the target download duration of the data to be downloaded are processed to generate download information of the data to be downloaded, wherein the download information of the data to be downloaded is used to characterize the final download duration and download timing of the data to be downloaded. According to the importance of the data and business needs, download priorities are assigned to the data to be downloaded, and the maximum time the data is retained in the download is determined, which may be based on the timeliness of the data or the business cycle. According to the priority and download duration, specific download strategies are implemented, such as preloading, delayed loading, etc., to determine the best time to download data, such as preloading data during low-load periods, and automated tools are used to implement download strategies and monitor their effects. According to monitoring results and business feedback, download strategies are continuously adjusted to optimize performance.

[0070] For example, suppose the applicant has an e-commerce website whose downloaded data includes user shopping cart information, product details, user reviews, etc. The applicant can handle it as follows:

[0071] -**User shopping cart information**: High priority, download time 30 minutes, because shopping cart information is critical to user experience and may be updated at any time.

[0072] -**Product Details**: Medium priority, download time 1 hour, because product details are updated less frequently but users visit them frequently.

[0073] -**User comments**: Low priority, download time 2 hours, because comments are usually not updated frequently and immediacy is not a high requirement.

[0074] By doing so, applicants can ensure that critical data is quickly accessed while optimizing the download efficiency of the server.

[0075] In another implementation, the download importance information is generated based on the real-time data download load information of the target server and in combination with the purpose and importance of the data to be downloaded. The following steps may be followed: First, monitor the usage of the current download, including the used space, access frequency, download hit rate, etc., divide the data to be downloaded into different categories, such as transaction data, user information, log records, etc., and evaluate the importance of each category of data. Considerations may include the sensitivity of the data, the impact on business decisions, legal and compliance requirements, etc., to determine the degree of impact of each type of data on business operations. For example, transaction data may be critical to the business, while log records may be mainly used for problem analysis and optimization.

[0076] Based on the evaluation results, set different download priorities for different categories of data. For example: high priority: transaction data, because they directly affect finance and customer trust; medium priority: user information, because they are critical to personalized services and user experience; low priority: log records, which are important for system maintenance and improvement, but have less impact on immediate business. According to the priority of the data, formulate corresponding download rules, including download duration, download location (memory or disk), download replacement strategy, etc., and download the data according to the formulated rules. Ensure that high-priority data is downloaded quickly and easily accessible, continuously monitor download performance and business impact, and adjust and optimize download strategies according to actual operating conditions. This can ensure that the server's download system can both efficiently process data and meet business needs and priorities for different data categories.

[0077] S109: Process the decrypted data to be downloaded based on the target download strategy to generate download data information.

[0078] In one implementation, the decrypted data to be downloaded is processed based on the target download strategy to generate download data information, and the principles and processes of data classification and grading need to be followed to ensure the security and compliance of the data. First, it is necessary to comprehensively sort out the data assets of the organization, including structured and unstructured data sources, to form a list of data assets, and to classify the data assets according to information such as the content, attributes, sources and context of the data. This can be completed with the assistance of automated tools, and manually verified to ensure the accuracy of the classification. According to the security level of the data and the degree of harm that may be caused, the data is divided into three levels: general data, important data and core data. The specific classification needs to be determined based on the degree of harm caused to national security, public interests or the legitimate rights and interests of individuals and organizations when the data is tampered with, destroyed, leaked or illegally obtained or illegally used.

[0079] According to the classification and grading results of the data, formulate corresponding data security protection strategies. Different protection measures should be taken for data of different categories and levels to ensure the security and legal use of the data. In the entire life cycle of the data, the data shall be classified and graded, including collection, storage, use, processing, transmission, provision and disclosure. The results of data classification and grading shall be reviewed, and the data classification and grading shall be dynamically updated according to the changes in the importance of the data and the degree of harm that may be caused. In the process of data processing throughout the life cycle, logs such as data processing, authority management, and personnel operations shall be recorded and monitored to facilitate the tracking and response of security incidents. Through the above steps, download data information can be generated and ensured to comply with the organization's data security policies and legal and regulatory requirements.

[0080] The application is that the target server obtains the digital certificate information, the unique identification information of the download terminal, the random number of the download terminal, the key-share information of the download terminal, the data processing level information of the download terminal and the security level information of the download terminal sent by the download terminal; obtains the random number of the target server and the key-share information of the target server; generates a pre-master key based on the key-share information of the download terminal and the key-share information of the target server; generates a temporary session key based on the random number of the download terminal, the random number of the target server and the pre-master key; processes the digital certificate information and the unique identification information of the download terminal based on the preset pairing rules to generate a processing result; if the processing result is to allow the target server to pair and connect with the download terminal, then obtains the configuration information, and the configuration information includes completing the connection with the download terminal The domain name certificate and other target server parameters required for the establishment process; encrypt the configuration information based on the temporary session key to generate the encrypted configuration information; obtain the real-time load balancing information of the target server and the data connection task information within the preset period; process the target server based on the data connection task information within the preset period to generate the preset connection progress information of the target server; process the data processing level information of the download terminal and the security level information of the download terminal to generate the target processing progress information, wherein the target processing progress information includes the processing time and connection time of the download terminal; process the preset connection progress information based on the target processing progress information to generate the connection priority of the download terminal; send the encrypted configuration information to the download terminal based on the connection priority of the download terminal to complete the connection establishment process.

[0081] Acquire the attribute information of the data to be downloaded, the access information of the target application and the biometric information of the target user sent by the download terminal; process the biometric information of the target user to generate initial facial image information and identity information of the target user, wherein the initial facial image information is the facial information of the target user within a preset time period; process the initial facial image information to generate the influencing factors of the facial expression characteristics of the target user; process the influencing factors of the facial expression characteristics of the target user based on a preset emotion recognition model to generate the target facial image information, wherein the target facial image information includes the expression change information of the target user; process the target facial image information to generate the emotional information of the target user; process the identity information of the target user and the emotional information of the target user to generate the identity attributes of the target user information, wherein the identity attribute information of the target user includes the identity information of the target user and the purpose information of the target user's data to be downloaded; obtaining a preset decryption mapping table, wherein the preset decryption mapping table includes data decryption information preset by several users; processing the identity attribute information of the target user based on the preset decryption mapping table to generate initial data decryption information, wherein the initial data decryption information includes several decryption rules set by the target user for different types of data to be downloaded; processing the initial data decryption information based on the attribute information of the data to be downloaded to generate target data decryption information, wherein the preset decryption rules are used to decrypt the encrypted data to be downloaded sent by the target server; processing the encrypted data to be downloaded based on the preset decryption rules to generate decrypted data to be downloaded.

[0082] Process the decrypted data to be downloaded to generate security level information of the download terminal of the data to be downloaded; process the attribute information of the data to be downloaded and the identity information of the target user to generate download priority information of the data to be downloaded; process the security level information of the download terminal of the data to be downloaded based on the download priority information of the data to be downloaded to generate an initial download duration of the data to be downloaded; process the initial download duration of the data to be downloaded based on the access information of the target application to generate a target download duration of the data to be downloaded; obtain the real-time data download processing information of the target server and other downloaded data information; process the usage information of the data to be downloaded based on the real-time data download processing information of the target server to generate download importance information of the data to be downloaded; process other downloaded data information based on the download importance information of the data to be downloaded to generate download data adjustment information, wherein the download data adjustment information is used to perform data deletion processing on the data to be downloaded or other downloaded data information; process the download priority information of the data to be downloaded and the target download duration of the data to be downloaded based on the download data adjustment information to generate download information of the data to be downloaded, wherein the download information of the data to be downloaded is used to characterize the final download duration and download timing of the data to be downloaded; process the decrypted data to be downloaded based on the target download strategy to generate download data information. The target server and the download terminal establish a connection based on preset rules, collect the attributes of the data to be downloaded, application access and user biometric information sent by it, process the user biometric information, and generate identity attribute information including identity and data usage. Combine the user identity attributes and the attributes of the data to be downloaded to create preset decryption rules for decrypting the encrypted data sent by the server, apply the decryption rules, generate decrypted data, and further process to generate security level information of the download terminal, and determine the download priority and target duration of the data by combining user identity, data attributes, security level and application access information. According to the preset download strategy, the download priority, target duration and user data usage are processed to form a target download strategy. According to the target download strategy, the decrypted data is finally processed to generate data information available for download, ensuring the security and priority management of the data during the download process, while taking into account the specific needs of the user and the security requirements of the system.

[0083] In one embodiment, if Figure 2 As shown, the present application also provides a microgrid system network security protection device, including:

[0084] The acquisition module 201 is used to acquire the attribute information of the data to be downloaded, the access information of the target application and the biometric information of the target user sent by the download terminal;

[0085] The processing module 202 is used to connect with the download terminal based on a preset processing rule; process the biometric information of the target user to generate the identity attribute information of the target user, wherein the identity attribute information of the target user includes the identity information of the target user and the purpose information of the data to be downloaded of the target user; generate a preset decryption rule based on the identity attribute information of the target user and the attribute information of the data to be downloaded, wherein the preset decryption rule is used to decrypt the encrypted data to be downloaded sent by the target server; process the encrypted data to be downloaded based on the preset decryption rule to generate decrypted data to be downloaded; process the decrypted data to be downloaded to generate security level information of the download terminal of the data to be downloaded; process the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded and the access information of the target application to generate the download priority information of the data to be downloaded and the target download duration of the data to be downloaded; process the download priority information of the data to be downloaded, the target download duration of the data to be downloaded and the purpose information of the data to be downloaded of the target user based on the preset download strategy to generate the target download strategy; process the decrypted data to be downloaded based on the target download strategy to generate download data information.

[0086] The present application embodiment provides an electronic device, such as Figure 3 As shown, the electronic device 3 includes a first processor 300, a memory 301, a bus 302 and a communication interface 303, and the first processor 300, the communication interface 303 and the memory 301 are connected via the bus 302; the memory 301 stores a computer program that can be run on the first processor 300, and when the first processor 300 runs the computer program, it executes the microgrid system network security protection method provided in any of the aforementioned embodiments of the present application.

[0087] The memory 301 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 303 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used.

[0088] The bus 302 may be an ISA bus, a PCI bus, or an EISA bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The memory 301 is used to store a program, and the first processor 300 executes the program after receiving an execution instruction. The microgrid system network security protection method disclosed in any implementation of the embodiment of the present application may be applied to the first processor 300, or implemented by the first processor 300.

[0089] The first processor 300 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the first processor 300. The above-mentioned first processor 300 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a readily available programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be embodied as a hardware decoding processor to execute, or a combination of hardware and software modules in the decoding processor to execute. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 301, and the first processor 300 reads the information in the memory 301 and completes the steps of the above method in combination with its hardware.

[0090] The electronic device provided in the above-mentioned embodiments of the present application and the method for protecting the network security of a microgrid system provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.

[0091] The present application embodiment provides a computer-readable storage medium, such as Figure 4 As shown, the computer-readable storage medium stores 401 a computer program, and the computer program is read and executed by the second processor 402 to implement the aforementioned microgrid system network security protection method.

[0092] The technical solution of the embodiment of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling an electronic device (which may be an air conditioner, a refrigeration device, a personal computer, a target server, or a network device, etc.) or a processor to execute all or part of the steps of the method described in the embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0093] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the microgrid system network security protection method provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.

[0094] An embodiment of the present application provides a computer program product, including a computer program, wherein the computer program is executed by a third processor to implement the method described above.

[0095] The computer program product provided in the above-mentioned embodiments of the present application and the method for protecting the network security of a microgrid system provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.

[0096] It should be noted that, in this application, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or still includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0097] Each embodiment in the present application is described in a related manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the protection method, electronic device, electronic device, and readable storage medium embodiment for evaluating the network security of a microgrid system, since they are basically similar to the above-mentioned protection method embodiment for the network security of a microgrid system, the description is relatively simple, and the relevant parts can be referred to the partial description of the above-mentioned protection method embodiment for the network security of a microgrid system.

[0098] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application shall be subject to the scope defined by the claims.

Claims

1. A method for protecting the network security of a microgrid system, characterized in that: Applied to the target server, including: Connecting with the download terminal based on preset processing rules; Acquire attribute information of the data to be downloaded, access information of the target application, and biometric information of the target user sent by the download terminal; Processing the biometric information of the target user to generate identity attribute information of the target user, wherein the identity attribute information of the target user includes the identity information of the target user and the usage information of the data to be downloaded by the target user; Generating a preset decryption rule based on the identity attribute information of the target user and the attribute information of the data to be downloaded, wherein the preset decryption rule is used to decrypt the encrypted data to be downloaded sent by the target server; Processing the encrypted data to be downloaded based on the preset decryption rule to generate decrypted data to be downloaded; Processing the decrypted data to be downloaded to generate security level information of a downloading terminal of the data to be downloaded; Processing the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded, and the access information of the target application to generate download priority information of the data to be downloaded and the target download duration of the data to be downloaded; Based on the preset download strategy, the download priority information of the data to be downloaded, the target download duration of the data to be downloaded, and the usage information of the data to be downloaded by the target user are processed to generate a target download strategy; Processing the decrypted data to be downloaded based on the target download strategy to generate download data information; Generating a preset decryption rule for the identity attribute information of the target user and the attribute information of the data to be downloaded, including: obtaining a preset decryption mapping table, wherein the preset decryption mapping table includes data decryption information preset by a plurality of users; processing the identity attribute information of the target user based on the preset decryption mapping table to generate initial data decryption information, wherein the initial data decryption information includes a plurality of decryption rules set by the target user for different types of data to be downloaded; processing the initial data decryption information based on the attribute information of the data to be downloaded to generate target data decryption information; The identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded, and the access information of the target application are processed to generate the download priority information of the data to be downloaded and the target download duration of the data to be downloaded, including: processing the attribute information of the data to be downloaded and the identity information of the target user to generate the download priority information of the data to be downloaded; processing the security level information of the download terminal of the data to be downloaded based on the download priority information of the data to be downloaded to generate the initial download duration of the data to be downloaded; processing the initial download duration of the data to be downloaded based on the access information of the target application to generate the target download duration of the data to be downloaded; Based on a preset download strategy, the download priority information of the data to be downloaded, the target download duration of the data to be downloaded and the usage information of the data to be downloaded of the target user are processed to generate a target download strategy, including: obtaining real-time data download processing information and other downloaded data information of the target server; processing the usage information of the data to be downloaded based on the real-time data download processing information of the target server to generate download importance information of the data to be downloaded; processing the other downloaded data information based on the download importance information of the data to be downloaded to generate download data adjustment information, wherein the download data adjustment information is used to perform data deletion processing on the data to be downloaded or other downloaded data information; processing the download priority information of the data to be downloaded and the target download duration of the data to be downloaded based on the download data adjustment information to generate download information of the data to be downloaded, wherein the download information of the data to be downloaded is used to characterize the final download duration and download timing of the data to be downloaded.

2. The method according to claim 1, characterized in that: Connect with the download terminal based on preset processing rules, including: Obtaining digital certificate information, unique identification information of the download terminal, random number of the download terminal, key-share information of the download terminal, data processing level information of the download terminal, and security level information of the download terminal sent by the download terminal; Get the target server random number and target server key-share information; Generate a pre-master key based on the download terminal key-share information and the target server key-share information; Generate a temporary session key based on the download terminal random number, the target server random number and the pre-master key; Processing the digital certificate information and the unique identification information of the download terminal based on a preset pairing rule to generate a processing result; If the processing result is to allow the target server to pair with the download terminal, then obtain configuration information, the configuration information including the domain name certificate and other target server parameters required to complete the connection establishment process with the download terminal; Encrypting the configuration information based on the temporary session key to generate encrypted configuration information; Processing the data processing level information of the download terminal and the security level information of the download terminal to generate a connection priority of the download terminal; The encrypted configuration information is sent to the download terminal based on the connection priority of the download terminal to complete the connection establishment process.

3. The method according to claim 2, characterized in that Processing the data processing level information of the download terminal and the security level information of the download terminal to generate a connection priority of the download terminal includes: Obtain the target server's real-time load balancing information and data connection task information within a preset period; Processing the target server based on the data connection task information within the preset period to generate preset connection progress information of the target server; Processing the data processing level information of the download terminal and the security level information of the download terminal to generate target processing progress information, wherein the target processing progress information includes the processing time and connection time of the download terminal; The preset connection progress information is processed based on the target processing progress information to generate a connection priority of the download terminal.

4. The method according to claim 1, characterized in that: The biometric information of the target user is processed to generate identity attribute information of the target user, including: Processing the biometric information of the target user to generate initial facial image information and identity information of the target user, wherein the initial facial image information is facial information of the target user within a preset time period; Processing the initial facial image information to generate expression feature influencing factors of the target user; Processing the influencing factors of the target user's expression characteristics based on a preset emotion recognition model to generate target face image information, wherein the target face image information includes expression change information of the target user; Processing the target face image information to generate emotion information of the target user; The identity information of the target user and the emotion information of the target user are processed to generate identity attribute information of the target user.

5. A protection device for microgrid system network security, characterized in that: include: An acquisition module, used to acquire attribute information of the data to be downloaded, access information of the target application, and biometric information of the target user sent by the download terminal; A processing module, used to connect with a download terminal based on a preset processing rule; process the biometric information of the target user to generate the identity attribute information of the target user, wherein the identity attribute information of the target user includes the identity information of the target user and the purpose information of the data to be downloaded of the target user; generate a preset decryption rule based on the identity attribute information of the target user and the attribute information of the data to be downloaded, wherein the preset decryption rule is used to decrypt the encrypted data to be downloaded sent by the target server; process the encrypted data to be downloaded based on the preset decryption rule to generate the decrypted data to be downloaded; process the decrypted data to be downloaded to generate the security level information of the download terminal of the data to be downloaded; process the identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded and the access information of the target application to generate the download priority information of the data to be downloaded and the target download duration of the data to be downloaded; process the download priority information of the data to be downloaded, the target download duration of the data to be downloaded and the purpose information of the data to be downloaded of the target user based on the preset download strategy to generate the target download strategy; process the decrypted data to be downloaded based on the target download strategy to generate the download data information; Generating a preset decryption rule for the identity attribute information of the target user and the attribute information of the data to be downloaded, including: obtaining a preset decryption mapping table, wherein the preset decryption mapping table includes data decryption information preset by a plurality of users; processing the identity attribute information of the target user based on the preset decryption mapping table to generate initial data decryption information, wherein the initial data decryption information includes a plurality of decryption rules set by the target user for different types of data to be downloaded; processing the initial data decryption information based on the attribute information of the data to be downloaded to generate target data decryption information; The identity information of the target user, the attribute information of the data to be downloaded, the security level information of the download terminal of the data to be downloaded, and the access information of the target application are processed to generate the download priority information of the data to be downloaded and the target download duration of the data to be downloaded, including: processing the attribute information of the data to be downloaded and the identity information of the target user to generate the download priority information of the data to be downloaded; processing the security level information of the download terminal of the data to be downloaded based on the download priority information of the data to be downloaded to generate the initial download duration of the data to be downloaded; processing the initial download duration of the data to be downloaded based on the access information of the target application to generate the target download duration of the data to be downloaded; Based on a preset download strategy, the download priority information of the data to be downloaded, the target download duration of the data to be downloaded and the usage information of the data to be downloaded of the target user are processed to generate a target download strategy, including: obtaining real-time data download processing information and other downloaded data information of the target server; processing the usage information of the data to be downloaded based on the real-time data download processing information of the target server to generate download importance information of the data to be downloaded; processing the other downloaded data information based on the download importance information of the data to be downloaded to generate download data adjustment information, wherein the download data adjustment information is used to perform data deletion processing on the data to be downloaded or other downloaded data information; processing the download priority information of the data to be downloaded and the target download duration of the data to be downloaded based on the download data adjustment information to generate download information of the data to be downloaded, wherein the download information of the data to be downloaded is used to characterize the final download duration and download timing of the data to be downloaded.

6. An electronic device, characterized in that: include: a first processor; as well as A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the microgrid system network security protection method as described in any one of claims 1 to 4 by executing the executable instructions.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the second processor, the method for protecting the network security of the microgrid system described in any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Vehicle-mounted OTA downloading method, device and equipment and storage medium

    CN116996863A

  • Power communication network data management method and device, electronic equipment and storage medium

    CN117807576A

  • Network security management method and related equipment

    CN118573483A