Dynamic access control method, device, computer equipment, readable storage medium and program product for a power platform

By evaluating the trust level and adjusting dynamic permissions on the access device side of the power platform, the problem that traditional protection methods cannot cope with diversified network attacks is solved, and efficient and secure access control of the power platform is achieved.

CN119094227BActive Publication Date: 2025-05-30ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411322734.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-05-30
Estimated Expiration
2044-09-23

AI Technical Summary

Technical Problem

Traditional network firewalls or virtual private networks cannot effectively protect the diverse network attack methods in new power systems, resulting in poor security access protection for power platforms.

Method used

By evaluating the trust level of the access device of the power platform, we can obtain the identity trust and behavioral trust of the target subject, the average resource conversion rate of the target object, and the network security status value of the access device, and dynamically adjust these trust levels, and dynamically adjust the current access permission level of the access device.

Benefits of technology

It realizes meticulous and accurate risk assessment and dynamic access control of the power platform, effectively improving the secure access protection of the power platform and adapting to the dynamic access control needs in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094227B_ABST
    Figure CN119094227B_ABST
Patent Text Reader

Abstract

The present application relates to a dynamic access control method, device, equipment, readable storage medium and program product for a power platform, and relates to the technical field of power security. The present application can improve the security protection of the power platform. The method includes: obtaining the identity trust degree and behavior trust degree of a target subject, and obtaining the first trust degree of the target subject according to the identity trust degree and behavior trust degree; obtaining the average value of the resource conversion rate of a target object, determining the target interval where the average value of the resource conversion rate is located, and obtaining the second trust degree of the target object according to the risk level corresponding to the target interval; obtaining the third trust degree of the access device end according to the network security state value of the access device end; obtaining the comprehensive trust degree of the access device end according to the first trust degree, the second trust degree, the third trust degree and the historical trust degree of the access device end, and dynamically adjusting the current access permission level of the access device end according to the initial trust degree and the comprehensive trust degree of the access device end.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of power security, and particularly to a dynamic access control method, device, computer device, computer-readable storage medium, and computer program product for a power platform. Background Art

[0002] With the rapid growth in the number of power facilities, the amount of data that the power platform needs to process is increasing, and it is necessary to ensure strong real-time performance and high reliability in data processing. The power platform corresponds to numerous power terminals, which requires the power platform to be able to implement complex, fine-grained, and large-scale access control.

[0003] To ensure the access security of the power platform, traditional network security access mostly relies on means such as network firewalls or virtual private networks. However, with the emergence of new power systems, there are many terminal devices connected to the power Internet of Things, and the services of each terminal device are numerous and complex. There are various network attack methods for different terminal devices, making it difficult to protect. Traditional means such as network firewalls or virtual private networks cannot ensure the secure access of the power platform and have problems with poor security protection. Summary of the Invention

[0004] Based on this, it is necessary to provide a dynamic access control method, device, computer device, computer-readable storage medium, and computer program product for a power platform in view of the above technical problems.

[0005] In a first aspect, the present application provides a dynamic access control method for a power platform, including:

[0006] For the power platform to be monitored, determine the access device end of the power platform and the target subject and target object of the access device end;

[0007] Obtain the identity trust degree and behavior trust degree of the target subject, and obtain the first trust degree of the target subject according to the identity trust degree and the behavior trust degree;

[0008] Obtain the average value of the resource conversion rate of the target object, determine the target interval where the average value of the resource conversion rate is located, and obtain the second trust degree of the target object according to the risk level corresponding to the target interval;

[0009] Obtain the network security status value of the access device end, and obtain the third trust degree of the access device end according to the network security status value;

[0010] Obtain the historical trust level of the access device end. Based on the first trust level, the second trust level, the third trust level, and the historical trust level, obtain the comprehensive trust level of the access device end, and dynamically adjust the current access permission level of the access device end according to the initial trust level and the comprehensive trust level of the access device end.

[0011] In one embodiment, the obtaining the identity trust level and the behavior trust level of the target subject includes:

[0012] Based on a static verification mechanism, perform security verification on each of the target subjects to obtain the trust values of each of the target subjects, perform a summation calculation on the trust values to obtain the identity trust level; based on a dynamic judgment mechanism, determine the security trust level of the target subject according to the unauthorized access records of the target subject, and determine the performance trust level of the target subject according to the subject access performance of the target subject; perform a fusion calculation on the security trust level and the performance trust level to obtain the behavior trust level.

[0013] In one embodiment, the obtaining the average resource conversion rate of the target object includes:

[0014] Determine various to-be-accessed resources included in the target object; obtain the resource access volume and the resource processing volume of each of the to-be-accessed resources, and obtain the resource conversion rate corresponding to each of the to-be-accessed resources according to the resource access volume and the resource processing volume; perform an average calculation on the resource conversion rates to obtain the average resource conversion rate.

[0015] In one embodiment, the obtaining the network security status value of the access device end and obtaining the third trust level of the access device end according to the network security status value includes:

[0016] Calculate the network security status value according to the risk warning records of the access device end; if the network security status value meets the security threshold condition, record the third trust level as a first value; if the network security status value does not meet the security threshold condition, record the third trust level as a second value.

[0017] In one embodiment, before dynamically adjusting the current access permission level of the access device end according to the initial trust level and the comprehensive trust level of the access device end, it further includes:

[0018] Obtain the relevant trust level data of the same type of access device end, determine the initial trust level based on the average value of the relevant trust level data; determine the initial access permission level of the access device end according to the initial trust level;

[0019] Dynamically adjusting the current access permission level of the access device terminal according to the initial trust level and the comprehensive trust level of the access device terminal includes:

[0020] Obtaining the trust level difference between the comprehensive trust level and the initial trust level, and determining the adjustment amount of the permission level according to the trust level difference; dynamically adjusting the current access permission level of the access device terminal according to the adjustment amount of the permission level on the basis of the initial access permission level.

[0021] In one embodiment, obtaining the comprehensive trust level of the access device terminal according to the first trust level, the second trust level, the third trust level, and the historical trust level includes:

[0022] Inputting the first trust level, the second trust level, and the third trust level into a preset current trust level calculation model to obtain the current trust level of the access device terminal; inputting the current trust level and the historical trust level into a preset comprehensive trust level calculation model to obtain the comprehensive trust level of the access device terminal.

[0023] In a second aspect, the present application further provides a dynamic access control device for a power platform, including:

[0024] An object determination module, configured to determine the access device terminal of the power platform, as well as the target subject and target object of the access device terminal, for the power platform to be monitored;

[0025] A first calculation module, configured to obtain the identity trust level and behavior trust level of the target subject, and obtain the first trust level of the target subject according to the identity trust level and the behavior trust level;

[0026] A first calculation module, configured to obtain the average value of the resource conversion rate of the target object, determine the target interval where the average value of the resource conversion rate is located, and obtain the second trust level of the target object according to the risk level corresponding to the target interval;

[0027] A first calculation module, configured to obtain the network security status value of the access device terminal, and obtain the third trust level of the access device terminal according to the network security status value;

[0028] A level adjustment module, configured to obtain the historical trust level of the access device terminal, obtain the comprehensive trust level of the access device terminal according to the first trust level, the second trust level, the third trust level, and the historical trust level, and dynamically adjust the current access permission level of the access device terminal according to the initial trust level and the comprehensive trust level of the access device terminal.

[0029] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0030] For a power platform to be monitored, determine the access device end of the power platform, as well as the target subject and target object of the access device end; obtain the identity trust degree and behavior trust degree of the target subject, and based on the identity trust degree and the behavior trust degree, obtain the first trust degree of the target subject; obtain the average resource conversion rate of the target object, determine the target interval where the average resource conversion rate is located, and based on the risk level corresponding to the target interval, obtain the second trust degree of the target object; obtain the network security status value of the access device end, and based on the network security status value, obtain the third trust degree of the access device end; obtain the historical trust degree of the access device end, and based on the first trust degree, the second trust degree, the third trust degree, and the historical trust degree, obtain the comprehensive trust degree of the access device end, and dynamically adjust the current access permission level of the access device end according to the initial trust degree and the comprehensive trust degree of the access device end.

[0031] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0032] For a power platform to be monitored, determine the access device end of the power platform, as well as the target subject and target object of the access device end; obtain the identity trust degree and behavior trust degree of the target subject, and based on the identity trust degree and the behavior trust degree, obtain the first trust degree of the target subject; obtain the average resource conversion rate of the target object, determine the target interval where the average resource conversion rate is located, and based on the risk level corresponding to the target interval, obtain the second trust degree of the target object; obtain the network security status value of the access device end, and based on the network security status value, obtain the third trust degree of the access device end; obtain the historical trust degree of the access device end, and based on the first trust degree, the second trust degree, the third trust degree, and the historical trust degree, obtain the comprehensive trust degree of the access device end, and dynamically adjust the current access permission level of the access device end according to the initial trust degree and the comprehensive trust degree of the access device end.

[0033] In a fifth aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0034] For the power platform to be monitored, determine the access device end of the power platform, as well as the target subject and target object of the access device end; obtain the identity trust degree and behavior trust degree of the target subject, and based on the identity trust degree and the behavior trust degree, obtain the first trust degree of the target subject; obtain the average value of the resource conversion rate of the target object, determine the target interval where the average value of the resource conversion rate is located, and based on the risk level corresponding to the target interval, obtain the second trust degree of the target object; obtain the network security status value of the access device end, and based on the network security status value, obtain the third trust degree of the access device end; obtain the historical trust degree of the access device end, and based on the first trust degree, the second trust degree, the third trust degree and the historical trust degree, obtain the comprehensive trust degree of the access device end, and based on the initial trust degree and the comprehensive trust degree of the access device end, dynamically adjust the current access permission level of the access device end.

[0035] The above-mentioned dynamic access control method, device, computer device, computer-readable storage medium and computer program product of the power platform start from the access device end of the power platform, evaluate the trust degree in dimensions such as the target subject, target object and network security status value of the access device end, and respectively obtain the first trust degree of the target subject, the second trust degree of the target object and the third trust degree of the device end. Furthermore, based on the results of each trust degree evaluation and the historical trust degree of the access device end, calculate the comprehensive trust degree of the access device end, and then perform dynamic access control on the access device end according to the comprehensive trust degree to realize the dynamic adjustment of the access permission of the device end, which can effectively ensure the secure access of the power platform and improve the security protection of the power platform at the same time. In addition, compared with the means such as network firewalls or virtual private networks used in traditional technologies, this solution directly starts from the specific device end for risk assessment, can analyze the risk situation of the device end more carefully and accurately, and adapt to the dynamic access control in various complex environments. Brief Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0037] Figure 1 It is an application environment diagram of the dynamic access control method of the power platform in an embodiment;

[0038] Figure 2 It is a flowchart of the dynamic access control method of the power platform in an embodiment;

[0039] Figure 3 Schematic diagram of the framework of the first trust level in an embodiment;

[0040] Figure 4 Schematic flow chart of the calculation steps of the average value of the resource conversion rate in an embodiment;

[0041] Figure 5 Schematic flow chart of the third trust level determination step in an embodiment;

[0042] Figure 6 Schematic flow chart of the dynamic access control method of the power platform in a specific embodiment;

[0043] Figure 7 Block diagram of the structure of the dynamic access control device of the power platform in an embodiment;

[0044] Figure 8 Internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0045] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0046] The dynamic access control method of the power platform provided by the embodiments of the present application can be applied to an application environment as shown in Figure 1 wherein, the terminal communicates with the server through a network. The data storage system can store the data that the server needs to process. The data storage system can be integrated on the server, or can be placed in the cloud or other network servers.

[0047] Specifically, the dynamic access control method of the power platform provided by the embodiments of the present application can be executed by the server.

[0048] Exemplarily, for the power platform to be monitored, the server determines the access device end of the power platform, as well as the target subject and target object of the access device end; the server obtains the identity trust level and behavior trust level of the target subject, and based on the identity trust level and behavior trust level, obtains the first trust level of the target subject; the server obtains the average resource conversion rate of the target object, determines the target interval in which the average resource conversion rate is located, and based on the risk level corresponding to the target interval, obtains the second trust level of the target object; the server obtains the network security status value of the access device end, and based on the network security status value, obtains the third trust level of the access device end; the server obtains the historical trust level of the access device end, and based on the first trust level, the second trust level, the third trust level and the historical trust level, obtains the comprehensive trust level of the access device end, and dynamically adjusts the current access permission level of the access device end according to the initial trust level and the comprehensive trust level of the access device end.

[0049] In an application environment as Figure 1 shown, the terminal can be, but is not limited to, various personal computers, laptop computers, smart phones and tablet computers. The server can be implemented by an independent server or a server cluster composed of multiple servers.

[0050] In one embodiment, as Figure 2 shown, a dynamic access control method for a power platform is provided. Taking the server in Figure 1 as an example for illustration, the method includes the following steps:

[0051] Step S201, for the power platform to be monitored, determine the access device end of the power platform, as well as the target subject and target object of the access device end.

[0052] Among them, the access device end can be, but is not limited to, various personal computers, laptop computers, smart phones and tablet computers, etc.

[0053] Among them, the target subject of the access device end can be a person, device, application or system that actively initiates a resource access behavior, that is, any one or more of the user, device, application or system of the access device end.

[0054] Among them, the target object of the access device end can be data resources, application resources, service resources, etc. within the power platform.

[0055] Specifically, the server, for the power platform to be monitored, in response to the dynamic access control instruction of the power platform, determines the access device end of the power platform, as well as the target subject and target object of the access device end.

[0056] Step S202, obtain the identity trust level and behavior trust level of the target subject, and based on the identity trust level and behavior trust level, obtain the first trust level of the target subject.

[0057] Among them, the identity trust level of the target entity can be determined from the user level, device level, application level, and system level.

[0058] Among them, the behavior trust level of the target entity can be specifically divided into security trust level and performance trust level. The security trust level is related to the unauthorized access of the entity to the power platform, and the performance trust level is a trust evaluation based on the performance of the entity accessing the power platform.

[0059] Specifically, the server obtains the identity trust level of the target entity based on a static verification mechanism, obtains the behavior trust level of the target entity based on a dynamic judgment mechanism, and obtains the first trust level of the target entity according to the identity trust level and the behavior trust level.

[0060] Step S203: Obtain the average value of the resource conversion rate of the target object, determine the target interval where the average value of the resource conversion rate is located, and obtain the second trust level of the target object according to the risk level corresponding to the target interval.

[0061] Among them, the average value of the resource conversion rate can be the average value corresponding to the access conversion rates of data resources, application resources, and service resources.

[0062] Among them, the target interval can be any one of a low-risk interval, a medium-risk interval, and a high-risk interval.

[0063] Specifically, the server obtains the resource access volume and resource processing volume of various resources to be accessed, obtains the resource conversion rate corresponding to each resource to be accessed according to the resource access volume and the resource processing volume; calculates the average value of the resource conversion rate, determines the target interval where the average value of the resource conversion rate is located, and obtains the second trust level of the target object according to the risk level corresponding to the target interval.

[0064] Step S204: Obtain the network security status value of the access device end, and obtain the third trust level of the access device end according to the network security status value.

[0065] Among them, the network security status value can be used to evaluate the network security status of the access device end, and is mainly obtained by evaluating the number of risk warning events occurring and the consequences caused after the warning events occur.

[0066] Specifically, the server obtains the risk warning records of the access device end, calculates the network security status value according to the risk warning records; if the network security status value meets the security threshold condition, then records the third trust level as the first value; if the network security status value does not meet the security threshold condition, then records the third trust level as the second value.

[0067] Step S205: Obtain the historical trust level of the access device end. Based on the first trust level, the second trust level, the third trust level, and the historical trust level, obtain the comprehensive trust level of the access device end, and dynamically adjust the current access permission level of the access device end according to the initial trust level and the comprehensive trust level of the access device end.

[0068] Among them, the historical trust level can be the trust level data generated by the access device end within a specified historical period.

[0069] Specifically, the server obtains the historical trust level of the access device end. Based on the first trust level, the second trust level, the third trust level, and the historical trust level, it obtains the comprehensive trust level of the access device end, obtains the trust level difference between the comprehensive trust level and the initial trust level, and determines the permission level adjustment amount according to the trust level difference; on the basis of the initial access permission level, it dynamically adjusts the current access permission level of the access device end according to the permission level adjustment amount to achieve dynamic access control of the power platform.

[0070] The above dynamic access control method for the power platform starts from the access device end of the power platform, conducts trust level evaluations on dimensions such as the target subject, target object, and network security status value of the access device end, respectively obtains the first trust level of the target subject, the second trust level of the target object, and the third trust level of the device end, and then calculates the comprehensive trust level of the access device end based on each trust level evaluation result and the historical trust level of the access device end. Then, according to the comprehensive trust level, it conducts dynamic access control on the access device end to achieve dynamic adjustment of the access permission of the device end, which can effectively ensure the secure access of the power platform and improve the security protection of the power platform at the same time. In addition, compared with the means such as network firewalls or virtual private networks used in traditional technologies, this solution directly starts from the specific device end for risk assessment, can analyze the risk situation of the device end more carefully and accurately, and adapts to dynamic access control in various complex environments.

[0071] In one embodiment, in the above step S202, obtaining the identity trust level and behavior trust level of the target subject specifically includes the following steps:

[0072] Based on the static verification mechanism, conduct security verification on each target subject to obtain the trust value of each target subject, perform a summation calculation on the trust values to obtain the identity trust level; based on the dynamic judgment mechanism, determine the security trust level of the target subject according to the unauthorized access record of the target subject, and determine the performance trust level of the target subject according to the subject access performance of the target subject; perform a fusion calculation on the security trust level and the performance trust level to obtain the behavior trust level.

[0073] Specifically, as Figure 3 shown, the trust level access for the target subject can be divided into the identity trust level and the behavior trust level:

[0074] 1. The identity-based trust level is determined by a static verification mechanism, including the user identification code at the user level, the device identification code, physical address, and IP address at the device level, the application software at the application level, and the operating system at the system level. Corresponding security trust values are configured for the specific content of each level. If any item is identified as secure, the trust value is 1; otherwise, it is 0. The calculation method of the identity-based trust level is as follows: Identity-based trust level = Trust value of user identification code + Trust value of device identification code + Trust value of physical address + Trust value of IP address + Trust value of application software + Trust value of operating system.

[0075] 2. The behavior-based trust level is dynamically judged by the historical and current behaviors of the subject, which can be specifically divided into security trust level and performance trust level:

[0076] (1) Security trust level

[0077] The security trust level of the subject is related to the unauthorized access of the subject to the power platform. represents the number of unauthorized accesses of the user , represents the unauthorized access frequency of the user , represents the average unauthorized access frequency of all users, represents the variance of f, then follows a normal distribution. Thus, the interval where is located can be calculated, and combined with the risk levels corresponding to each pre-given interval, the security trust level of the subject is determined. Falling into the interval corresponding to the risk level is , ), and the corresponding security trust level is 1; when falling into other intervals, the corresponding security trust level is 0.

[0078] (2) Performance trust level

[0079] The performance trust level of the subject is a trust evaluation based on the performance of the subject's access to the power platform. The subject performance includes the number of bytes of the request sent by the subject to the power platform, the number of bytes of the response request of the power platform, and the time difference between the two. The calculation formula for the performance trust level of the subject is:

[0080]

[0081] In the above formula, , and are the influencing factors of the trust levels of the corresponding performances, which can be determined by combining historical statistical data. The number of bytes of the data request sent by the user accessing the device side to the power platform, The number of bytes for the power platform to respond to the data request, The time difference between the sending and response of the data request.

[0082] In one embodiment, as Figure 4 shown, in the above step S203, obtaining the average resource conversion rate of the target object specifically includes the following steps:

[0083] Step S401, determining multiple resources to be accessed included in the target object.

[0084] Step S402, obtaining the resource access amount and resource processing amount of various resources to be accessed, and obtaining the resource conversion rate corresponding to each resource to be accessed according to the resource access amount and resource processing amount.

[0085] Step S403, calculating the average value of the resource conversion rates to obtain the average resource conversion rate.

[0086] Specifically, the server determines multiple resources to be accessed included in the target object; obtains the resource access amount and resource processing amount of various resources to be accessed, and obtains the resource conversion rate corresponding to each resource to be accessed according to the resource access amount and resource processing amount; finally, calculates the average value of the resource conversion rates to obtain the average resource conversion rate.

[0087] For example, the object accessing the device side includes data resources, application resources, service resources, etc. in the power platform. The trust level of the object accessing the device side is calculated through the conversion rate of the resource access of the device side to the power platform. After the access device of the power terminal accesses the resources of the power platform, it processes the accessed resources, that is, converts them. Let be the resource access amount of the access device to the power platform, be the processing amount of the accessed resources, then the access conversion rate calculation formula is . Calculate the access conversion rates of data resources, application resources, and service resources respectively, and calculate the average value of their conversion rates. Calculate the average conversion rate s of all access device sides through historical data and calculate the variance . obeys normal distribution. From this, the interval where is located can be calculated. Combining the risk levels corresponding to each interval, the trust level of the object accessing the device side can be determined.

[0088] For further explanation, to determine the security trust level of user u, we can calculate the interval where is located, and then determine the risk level according to this interval. The calculation formula can be expressed as:

[0089]

[0090] In the above formula, represents the probability density of the unauthorized access frequency of user u in the normal distribution. Next, in order to determine the interval where it is located, we can calculate its standardized score (Z-score):

[0091]

[0092] In the above formula, is the standard deviation of F, that is . Then, a standard normal distribution table or calculation method can be used to determine the corresponding cumulative probability, and further determine the interval where F is located.

[0093] Finally, according to the pre-given risk level interval, we can determine the security trust level of user u. If falls within the low-risk interval, then the security trust level of user u is high. If falls within the medium-risk interval, then the security trust level of user u is medium. If falls within the high-risk interval, then the security trust level of user u is low. The summary formula is as follows:

[0094]

[0095] Among them, is a mapping function that maps the value of to the corresponding risk level.

[0096] In one of the embodiments, as Figure 5 shown, in the above step S204, obtaining the network security status value of the access device end, and according to the network security status value, obtaining the third trust level of the access device end, specifically including the following steps:

[0097] Step S501, calculate the network security status value according to the risk warning record of the access device end.

[0098] Step S502, if the network security status value meets the security threshold condition, then record the third trust level as the first value.

[0099] Step S503, if the network security status value does not meet the security threshold condition, then record the third trust level as the second value.

[0100] Specifically, the server inputs the risk warning records of the access device end into a preset network security status value calculation model to obtain the network security status value of the access device end; then it determines whether the network security status value meets the security threshold condition. If the network security status value meets the security threshold condition, the third trust level is recorded as the first value; if the network security status value does not meet the security threshold condition, the third trust level is recorded as the second value.

[0101] For example, the power platform sets multiple monitoring components to monitor the network environment of the access to the access device end. The diversity of each monitoring component generates multiple different risk warning events. The network security status value can be calculated through to calculate, represents the proportion of the number of occurrences of risk warning events of type in all events; represents the consequences caused after the warning events of type occur, represents the network security status, from which the network security status is calculated. When the calculated network security status is greater than the set security threshold, the trust level of the network environment of the access device end is 1, otherwise it is 0.

[0102] In one embodiment, before dynamically adjusting the current access permission level of the access device end according to the initial trust level and the comprehensive trust level of the access device end, the method of the present application further includes the following steps:

[0103] Obtain the relevant trust level data of the same type of access device end, determine the initial trust level based on the average value of the relevant trust level data; determine the initial access permission level of the access device end according to the initial trust level;

[0104] In the above step S205, dynamically adjusting the current access permission level of the access device end according to the initial trust level and the comprehensive trust level of the access device end specifically includes the following steps:

[0105] Obtain the trust level difference between the comprehensive trust level and the initial trust level, and determine the permission level adjustment amount according to the trust level difference; on the basis of the initial access permission level, dynamically adjust the current access permission level of the access device end according to the permission level adjustment amount.

[0106] Specifically, the server obtains the relevant trust level data of the same type of access device end, determines the initial trust level based on the average value of the relevant trust level data; determines the initial access permission level of the access device end according to the initial trust level; then, the server obtains the trust level difference between the comprehensive trust level and the initial trust level, and determines the permission level adjustment amount according to the trust level difference; on the basis of the initial access permission level, dynamically adjust the current access permission level of the access device end according to the permission level adjustment amount.

[0107] For example, for a device terminal that first accesses the power platform, an initial value of trust needs to be assigned to it. This initial value cannot be too low, as being too low will cause the device terminal to be unable to access the power platform, or even if it can access the power platform, it cannot guarantee appropriate access permissions. Of course, this initial value cannot be too high either, as too high a trust level will bring great access risks to the power platform. This solution uses the average trust level of devices of the same type to assign an initial value to this device terminal. , where represents the trust level of the i-th device of the same type, and assigns an initial value to this device terminal.

[0108] The power platform dynamically adjusts the corresponding access permissions according to the change in the trust level of the accessed device terminal, and calculates the current trust level of the accessed device terminal based on the above steps . The power platform determines the trust level of the accessed device terminal based on the current trust level and historical trust level of the accessed device terminal.

[0109]

[0110] represents the historical trust level; represents the historical factor, that is, the role of the historical trust level in the current trust level; represents the current trust level, that is, the calculated above.

[0111]

[0112] In the above formula, is the attenuation rate with a value in the range of [0, 1], is a value in the range of [0, 1] and can be adjusted manually based on experience.

[0113]

[0114] In the above formula, represents the trust levels corresponding to each historical moment, n represents the selected multiple historical moments, and n is a positive integer greater than 1; according to the calculated of the accessed device terminal, configure the corresponding access permission level for the device terminal.

[0115] In one embodiment, in the above step S205, according to the first trust level, the second trust level, the third trust level, and the historical trust level, obtain the comprehensive trust level of the accessed device terminal, which specifically includes the following steps:

[0116] Input the first trust level, the second trust level, and the third trust level into a preset current trust level calculation model to obtain the current trust level of the access device end; input the current trust level and the historical trust level into a preset comprehensive trust level calculation model to obtain the comprehensive trust level of the access device end.

[0117] Specifically, the server inputs the first trust level, the second trust level, and the third trust level into a preset current trust level calculation model to obtain the current trust level of the access device end; then inputs the current trust level and the historical trust level into a preset comprehensive trust level calculation model to obtain the comprehensive trust level of the access device end.

[0118] For example, for the accessed device end, introduce the concept of continuous monitoring under time granularity and perform dynamic access control on the accessed device end:

[0119]

[0120] Indicates the trust level of the accessed device end evaluated under consecutive time granularities, where α + β + γ = 1. Indicates the trust level of the subject of the access device end of the power platform, Indicates the trust level evaluation of the object accessed in the power platform, Indicates the trust level of the network environment of the access device end.

[0121] In one embodiment, as Figure 6 shown, a dynamic access control method for a power platform in a specific embodiment is provided, which specifically includes the following steps:

[0122] Step S601, for the power platform to be monitored, determine the access device end of the power platform and the target subject and target object of the access device end.

[0123] Step S602, based on the static verification mechanism, perform security verification on each target subject to obtain the trust value of each target subject, perform a summation calculation on the trust values to obtain the identity trust level; based on the dynamic judgment mechanism, determine the security trust level of the target subject according to the unauthorized access record of the target subject, and determine the performance trust level of the target subject according to the subject access performance of the target subject; perform a fusion calculation on the security trust level and the performance trust level to obtain the behavior trust level; obtain the first trust level of the target subject according to the identity trust level and the behavior trust level.

[0124] Step S603: Determine various resources to be accessed in the target object; obtain the resource access volume and resource processing volume of each resource to be accessed, and based on the resource access volume and resource processing volume, obtain the resource conversion rate corresponding to each resource to be accessed; calculate the average value of the resource conversion rates to obtain the average resource conversion rate, determine the target interval where the average resource conversion rate is located, and based on the risk level corresponding to the target interval, obtain the second trust level of the target object.

[0125] Step S604: Calculate the network security status value based on the risk warning records of the access device end; if the network security status value meets the security threshold condition, record the third trust level as the first value; if the network security status value does not meet the security threshold condition, record the third trust level as the second value.

[0126] Step S605: Obtain the historical trust level of the access device end, input the first trust level, the second trust level, and the third trust level into the preset current trust level calculation model to obtain the current trust level of the access device end; input the current trust level and the historical trust level into the preset comprehensive trust level calculation model to obtain the comprehensive trust level of the access device end.

[0127] Step S606: Obtain the relevant trust level data of the same type of access device end, determine the initial trust level based on the average value of the relevant trust level data; determine the initial access permission level of the access device end according to the initial trust level; obtain the trust level difference between the comprehensive trust level and the initial trust level, and determine the permission level adjustment amount according to the trust level difference; dynamically adjust the current access permission level of the access device end based on the permission level adjustment amount on the basis of the initial access permission level.

[0128] The beneficial effects brought by the above embodiments are as follows:

[0129] This solution starts from the access device end of the power platform, evaluates the trust levels in dimensions such as the target subject, target object, and network security status value of the access device end, respectively obtaining the first trust level of the target subject, the second trust level of the target object, and the third trust level of the device end. Then, based on the results of each trust level evaluation and the historical trust level of the access device end, the comprehensive trust level of the access device end is calculated. Subsequently, according to the comprehensive trust level, dynamic access control is performed on the access device end to achieve dynamic adjustment of the device end access permissions, which can effectively ensure the secure access of the power platform and improve the security protection of the power platform at the same time. Compared with traditional methods such as using network firewalls or virtual private networks, this solution directly starts from the specific device end for risk assessment and can analyze the risk situation of the device end more meticulously and accurately. In the complex application scenario where different power terminal devices correspond to different service types and may adopt different network attack methods, the dynamic access control method of the power platform based on trust level in this solution is more flexible and can adapt to dynamic access control in various complex environments.

[0130] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment but can be executed at different moments, and the execution order of these steps or stages is not necessarily sequential but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0131] Based on the same inventive concept, an embodiment of the present application also provides a dynamic access control device for a power platform for implementing the dynamic access control method of the power platform involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the dynamic access control device for the power platform provided below can refer to the limitations on the dynamic access control method of the power platform in the above text and will not be elaborated here.

[0132] In an exemplary embodiment, as Figure 7 shown, a dynamic access control device for a power platform is provided, including:

[0133] An object determination module 701, configured to determine the access device end of the power platform and the target subject and target object of the access device end for the power platform to be monitored;

[0134] The first calculation module 702 is configured to obtain the identity trust degree and the behavior trust degree of the target subject, and obtain the first trust degree of the target subject according to the identity trust degree and the behavior trust degree;

[0135] The second calculation module 703 is configured to obtain the average value of the resource conversion rate of the target object, determine the target interval in which the average value of the resource conversion rate is located, and obtain the second trust degree of the target object according to the risk level corresponding to the target interval;

[0136] The third calculation module 704 is configured to obtain the network security status value of the access device end, and obtain the third trust degree of the access device end according to the network security status value;

[0137] The level adjustment module 705 is configured to obtain the historical trust degree of the access device end, obtain the comprehensive trust degree of the access device end according to the first trust degree, the second trust degree, the third trust degree and the historical trust degree, and dynamically adjust the current access permission level of the access device end according to the initial trust degree and the comprehensive trust degree of the access device end.

[0138] In one embodiment, the first calculation module 702 is further configured to perform security verification on each target subject based on a static verification mechanism, obtain the trust value of each target subject, perform a summation calculation on the trust values to obtain the identity trust degree; based on a dynamic judgment mechanism, determine the security trust degree of the target subject according to the unauthorized access record of the target subject, and determine the performance trust degree of the target subject according to the subject access performance of the target subject; perform a fusion calculation on the security trust degree and the performance trust degree to obtain the behavior trust degree.

[0139] In one embodiment, the second calculation module 703 is further configured to determine various resources to be accessed included in the target object; obtain the resource access amount and the resource processing amount of each resource to be accessed, and obtain the resource conversion rate corresponding to each resource to be accessed according to the resource access amount and the resource processing amount; perform an average value calculation on the resource conversion rate to obtain the average value of the resource conversion rate.

[0140] In one embodiment, the third calculation module 704 is further configured to calculate the network security status value according to the risk warning record of the access device end; if the network security status value meets the security threshold condition, record the third trust degree as a first value; if the network security status value does not meet the security threshold condition, record the third trust degree as a second value.

[0141] In one embodiment, the dynamic access control device of the power platform further includes a level determination module, configured to obtain relevant trustworthiness data of access device ends of the same type, determine an initial trustworthiness based on the average value of the relevant trustworthiness data; determine an initial access permission level of the access device end according to the initial trustworthiness; a level adjustment module 705, further configured to obtain a trustworthiness difference between the comprehensive trustworthiness and the initial trustworthiness, and determine an adjustment amount of the permission level according to the trustworthiness difference; and dynamically adjust the current access permission level of the access device end based on the adjustment amount of the permission level on the basis of the initial access permission level.

[0142] In one embodiment, the level adjustment module 705 is further configured to input the first trustworthiness, the second trustworthiness, and the third trustworthiness into a preset current trustworthiness calculation model to obtain the current trustworthiness of the access device end; and input the current trustworthiness and the historical trustworthiness into a preset comprehensive trustworthiness calculation model to obtain the comprehensive trustworthiness of the access device end.

[0143] Each module in the above-mentioned dynamic access control device of the power platform can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor in the computer device in the form of hardware or be independent of the processor, or can be stored in the memory in the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above-mentioned modules.

[0144] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for communicating with an external terminal through a network connection. The computer program, when executed by the processor, implements a dynamic access control method for a power platform.

[0145] Those skilled in the art can understand, Figure 8The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0146] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0147] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0148] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0149] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0150] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0151] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in the present application.

[0152] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A dynamic access control method for a power platform, characterized in that: The method comprises: For the power platform to be monitored, determining the access device end of the power platform and the target subject and target object of the access device end; Acquire the identity trust and behavior trust of the target subject, and obtain a first trust of the target subject according to the identity trust and the behavior trust; Obtaining an average resource conversion rate of the target object, determining a target interval in which the average resource conversion rate is located, and obtaining a second trust level of the target object according to a risk level corresponding to the target interval; the average resource conversion rate is an average value corresponding to the access conversion rate of data resources, application resources, and service resources in the power platform; Acquire a network security status value of the access device end, and obtain a third trust level of the access device end according to the network security status value; Obtain the historical trust of the access device end, obtain the comprehensive trust of the access device end according to the first trust, the second trust, the third trust and the historical trust, and dynamically adjust the current access permission level of the access device end according to the initial trust of the access device end and the comprehensive trust; the initial trust is the average value of the relevant trust data of the same type of access device ends.

2. The method according to claim 1, characterized in that The obtaining of the identity trust and behavior trust of the target subject includes: Based on the static verification mechanism, security verification is performed on each of the target subjects to obtain a trust value of each of the target subjects, and the trust values ​​are summed to obtain the identity trust degree; Based on a dynamic judgment mechanism, the security trust of the target subject is determined according to the unauthorized access record of the target subject, and the performance trust of the target subject is determined according to the subject access performance of the target subject; the security trust and the performance trust are fused and calculated to obtain the behavior trust.

3. The method according to claim 1, characterized in that The obtaining the average resource conversion rate of the target object includes: Determining a plurality of resources to be accessed contained in the target object; Obtaining resource access amounts and resource processing amounts of various resources to be accessed, and obtaining resource conversion rates corresponding to various resources to be accessed according to the resource access amounts and the resource processing amounts; An average value of the resource conversion rate is calculated to obtain an average value of the resource conversion rate.

4. The method according to claim 1, characterized in that: The acquiring the network security status value of the access device end, and obtaining the third trust level of the access device end according to the network security status value, comprises: Calculating the network security status value according to the risk warning record of the access device end; If the network security status value satisfies the security threshold condition, the third trust degree is recorded as the first value; If the network security status value does not meet the security threshold condition, the third trust level is recorded as the second value.

5. The method according to claim 1, characterized in that Before dynamically adjusting the current access authority level of the access device terminal according to the initial trust of the access device terminal and the comprehensive trust, the method further includes: Obtain relevant trust data of the same type of access device terminals, and determine the initial trust based on an average value of the relevant trust data; Determining an initial access permission level of the access device terminal according to the initial trust level; The dynamically adjusting the current access permission level of the access device terminal according to the initial trust level and the comprehensive trust level of the access device terminal includes: Obtaining a trust difference between the comprehensive trust and the initial trust, and determining an authority level adjustment amount according to the trust difference; Based on the initial access permission level, the current access permission level of the access device is dynamically adjusted according to the permission level adjustment amount.

6. The method according to any one of claims 1 to 5, characterized in that: The obtaining of the comprehensive trust of the access device terminal according to the first trust, the second trust, the third trust and the historical trust includes: Inputting the first trust, the second trust, and the third trust into a preset current trust calculation model to obtain the current trust of the access device end; The current trust and the historical trust are input into a preset comprehensive trust calculation model to obtain the comprehensive trust of the access device.

7. A dynamic access control device for a power platform, characterized in that: The device comprises: An object determination module is used to determine, for a power platform to be monitored, an access device end of the power platform and a target subject and a target object of the access device end; A first calculation module, used to obtain the identity trust and behavior trust of the target subject, and obtain a first trust of the target subject according to the identity trust and the behavior trust; a second calculation module, for obtaining an average resource conversion rate of the target object, determining a target interval in which the average resource conversion rate is located, and obtaining a second trust level of the target object according to a risk level corresponding to the target interval; the average resource conversion rate is an average value corresponding to the access conversion rate of data resources, application resources and service resources in the power platform; A third calculation module, used to obtain a network security status value of the access device end, and obtain a third trust level of the access device end according to the network security status value; A level adjustment module is used to obtain the historical trust of the access device end, obtain the comprehensive trust of the access device end according to the first trust, the second trust, the third trust and the historical trust, and dynamically adjust the current access permission level of the access device end according to the initial trust of the access device end and the comprehensive trust; the initial trust is the average value of the relevant trust data of the same type of access device ends.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Credit big data-oriented risk control method and credit big data-oriented risk control system

    CN111177743A

  • Zero-trust power Internet of Things equipment and user real-time trust degree evaluation method

    CN112055029A