Virtual power plant data security protection method, platform, device and system based on cloud computing platform

By employing data segmentation and encryption methods from a cloud computing platform in a virtual power plant, and combining data security level, device IP, data value, and type, personalized encryption keys are generated. This solves the security problem caused by key leakage during data transmission in the virtual power plant, and improves transmission efficiency and security.

CN119299147BActive Publication Date: 2026-05-12HUBEI RONGHUI INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUBEI RONGHUI INFORMATION TECH CO LTD
Filing Date
2024-09-29
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In the data transmission of virtual power plants, the leakage of fixed keys can easily lead to data leaks, and existing technologies are insufficient to effectively protect the security and transmission efficiency of sensitive data.

Method used

A data security protection method based on a cloud computing platform is adopted. After receiving the data acquisition request from the target device, the target data is read, segmented, and a dynamic encryption key is determined according to the data volume, security level, device IP, data value and type. The data is then encrypted and transmitted.

Benefits of technology

It improves the efficiency and security of data transmission. The generation of dynamic encryption keys enhances the security and flexibility of data transmission and reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119299147B_ABST
    Figure CN119299147B_ABST
Patent Text Reader

Abstract

The application relates to a virtual power plant data security protection method, platform, equipment and system based on a cloud computing platform, applied to the field of data security protection, and the method comprises the following steps: receiving a data acquisition request of a target equipment, wherein the data acquisition request comprises to-be-acquired data information and a data security level; reading target data corresponding to the to-be-acquired data information from a database; performing data segmentation on the target data according to a data volume, to obtain a plurality of segmented data; determining an encryption key according to the data security level, the IP of the target equipment, data value and data type; encrypting the plurality of segmented data through the encryption key, and sending the encrypted data to the target equipment; the encryption key can be determined by combining information on the target equipment side and information of the target data in the platform, so that the key security is better, and the data transmission is safer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security protection, and in particular to a method, platform, device and system for data security protection of a virtual power plant based on a cloud computing platform. Background Technology

[0002] With the rapid development of smart grids and distributed energy technologies, the data security of virtual power plants, as an important platform for integrating distributed resources and optimizing energy allocation, has become particularly crucial. Virtual power plants involve a large amount of sensitive data, including but not limited to the status of power generation equipment, electricity trading information, and user privacy data. The security of this data directly affects the stable operation of the power grid, the fairness of market transactions, and the protection of user privacy.

[0003] When virtual power plants transmit data to distributed energy management devices or energy consumer devices, a unique key is typically assigned to each device to encrypt the data and ensure data transmission security. However, if this fixed key is leaked, data breaches can easily occur. Summary of the Invention

[0004] The purpose of this application is to provide a method, platform, device, and system for data security protection of virtual power plants based on a cloud computing platform, which can reduce the occurrence of data leakage.

[0005] Firstly, a data security protection method for virtual power plants based on a cloud computing platform is provided, including:

[0006] Receive a data acquisition request from the target device, the data acquisition request including the data information to be acquired and the data security level;

[0007] Read target data corresponding to the data information to be acquired from the database. The database stores power generation equipment information and electricity consumption information related to virtual power plant data. The target data includes data to be processed, data volume, data value, and data type.

[0008] The target data is segmented according to the data volume to obtain several segmented data;

[0009] The encryption key is determined based on the data security level, the target device's IP address, the data value, and the data type.

[0010] The data segments are encrypted using an encryption key, and the encrypted data is then sent to the target device.

[0011] By adopting the above technical solution, after receiving a data acquisition request from the target device, the target data can be read and segmented based on the data volume. This not only improves the efficiency of data transmission but also further enhances data security. By combining the data security level in the data acquisition request, the target device's IP address, and other target device-side information, as well as the data value and data type of the target data within the platform, the encryption key is jointly determined by data information from two different sources. This ensures that the key is determined based on the actual situation, resulting in better security and making data transmission more secure.

[0012] In a preferred embodiment, this application can be further configured as follows: the target data is segmented according to the data volume to obtain several segmented data, including:

[0013] Based on current and historical equipment performance information, predict equipment performance information during the data transmission period;

[0014] Determine the data volume and device performance information during the data transmission period to determine whether data segmentation is necessary.

[0015] If data segmentation is required, the initial horizontal segmentation information is determined based on the data type of the target data; the initial vertical segmentation information is determined based on the data value corresponding to each data point in the target data.

[0016] Based on the device performance information during the data transmission period, the initial horizontal segmentation information and the initial vertical segmentation information are corrected to obtain the horizontal segmentation information and the vertical segmentation information.

[0017] The target data is segmented according to the horizontal and vertical segmentation information to obtain several segmented data.

[0018] By adopting the above technical solution, the device performance during the data transmission period is accurately predicted based on current and historical device performance information. Based on the predicted device performance and data volume, it intelligently determines whether data segmentation is necessary. If the data volume exceeds the device's processing capacity during the transmission cycle, the segmentation strategy is further refined. By considering the data type of the target data, an initial horizontal segmentation strategy is determined to ensure that different types of data are processed in the most appropriate way. Simultaneously, an initial vertical segmentation strategy is formulated based on the specific value of each data item. The initial segmentation strategy is dynamically adjusted based on real-time predicted device performance information to ensure that the segmented data meets transmission requirements while optimizing transmission efficiency, thereby improving the reliability and efficiency of data transmission.

[0019] In a preferred embodiment, this application can be further configured such that: predicting device performance information within a data transmission period based on current device performance information and historical device performance information includes:

[0020] A device performance prediction model is obtained, which is trained based on multiple historical device information. The historical device information includes: historical device performance information for the current time period from multiple adjacent historical dates, and historical device performance information for the next time period after the current time period.

[0021] Based on the current device performance information, the device performance prediction model is used to predict the device performance information during the data transmission period.

[0022] Determine whether the current time is an abnormal time. If so, adjust the device performance information for the data transmission period based on the current time to obtain the adjusted device performance information for the data transmission period.

[0023] By adopting the above technical solution, a device performance prediction model based on a large amount of historical data is obtained. This model not only learns the performance change patterns of the device in different time periods to achieve accurate prediction of future device performance and obtain device performance prediction information during the data transmission period, but also has the ability to detect abnormal moments. Once it is found that the current moment is an abnormal moment (such as holidays), it can quickly adjust the prediction results to ensure that the prediction information remains highly accurate in complex and ever-changing real environments.

[0024] In a preferred embodiment, this application can be further configured such that determining the encryption key based on the data security level, the target device's IP address, the data value, and the data type includes:

[0025] By integrating the various sets of data and data security levels in the target device's IP address, a first value is obtained;

[0026] When the data security level is greater than the preset data security level threshold, the first determination step is executed;

[0027] When the data security level is not greater than the preset data security level threshold, the second determination step is executed;

[0028] The first determining step includes: dividing the first value by the value corresponding to the data value to obtain a second value, wherein the second value includes an integer divisor and a remainder; if there is no remainder, dividing the integer value by the value corresponding to the data type to obtain a third value, and determining the row value and column value based on the third value; if there is a remainder, using the remainder as the column value, and determining the row value corresponding to the column value; and determining the encryption key from a preset list of keys and encryption key lengths based on the row value and column value.

[0029] The second determination step includes: determining the encryption key length based on the data value and data type, and determining the encryption key based on the encryption key length and data security level.

[0030] By adopting the above technical solution, a more complex determination process is used to generate the encryption key when the data security level is high, while a relatively simplified process is used when the data security level is low. This hierarchical processing not only improves the system's processing efficiency but also ensures data protection effectiveness under different security requirements. Furthermore, in the first determination step, the encryption key determination process fully considers multiple factors such as the target device's IP address, data security level, data value, and data type. The dynamically generated encryption key not only improves the security of data transmission but also enhances the system's flexibility and adaptability. In addition, determining the row and column positions of the encryption key through integer division and remainder operations further increases the difficulty of cracking.

[0031] In a preferred embodiment, this application can be further configured such that determining the encryption key based on the data security level, the target device's IP address, the data value, and the data type includes:

[0032] Based on the target device's IP address and the preset network risk area distribution information, determine the first security level corresponding to the target device's IP address;

[0033] Based on the data value, the second security level corresponding to the data value is obtained by using the correspondence between the preset value and the security coefficient.

[0034] Based on the data type, the third security level corresponding to the data type is obtained by using the pre-defined correspondence between the data type and the security factor;

[0035] Based on the data security level, the first security level, the second security level, and the third security level, the comprehensive security level is determined, and an encryption algorithm is selected and an encryption key is generated based on the comprehensive security level.

[0036] By employing the above technical solution, the network environment risk level of the target device can be quickly identified by matching the target device's IP address with preset network risk area distribution information, i.e., the first security level. Based on the value of the data, the system automatically assesses the importance of the data itself using a preset correspondence between value and security coefficient, and converts it into the second security level. Based on the data type, the third security level corresponding to the data type is determined through a preset correspondence between type and security coefficient. By integrating information from the four dimensions of data security level, first security level, second security level, and third security level, a comprehensive security level is determined, and the most suitable encryption algorithm and corresponding encryption key are selected accordingly.

[0037] In a preferred embodiment, this application can be further configured to: after reading the target data corresponding to the data information to be acquired from the database, it also includes:

[0038] Obtain the user's permission level for the data type corresponding to the target device;

[0039] When the permission level does not reach the preset level, the system identifies a single sensitive word in the data to be processed and the first position corresponding to the single sensitive word; and identifies pairs of sensitive words in the data to be processed and the second position corresponding to the pairs of sensitive words.

[0040] The sensitive words corresponding to the first and second positions are de-sensitized to obtain the de-sensitized data to be processed.

[0041] Accordingly, the target data is segmented based on the data volume to obtain several segmented data, including:

[0042] Based on the data volume, the desensitized target data is segmented to obtain several segmented data.

[0043] By adopting the above technical solution, the leakage of sensitive information is effectively prevented by checking the permission level of the target device user and de-identifying sensitive words before data transmission.

[0044] In a preferred embodiment, this application can be further configured to: identify a single sensitive word in the data to be processed and a first position corresponding to the single sensitive word; and identify pairs of sensitive words in the data to be processed and a second position corresponding to the pairs of sensitive words, including:

[0045] The data to be processed is segmented to obtain several sub-data, and the correlation between adjacent sub-data is determined;

[0046] The data sub-data are grouped such that the number of data groups is at least greater than 2, and the correlation between the sub-data at the boundary of two adjacent data groups is not greater than a preset threshold.

[0047] For each data set, identify a single sensitive word in the data set and its corresponding first position; and identify pairs of sensitive words in the data set and their corresponding second positions.

[0048] By adopting the above technical solution, this method employs steps such as data segmentation, relevance determination, and data grouping when identifying sensitive words. This refined processing method can more accurately identify sensitive information in the data to be processed and effectively de-identify it.

[0049] Secondly, a cloud computing platform is provided, including:

[0050] A receiving module is used to receive a data acquisition request from a target device, wherein the data acquisition request includes the data information to be acquired and the data security level;

[0051] The reading module is used to read target data corresponding to the data information to be acquired from the database. The database stores power generation equipment related information and electricity consumption related information of virtual power plant data. The target data includes data to be processed, data volume, data value, and data type.

[0052] The segmentation module is used to segment the target data according to the data volume to obtain several segmented data;

[0053] An encryption key determination module is used to determine an encryption key based on the data security level, the IP address of the target device, the data value, and the data type.

[0054] The encryption and transmission module is used to encrypt the several segments of data using an encryption key and send the encrypted data to the target device.

[0055] Thirdly, electronic devices are provided, including:

[0056] One or more processors;

[0057] Memory;

[0058] One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, the one or more applications being configured to: perform the steps of the method according to any one of the first aspects.

[0059] Fourthly, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method as shown in any possible implementation of the first aspect.

[0060] Fifthly, a virtual power plant data security protection system based on a cloud computing platform is provided, including:

[0061] Electronic devices as described in the third aspect;

[0062] as well as,

[0063] The target device is used to send a data acquisition request, and after receiving the encrypted data, it decrypts and aggregates the data.

[0064] In summary, this application includes at least one of the following beneficial technical effects: upon receiving a data acquisition request from the target device, it can read the target data and segment the data based on the data volume, which not only improves the efficiency of data transmission but also further enhances data security; by combining the data security level in the data acquisition request, the target device's IP address, and other target device-side information, as well as the data value and data type of the target data within the platform, the encryption key is jointly determined by data information from two different sources, making the key determined according to the actual situation, thus improving security and making data transmission more secure. Attached Figure Description

[0065] Figure 1 A schematic diagram of the structure of a virtual power plant data security protection system based on a cloud computing platform provided in this application embodiment;

[0066] Figure 2 This is a schematic diagram of a data security protection method for a virtual power plant based on a cloud computing platform, provided in an embodiment of this application.

[0067] Figure 3 This is a schematic diagram of a key determination process provided in an embodiment of this application;

[0068] Figure 4 This is a schematic diagram of the structure of a cloud computing platform provided in an embodiment of this application;

[0069] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0070] This specific embodiment is merely an explanation of this application and is not intended to limit it. After reading this specification, those skilled in the art can make modifications to this embodiment without contributing any inventive step, but such modifications are protected by patent law as long as they fall within the scope of the claims of this application.

[0071] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0072] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.

[0073] When virtual power plants transmit data to distributed energy management devices or energy consumer devices, a unique key is typically assigned to each device to encrypt the data and ensure data transmission security. However, if this fixed key is leaked, data breaches can easily occur.

[0074] Therefore, this application provides a data security protection method for a virtual power plant based on a cloud computing platform to address the aforementioned technical problems. After reading the corresponding target data based on a data acquisition request, the target data is segmented. Smaller data segments help improve transmission efficiency, and the segmented data is transmitted encrypted, reducing the possibility of data leakage. Furthermore, during encryption, the encryption key is determined by combining the data security level in the data acquisition request, the target device's IP address, and other target device-side information, as well as the data value and data type of the target data within the platform. This combination of data information from two different sources ensures that the key is determined based on the actual situation, resulting in better security and making data transmission more secure.

[0075] For ease of understanding, please refer to Figure 1 , Figure 1 A virtual power plant data security protection system based on a cloud computing platform, provided in this application embodiment, includes: an electronic device for implementing a virtual power plant data security protection method based on a cloud computing platform; and a target device;

[0076] The electronic device can be a server that has deployed a virtual power plant data security protection platform based on a cloud computing platform. This server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.

[0077] The target device sends a data acquisition request;

[0078] The electronic device receives a data acquisition request from the target device. The request includes the data to be acquired and its security level. It then reads the target data corresponding to the data to be acquired from a database. The database stores information related to power generation equipment and electricity consumption from the virtual power plant data. The target data includes the data to be processed, the data volume, the data value, and the data type. Based on the data volume, the target data is segmented into several segments. An encryption key is determined based on the target device's IP address, data value, and data type. The segmented data is then encrypted using the encryption key, and the encrypted data is sent to the target device. Upon receiving the encrypted data, the target device decrypts and aggregates the data. Specifically, the electronic device sends the decryption key to the target device or sends key information to the blockchain. This allows the target device to automatically generate a key pair after reading the key information from the blockchain, which is then used to decrypt the data. The key information is essential for generating the key.

[0079] Furthermore, the target equipment can be the equipment corresponding to the distributed grid of the virtual power plant, or the user client equipment corresponding to the consumer grid.

[0080] The database in an electronic device stores multiple types of data, which may include:

[0081] Distributed energy resource data corresponding to distributed power grids include, specifically, distributed generation data: including operational data of renewable energy power generation devices such as solar photovoltaic and wind power, such as power generation, power output, and power generation efficiency; and energy storage system data: status data of energy storage devices such as energy storage batteries, compressed air energy storage, and water pump energy storage, such as energy storage capacity, charging and discharging status, and charging and discharging power.

[0082] The virtual power plant contains controllable load data for multiple regions, such as: industrial adjustable load data, including the operating status and energy consumption data of adjustable loads such as industrial production lines and refrigeration equipment; building air conditioning load data, including the temperature, operating status, and energy consumption data of public areas in large buildings. This data is of great significance for achieving demand response and participating in peak regulation in the electricity market; and electric vehicle data, including the charging status, charging power, and charging time of electric vehicles.

[0083] Power grid status data, including transmission and distribution network data: such as network architecture, voltage, current, frequency, and other power grid operation monitoring data.

[0084] Market transaction data, including real-time electricity prices, transaction volumes, and transaction contracts, plays a crucial role in enabling virtual power plants to participate in electricity market transactions and optimize their economic benefits.

[0085] Environmental and forecasting data, meteorological data such as temperature, humidity, wind speed, and light intensity, are of great significance for predicting the power generation of distributed generation units and optimizing the charging and discharging strategies of energy storage systems; load forecasting data, based on historical and real-time data, predicts the power load for a period of time in the future, providing support for the scheduling decisions of virtual power plants.

[0086] User behavior data: Data such as users' electricity consumption habits and electricity demand helps virtual power plants better understand user needs and provide more personalized services.

[0087] Equipment status monitoring data: Real-time monitoring of the operating status of various equipment in the virtual power plant, timely detection and handling of potential faults, and ensuring the stable operation of the virtual power plant.

[0088] The devices in a distributed power grid can interact with electronic devices, and the content of the interaction includes, but is not limited to, distributed energy resource data and equipment status monitoring data.

[0089] The content of information exchange between user client devices and electronic devices includes, but is not limited to: distributed energy resource data corresponding to distributed power grids, controllable load data of multiple regions corresponding to virtual power plants, power grid status data, market transaction data, environmental and forecast data, user behavior data, and equipment status monitoring data.

[0090] Specifically, this application provides a data security protection method for virtual power plants based on a cloud computing platform, such as... Figure 2 As shown, the method includes:

[0091] S101. Receive a data acquisition request from the target device. The data acquisition request includes the data information to be acquired and the data security level.

[0092] The target device refers to the device that issues the data acquisition request. It can be any device with communication permissions that needs to access or process specific data, such as a server, personal computer, or smartphone. These devices are connected to the data processing system via a network or other communication means to request the necessary data information.

[0093] The data to be acquired refers to the identifier information of the specific data content that the target device wishes to retrieve or access from the data processing system. The data security level refers to the security level requirements specified in the data acquisition request.

[0094] S102. Read the target data corresponding to the data information to be acquired from the database. The database stores power generation equipment related information and electricity consumption related information of virtual power plant data. The target data includes the data to be processed, data volume, data value, and data type.

[0095] Among them, target data refers to the data actually read from the database based on the data information to be acquired, including but not limited to the data to be processed (the target device's required data), data volume (representing the total amount or size of data), data value (the usefulness of data), and data type (text, numbers, images, etc.).

[0096] The power generation equipment information in the virtual power plant data refers to the detailed information about each power generation device in the virtual power plant stored in the database, such as equipment type, capacity, power generation efficiency, and operating status. Electricity consumption information refers to the data related to electricity consumption stored in the database, including but not limited to user electricity consumption, electricity consumption time, and electricity load. Optionally, one implementation method is to use the query interface of the database management system. A corresponding query statement is constructed based on the description of the data information to be retrieved; the query statement is sent to the database through a database connection pool or by directly connecting to the database; the query results returned by the database are received and parsed to obtain the target data. It is understood that other methods can also be used to implement this step, such as using an ORM (Object-Relational Mapping) framework to simplify database operations or utilizing caching techniques to improve data reading efficiency. No limitation is made here; the specific implementation method can be selected and optimized based on factors such as system requirements, database size, and performance requirements.

[0097] S103. Divide the target data into several segments based on the data volume to obtain several segmented data;

[0098] The purpose of data partitioning is usually to improve the efficiency of data processing. Each partitioned dataset is called a partitioned dataset.

[0099] For example, suppose the target data is a user electricity consumption data table containing 1 million records. The data volume is huge and difficult to process all at once. In this case, it can be divided according to the size of the data, for example, into 100,000 records per partition. This results in 10 smaller datasets, each containing a portion of the original data, which facilitates subsequent processing and analysis.

[0100] The specific segmentation rules can be based on a fixed preset data volume to segment the target data, or the data volume of each segmented data can be dynamically adjusted. Users can set these rules according to their actual situation, as long as they can achieve the purpose of this application embodiment.

[0101] S104. Determine the encryption key based on the data security level, the target device's IP address, the data value, and the data type;

[0102] The target device's IP (Internet Protocol) address is a unique address for each device on the Internet, used to enable communication between devices.

[0103] In this step, the encryption key is determined based on the data security level, the target device's IP address, the data value, and the data type. This makes the generation of the encryption key dynamic and personalized, aiming to improve data security and protection efficiency.

[0104] Alternatively, one implementation method is to use a hash function combined with data characteristics to generate the encryption key. Specifically, the data security level, the target device's IP address, the quantified value of the data (weighted according to the data sensitivity), and the data type identifier are used as input parameters; one or more hash functions are used to hash the parameters to generate a fixed-length hash value; this hash value is then used as the encryption key or part of the encryption key, and combined with a preset key, sorted in a predetermined order to obtain the encryption key, where the preset key can be customized. This method is simple and easy to implement, and the one-way nature of hash functions ensures the unpredictability of the encryption key.

[0105] Alternatively, another implementation method is to use a Key Derivation Function (KDF) to generate the encryption key. A KDF is an algorithm that derives one or more keys from initial key material (such as cryptography, random numbers, etc.). Specifically, the data security level, the target device's IP address, the quantified value of the data, and the identifier of the data type are used as input parameters to the KDF. Based on the selected KDF algorithm (such as PBKDF2, Argon2, etc.), an encryption key is generated through multiple rounds of iteration and hash operations. This method offers higher security and flexibility, making it suitable for scenarios with high data security requirements.

[0106] Alternatively, another implementation method includes: integrating the various sets of data and data security levels in the target device's IP to obtain a first value;

[0107] When the encryption requirement exceeds the preset encryption requirement threshold, the second value is obtained by dividing the first value by the value corresponding to the data value, where the second value includes the integer divisor and the remainder. If there is no remainder, the integer value is divided by the value corresponding to the data type to obtain the third value, and the row value and column value are determined based on the third value. If there is a remainder, the remainder is used as the column value, and the row value corresponding to the column value is determined. Based on the row value and column value, the encryption key is determined from the preset list relationship between the key and the encryption key length.

[0108] When the encryption requirement is no greater than the preset encryption requirement threshold, integrate the data from each group in the target device's IP and the data security level to obtain the first value; determine the encryption key length based on the data value and data type, and determine the encryption key based on the encryption key length and the data security level.

[0109] It is understandable that other methods can be used to determine the encryption key, and no specific method is specified here. The specific method should be selected based on factors such as actual needs, security standards, and technical feasibility.

[0110] S105. Encrypt several segments of data using an encryption key and send the encrypted data to the target device.

[0111] As can be seen, in this embodiment, after receiving a data acquisition request from the target device, the target data can be read and segmented based on the data volume, which not only improves the efficiency of data transmission but also further enhances data security. By combining the data security level in the data acquisition request, the target device's IP address, and other target device-side information, as well as the data value and data type of the target data within the platform, the encryption key is jointly determined by data information from two different sources. This ensures that the key is determined based on the actual situation, resulting in better security and making data transmission more secure.

[0112] Furthermore, to improve read efficiency, the database includes sub-databases corresponding to multiple data types;

[0113] Read the target data corresponding to the data information to be obtained from the database, including:

[0114] From the database, determine several sub-databases corresponding to the data information to be acquired, and read the sub-target data corresponding to the data information to be acquired from the several sub-databases;

[0115] When the number of sub-databases is 1, the sub-target data is determined as the target data;

[0116] When the number of sub-databases is greater than 1, all sub-target data are integrated to obtain the target data.

[0117] In this embodiment of the application, the database maintains multiple sub-databases corresponding to different data types, and each sub-database is used to store a certain type or several types of specific data.

[0118] The data to be acquired may be contained in one or more sub-databases.

[0119] In some embodiments, this process can be implemented in a variety of ways:

[0120] Optionally, the electronic device traverses and matches all sub-databases related to the data information to be acquired in the database according to the preset mapping relationship; performs parallel or sequential query operations on these sub-databases to quickly locate and extract the sub-target data; and integrates the collected sub-target data to obtain the target data.

[0121] Optionally, to improve query efficiency, the system can pre-establish an index mechanism for each sub-database in the database; using the index mechanism, the system can quickly locate the sub-database that may contain the target data and reduce unnecessary query overhead; perform specific query operations in these sub-databases to obtain the sub-target data; and integrate the collected sub-target data to obtain the target data.

[0122] It is understandable that other methods can be used to achieve this process. No specific limitations are made here. As long as the goal of identifying and reading the sub-target data corresponding to the data information to be acquired from the database can be achieved, it is a feasible implementation method for this step.

[0123] As can be seen, in this embodiment of the application, the multi-type sub-database design of the database can accurately extract the required data from the corresponding sub-database when reading target data, reducing unnecessary data retrieval time.

[0124] Furthermore, when the number of sub-databases is greater than one, the target data is partitioned based on the data volume to obtain several partitioned data, including:

[0125] Determine if the data volume exceeds the preset data volume threshold;

[0126] If the data volume is greater than the preset data volume threshold, then for each sub-target data, determine whether the sub-target data is greater than the preset quantity threshold. If the sub-target data is greater than the preset quantity threshold, then the sub-target data is segmented so that the data volume of each segmented sub-target data is less than the preset data volume threshold.

[0127] All sub-target data that are no greater than a preset threshold, as well as the sub-target data that are segmented, are taken as several segmentation data.

[0128] If the data volume is not greater than the preset data volume threshold, the number of data segments is determined to be 1, that is, no data segmentation is performed.

[0129] In this embodiment, the preset data volume threshold is a custom setting or a setting based on the current bandwidth (the better the network conditions, the larger the preset data volume threshold). The segmentation operation helps to reduce the burden on individual processing tasks and improve overall processing efficiency. When the data volume is greater than the preset data volume threshold, if there is a sub-target data that is greater than the preset quantity threshold, the sub-target data is segmented so that the final segmented data is all less than the preset data volume threshold.

[0130] Optionally, one implementation is as follows: determine whether the amount of data to be processed is greater than a preset data amount threshold; if it is greater, enter the sub-target data processing loop and check the quantity of each sub-target data; for sub-target data whose quantity exceeds the preset quantity threshold, use equal division, hashing or other splitting algorithms to split the data to ensure that the amount of each split sub-target data meets the requirements; merge all unsplit sub-target data and split sub-target data to form several split data.

[0131] As can be seen, in this embodiment, when the data volume is large, the target data is intelligently segmented by setting preset data volume thresholds and quantity thresholds. This not only avoids transmission delays or failures caused by excessive data volume, but also further enhances data transmission security by refining the encryption granularity. Simultaneously, smaller sub-target data is also appropriately processed to ensure balanced transmission of all data.

[0132] Furthermore, the target data is segmented based on the data volume, resulting in several segmented data, including: SP1-SP5 (not shown in the attached diagram), wherein:

[0133] SP1: Based on current and historical device performance information, predict device performance information during the data transmission period.

[0134] The data transmission period refers to the time segment corresponding to the moment the data is transmitted. Device performance information includes multiple device performance characteristics, including but not limited to network bandwidth and CPU processing power.

[0135] In one feasible approach, historical device performance information comprises historical device performance information for a first preset time period prior to the current time and historical device performance information for a second preset time period prior to the current time. The first preset time period is the period from the current time to the first moment, and the second preset time period is the period from the current time to the second moment. Both the first and second moments are earlier than the current time, and the second moment is earlier than the first moment. The performance change rate for the first and second preset time periods is calculated. A weighted average of the two change rates is then calculated to obtain a comprehensive change rate, where the weight of the first preset time period is greater than the weight of the second preset time period. Based on the current device performance information and the comprehensive change rate, the device performance information for the data transmission period is predicted.

[0136] In another feasible approach, based on current and historical device performance information, device performance information for the data transmission period is predicted, including SP11-SP13 (not shown in the attached diagram), where:

[0137] SP11. Obtain the equipment performance prediction model. The equipment performance prediction model is obtained by training the prediction model based on multiple historical equipment information. The historical equipment information includes: the historical equipment performance information corresponding to the current time period in multiple adjacent historical dates, and the historical equipment performance information corresponding to the next time period after the current time period.

[0138] Specifically, the model training method includes: obtaining historical device performance information for the current time period and the historical device performance information for the next time period in multiple adjacent historical dates, such as 12:00-13:00 and 13:00-14:00 on May 15, 2024, and 12:00-13:00 and 13:00-14:00 on May 14, 2024; inputting multiple historical device performance information into the prediction model to determine the predicted device performance information for the next time period in each historical date; and iteratively training the prediction model based on the differences between the historical device performance information for the next time period in multiple historical dates and the multiple predicted device performance information to obtain the device performance prediction model.

[0139] SP12. Based on the current equipment performance information, use the equipment performance prediction model to make predictions and obtain the equipment performance information during the data transmission period.

[0140] SP13. Determine whether the current time is an abnormal time. If so, adjust the device performance information for the data transmission period based on the current time to obtain the adjusted device performance information for the data transmission period.

[0141] The current time is 12:00 on May 1, 2024, which is a holiday. This is a special date, which may put greater pressure on the equipment and reduce its performance.

[0142] In this application embodiment, a device performance prediction model based on a large amount of historical data is obtained. This model not only learns the performance change patterns of the device in different time periods to achieve accurate prediction of future device performance and obtain device performance prediction information during the data transmission period, but also has the ability to detect abnormal moments. Once it is found that the current moment is an abnormal moment (such as holidays), the prediction results can be quickly adjusted to ensure that the prediction information remains highly accurate in complex and ever-changing real environments.

[0143] SP2: Determine the data volume and device performance information during the data transmission period to determine whether data segmentation is necessary;

[0144] Specifically, the maximum amount of data that can be processed or transmitted within a given time is estimated based on the device's performance information; the maximum transmission capacity is compared with the data volume; if the actual data volume is less than or equal to the theoretical maximum transmission capacity, data segmentation is not required; otherwise, if the actual data volume is greater than the theoretical maximum transmission capacity, segmentation is required.

[0145] SP3. If data segmentation is required, determine the initial horizontal segmentation information based on the data type of the target data; determine the initial vertical segmentation information based on the data value corresponding to each data point in the target data.

[0146] When the target data includes only one type of data, the initial horizontal segmentation information is determined as a segmentation position, which is the position of the next row after the last row of data to be processed; when the target data includes multiple types of data, the position between different types of data is determined as the initial horizontal segmentation information.

[0147] Based on the mapping relationship between the data value of each data point and the preset quantity and value range, the number of segments is determined. The higher the value range, the more segments are required. Then, the vertical length is divided equally to obtain multiple vertical segmentation positions, which are recorded as the initial vertical segmentation information.

[0148] SP4. Based on the device performance information during the data transmission period, the initial horizontal segmentation information and the initial vertical segmentation information are corrected to obtain the horizontal segmentation information and the vertical segmentation information.

[0149] To ensure the reliability of data transmission, it is also necessary to ensure that the segmented data conforms to the device performance information during the data transmission period. Therefore, it is also necessary to make corrections based on the device performance information during the data transmission period.

[0150] Specifically, based on the device performance information within the data transmission period, the target data location of the sub-data that exceeds the device performance information within the data transmission period is selected; and horizontal and / or vertical segmentation information is added to the target data location so that the final sub-data can all meet the device performance requirements, thus obtaining horizontal and vertical segmentation information.

[0151] SP5. Based on the horizontal and vertical segmentation information, the target data is segmented to obtain several segmented data.

[0152] By adopting the above technical solution, the device performance during the data transmission period is accurately predicted based on current and historical device performance information. Based on the predicted device performance and data volume, it intelligently determines whether data segmentation is necessary. If the data volume exceeds the device's processing capacity during the transmission cycle, the segmentation strategy is further refined. By considering the data type of the target data, an initial horizontal segmentation strategy is determined to ensure that different types of data are processed in the most appropriate way. Simultaneously, an initial vertical segmentation strategy is formulated based on the specific value of each data item. The initial segmentation strategy is dynamically adjusted based on real-time predicted device performance information to ensure that the segmented data meets transmission requirements while optimizing transmission efficiency, thereby improving the reliability and efficiency of data transmission.

[0153] Furthermore, refer to Figure 3 Based on the data security level, the target device's IP address, the data value, and the data type, the encryption key is determined, including:

[0154] By integrating the various sets of data and data security levels in the target device's IP address, a first value is obtained;

[0155] When the data security level is greater than the preset data security level threshold, execute the first determination step;

[0156] If the data security level is not greater than the preset data security level threshold, proceed to the second determination step;

[0157] Specifically, the process of obtaining the first value includes: adding the data from each group in the target device's IP address and the data security level to obtain the first value. For example, if the target device's IP address is 192.168.0.0 and the data security level is 2, then the first value is 192 + 168 + 0 + 0 + 2 = 362. Alternatively, adding the data from each group in the target device's IP address and using the data security level as the last digit to obtain the first value, such as (192 + 168 + 0 + 0) * 10 + 2 = 3602. Of course, other methods are also possible, and this application embodiment does not limit the specific method; users can set the values ​​according to their actual needs.

[0158] The user can customize the preset data security level threshold. When the threshold is greater than the preset level threshold, the encryption key can be determined using the first determination step; otherwise, the encryption key is determined using the second determination step.

[0159] In this embodiment, when the data security level is high, a more complex determination step is used to generate the encryption key; while when the data security level is low, a relatively simplified step is used. This hierarchical processing method not only improves the system's processing efficiency but also ensures the data protection effect under different security requirements.

[0160] Specifically, the first determining step includes: S1-S4 (not shown in the attached diagram), wherein:

[0161] S1. Divide the first value by the value corresponding to the data value to obtain the second value, wherein the second value includes the integer divisibility value and the remainder value;

[0162] Regarding data value, once data is written into the database, a corresponding value is automatically assigned to it according to the set rules.

[0163] S2. If there is no remainder, divide the integer value by the value corresponding to the data type to obtain the third value, and determine the row value and column value based on the third value.

[0164] Different data types correspond to different values. When data is written to the database, the corresponding data type and its corresponding value are automatically set according to the set rules.

[0165] The row and column values ​​are determined based on the third value, specifically including: determining the number of keys in the list relationship between the preset key and the encryption key length; dividing the integer value of the third value by the number of keys to obtain an integer 'a' and a remainder 'b'; if the remainder 'b' is 0, the row value is determined to be the last row, and the column number of the first key length corresponding to the last row is taken as the column value; if the remainder 'b' is not zero, the row value is determined to be the remainder 'b', and the column number of the first key length corresponding to row 'b' is taken as the column value.

[0166] In this step, if the second value has no remainder, the third value is used to determine the row value, and then the column value is determined.

[0167] S3. If there is a remainder, determine the column value based on the remainder and determine the row value corresponding to the column value.

[0168] In this embodiment of the application, the number of key lengths in the list relationship between the preset key and the encryption key length is determined. The remainder value is divided by the number of key lengths to obtain an integer c and a remainder d. If the remainder d is 0, the column value is determined to be the last column, and the row number of the first key corresponding to the last column is taken as the row value. If the remainder d is not zero, the column value is determined to be the remainder d, and the row number of the first key corresponding to column d is taken as the row value.

[0169] In this step, if there is no remainder when the remainder value is divided by the number of key lengths, the column value is determined first, and then the row value is determined.

[0170] S4. Determine the encryption key from the preset list of keys and encryption key lengths based on the row and column values.

[0171] There is a pre-defined list relationship between keys and encryption key lengths, including key type and encryption key length. The encryption key can be determined from the list based on the remainder and integer, as shown in Table 1.

[0172] Table 1

[0173] For example, the total number of rows is 4 and the total number of columns is 10; when the first value is 321, the value corresponding to the data value is 2 and the value corresponding to the data type is 3; 321 / 2 = 160 remainder 1; 1 / 10 = 0 remainder 1, so it is determined to be 112, 3DES. Therefore, the key type is determined to be 3des and the length is 112, and then the encryption key is determined according to the actual needs.

[0174] For example, if the total number of rows is 4 and the total number of columns is 10, and the first value is 168, the corresponding value of the data is 12.

[0175] The data type corresponds to the value 3; 168 / 12=14; 14 / 3=4 remainder 2, 2 / 4=0 remainder 2, so we determine it to be RES and 12. Therefore, we determine the key type to be RES and the length to be 128, and then determine the encryption key according to the actual needs.

[0176] In this embodiment, the process of determining the encryption key fully considers multiple factors such as the target device's IP address, data security level, data value, and data type. The dynamically generated encryption key not only improves the security of data transmission but also enhances the system's flexibility and adaptability. Furthermore, determining the row and column positions of the encryption key through integer division and remainder operations further increases the difficulty of cracking.

[0177] The second determining step includes: SA1-SA2 (not shown in the attached diagram), wherein:

[0178] SA1. Determine the encryption key length based on the data value and data type.

[0179] In one feasible approach, a data value-to-encryption key length mapping table is established, corresponding different data value levels to recommended key lengths; the corresponding key length is looked up based on the data value; and the key length selection is adjusted according to the data type, for example, the key length can be appropriately increased for data types requiring higher security.

[0180] In another feasible approach, an evaluation value is obtained by weighting the data value and data type; the encryption key length is then determined based on the evaluation value and a mapping table, where the mapping table represents the correspondence between multiple evaluation values ​​and multiple encryption key lengths.

[0181] SA2. Determine the encryption key based on the encryption key length and data security level.

[0182] In some embodiments, optionally, an encryption policy library is first established, which contains recommended encryption key lengths and corresponding key generation rules for different security levels. When data needs to be encrypted, the corresponding key length and generation rules are retrieved from the policy library according to the data's security level, and then an encryption key is generated according to the rules.

[0183] Furthermore, based on the data security level, the target device's IP address, the data value, and the data type, the encryption key is determined, including:

[0184] Based on the target device's IP address and the preset network risk area distribution information, determine the first security level corresponding to the target device's IP address; based on the data value, use the preset correspondence between value and security coefficient to obtain the second security level corresponding to the data value; based on the data type, use the preset correspondence between type and security coefficient to obtain the third security level corresponding to the data type; based on the data security level, the first security level, the second security level, and the third security level, determine the comprehensive security level, and select an encryption algorithm and generate an encryption key based on the comprehensive security level.

[0185] Specifically, the preset network risk area distribution information refers to the network risk area information and security level of each area set based on historical data, geographical location, network environment, and other factors, used to assess the network security risk level of different regions. The correspondence between preset value and security coefficient, as well as the correspondence between preset type and security coefficient, is set by the user based on practical experience. The comprehensive security level is a security level determined by comprehensively considering multiple factors such as data security level, first security level (network environment risk), second security level (data value), and third security level (data type), reflecting the required protection strength for the data.

[0186] If any of the data security levels, first security level, second security level, and third security level is greater than the preset level, then the highest level will be used as the overall security level; otherwise, the overall security level will be obtained by weighting each security level according to its corresponding weight.

[0187] By employing the above technical solution, the network environment risk level of the target device can be quickly identified by matching the target device's IP address with preset network risk area distribution information, i.e., the first security level. Based on the value of the data, the system automatically assesses the importance of the data itself using a preset correspondence between value and security coefficient, and converts it into the second security level. Based on the data type, the third security level corresponding to the data type is determined through a preset correspondence between type and security coefficient. By integrating information from the four dimensions of data security level, first security level, second security level, and third security level, a comprehensive security level is determined, and the most suitable encryption algorithm and corresponding encryption key are selected accordingly.

[0188] Furthermore, in one feasible embodiment, after reading the target data corresponding to the data information to be acquired from the database, the method further includes: SC1-SC3 (not shown in the figures), wherein:

[0189] SC1. Obtain the user's permission level for the data type on the target device. The permission level is used to measure the level of access permission a user has for a certain data type on the target device. It is usually divided according to the user's role, responsibility or security policy. Different permission levels correspond to different data access and operation permissions.

[0190] Electronic devices maintain a user permission database, which records the permission level information for each user on different devices for different data types. When it is necessary to retrieve the permission level, the system retrieves the corresponding permission level information from the database based on the user ID, device ID, and data type as query conditions.

[0191] SC2. When the permission level does not reach the preset level, identify a single sensitive word in the data to be processed and the first position corresponding to the single sensitive word; and identify pairs of sensitive words in the data to be processed and the second position corresponding to the pairs of sensitive words.

[0192] The preset permission level is a pre-defined threshold used to determine whether the current user has sufficient permissions. A single sensitive word refers to a single word or phrase that is considered sensitive due to its potential involvement with privacy, confidential information, etc., and requires special attention. The first position indicates the specific location of the single sensitive word in the data to be processed, facilitating subsequent processing or labeling. Paired sensitive words refer to sensitive word groups composed of two or more words; their combined appearance may carry specific sensitive meanings.

[0193] Specifically, when the system detects that a user's permission level is lower than a preset level, it triggers a sensitive word recognition mechanism. First, it iterates through the data to be processed, using a predefined sensitive word library or algorithm to identify individual sensitive words and record their specific locations (i.e., the first location). Simultaneously, it checks for pairs of sensitive words in the data. These pairs may consist of specific word sequences or patterns, exhibiting higher sensitivity and greater difficulty in recognition. When pairs of sensitive words are identified, their location information within the data is also recorded (i.e., the second location).

[0194] In some embodiments, the above steps can be implemented in multiple ways:

[0195] Optionally, regular expression matching can be used. First, a regular expression library containing single sensitive words and paired sensitive word patterns is built. Then, the data to be processed is taken as input, and the regular expression engine is used for matching. The regular expression library can also be continuously updated and maintained to accommodate new sensitive words and patterns.

[0196] Optionally, SC2 identifies a single sensitive word in the data to be processed and its corresponding first position; and identifies pairs of sensitive words in the data to be processed and their corresponding second positions, including: SC21-SC23 (not shown in the attached figures), wherein:

[0197] SC21. Perform data segmentation on the data to be processed, obtaining several sub-data sets, and determine the correlation between adjacent sub-data sets. The data to be processed may be difficult to process directly due to its large scale, complex structure, or presence of noise. Therefore, data segmentation can divide the dataset into smaller units, simplifying the data processing process, improving processing efficiency, and helping to discover hidden patterns or relationships in the data. An important consideration during data segmentation is the correlation between adjacent sub-data sets. Adjacent sub-data sets refer to the sub-data sets that are adjacent when arranged in order after data segmentation. The correlation is used to quantify the similarity, dependence, or association between these adjacent sub-data sets. SC22. Group the several sub-data sets so that the number of data groups is at least two, and the correlation between the sub-data sets at the boundary of two adjacent data groups does not exceed a preset threshold.

[0198] Optionally, a hierarchical clustering algorithm can be used for grouping. First, each sub-data set is treated as an initial data group. Then, the distance or similarity between all data groups is calculated, and the two closest data sets are merged into a new data group. This process is repeated until all data groups are merged into one large data group, or a preset number of groups is reached. During the merging process, the correlation between sub-data sets at the boundaries of adjacent data groups needs to be monitored to ensure that they do not exceed a preset threshold. If this condition is not met, the merging strategy may need to be adjusted or the threshold reset.

[0199] SC23. For each data set, identify a single sensitive word in the data set and the first position corresponding to the single sensitive word; and identify pairs of sensitive words in the data set and the second position corresponding to the pairs of sensitive words.

[0200] In some embodiments, regular expressions are used for sensitive word matching. Based on the characteristics and patterns of sensitive words, corresponding regular expression patterns are constructed; each word or phrase in the data set is traversed, and a regular expression is used for matching; if a match is successful, the sensitive word and its location information are determined based on the matching result.

[0201] In other embodiments, machine learning models are used for sensitive word identification. A batch of data containing sensitive words is collected and labeled as a training set; a classification or sequence labeling model, such as Naive Bayes, Support Vector Machine, Conditional Random Field, etc., is trained using this training data; after training, the model is used to classify or label each word or phrase in the data set, identifying the sensitive words and their location information.

[0202] In this embodiment of the application, when identifying sensitive words, the method employs steps such as data segmentation, relevance determination, and data grouping. This refined processing method can more accurately identify sensitive information in the data to be processed and effectively desensitize it.

[0203] SC3. Desensitize the sensitive words corresponding to the first and second positions to obtain the desensitized data to be processed;

[0204] Anonymization refers to a data transformation operation performed on identified sensitive words. It aims to eliminate or obscure sensitive information to protect personal privacy or corporate secrets. This process can be achieved in various ways, such as replacement, deletion, encryption, or obfuscation. For example, in text data, sensitive words can be replaced with asterisks (*) or specific placeholders to achieve anonymization.

[0205] Accordingly, the target data is segmented based on the data volume to obtain several segmented data, including:

[0206] Based on the amount of data, the anonymized target data is segmented to obtain several segmented data.

[0207] As can be seen, in this embodiment of the application, by checking the permission level of the target device user and desensitizing sensitive words before data transmission, the leakage of sensitive information is effectively prevented.

[0208] This application provides a cloud computing platform 200, such as... Figure 4 As shown, it includes:

[0209] The receiving module 210 is used to receive a data acquisition request from the target device. The data acquisition request includes the data information to be acquired and the data security level.

[0210] The reading module 220 is used to read the target data corresponding to the data information to be acquired from the database. The database stores power generation equipment related information and electricity consumption related information of virtual power plant data. The target data includes the data to be processed, data volume, data value, and data type.

[0211] The segmentation module 230 is used to segment the target data according to the data volume to obtain several segmented data;

[0212] The encryption key determination module 240 is used to determine the encryption key based on the data security level, the IP address of the target device, the data value, and the data type.

[0213] The encryption and transmission module 250 is used to encrypt several segments of data using an encryption key and send the encrypted data to the target device.

[0214] In one possible embodiment, the segmentation module 230 is further configured to:

[0215] Based on current and historical equipment performance information, predict equipment performance information during the data transmission period;

[0216] Determine the data volume and device performance information during the data transmission period to determine whether data segmentation is necessary.

[0217] If data segmentation is required, the initial horizontal segmentation information is determined based on the data type of the target data; the initial vertical segmentation information is determined based on the data value corresponding to each data point in the target data.

[0218] Based on the device performance information during the data transmission period, the initial horizontal segmentation information and the initial vertical segmentation information are corrected to obtain the horizontal segmentation information and the vertical segmentation information.

[0219] The target data is segmented according to the horizontal and vertical segmentation information to obtain several segmented data.

[0220] In one feasible embodiment, the segmentation module 230 is further configured to: acquire a device performance prediction model, which is obtained by training the prediction model based on multiple historical device information, including: historical device performance information corresponding to the current time period in multiple adjacent historical dates and historical device performance information corresponding to the next time period after the current time period.

[0221] Based on the current equipment performance information, the equipment performance prediction model is used to predict the equipment performance information during the data transmission period.

[0222] Determine whether the current time is an abnormal time. If so, adjust the device performance information for the data transmission period based on the current time to obtain the adjusted device performance information for the data transmission period.

[0223] In one possible embodiment, the encryption key determination module 240 is further configured to:

[0224] By integrating the various sets of data and data security levels in the target device's IP address, a first value is obtained;

[0225] When the data security level is greater than the preset data security level threshold, execute the first determination step;

[0226] If the data security level is not greater than the preset data security level threshold, proceed to the second determination step;

[0227] The first determination step includes: dividing the first value by the value corresponding to the data value to obtain the second value, wherein the second value includes an integer divisor and a remainder; if there is no remainder, dividing the integer value by the value corresponding to the data type to obtain the third value, and determining the row value and column value based on the third value; if there is a remainder, using the remainder as the column value, and determining the row value corresponding to the column value; and determining the encryption key from a preset list of keys and encryption key lengths based on the row value and column value.

[0228] The second determination step includes: determining the encryption key length based on the data value and data type, and determining the encryption key based on the encryption key length and data security level.

[0229] In one possible embodiment, the encryption key determination module 240 is further configured to:

[0230] Based on the target device's IP address and the preset network risk area distribution information, determine the first security level corresponding to the target device's IP address;

[0231] Based on the data value, the second security level corresponding to the data value is obtained by using the correspondence between the preset value and the security coefficient.

[0232] Based on the data type, the third security level corresponding to the data type is obtained by using the pre-defined correspondence between the data type and the security factor;

[0233] Based on the data security level, the first security level, the second security level, and the third security level, the comprehensive security level is determined, and an encryption algorithm is selected and an encryption key is generated based on the comprehensive security level.

[0234] In one feasible embodiment, it further includes:

[0235] The desensitization module is used for:

[0236] Obtain the user's permission level for the target device based on the data type;

[0237] When the permission level does not reach the preset level, the system identifies a single sensitive word in the data to be processed and the first position corresponding to the single sensitive word; and identifies pairs of sensitive words in the data to be processed and the second position corresponding to the pairs of sensitive words.

[0238] The sensitive words corresponding to the first and second positions are desensitized to obtain the desensitized data to be processed.

[0239] Correspondingly, the segmentation module 230 is also used for:

[0240] Based on the amount of data, the anonymized target data is segmented to obtain several segmented data.

[0241] In one feasible embodiment, the desensitization module is used to:

[0242] The data to be processed is segmented into several sub-data, and the correlation between adjacent sub-data is determined.

[0243] Group several sub-data sets such that the number of data sets is at least 2, and the correlation between sub-data sets at the boundary of two adjacent data sets is not greater than a preset threshold.

[0244] For each data set, identify a single sensitive word in the data set and its corresponding first position; and identify pairs of sensitive words in the data set and their corresponding second positions.

[0245] This application provides an electronic device, such as... Figure 5 As shown, Figure 5The illustrated electronic device 300 includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the electronic device 300 may also include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one type, and the structure of this electronic device 300 does not constitute a limitation on the embodiments of this application.

[0246] Processor 301 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 301 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0247] Bus 302 may include a pathway for transmitting information between the aforementioned components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 302 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0248] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device capable of storing static information and instructions, RAM (Random Access Memory) or other type of dynamic storage device capable of storing information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.

[0249] The memory 303 is used to store application code that executes the solution of this application, and its execution is controlled by the processor 301. The processor 301 is used to execute the application code stored in the memory 303 to implement the content shown in the foregoing method embodiments.

[0250] Among them, electronic devices include, but are not limited to: mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0251] This application provides a computer-readable storage medium storing a computer program that, when run on a computer, enables the computer to execute the corresponding content in the aforementioned method embodiments.

[0252] This application provides a computer program product, including a computer program that, when executed by a processor, implements the corresponding content in the aforementioned method embodiments.

[0253] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0254] The above are only some embodiments of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A data security protection method for virtual power plants based on a cloud computing platform, characterized in that, include: Receive a data acquisition request from the target device, the data acquisition request including the data information to be acquired and the data security level; Read target data corresponding to the data information to be acquired from the database. The database stores power generation equipment information and electricity consumption information related to virtual power plant data. The target data includes data to be processed, data volume, data value, and data type. Obtain a device performance prediction model; the device performance prediction model is obtained by training the prediction model based on multiple historical device information, the historical device information includes the historical device performance information corresponding to the current time period in multiple adjacent historical dates and the historical device performance information corresponding to the next time period after the current time period; Based on the current device performance information, the device performance prediction model is used to predict the device performance information during the data transmission period, where the device performance information is network bandwidth. Determine whether the current time is an abnormal time. If so, adjust the device performance information within the data transmission period based on the current time. Estimate the maximum amount of data that can be processed within the data transmission period based on the device performance information. If the data volume is greater than the maximum data volume, then the initial horizontal segmentation information is determined according to the data type of the target data; Based on the data value corresponding to each data point in the target data, the initial vertical segmentation information is determined; Based on the device performance information during the data transmission period, the initial horizontal segmentation information and the initial vertical segmentation information are corrected to obtain the horizontal segmentation information and the vertical segmentation information. The target data is segmented according to the horizontal segmentation information and the vertical segmentation information to obtain several segmented data. By integrating the various sets of data and data security levels in the target device's IP address, a first value is obtained; When the data security level is greater than the preset data security level threshold, the first determination step is executed; When the data security level is not greater than the preset data security level threshold, the second determination step is executed; The first determining step includes: dividing the first value by the value corresponding to the data value to obtain a second value, wherein the second value includes an integer divisor and a remainder; if there is no remainder, dividing the integer value by the value corresponding to the data type to obtain a third value, and determining the row value and column value based on the third value; if there is a remainder, using the remainder as the column value and determining the row value corresponding to the column value; and determining the encryption key from a preset list of keys and encryption key lengths based on the row value and column value. The second determination step includes: determining the encryption key length based on the data value and the data type, and determining the encryption key based on the encryption key length and the data security level; The data segments are encrypted using an encryption key, and the encrypted data is then sent to the target device. The step of reading the target data corresponding to the data information to be acquired from the database includes: From the database, several sub-databases corresponding to the data information to be acquired are determined, and sub-target data corresponding to the data information to be acquired is read from the several sub-databases; when the number of the several sub-databases is 1, the sub-target data is determined as the target data; when the number of the several sub-databases is greater than 1, all the sub-target data are integrated to obtain the target data; the database maintains several sub-databases corresponding to different data types.

2. The method according to claim 1, characterized in that, The method further includes: Based on the target device's IP address and the preset network risk area distribution information, determine the first security level corresponding to the target device's IP address; Based on the data value, the second security level corresponding to the data value is obtained by using the correspondence between the preset value and the security coefficient. Based on the data type, the third security level corresponding to the data type is obtained by using the pre-defined correspondence between the data type and the security factor; Based on the data security level, the first security level, the second security level, and the third security level, the comprehensive security level is determined, and an encryption algorithm is selected and an encryption key is generated based on the comprehensive security level.

3. The method according to any one of claims 1 to 2, characterized in that, After reading the target data corresponding to the data information to be acquired from the database, the method further includes: Obtain the user's permission level for the data type corresponding to the target device; When the permission level does not reach the preset level, the system identifies a single sensitive word in the data to be processed and the first position corresponding to the single sensitive word; and identifies pairs of sensitive words in the data to be processed and the second position corresponding to the pairs of sensitive words. The sensitive words corresponding to the first and second positions are de-sensitized to obtain the de-sensitized data to be processed. Accordingly, the target data is segmented based on the data volume to obtain several segmented data, including: Based on the data volume, the desensitized target data is segmented to obtain several segmented data.

4. The method according to claim 3, characterized in that, Identify a single sensitive word in the data to be processed and the first position corresponding to the single sensitive word; And, identifying pairs of sensitive words and their corresponding second positions in the data to be processed, including: The data to be processed is segmented to obtain several sub-data, and the correlation between adjacent sub-data is determined; The data sub-data are grouped such that the number of data groups is at least greater than 2, and the correlation between the sub-data at the boundary of two adjacent data groups is not greater than a preset threshold. For each data set, identify a single sensitive word in the data set and its corresponding first position; and identify pairs of sensitive words in the data set and their corresponding second positions.

5. A cloud computing platform, characterized in that, include: A receiving module is used to receive a data acquisition request from a target device, wherein the data acquisition request includes the data information to be acquired and the data security level; The reading module is used to read target data corresponding to the data information to be acquired from the database. The database stores power generation equipment related information and electricity consumption related information of virtual power plant data. The target data includes data to be processed, data volume, data value, and data type. The segmentation module is used to obtain the equipment performance prediction model. The equipment performance prediction model is obtained by training the prediction model based on multiple historical equipment information. The historical equipment information includes the historical equipment performance information corresponding to the current time period in multiple adjacent historical dates and the historical equipment performance information corresponding to the next time period after the current time period. Based on the current device performance information, the device performance prediction model is used to predict the device performance information during the data transmission period, where the device performance information is network bandwidth. Determine whether the current time is an abnormal time. If so, adjust the device performance information within the data transmission period based on the current time. Estimate the maximum amount of data that can be processed within the data transmission period based on the device performance information. If the data volume is greater than the maximum data volume, then the initial horizontal segmentation information is determined according to the data type of the target data; Based on the data value corresponding to each piece of the target data, initial vertical segmentation information is determined; based on the device performance information during the data transmission period, the initial horizontal segmentation information and the initial vertical segmentation information are corrected to obtain horizontal segmentation information and vertical segmentation information; the target data is segmented according to the horizontal segmentation information and the vertical segmentation information to obtain several segmented data. The encryption key determination module is used to integrate the various sets of data and data security levels in the target device's IP to obtain a first value; When the data security level is greater than the preset data security level threshold, the first determination step is executed; When the data security level is not greater than the preset data security level threshold, the second determination step is executed; The first determining step includes: dividing the first value by the value corresponding to the data value to obtain a second value, wherein the second value includes an integer divisor and a remainder; if there is no remainder, dividing the integer value by the value corresponding to the data type to obtain a third value, and determining the row value and column value based on the third value; if there is a remainder, using the remainder as the column value and determining the row value corresponding to the column value; and determining the encryption key from a preset list of keys and encryption key lengths based on the row value and column value. The second determination step includes: determining the encryption key length based on the data value and the data type, and determining the encryption key based on the encryption key length and the data security level; The encryption and transmission module is used to encrypt the several segments of data using an encryption key, and then send the encrypted data to the target device. The step of reading the target data corresponding to the data information to be acquired from the database includes: From the database, several sub-databases corresponding to the data information to be acquired are determined, and sub-target data corresponding to the data information to be acquired is read from the several sub-databases; when the number of the several sub-databases is 1, the sub-target data is determined as the target data; when the number of the several sub-databases is greater than 1, all the sub-target data are integrated to obtain the target data; the database maintains several sub-databases corresponding to different data types.

6. An electronic device, characterized in that, include: One or more processors; Memory; One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, the one or more applications being configured to: perform the steps of the method according to any one of claims 1 to 4.

7. A virtual power plant data security protection system based on a cloud computing platform, characterized in that, include: The electronic device as described in claim 6; In addition, the target device is used to send a data acquisition request, and after receiving the encrypted data, it performs data decryption and aggregation.