Blockchain-based power iiot device data access management method and system

By adopting a blockchain-based power IoT device data access management method, information on devices and access users is obtained, and importance and security indices are calculated. This solves the problem that existing technologies cannot accurately assess the importance of device data and access permissions, and achieves efficient data access management and security assurance.

CN119363403BActive Publication Date: 2025-11-21CHUZHOU POWER SUPPLY CO OF STATE GRID ANHUI ELECTRIC POWER CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411413730.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-11
Publication Date
2025-11-21
Estimated Expiration
2044-10-11

AI Technical Summary

Technical Problem

Existing technologies cannot accurately assess the importance of power equipment data based on the attribute information of power Internet of Things (IoT) device data, cannot analyze the data access environment based on the specific information of the accessing users, cannot accurately assess the access permissions of the accessing users, and cannot accurately assess the security status of data access.

Method used

By adopting a blockchain-based power IoT device data access management method, information about devices and users is obtained, the importance index of device data, the data access environment coefficient and the security index are calculated, the access user's permissions and security are determined, and blockchain technology is used for data access management.

Benefits of technology

It enables accurate evaluation of data from power IoT devices, improves the efficiency of access control management, and ensures the reliability and stability of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363403B_ABST
    Figure CN119363403B_ABST
Patent Text Reader

Abstract

The application discloses a blockchain-based power Internet of Things equipment data access management method and system, relates to the technical field of data access management, and comprises the following steps: obtaining power Internet of Things equipment information, obtaining power Internet of Things equipment data according to the power Internet of Things equipment information, obtaining an equipment data importance index according to the power Internet of Things equipment data, and judging whether an access user has the data access permission according to a data access basic index. The application accurately evaluates the importance of power Internet of Things equipment data through the equipment data importance index, adjusts the permission of the access user through a data access environment coefficient, evaluates the access permission of the access user through the data access basic index, improves the data access management efficiency, and manages the data access request of the access user through a data access security index, thereby ensuring the reliability and stability of the power Internet of Things equipment data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data access management technology, specifically to a blockchain-based method and system for managing data access to power Internet of Things (IoT) devices. Background Technology

[0002] With the rapid development of the power system, the demand for power system monitoring is also increasing. The construction of a cloud-based visualization platform can enable more intuitive and accurate monitoring of power equipment. However, due to the large amount and number of data from IoT devices, it is difficult to meet the needs of users for flexible control of IoT devices, such as the management of permissions for each user and type of device.

[0003] Currently, the management of access to power IoT device data still faces several challenges: it cannot accurately assess the importance of power device data based on its data attribute information; it cannot analyze the data access environment based on the specific information of the accessing users; it cannot accurately assess the access permissions of the accessing users; and it cannot accurately assess the security status of data access. Summary of the Invention

[0004] To address the aforementioned technical issues, this paper provides a blockchain-based method and system for managing data access to power IoT devices. This technical solution resolves the problems mentioned in the background section, namely, the inability to accurately assess the importance of power device data based on its data attribute information, the inability to analyze the data access environment based on the specific information of the accessing user, the inability to accurately assess the access permissions of the accessing user, and the inability to accurately assess the security status of data access.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] A blockchain-based method for managing data access to power IoT devices includes:

[0007] Obtain information about power IoT devices, including device specifications, device operating status, and device geographic information;

[0008] Based on the information from the power Internet of Things (IoT) devices, data from the power IoT devices is obtained. This data includes power system operation data, power system sensitive data, power system operation data, and environmental data.

[0009] Based on data from power IoT devices, obtain key indices for device data.

[0010] Obtain access user information, which includes access address information and user identity information;

[0011] Based on the access user information, target access data information is obtained, which includes target access data geographic information and target access data type information;

[0012] Based on the target access data information and access address information, obtain the data access environment coefficient;

[0013] Based on the data access environment coefficient and user identity information, obtain the basic data access index;

[0014] Based on the basic data access index, determine whether the user has the right to access the data. If not, reject the user's data access request. If so, obtain the data access security index based on the data access environment coefficient, device data importance index, and user identity information.

[0015] Based on the data access security index, determine whether to grant the user's data access request. If yes, the user's data access is successful; otherwise, the user's data access request is rejected.

[0016] Preferably, obtaining the device data importance index based on power Internet of Things (IoT) device data specifically includes:

[0017] Based on data from power IoT devices, obtain data geographic attribute information;

[0018] Obtain power network information, which includes power regional distribution information and regional power data corresponding to each region;

[0019] Based on power network information and data geographic attribute information, obtain the basic index of equipment data;

[0020] Based on the basic index of equipment data and the equipment data of the power Internet of Things, obtain the important index of equipment data;

[0021] The formula for calculating the equipment data basic index is as follows:

[0022]

[0023] In the formula, S is the basic index of device data for the i-th power IoT device. i Let D be the area of ​​the power region to which the data of the i-th power IoT device belongs. i Let S0 be the total power area of ​​the power region to which the data of the i-th power IoT device belongs, and D0 be the total power area of ​​the power network.

[0024] The formula for calculating the importance index of equipment data is:

[0025]

[0026] In the formula, Q(i) is the device data importance index of the i-th power Internet of Things device data, and α i Let τ be the data volume of the i-th power IoT device. i τ represents the data type influence coefficient, where τ is the data from the i-th power IoT device if it is environmental data. i =1, if the data of the i-th power IoT device is power system operation data, then τ i =2, if the data of the i-th power IoT device is power system operation data, then τ i =3, if the data of the i-th power IoT device is sensitive data of the power system, then τ i =5.

[0027] Preferably, determining whether a user has the necessary data access permissions based on the basic data access index specifically includes:

[0028] Based on the target access data information, obtain the geographic information of the target access data;

[0029] Based on the geographic information and access address information of the target access data, obtain the data access environment coefficient;

[0030] Based on the data access environment coefficient and user identity information, obtain the basic data access index;

[0031] Based on data access management requirements, obtain the basic data access index threshold;

[0032] Based on the basic data access index and the basic data access index threshold, it is determined whether the user has the right to access the data. If the basic data access index is lower than the basic data access index threshold, the user does not have the right to access the data and the user's data access request is rejected.

[0033] If the basic data access index is higher than the basic data access index threshold, then the data access security index is obtained based on the data access environment coefficient, the device data importance index, and the user identity information.

[0034] The formula for calculating the data access environment coefficient is as follows:

[0035]

[0036] In the formula, E is the data access environment coefficient, L is the distance between the geographic location of the target access data and the access address, and σ(1, μ) represents the data coherence index between the geographic location of the target access data and the access address, where μ is the number of power zones between the geographic location of the target access data and the access address. If the geographic location of the target access data and the access address are in the same power zone, then σ(1, μ) = 1; if the geographic location of the target access data and the access address are in different power zones, then σ(1, μ) = e -μ .

[0037] Preferably, obtaining the basic data access index based on the data access environment coefficient and user identity information specifically includes:

[0038] Based on user identity information and data access management permission allocation, obtain user identity and permission information;

[0039] Based on the data access environment coefficient and user identity and permission information, obtain the basic data access index;

[0040] The formula for calculating the basic data access index is as follows:

[0041]

[0042] In the formula, R is the basic data access index, E is the data access environment coefficient, A is the basic access user identity permission index, and B(T, T1, T2) is the user login time difference index, where T is the user login time, (T1, T2) is the standard login time range for the user, and if T∈(T1, T2), then B(T, T1, T2)=1. but b represents the sensitivity coefficient for login time differences.

[0043] Preferably, determining whether to approve a user's data access request based on a data access security index specifically includes:

[0044] Based on the target access data information, obtain the target access data association information, which indicates the mutual association status of the target access data;

[0045] Based on the access user information, obtain the user access operation information, which represents the user's request to perform access operations on the data;

[0046] The data access security index is obtained based on the data access environment coefficient, device data importance index, target access data association information, and user access operation information.

[0047] Based on the data access security index, determine whether to grant access to the user's data access request.

[0048] Preferably, determining whether to approve a user's data access request based on a data access security index specifically includes:

[0049] Based on user access operation information and operation permission requirement analysis, obtain the access operation sensitivity coefficient;

[0050] The data access security index is obtained based on the data access environment coefficient, device data importance index, target access data association information, and access operation sensitivity coefficient.

[0051] Based on data access management requirements, obtain the data access security index threshold;

[0052] Based on the data access security index and the data access security index threshold, it is determined whether to approve the user's data access request. If the data access security index is lower than the data access security index threshold, the user's data access request will be denied.

[0053] If the data access security index is higher than the data access security index threshold, the user's data access request will be approved.

[0054] Among them, based on data access management requirements, the sensitivity coefficient threshold for access operations is obtained;

[0055] Based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold, it is determined whether the access operation behavior of the accessing user should be included in the third-party monitoring mechanism. If the access operation sensitivity coefficient exceeds the access operation sensitivity coefficient threshold, the access operation behavior of the accessing user will be subject to third-party monitoring.

[0056] The formula for calculating the access operation sensitivity coefficient is:

[0057]

[0058] In the formula, k is the access operation sensitivity coefficient, and δ j Q(j) is the permission requirement index for accessing the i-th access operation of a user, and Q(j) is the device data importance index for accessing the target data of the j-th access operation of a user.

[0059] The formula for calculating the data access security index is:

[0060]

[0061] In the formula, W(s) is the data access security index of the user accessing the s-th target data, and Q... s ε is the device data importance index for accessing the user's s-th target access data. gsθ represents the distance between the power IoT device and the g-th target access data associated with the s-th target access data of the accessing user, where θ is the power IoT device data distance influence coefficient.

[0062] Furthermore, a blockchain-based power IoT device data access management system is proposed to implement the management methods described above, including:

[0063] The main control module is used to determine whether an accessing user has the right to access the data based on the basic data access index and the basic data access index threshold; to determine whether to approve the accessing user's data access request based on the data access security index and the data access security index threshold; to determine whether the accessing user's access operation behavior is included in the third-party monitoring mechanism based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold; to obtain the user's identity and permission information based on the user's identity information and the data access management permission allocation; and to obtain the target access data association information based on the target access data information, and to perform third-party monitoring on the accessing user's access operation behavior.

[0064] The information acquisition module is used to acquire power Internet of Things (IoT) device information, device specification information, device operating status information, and device geographic information. Based on the power IoT device information, it acquires power IoT device data, power system operating data, power system sensitive data, power system operation data, and environmental data. It also acquires access user information, access address information, and user identity information. Based on the access user information, it acquires target access data information, target access data geographic information, and target access data type information.

[0065] The evaluation module is used to obtain the basic index of equipment data based on power network information and data geographic attribute information; obtain the importance index of equipment data based on the basic index of equipment data and power Internet of Things equipment data; obtain the data access environment coefficient based on the geographic information and access address information of the target access data; obtain the basic index of data access based on the data access environment coefficient and user identity information; obtain the access operation sensitivity coefficient based on the user access operation information and operation permission requirement analysis; and obtain the data access security index based on the data access environment coefficient, equipment data importance index, target access data association information and access operation sensitivity coefficient.

[0066] The display module interacts with the main control module and is used to display power Internet of Things (IoT) device data, device data importance index, target access data association information, data access basic index, user access operation information, and data access security index.

[0067] Optionally, the main control module specifically includes:

[0068] The control unit is used to obtain user identity and permission information based on data access management permission allocation according to user identity information, obtain target access data association information based on target access data information, and conduct third-party monitoring of the access operation behavior of the accessing user.

[0069] An information receiving unit interacts with the information acquisition module and the evaluation module to receive data and transmit it to the judgment unit.

[0070] The judgment unit is used to determine whether the accessing user has the right to access the data based on the basic data access index and the basic data access index threshold; to determine whether the accessing user's data access request is approved based on the data access security index and the data access security index threshold; and to determine whether the accessing user's access operation behavior is subject to a third-party monitoring mechanism based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold.

[0071] Optionally, the information acquisition module specifically includes:

[0072] The first acquisition unit is used to acquire power Internet of Things (IoT) device information, device specification information, device operating status information and device geographical information, and acquire power IoT device data, power system operating data, power system sensitive data, power system operation data and environmental data based on the power IoT device information.

[0073] The second acquisition unit is used to acquire access user information, access address information and user identity information, and based on the access user information, acquire target access data information, target access data geographic information and target access data type information.

[0074] Optionally, the evaluation module specifically includes:

[0075] The data evaluation unit is used to obtain the basic index of equipment data based on power network information and data geographic attribute information, and to obtain the important index of equipment data based on the basic index of equipment data and power Internet of Things equipment data.

[0076] The access evaluation unit is used to obtain a data access environment coefficient based on the geographic information and access address information of the target access data, obtain a basic data access index based on the data access environment coefficient and user identity information, obtain an access operation sensitivity coefficient based on the user access operation information and operation permission requirement analysis, and obtain a data access security index based on the data access environment coefficient, device data importance index, target access data association information and access operation sensitivity coefficient.

[0077] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0078] This invention proposes a blockchain-based method and system for managing data access to power IoT devices. It accurately assesses the importance of power IoT device data through a device data importance index, adjusts user permissions through a data access environment coefficient to achieve accurate analysis of user permissions, evaluates user access permissions through a data access basic index to improve data access management efficiency, and manages user data access requests through a data access security index to ensure the reliability and stability of power IoT device data. Attached Figure Description

[0079] Figure 1 This is a flowchart of the blockchain-based power Internet of Things (IoT) device data access management method proposed in this invention.

[0080] Figure 2 This is a flowchart of the data access basic index acquisition process in this invention;

[0081] Figure 3 This is a flowchart of the data access security index acquisition process in this invention;

[0082] Figure 4 This is a block diagram of the blockchain-based power IoT device data access management system proposed in this invention. Detailed Implementation

[0083] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.

[0084] Reference Figure 1 - Figure 3 As shown in the figure, the blockchain-based power IoT device data access management method in this embodiment of the invention includes:

[0085] S100: Obtain information about power IoT devices, including device specification information, device operating status information, and device geographic information;

[0086] S200: Based on the information of the power Internet of Things (IoT) devices, obtain the power IoT device data, which includes power system operation data, power system sensitive data, power system operation data, and environmental data;

[0087] S300: Obtain important indices of equipment data based on data from power IoT devices;

[0088] Specifically, based on data from power IoT devices, key indices for device data are obtained, including:

[0089] Based on data from power IoT devices, obtain data geographic attribute information;

[0090] Obtain power network information, which includes power regional distribution information and regional power data corresponding to each region;

[0091] Based on power network information and data geographic attribute information, obtain the basic index of equipment data;

[0092] Based on the basic index of equipment data and the equipment data of the power Internet of Things, obtain the important index of equipment data;

[0093] The formula for calculating the equipment data basic index is as follows:

[0094]

[0095] In the formula, S is the basic index of device data for the i-th power IoT device. i Let D be the area of ​​the power region to which the data of the i-th power IoT device belongs. i Let S0 be the total power area of ​​the power region to which the data of the i-th power IoT device belongs, and D0 be the total power area of ​​the power network.

[0096] The formula for calculating the importance index of equipment data is:

[0097]

[0098] In the formula, Q(i) is the device data importance index of the i-th power Internet of Things device data, and α i Let τ be the data volume of the i-th power IoT device. i τ represents the data type influence coefficient, where τ is the data from the i-th power IoT device if it is environmental data. i =1, if the data of the i-th power IoT device is power system operation data, then τ i =2, if the data of the i-th power IoT device is power system operation data, then τ i =3, if the data of the i-th power IoT device is sensitive data of the power system, then τ i =5.

[0099] In this solution, geographical attribute information of power IoT device data is obtained. Based on power network information and geographical attribute information of data, the basic index of device data is obtained. Based on the basic index of device data and power IoT device data, the importance index of device data is obtained. The importance index of device data of power IoT device data is accurately assessed, thereby improving the efficiency of data access and management.

[0100] It is understandable that different types of power IoT data contain different amounts of information and require vastly different access permissions. In this embodiment, the ambient temperature, humidity and air pressure monitored by the power IoT devices are used as environmental data, the operation logs, maintenance records and equipment configurations of the power devices are used as power system operation data, the real-time power load, grid status and power device operating status are used as power system operation data, and the specific electricity consumption information of the area, including the specific electricity user name, address and historical electricity consumption, is used as power system sensitive data.

[0101] S400: Obtain access user information, the access user information including access address information and user identity information;

[0102] S500: Based on the accessing user information, obtain the target access data information, which includes the target access data geographic information and the target access data type information;

[0103] S600: Obtain the data access environment coefficient based on the target access data information and access address information;

[0104] S700: Obtain the basic data access index based on the data access environment coefficient and user identity information;

[0105] S800: Based on the basic data access index, determine whether the user has the right to access the data. If not, reject the user's data access request. If so, obtain the data access security index based on the data access environment coefficient, the device data importance index, and the user's identity information.

[0106] Specifically, based on the basic data access index, it is determined whether the user has the necessary access rights to the data, including:

[0107] Based on the target access data information, obtain the geographic information of the target access data;

[0108] Based on the geographic information and access address information of the target access data, obtain the data access environment coefficient;

[0109] Based on the data access environment coefficient and user identity information, obtain the basic data access index;

[0110] Based on data access management requirements, obtain the basic data access index threshold;

[0111] Based on the basic data access index and the basic data access index threshold, it is determined whether the user has the right to access the data. If the basic data access index is lower than the basic data access index threshold, the user does not have the right to access the data and the user's data access request is rejected.

[0112] If the basic data access index is higher than the basic data access index threshold, then the data access security index is obtained based on the data access environment coefficient, the device data importance index, and the user identity information.

[0113] The formula for calculating the data access environment coefficient is as follows:

[0114]

[0115] In the formula, E is the data access environment coefficient, L is the distance between the geographic location of the target access data and the access address, and σ(1, μ) represents the data coherence index between the geographic location of the target access data and the access address, where μ is the number of power zones between the geographic location of the target access data and the access address. If the geographic location of the target access data and the access address are in the same power zone, then σ(1, μ) = 1; if the geographic location of the target access data and the access address are in different power zones, then σ(1, μ) = e -μ .

[0116] Specifically, based on the data access environment coefficient and user identity information, a basic data access index is obtained, which includes:

[0117] Based on user identity information and data access management permission allocation, obtain user identity and permission information;

[0118] Based on the data access environment coefficient and user identity and permission information, obtain the basic data access index;

[0119] The formula for calculating the basic data access index is as follows:

[0120]

[0121] In the formula, R is the basic data access index, E is the data access environment coefficient, A is the basic access user identity permission index, and B(T, T1, T2) is the user login time difference index, where T is the user login time, (T1, T2) is the standard login time range for the user, and if T∈(T1, T2), then B(T, T1, T2)=1. but b represents the sensitivity coefficient for login time differences.

[0122] In this solution, the data access environment coefficient is obtained by using the geographic information and access address information of the target access data. Based on the data access environment coefficient and user identity information, the basic data access index is obtained. Based on the basic data access index and the basic data access index threshold, it is determined whether the accessing user has the right to access the data. The access rights of the accessing user are adjusted by using the data access environment coefficient. The access rights of the accessing user are accurately evaluated by using the basic data access index.

[0123] Understandably, different users have different access permissions. Based on the user's identity, a different basic data access permission index is assigned. This index is then adjusted according to the access address and the target data address. For example, if a user is a power maintenance worker whose access address is in area A of the power network, and the target data is power IoT device data in area B of the power network, this user may be acting suspiciously. Therefore, their access permissions would be reduced to prevent data leakage and tampering.

[0124] It should be noted that in this embodiment, the access permissions of users are analyzed through the basic data access index, without involving the specific analysis of the attributes of the target access data, which improves the efficiency of data access management and reduces resource costs.

[0125] S900: Based on the data access security index, determine whether to approve the user's data access request. If yes, the user's data access is successful; otherwise, the user's data access request is rejected.

[0126] Specifically, based on the data access security index, it is determined whether to grant access to a user's data access request, including:

[0127] Based on the target access data information, obtain the target access data association information, which indicates the mutual association status of the target access data;

[0128] Based on the access user information, obtain the user access operation information, which represents the user's request to perform access operations on the data;

[0129] The data access security index is obtained based on the data access environment coefficient, device data importance index, target access data association information, and user access operation information.

[0130] Based on the data access security index, determine whether to grant access to the user's data access request.

[0131] Specifically, based on the data access security index, it is determined whether to grant access to a user's data access request, including:

[0132] Based on user access operation information and operation permission requirement analysis, obtain the access operation sensitivity coefficient;

[0133] The data access security index is obtained based on the data access environment coefficient, device data importance index, target access data association information, and access operation sensitivity coefficient.

[0134] Based on data access management requirements, obtain the data access security index threshold;

[0135] Based on the data access security index and the data access security index threshold, it is determined whether to approve the user's data access request. If the data access security index is lower than the data access security index threshold, the user's data access request will be denied.

[0136] If the data access security index is higher than the data access security index threshold, the user's data access request will be approved.

[0137] Among them, based on data access management requirements, the sensitivity coefficient threshold for access operations is obtained;

[0138] Based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold, it is determined whether the access operation behavior of the accessing user should be included in the third-party monitoring mechanism. If the access operation sensitivity coefficient exceeds the access operation sensitivity coefficient threshold, the access operation behavior of the accessing user will be subject to third-party monitoring.

[0139] The formula for calculating the access operation sensitivity coefficient is:

[0140]

[0141] In the formula, k is the access operation sensitivity coefficient, and δ j Q(j) is the permission requirement index for accessing the i-th access operation of a user, and Q(j) is the device data importance index for accessing the target data of the j-th access operation of a user.

[0142] The formula for calculating the data access security index is:

[0143]

[0144] In the formula, W(s) is the data access security index of the user accessing the s-th target data, and Q... s ε is the device data importance index for accessing the user's s-th target access data. gs θ represents the distance between the power IoT device and the g-th target access data associated with the s-th target access data of the accessing user, where θ is the power IoT device data distance influence coefficient.

[0145] In this solution, target access data information is used to obtain target access data association information. Based on user access operation information and operation permission requirement analysis, access operation sensitivity coefficient is obtained. Based on data access environment coefficient, device data importance index, target access data association information, and access operation sensitivity coefficient, data access security index is obtained. Based on the data access security index and data access security index threshold, it is determined whether to approve the user's data access request. Based on access operation sensitivity coefficient and access operation sensitivity threshold, it is determined whether the user's access operation behavior is added to the third-party monitoring mechanism. If the access operation sensitivity coefficient exceeds the access operation sensitivity coefficient threshold, the user's access operation behavior is monitored by a third party.

[0146] Understandably, when dealing with sensitive access operations involving data from power IoT devices—that is, reading or modifying sensitive power system data or adjusting power IoT devices—even if the user has sufficient permissions, it is necessary to have a third party monitor the user's access operations to prevent anomalies, for the sake of data security and stability.

[0147] Reference Figure 4 As shown, further, combining the above-mentioned blockchain-based power IoT device data access management method, a blockchain-based power IoT device data access management system is proposed, including:

[0148] The main control module is used to determine whether an accessing user has the right to access the data based on the basic data access index and the basic data access index threshold; to determine whether to approve the accessing user's data access request based on the data access security index and the data access security index threshold; to determine whether the accessing user's access operation behavior is included in the third-party monitoring mechanism based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold; to obtain the user's identity and permission information based on the user's identity information and the data access management permission allocation; and to obtain the target access data association information based on the target access data information, and to perform third-party monitoring on the accessing user's access operation behavior.

[0149] The information acquisition module is used to acquire power Internet of Things (IoT) device information, device specification information, device operating status information, and device geographic information. Based on the power IoT device information, it acquires power IoT device data, power system operating data, power system sensitive data, power system operation data, and environmental data. It also acquires access user information, access address information, and user identity information. Based on the access user information, it acquires target access data information, target access data geographic information, and target access data type information.

[0150] The evaluation module is used to obtain the basic index of equipment data based on power network information and data geographic attribute information; obtain the importance index of equipment data based on the basic index of equipment data and power Internet of Things equipment data; obtain the data access environment coefficient based on the geographic information and access address information of the target access data; obtain the basic index of data access based on the data access environment coefficient and user identity information; obtain the access operation sensitivity coefficient based on the user access operation information and operation permission requirement analysis; and obtain the data access security index based on the data access environment coefficient, equipment data importance index, target access data association information and access operation sensitivity coefficient.

[0151] The display module interacts with the main control module and is used to display power Internet of Things (IoT) device data, device data importance index, target access data association information, data access basic index, user access operation information, and data access security index.

[0152] The main control module specifically includes:

[0153] The control unit is used to obtain user identity and permission information based on data access management permission allocation according to user identity information, obtain target access data association information based on target access data information, and conduct third-party monitoring of the access operation behavior of the accessing user.

[0154] An information receiving unit interacts with the information acquisition module and the evaluation module to receive data and transmit it to the judgment unit.

[0155] The judgment unit is used to determine whether the accessing user has the right to access the data based on the basic data access index and the basic data access index threshold; to determine whether the accessing user's data access request is approved based on the data access security index and the data access security index threshold; and to determine whether the accessing user's access operation behavior is subject to a third-party monitoring mechanism based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold.

[0156] The information acquisition module specifically includes:

[0157] The first acquisition unit is used to acquire power Internet of Things (IoT) device information, device specification information, device operating status information and device geographical information, and acquire power IoT device data, power system operating data, power system sensitive data, power system operation data and environmental data based on the power IoT device information.

[0158] The second acquisition unit is used to acquire access user information, access address information and user identity information, and based on the access user information, acquire target access data information, target access data geographic information and target access data type information.

[0159] The evaluation module specifically includes:

[0160] The data evaluation unit is used to obtain the basic index of equipment data based on power network information and data geographic attribute information, and to obtain the important index of equipment data based on the basic index of equipment data and power Internet of Things equipment data.

[0161] The access evaluation unit is used to obtain a data access environment coefficient based on the geographic information and access address information of the target access data, obtain a basic data access index based on the data access environment coefficient and user identity information, obtain an access operation sensitivity coefficient based on the user access operation information and operation permission requirement analysis, and obtain a data access security index based on the data access environment coefficient, device data importance index, target access data association information and access operation sensitivity coefficient.

[0162] In summary, the advantages of this invention are as follows: It obtains a basic index for device data through power network information and data geographic attribute information; it obtains a device data importance index based on the basic index and power IoT device data; it accurately assesses the importance of power IoT device data through the device data importance index; it obtains a data access environment coefficient based on the target access data geographic information and access address information; it adjusts the access user's permissions based on the data access environment coefficient and user identity information; it obtains a basic data access index based on the data access environment coefficient and user identity information; it evaluates the access user's access permissions based on the basic data access index; it obtains an access operation sensitivity coefficient based on user access operation information and operation permission requirement analysis; and it obtains a data access security index based on the data access environment coefficient, device data importance index, target access data association information, and access operation sensitivity coefficient; it manages the data access requests of access users through the data access security index, thus ensuring the reliability and stability of power IoT device data.

[0163] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.

Claims

1. A blockchain-based method for managing data access to power IoT devices, characterized in that, include: Obtain information about power IoT devices, including device specifications, device operating status, and device geographic information; Based on the information from the power Internet of Things (IoT) devices, data from the power IoT devices is obtained. This data includes power system operation data, power system sensitive data, power system operation data, and environmental data. Based on data from power IoT devices, obtain key indices for device data. Obtain access user information, which includes access address information and user identity information; Based on the access user information, target access data information is obtained, which includes target access data geographic information and target access data type information; Based on the target access data information and access address information, obtain the data access environment coefficient; Based on the data access environment coefficient and user identity information, obtain the basic data access index; Based on the basic data access index, determine whether the user has the right to access the data. If not, reject the user's data access request. If so, obtain the data access security index based on the data access environment coefficient, device data importance index, and user identity information. Based on the data access security index, determine whether to grant the user's data access request. If yes, the user's data access is successful; otherwise, the user's data access request is rejected. The process of obtaining important indices for device data based on power IoT device data specifically includes: Based on data from power IoT devices, obtain data geographic attribute information; Obtain power network information, which includes power regional distribution information and regional power data corresponding to each region; Based on power network information and data geographic attribute information, obtain the basic index of equipment data; Based on the basic index of equipment data and the equipment data of the power Internet of Things, obtain the important index of equipment data; The formula for calculating the equipment data basic index is as follows: In the formula, S is the basic index of device data for the i-th power IoT device. i Let D be the area of ​​the power region to which the data of the i-th power IoT device belongs. i Let S0 be the total power area of ​​the power region to which the data of the i-th power IoT device belongs, and D0 be the total power area of ​​the power network. The formula for calculating the importance index of equipment data is: In the formula, Q(i) is the device data importance index of the i-th power Internet of Things device data, and α i Let τ be the data volume of the i-th power IoT device. i τ represents the data type influence coefficient, where τ is the data from the i-th power IoT device if it is environmental data. i =1, if the data of the i-th power IoT device is power system operation data, then τ i =2, if the data of the i-th power IoT device is power system operation data, then τ i =3, if the data of the i-th power IoT device is sensitive data of the power system, then τ i =5.

2. The blockchain-based power IoT device data access management method according to claim 1, characterized in that, The step of determining whether a user has the necessary data access permissions based on a basic data access index specifically includes: Based on the target access data information, obtain the geographic information of the target access data; Based on the geographic information and access address information of the target access data, obtain the data access environment coefficient; Based on the data access environment coefficient and user identity information, obtain the basic data access index; Based on data access management requirements, obtain the basic data access index threshold; Based on the basic data access index and the basic data access index threshold, it is determined whether the user has the right to access the data. If the basic data access index is lower than the basic data access index threshold, the user does not have the right to access the data and the user's data access request is rejected. If the basic data access index is higher than the basic data access index threshold, then the data access security index is obtained based on the data access environment coefficient, the device data importance index, and the user identity information. The formula for calculating the data access environment coefficient is as follows: In the formula, E is the data access environment coefficient, L is the distance between the geographic location of the target access data and the access address, and σ(1, μ) represents the data coherence index between the geographic location of the target access data and the access address, where μ is the number of power zones between the geographic location of the target access data and the access address. If the geographic location of the target access data and the access address are in the same power zone, then σ(1, μ) = 1; if the geographic location of the target access data and the access address are in different power zones, then σ(1, μ) = e -μ .

3. The blockchain-based power IoT device data access management method according to claim 2, characterized in that, The process of obtaining the basic data access index based on the data access environment coefficient and user identity information specifically includes: Based on user identity information and data access management permission allocation, obtain user identity and permission information; Based on the data access environment coefficient and user identity and permission information, obtain the basic data access index; The formula for calculating the basic data access index is as follows: In the formula, R is the basic data access index, E is the data access environment coefficient, A is the basic access user identity permission index, and B(T, T1, T2) is the user login time difference index, where T is the user login time, (T1, T2) is the standard login time range for the user, and if T∈(T1, T2), then B(T, T1, T2)=1. but b represents the sensitivity coefficient for login time differences.

4. The blockchain-based power IoT device data access management method according to claim 1, characterized in that, The process of determining whether to grant access to a user's data access request based on a data access security index specifically includes: Based on the target access data information, obtain the target access data association information, which indicates the mutual association status of the target access data; Based on the access user information, obtain the user access operation information, which represents the user's request to perform access operations on the data; The data access security index is obtained based on the data access environment coefficient, device data importance index, target access data association information, and user access operation information. Based on the data access security index, determine whether to grant access to the user's data access request.

5. The blockchain-based power IoT device data access management method according to claim 4, characterized in that, The process of determining whether to grant access to a user's data access request based on a data access security index specifically includes: Based on user access operation information and operation permission requirement analysis, obtain the access operation sensitivity coefficient; The data access security index is obtained based on the data access environment coefficient, device data importance index, target access data association information, and access operation sensitivity coefficient. Based on data access management requirements, obtain the data access security index threshold; Based on the data access security index and the data access security index threshold, it is determined whether to approve the user's data access request. If the data access security index is lower than the data access security index threshold, the user's data access request will be denied. If the data access security index is higher than the data access security index threshold, the user's data access request will be approved. Among them, based on data access management requirements, the sensitivity coefficient threshold for access operations is obtained; Based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold, it is determined whether the access operation behavior of the accessing user should be included in the third-party monitoring mechanism. If the access operation sensitivity coefficient exceeds the access operation sensitivity coefficient threshold, the access operation behavior of the accessing user will be subject to third-party monitoring. The formula for calculating the access operation sensitivity coefficient is: In the formula, k is the access operation sensitivity coefficient, and δ j Q(j) is the permission requirement index for accessing the i-th access operation of a user, and Q(j) is the device data importance index for accessing the target data of the j-th access operation of a user. The formula for calculating the data access security index is: In the formula, W(s) is the data access security index of the user accessing the s-th target data, and Q... s ε is the device data importance index for accessing the user's s-th target access data. gs θ represents the distance between the power IoT device and the g-th target access data associated with the s-th target access data of the accessing user, where θ is the power IoT device data distance influence coefficient.

6. A blockchain-based power IoT device data access management system, used to implement the management method as described in any one of claims 1-5, characterized in that, include: The main control module is used to determine whether an accessing user has the right to access the data based on the basic data access index and the basic data access index threshold; to determine whether to approve the accessing user's data access request based on the data access security index and the data access security index threshold; to determine whether the accessing user's access operation behavior is included in the third-party monitoring mechanism based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold; to obtain the user's identity and permission information based on the user's identity information and the data access management permission allocation; and to obtain the target access data association information based on the target access data information, and to perform third-party monitoring on the accessing user's access operation behavior. The information acquisition module is used to acquire power Internet of Things (IoT) device information, device specification information, device operating status information, and device geographic information. Based on the power IoT device information, it acquires power IoT device data, power system operating data, power system sensitive data, power system operation data, and environmental data. It also acquires access user information, access address information, and user identity information. Based on the access user information, it acquires target access data information, target access data geographic information, and target access data type information. The evaluation module is used to obtain the basic index of equipment data based on power network information and data geographic attribute information; obtain the importance index of equipment data based on the basic index of equipment data and power Internet of Things equipment data; obtain the data access environment coefficient based on the geographic information and access address information of the target access data; obtain the basic index of data access based on the data access environment coefficient and user identity information; obtain the access operation sensitivity coefficient based on the user access operation information and operation permission requirement analysis; and obtain the data access security index based on the data access environment coefficient, equipment data importance index, target access data association information and access operation sensitivity coefficient. The display module interacts with the main control module and is used to display power Internet of Things (IoT) device data, device data importance index, target access data association information, data access basic index, user access operation information, and data access security index.

7. The blockchain-based power IoT device data access management system according to claim 6, characterized in that, The main control module specifically includes: The control unit is used to obtain user identity and permission information based on data access management permission allocation according to user identity information, obtain target access data association information based on target access data information, and conduct third-party monitoring of the access operation behavior of the accessing user. An information receiving unit interacts with the information acquisition module and the evaluation module to receive data and transmit it to the judgment unit. The judgment unit is used to determine whether the accessing user has the right to access the data based on the basic data access index and the basic data access index threshold; to determine whether the accessing user's data access request is approved based on the data access security index and the data access security index threshold; and to determine whether the accessing user's access operation behavior is subject to a third-party monitoring mechanism based on the access operation sensitivity coefficient and the access operation sensitivity coefficient threshold.

8. The blockchain-based power IoT device data access management system according to claim 6, characterized in that, The information acquisition module specifically includes: The first acquisition unit is used to acquire power Internet of Things (IoT) device information, device specification information, device operating status information and device geographical information, and acquire power IoT device data, power system operating data, power system sensitive data, power system operation data and environmental data based on the power IoT device information. The second acquisition unit is used to acquire access user information, access address information and user identity information, and based on the access user information, acquire target access data information, target access data geographic information and target access data type information.

9. The blockchain-based power IoT device data access management system according to claim 6, characterized in that, The evaluation module specifically includes: The data evaluation unit is used to obtain the basic index of equipment data based on power network information and data geographic attribute information, and to obtain the important index of equipment data based on the basic index of equipment data and power Internet of Things equipment data. The access evaluation unit is used to obtain a data access environment coefficient based on the geographic information and access address information of the target access data, obtain a basic data access index based on the data access environment coefficient and user identity information, obtain an access operation sensitivity coefficient based on the user access operation information and operation permission requirement analysis, and obtain a data access security index based on the data access environment coefficient, device data importance index, target access data association information and access operation sensitivity coefficient.

Citation Information

Patent Citations

  • Power grid data analysis method based on state grid GIS designated area and system thereof

    CN104933501A

  • Cloud equipment and method for cooperatively controlling access rights of cloud network

    CN108667818A