A power data diversion model based on cloud security technology

By decoupling traditional security protection equipment, an adaptive control system for cloud-based and on-premises security protection is established. Combining various traffic diversion schemes and graph neural networks, the problem of inconsistent security protection components in multi-cloud environments is solved. This enables efficient and secure diversion of power data and flexible utilization of resources, thereby improving the security and stability of the cloud platform.

CN119743500BActive Publication Date: 2025-11-14STATE GRID HENAN INFORMATION & TELECOMM CO +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411761508.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-03
Publication Date
2025-11-14
Estimated Expiration
2044-12-03

AI Technical Summary

Technical Problem

In complex environments where multiple clouds coexist, existing security protection components are not standardized and traditional security protection architectures cannot be adapted to cloud platforms, resulting in a lack of coordinated security protection capabilities, complex management, and vulnerabilities, making it difficult to achieve effective security control over cloud platforms.

Method used

By decoupling traditional security protection devices, an adaptive management and control system for cloud and on-premises security protection is established. Combined with traffic diversion solutions such as SDN traffic diversion, API traffic diversion, and proxy traffic diversion, traffic is directed to traditional virtual security resources, Huawei Cloud and Alibaba Cloud virtual security resources. A multi-origin coordinate-based traffic diversion data model is constructed, and a security service function chain is built using graph neural networks to achieve effective utilization and security protection of various cloud virtual security resources.

Benefits of technology

It enables efficient utilization of various virtual security resources, improves security protection capabilities and the stability of cloud security operations, ensures the security and integrity of power data, and enhances the flexibility and adaptability of resource allocation.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This invention discloses a power data diversion model based on cloud security technology. This model combines multiple traffic diversion schemes to direct traffic to different cloud-based virtual security resources, achieving efficient resource utilization and security protection. The diversion model is constructed using traditional virtual security resources, Huawei Cloud, and Alibaba Cloud as triple coordinate origins, determining the location based on traffic parameters and featuring a dynamic update mechanism. Internally, it constructs an adaptively adjustable location representation sub-data model to adapt to different traffic characteristics and network environment changes. The diversion direction is determined based on the triple coordinate system and optimized according to virtual resource load balancing and security strategies. An algorithm for constructing a security service function chain based on graph neural networks is proposed to adapt to cloud environments of different scales. Through unified management of security technical defense measures, it enhances adaptive security protection capabilities and cloud security operation business support capabilities. This model enables flexible resource allocation, ensures accurate diversion, guarantees security and stability, and provides assurance for the secure operation of the power grid cloud platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to data-driven and information-based smart grid technology, and in particular to a power data diversion model based on cloud security technology. Background Technology

[0002] In today's era of rapid digital development, the State Grid Corporation of China is actively promoting the construction of new power systems. With the construction of the company's cloud platform and the continuous migration of business systems to the cloud, the demand for security protection of the cloud platform and cloud-based businesses is constantly increasing. However, in this process, various units within the company have encountered various problems in terms of security protection technical architecture, security component selection and deployment, and other aspects of their cloud platforms.

[0003] On the one hand, the lack of uniformity in security protection capabilities across multiple cloud platforms has become a prominent issue: in the complex environment of multiple clouds coexisting and operating in combination, different cloud platforms employ different security protection components, making unified security management extremely difficult. Due to the lack of unified standards and specifications, there are significant differences among cloud platforms in the formulation of security protection strategies, the application of security technologies, and the execution of security management. This inconsistency not only increases the complexity of security management but may also lead to the emergence of security vulnerabilities. Furthermore, different security protection components may have overlapping or missing functions, preventing the formation of an effective security protection system.

[0004] On the other hand, the inability of traditional security architectures to adapt to cloud platforms is also a significant challenge: traditional security capabilities and cloud-based security capabilities fail to achieve synergy and unified management, and technical barriers exist between security components. This makes it impossible to automatically orchestrate security capabilities for different scenarios and to dynamically perceive the overall network security posture. In traditional security architectures, security devices are typically deployed independently, lacking deep integration with cloud platforms. However, in cloud environments, the dynamism and elasticity of business require security protection to adjust rapidly accordingly. However, due to the limitations of traditional security architectures, they cannot meet the needs of cloud platforms, leading to security vulnerabilities. Furthermore, traditional security architectures struggle to effectively manage multi-tenant environments on cloud platforms, easily resulting in incomplete security isolation between tenants.

[0005] The difficulty in achieving coordinated management of security protection components is also a pressing issue: the inconsistent interface standards of security protection components on both cloud and on-premises environments make it challenging to achieve unified traffic management and orchestration. This hinders the coordinated management of security protection components, preventing them from reaching their maximum protective effectiveness. In a cloud environment, different security protection components need to work together to build a complete security protection system. However, due to inconsistent interface standards, effective communication and collaboration between components are impossible. Furthermore, the lack of unified traffic management significantly reduces the effectiveness of security protection, allowing attackers to bypass certain security protection components to launch attacks.

[0006] To address these challenges, we are actively conducting research focusing on joint cloud and on-premises protection. First, we are decoupling the capabilities of traditional security devices. Traditional security devices are typically integrated, with relatively fixed functions that are difficult to adapt to the dynamic changes of cloud platforms. Decoupling allows us to break down the functions of security devices into multiple independent modules that can be flexibly combined according to different needs. This improves the adaptability of security devices while reducing the complexity of security management. Simultaneously, we are unifying the management of the capabilities of security components from different cloud platforms such as Alibaba Cloud and Huawei Cloud. Different cloud platforms have different strengths and weaknesses in terms of functionality and performance; unified management allows us to fully leverage the advantages of each component and maximize security protection capabilities.

[0007] Building upon this foundation, a cloud-based and on-premises security protection adaptive management and control system was established. This system transforms the current security protection approach, which relies on hardware or virtualization stacking, into an adaptive cloud security protection system that meets the needs of multiple cloud applications, flexible component deployment, and centralized protection management. This system can automatically adjust security protection strategies based on the business needs and security posture of the cloud platform to achieve intelligent and automated security protection.

[0008] Through relevant research, a comprehensive solution was proposed for the implementation of the State Grid Corporation's cloud security protection system. This solution integrates the capabilities of the State Grid Corporation's existing security technologies and mature cloud platform security components, reducing redundant construction of cloud security protection measures. Unified management and control of security technologies enhances adaptive security protection capabilities and the support capabilities for cloud security operations. In practical applications, this solution can effectively improve the security and reliability of the State Grid Corporation's cloud platform, ensuring the stable operation of the company's business.

[0009] The research on the joint scheduling of cloud and on-premises security protection resources of the State Grid Corporation of China is a work of great significance. Facing challenges such as inconsistent cloud security protection capabilities among multiple parties, the inability of traditional security protection architectures to adapt to cloud platforms, and the difficulty in achieving collaborative management of security protection components, this research provides strong support for the construction of the State Grid Corporation of China's cloud security protection system by decoupling the capabilities of traditional security protection equipment, unifying the management of security components across different cloud platforms, and establishing an adaptive management and control system for cloud and on-premises security protection. This provides a solid security guarantee for the company's digital transformation and the construction of a new power system. Summary of the Invention

[0010] The technical problem to be solved by the present invention is to provide a power data diversion model based on cloud security technology. This model combines multiple traffic diversion schemes to divert traffic to traditional virtual security resources, Huawei Cloud virtual security resources, Alibaba Cloud virtual security resources and other cloud virtual security resources, so as to achieve effective utilization and security protection of various cloud virtual security resources.

[0011] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows.

[0012] A power data diversion model based on cloud security technology is constructed to drive computing power flow in the complex environment of multiple clouds coexisting and operating in the construction of power grid cloud platforms, combining security and platform efficiency. The model is characterized by combining various traffic diversion schemes, including but not limited to SDN diversion, API diversion, proxy diversion and micro-proxy diversion, to drive traffic to traditional virtual security resources, Huawei Cloud virtual security resources, Alibaba Cloud virtual security resources and other cloud virtual security resources, so as to achieve effective utilization and security protection of various cloud virtual security resources.

[0013] As a preferred technical solution of the present invention, the various traffic redirection schemes have a high degree of synergy. In actual operation, they are automatically switched and combined according to the real-time status of the power network and business needs: SDN traffic redirection utilizes the flexibility of software-defined networks to dynamically adjust network traffic paths, accurately guiding traffic to suitable target virtual resources based on different virtual resource load conditions and security policies; API traffic redirection obtains detailed traffic information through interface interaction with various network applications, providing data support for accurate traffic redirection and seamlessly integrating with other traffic redirection schemes; proxy traffic redirection and micro-proxy traffic redirection set up proxy nodes at the network edge and in specific areas, preprocessing and filtering traffic according to its characteristics and the requirements of the target virtual resources, and deciding to further redirect traffic to the corresponding virtual resources.

[0014] As a preferred technical solution of the present invention, it further includes constructing a multi-origin coordinate-based diversion data model, using traditional virtual security resources, Huawei Cloud, and Alibaba Cloud as triple coordinate origins respectively. This system dynamically adapts to changes in power data traffic and the expansion or adjustment of virtual resources, maintaining the accuracy and effectiveness of determining the diversion direction. Specifically: the selection of coordinate origins and system dynamism: based on the importance and representativeness of different types of virtual resources in the power data diversion process, traditional virtual security resources, Huawei Cloud, and Alibaba Cloud are used as triple coordinate origins respectively, and the system has dynamic adaptability, dynamically adjusting as virtual resources in the power network increase, decrease, and performance changes; the correlation between coordinate system dimensions and traffic parameters: in the multi-origin coordinate-based diversion data system, the number of coordinate system dimensions depends on the number of parameters related to each traffic flow and the final security orchestration. In-depth analysis and classification of traffic parameters are performed to more accurately establish this correlation. In addition to common network parameters, specific parameters related to power business are also referenced, including but not limited to the operating status parameters of power equipment and traffic priority parameters. The dimensions of the coordinate system are determined based on the complexity and interrelationships of these parameters.

[0015] Furthermore, in the aforementioned multi-origin coordinate-based traffic diversion data system, the mechanism for determining the location of traffic within the system is specifically as follows:

[0016] A-1 Detailed Classification and Processing of Traffic Parameters and Coordinate Position Determination: In the multi-origin coordinate-based traffic data system, the parameters of each specific traffic flow play a decisive role. First, the traffic parameters are comprehensively and meticulously classified, covering basic network parameters including but not limited to bandwidth, latency, and packet loss rate; security-related parameters including but not limited to security level requirements and encryption type; and business-related parameters including but not limited to business type and priority. Differentiated quantification and normalization methods are then implemented for these different types of parameters.

[0017] For bandwidth in basic network parameters, A-1-1 uses standard network bandwidth measurement units, including but not limited to Mbps and Gbps, for precise quantification. At the same time, it is normalized according to the common bandwidth range in actual power network application scenarios and mapped to the numerical range on the coordinate system so that its representation in the coordinate system is reasonable and comparable.

[0018] Regarding security-related parameters, A-1-2 sets a quantitative numerical system from low to high to meet security level requirements. Specifically, 1 represents a low security level, which means only basic access control is required, and 5 represents a high security level, which includes, but is not limited to, confidential power data transmission, requiring multiple encryption and strict identity authentication. This allows for the accurate quantification of security level requirements.

[0019] The business types in the A-1-3 business-related parameters are identified by a predefined coding method, including but not limited to 01 representing power production data business and 02 representing power marketing data business. The business priority is divided into different levels according to the urgency and importance of the power business. Specifically, key businesses are set to the highest priority, and daily data statistics businesses are set to a lower priority, and are assigned corresponding numerical weights.

[0020] Through this multi-dimensional and refined parameter processing mode, the parameter values ​​of each traffic flow are precisely determined in three coordinate systems with traditional virtual security resources, Huawei Cloud, and Alibaba Cloud as the origin, so that the position fully and accurately reflects the characteristics of the traffic flow itself.

[0021] The A-2 dynamic update mechanism ensures real-time accuracy of traffic location. Based on the highly dynamic nature of the power network environment and the inherent volatility of traffic characteristics, a comprehensive dynamic update mechanism for traffic parameters is constructed. When any parameter of the traffic changes, including but not limited to situations such as network congestion leading to bandwidth reduction, power equipment failure causing service priority upgrades, and security policy adjustments resulting in changes in security level requirements, the system responds quickly and immediately initiates the process of recalculating the traffic's coordinate position in the coordinate system. Simultaneously, to adapt to new traffic types and parameter changes brought about by innovative developments in power services, the system is equipped with parameter adaptive learning capabilities. Through in-depth mining of massive historical traffic data and continuous analysis of real-time monitoring data, the system automatically and sensitively identifies newly emerging parameter characteristics. This includes, but is not limited to, new business parameters related to distributed energy management generated as new distributed energy sources are connected to the power network. The system can autonomously learn and promptly update relevant calculation rules, seamlessly incorporating these new parameters into the coordinate position calculation system, ensuring that the system consistently and accurately determines the position of traditional and new business traffic in the coordinate system.

[0022] As a preferred embodiment of the present invention, the model further includes a sub-data model for constructing a data representation of location, used to represent the location of flow in various coordinate systems, specifically:

[0023] B-1 Comprehensive Application of Multiple Representation Methods: The constructed data representation sub-data model for location includes multiple representation methods, including but not limited to length from the origin of multiple coordinate systems, angle with a selected coordinate axis, coordinate plane, or hyperplane as the zero-degree angle, or the ratio of length to radian angle, trigonometric function value of angle, ratio of length to trigonometric function of angle, linear combination and product of length and angle, and linear combination or product of length and trigonometric function values ​​of angle. These representation methods are optimized and combined to improve the adaptability and accuracy of the model. According to different flow characteristics and application scenarios, the system automatically selects the most suitable representation method or combination method: for flows that are close to the origin of coordinate systems and have relatively small angle changes, length is selected as the primary representation method; while for flows with large angle changes in a certain coordinate axis direction, the trigonometric function value of angle is selected as the primary representation method and combined with length for auxiliary representation. Through this intelligent selection mechanism of representation methods, the model more accurately reflects the position of flow in the coordinate system, especially in complex power network environments where different flows have different characteristics. Based on this flexible representation method model, the model can adapt to various situations.

[0024] B-2 Adaptive Adjustment of the Representation Model: The data representation sub-data model of location adaptively adjusts with changes in the power network environment and traffic characteristics. The model's representation parameters and weights are automatically adjusted: When a large amount of high-priority service traffic appears in the network, the model will adjust the representation method according to the service-related parameters, increasing the weight of service priority-related parameters in the representation to ensure that high-priority traffic can obtain more accurate location representation, thus allowing it to be prioritized during traffic diversion. At the same time, when the network topology changes, including but not limited to adding or deleting a network node, the model re-evaluates the construction of the coordinate system and the representation method to adapt to the new network environment, making the location representation accurate and effective, thereby providing a basis for determining the direction of traffic diversion.

[0025] Furthermore, the feature is that: specific selection and data modeling are carried out according to specific circumstances to adapt to the multiple influencing factors and high complexity of power grid operation in the real environment. For power grid diversion under working environment and task objectives, the assembly has a highly adaptable parameter combination, and the parameter combination is adjusted in real time according to the dynamic changes of the power grid operating environment to improve the efficiency and accuracy of diversion.

[0026] As a preferred technical solution of the present invention, the direction of traffic diversion is ultimately determined based on the position and data representation in the triple coordinate system. In the process of determining the direction of traffic diversion, optimization and adjustment are carried out according to the load balancing and security strategies of different virtual resources, so as to achieve the optimal utilization and security protection of various virtual resources.

[0027] As a preferred technical solution of the present invention, an algorithm for constructing a security service function chain based on graph neural networks is proposed to address the service orchestration problem in traditional secure cloud environments. This algorithm adapts to cloud environments of different scales and complexities, and dynamically adjusts the construction of the security service function chain according to changes in service requirements. Specifically:

[0028] The C-1 algorithm's adaptability to cloud environments: For small cloud environments, the algorithm converges quickly and accurately constructs the security service function chain, avoiding overcomputation and resource waste; for large and complex cloud environments, the algorithm processes a large amount of network topology information and security service requirements through layered processing and distributed computing, enabling the construction of the security service function chain to meet the security requirements of complex cloud environments.

[0029] C-2 Feature Extraction and Functional Chain Construction of Graph Neural Networks: Graph neural networks are used to extract network topology features and establish a security service functional chain for the power grid cloud platform. By learning the connection relationships and attribute information between network nodes, the graph neural network accurately extracts key features of the network topology. These features are used to construct the security service functional chain. Based on different security service requirements and network topology, the node order and connection method of the security service functional chain are determined. According to the security level requirements and business priorities of different areas in the network, security protection devices and services are connected in a reasonable order to form an efficient security service functional chain for the secure operation of the power grid cloud platform.

[0030] As a preferred technical solution of the present invention, the adaptive security protection capability and the support capability for cloud security operation are improved by unifying the management and control of security technical defense measures. This unified management and control includes centralized management and coordination of various security devices, algorithms, and strategies involved in the traffic redirection process, ensuring the safety and stability of the entire traffic redirection process. Specifically:

[0031] D-1 Unified Management of Security Measures: Establish a unified security management platform to manage the configuration and status of different types of security devices, including but not limited to firewalls and intrusion detection systems. At the same time, update and optimize traffic redirection algorithms and security policies in a unified manner to ensure the security and stability of the entire traffic redirection process.

[0032] D-2 Capability Enhancement Effectiveness Assessment and Continuous Improvement: To enhance adaptive security protection capabilities and support capabilities for cloud security operations, an effective performance evaluation index system will be established. This system will evaluate indicators including, but not limited to, security protection effectiveness, traffic diversion efficiency, and the stability of cloud security operations. Based on the evaluation results, security technical measures and traffic diversion methods will be continuously improved: When the intrusion detection success rate is low, the reasons will be analyzed and the algorithm or configuration of the intrusion detection system will be adjusted; when the traffic diversion success rate is not high, the coordination and parameter settings of the traffic diversion scheme will be optimized to improve adaptive security protection capabilities and support capabilities for cloud security operations.

[0033] The beneficial effects of adopting the above technical solutions are as follows: Through the collaborative work of multiple traffic diversion schemes and their automatic switching and combination based on the real-time status of the power network and business needs, efficient utilization of various virtual security resources is achieved, thereby improving the flexibility of resource allocation; the traffic diversion data model, with traditional virtual security resources, Huawei Cloud, and Alibaba Cloud as the triple coordinate origins, can accurately determine the traffic location and adapt to the dynamic changes of the power network, ensuring the accuracy and effectiveness of the diversion direction; unified management and control of security technical defense measures enhances adaptive security protection capabilities and the support capabilities for cloud security operation services, ensuring the safety and stability of the entire traffic diversion process; and the security service function chain construction algorithm based on graph neural networks adapts to different scale cloud environments and dynamically adjusts, providing strong support for the secure operation of the power grid cloud platform. Detailed Implementation

[0034] The following embodiments illustrate the present invention in detail. In the description of these embodiments, specific details such as particular system structures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods are omitted so as not to obscure the description of this application with unnecessary detail.

[0035] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0036] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0037] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0038] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0039] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0040] Implementation of Model 1

[0041] I. Implementation Background

[0042] In a large power grid region, the power system covers multiple cities and includes numerous power plants, substations, and a massive amount of terminal power equipment. With the development of smart grids, cloud platforms have become the core hub for power data processing and management, supporting critical business systems such as power production dispatching systems, power marketing management systems, and equipment monitoring and maintenance systems.

[0043] To ensure the secure and stable operation of the cloud platform and cloud-based services, traditional virtual security resources, Huawei Cloud virtual security resources, and Alibaba Cloud virtual security resources have been introduced.

[0044] II. Implementation Process

[0045] (I) Flow-Driven Scheme

[0046] 1. SDN traffic generation

[0047] The SDN controller monitors network traffic in real time, collecting information such as bandwidth utilization, latency, and packet loss rate of network links every 5 minutes. When a sudden power equipment failure in a certain area is detected, causing a large amount of monitoring data traffic (approximately 300Mbps) to flood the cloud platform, the SDN controller initiates dynamic adjustments according to preset policies.

[0048] First, calculate the load of each virtual security resource. The load calculation method is: current bandwidth occupied by the resource / total bandwidth of the resource. The total bandwidth of Huawei Cloud virtual security resources is 000Mbps, and the current bandwidth occupied is 300Mbps, so its load is 300 / 1000 = 0.3; the total bandwidth of Alibaba Cloud virtual security resources is 800Mbps, and the current bandwidth occupied is 200Mbps, so its load is 200 / 800 = 0.25; the total bandwidth of traditional virtual security resources is 500Mbps, and the current bandwidth occupied is 150Mbps, so its load is 150 / 500 = 0.3.

[0049] Because Alibaba Cloud's virtual security resources have relatively low load and their security policies are suitable for handling such device monitoring data (according to the security policy matching algorithm, Alibaba Cloud's matching degree is 0.8, Huawei Cloud's is 0.7, and traditional virtual security resources' is 0.6), the SDN controller directs the device monitoring data traffic in the fault area to Alibaba Cloud's virtual security resources for processing.

[0050] 2. API traffic generation

[0051] The API traffic redirection module establishes interface connections with key business systems such as the power production dispatch system and the power marketing management system. It interacts every 10 minutes to obtain detailed traffic information. The traffic generated by the power production dispatch system involves core power grid operation data and has high security requirements, so it is set to level 4 (security level quantification system: level 1-5, level 5 is the highest confidential level). The business type code is 01 (representing power production data business), and the business priority weight is set to 0.8 (the highest priority weight range for key businesses is 0.7-1).

[0052] Proxy traffic redirection and micro-proxy traffic redirection deploy proxy nodes at key nodes at the network edge (network access points near power plants and large substations) to preprocess traffic from the power production dispatch system. The traffic is checked against preset rules to ensure it complies with the security policy requirements of the target virtual security resource (Huawei Cloud), such as whether the encryption type matches (Huawei Cloud requires AES-256 encryption, and this traffic uses this encryption method). Once compliance is confirmed, the traffic is redirected to the Huawei Cloud virtual security resource.

[0053] (II) Multi-origin coordinate-based data model for diverting data

[0054] 1. Selection of coordinate origin and system dynamics

[0055] A traffic-driving data model is constructed using traditional virtual security resources, Huawei Cloud, and Alibaba Cloud as three coordinate origins. The system monitors the performance changes of virtual resources hourly, including computing power and storage capacity. When Huawei Cloud adds a set of high-performance computing nodes, increasing computing power by 30%, the system dynamically adjusts relevant parameters to adapt to the expansion of virtual resources.

[0056] 2. Relationship between coordinate system dimensions and flow parameters

[0057] For the traffic generated by the power marketing management system, in addition to the basic network parameters (bandwidth 100Mbps, latency 20ms, packet loss rate 0.1%), relevant parameters of power business are also taken into account. Based on the current marketing activities, the business priority is set to medium with a weight of 0.5 (the weight range of medium priority is 0.4-0.6). The number of traffic and security orchestration related parameters is 5 (bandwidth, latency, packet loss rate, business priority, security level requirements). Therefore, the coordinate system dimension is determined to be 5-dimensional.

[0058] The security level requirement is Level 3 (involving sensitive data such as customer information, requiring medium-strength encryption and identity authentication), and the business type code is 02 (representing power marketing data business).

[0059] The flow parameter processing procedure is as follows:

[0060] Bandwidth quantization: Using Mbps as the unit, 100Mbps is normalized within the common bandwidth range (50-200Mbps). Assuming the numerical range mapped to the coordinates is [0.4, 0.6], its normalized value is calculated to be 0.5.

[0061] Security level quantification: According to the established quantification system, the quantification value corresponding to security level 3 is 0.6 (0.2 for level 1 and 1 for level 5, calculated using linear interpolation).

[0062] Business type encoding conversion: 02 encoding corresponds to a specific vector representation in the preset business type encoding system, such as [0,1] (01 encoding is [1,0], used to distinguish different business types).

[0063] Business priority weight: set to 0.5.

[0064] Latency and packet loss rate are processed using a similar normalization method. For example, a latency of 20ms is normalized to 0.4, and a packet loss rate of 0.1% is normalized to 0.3.

[0065] These parameters determine the coordinates of the traffic in three 5D coordinate systems, with the traditional virtual security resource, Huawei Cloud, and Alibaba Cloud as the origins. For example, in the coordinate system with Huawei Cloud as the origin, the coordinates might be (0.5, 0.4, 0.3, 0.5, 0.6) (assuming the order is bandwidth, latency, packet loss rate, service priority, and security level).

[0066] (III) Data-driven representation of location sub-data model

[0067] 1. Comprehensive application of multiple representation methods

[0068] For power equipment monitoring data traffic that is close to the coordinate origin and has relatively small angle changes (such as the normal monitoring data traffic of some equipment in the aforementioned fault area, with a bandwidth of 50Mbps and a relatively stable position in the coordinate system), length is preferentially chosen as the primary representation method. The distance to the Huawei Cloud origin is calculated using the Euclidean distance formula. Where x0, y0, ..., n0 are the coordinates of the origin, and x1, y1, ..., n1 are the flow coordinates, which are assumed to be 5-dimensional coordinates. The calculated distance value is 0.3 (after normalization).

[0069] For power marketing management system flow rates that exhibit significant angular variations along a certain coordinate axis (such as those showing marked changes along the safety level coordinate axis), the trigonometric function value of the angle is chosen as the primary representation method, supplemented by length. The cosine of the angle between the flow rate and the safety level coordinate axis is calculated to be 0.7, and its location is represented by its distance from the origin (0.4 after normalization).

[0070] 2. Adaptive adjustment of the representation model

[0071] When a large amount of high-priority traffic occurs in the network (such as a large amount of high-priority traffic generated by the power production dispatching system in emergency dispatch situations), the model adjusts the representation method according to the relevant parameters of traffic priority. The traffic priority weight is increased from 0.8 to 0.9, and the representation position of the traffic in the coordinate system is recalculated to ensure that high-priority traffic can be more accurately represented in location, so that it can be prioritized during the traffic diversion process.

[0072] (iv) Determining the direction of drainage

[0073] 1. Determine the traffic diversion direction based on the position and data representation in the triple coordinate system, and optimize and adjust according to the load balancing and security strategies of different virtual resources.

[0074] The load and security policy adaptability of each virtual resource are reassessed every 15 minutes. When it is found that the Huawei Cloud load rises to 0.6 (calculated in the same way as before), and some security protection service resources are strained (such as the intrusion detection service resource utilization rate reaching 80%), while the Alibaba Cloud load is 0.3 and the security policy meets most of the current traffic demand, the system adjusts the algorithm according to the preset traffic diversion strategy, and diverts a portion of the power production scheduling system traffic that was originally diverted to Huawei Cloud (selecting an appropriate proportion, 30%, based on traffic characteristics and business needs) to Alibaba Cloud, so as to achieve effective utilization of various virtual resources and optimization of security protection.

[0075] (V) Algorithm for Constructing Security Service Function Chain

[0076] 1. Algorithm adaptability to cloud environment

[0077] In a small cloud environment (a cloud platform subsystem of a small substation within a region, containing a few devices and simple services), a graph neural network is used to quickly converge and accurately construct a security service function chain. By learning the connection relationships and attribute information (device type, service functions, etc.) between network nodes in this small cloud environment, the graph neural network quickly extracts key features and constructs a simple security service function chain including a firewall (for access control), an intrusion detection system (for real-time monitoring), and a data encryption module (for data security), avoiding over-computation and resource waste.

[0078] In large-scale, complex cloud environments (the core cloud platform for the entire power grid region), a layered processing and distributed computing approach is adopted. The network topology is divided into multiple layers, such as the core layer, aggregation layer, and access layer, and features are extracted at each layer. For example, the core layer focuses on large-scale data transmission and the connectivity of core business systems, while the aggregation layer focuses on the aggregation status of devices within the region. Distributed computing nodes process large amounts of network topology information and security service requirements in parallel, constructing a complex security service function chain to meet the security requirements of complex cloud environments.

[0079] 2. Feature Extraction and Functional Chain Construction of Graph Neural Networks

[0080] To address the differences in security level requirements and business priorities across different areas within the power grid region, a corresponding security service function chain is constructed. For example, in the power plant area, the security level requirements are extremely high, and the business priority is also high. After extracting the network topology features of this area using a graph neural network, the node order of the security service function chain is determined as follows: first, an advanced firewall (for strict access control); then, a multi-layer encryption module (for high-strength encryption of power generation data); next, an intrusion detection and prevention system (for real-time monitoring and attack mitigation); and finally, a data backup and recovery node (to ensure data security). These security protection devices and services are connected in a logical order to form an efficient security service function chain for the secure operation of the power grid cloud platform in this area.

[0081] (vi) Unified management and control of security technology measures

[0082] 1. Unified management and control of security technology measures

[0083] Establish a unified security management platform to centrally manage the configuration and status of different types of security devices (firewalls, intrusion detection systems, encryption devices, etc.). Collect the status information of security devices every 30 minutes, including the number of firewall rule matches and the number of intrusion detection system alerts. Adjust the configuration of security devices promptly based on this information. For example, if an abnormally high number of firewall rule matches is detected in a certain area, indicating a potential attack risk, update the firewall rules in a timely manner and add access restriction rules for that area.

[0084] Simultaneously, the traffic redirection algorithm and security strategy are updated and optimized in a unified manner. Performance metrics of the traffic redirection algorithm, such as success rate and traffic distribution balance, are analyzed regularly (weekly). When the traffic redirection success rate is below 80% for two consecutive days, the cause is analyzed in depth. If it is found to be an adaptability issue of the SDN traffic redirection path selection algorithm in complex network topologies, the algorithm parameters are adjusted promptly, and the path selection strategy is optimized.

[0085] 2. Evaluation and Continuous Improvement of Capacity Building Effects

[0086] Establish an effective performance evaluation indicator system, including evaluation indicators for security protection effectiveness (intrusion detection success rate, number of data breaches), traffic redirection efficiency (traffic redirection success rate, average traffic redirection latency), and cloud security operation stability (system failure rate, service downtime). These indicator data should be collected and analyzed daily.

[0087] When the intrusion detection success rate is below 90% for a consecutive week, the reasons may include an outdated signature database or insufficient algorithm recognition of new types of attacks. To address the outdated signature database issue, download the latest intrusion detection signature database promptly. For algorithmic issues, organize security experts to optimize or upgrade the algorithm.

[0088] When the success rate of traffic redirection drops to 70% during a certain period, optimize the synergy and parameter settings of the traffic redirection scheme. For example, adjust the interaction parameters between API traffic redirection and other traffic redirection schemes to improve the accuracy and timeliness of data interaction, thereby enhancing adaptive security protection capabilities and the support capabilities for cloud security operations.

[0089] III. Implementation Results

[0090] By implementing a power data diversion model based on cloud security technology, the cloud platform of this large power grid area has achieved efficient and secure data diversion.

[0091] 1. Resource utilization efficiency has been significantly improved, and the load balancing of various virtual security resources has been effectively improved, avoiding resource idleness and overload, and the overall resource utilization rate has increased by 25%.

[0092] 2. Enhanced security protection capabilities, with intrusion detection success rate increasing to over 95% and data breach incidents reduced by 90%, effectively ensuring the security and integrity of power data.

[0093] 3. The efficiency of diversion has been greatly improved, the success rate of traffic diversion has been stabilized at over 90%, and the average diversion delay has been reduced by 40%, ensuring the stable operation of the power business system.

[0094] 4. The stability of cloud security operations is guaranteed, the system failure rate is reduced to less than once a month, and the service interruption time is almost zero, providing strong support for the reliable power supply of the power grid.

[0095] In actual operation, the model can automatically adjust the diversion strategy according to the real-time status of the power network and business needs, adapt to the dynamic changes of power grid business, and provide a solid security guarantee for the intelligent development of the power grid.

[0096] Example 2: Distributed Energy Access Scenario (Traffic Diversion)

[0097] I. Implementation Background

[0098] In an emerging smart grid demonstration zone, the integration of distributed energy sources (such as solar power plants and small wind farms) into the power grid system is being actively promoted. With the large-scale integration of distributed energy, the cloud platform needs to process massive amounts of data from different energy sources and traditional power grid equipment while ensuring data security and efficient flow. The cloud platform in this region integrates traditional virtual security resources, Huawei Cloud virtual security resources, and Alibaba Cloud virtual security resources to address the complex security protection and data management challenges.

[0099] II. Implementation Process

[0100] (I) Flow-Driven Scheme

[0101] SDN Traffic Generation: The SDN controller continuously monitors network traffic, collecting traffic data every 3 minutes. When distributed energy generation surges during midday (peak solar power generation), causing a large influx of real-time power generation data (approximately 400Mbps) into the cloud platform, the SDN controller quickly analyzes the load status of each virtual security resource. The formula for calculating the load is: Current occupied computing resources / Total computing resources (assuming computing resources are proportional to the amount of traffic that can be processed). Assuming Huawei Cloud virtual security resources currently occupy computing resources equivalent to 350Mbps of traffic processing capacity, and the total computing resources can handle 1200Mbps of traffic, its load is 350 / 1200≈0.29; Alibaba Cloud virtual security resources currently occupy computing resources equivalent to 280Mbps of traffic processing capacity, and the total computing resources can handle 1000Mbps of traffic, with a load of 280 / 1000=0.28; traditional virtual security resources currently occupy computing resources equivalent to 300Mbps of traffic processing capacity, and the total computing resources can handle 800Mbps of traffic, with a load of 300 / 800=0.375.

[0102] Because Alibaba Cloud's virtual security resources have a relatively light load and good elastic scaling capabilities (according to the resource elasticity assessment algorithm, Alibaba Cloud's elasticity score is 0.85, Huawei Cloud's is 0.75, and traditional virtual security resources are 0.6), the SDN controller directs this part of the power generation data traffic to Alibaba Cloud's virtual security resources for preliminary processing.

[0103] API Traffic Generation: API traffic generation interacts with the distributed energy management system and the power grid dispatching system, obtaining detailed traffic information every 8 minutes. For example, traffic generated by the distributed energy management system involves critical data such as power generation adjustment instructions, with a security level requirement of Level 3 (important operation instructions require medium-strength security protection), a business type code of 0 (representing distributed energy management business), and a business priority weight set to 0.7 (traffic related to critical business operations has a higher priority).

[0104] Proxy traffic redirection and micro-proxy traffic redirection involve setting up proxy nodes at the network edge near the distributed energy access point to filter traffic from the distributed energy management system. For example, it checks whether the command format in the traffic conforms to standard specifications (one of the important requirements for secure access to distributed energy). Once confirmed to be compliant, the traffic is redirected to Huawei Cloud virtual security resources according to preset policies (Huawei Cloud has high efficiency in processing this type of command-type traffic; based on historical data processing efficiency assessments, Huawei Cloud's processing efficiency is 0.9, Alibaba Cloud's is 0.8, and traditional virtual security resources' is 0.7).

[0105] (II) Multi-origin coordinate-based data model for diverting data

[0106] Coordinate Origin Selection and System Dynamics: A traffic diversion data model is constructed using traditional virtual security resources, Huawei Cloud, and Alibaba Cloud as triple coordinate origins. As the number of distributed energy sources connected increases or decreases (e.g., a small wind farm is newly connected, or a solar power station is temporarily shut down for maintenance), the system monitors and adjusts relevant parameters in real time. When a new distributed energy source is connected, the system updates resource information within 5 minutes and dynamically adjusts the relevant parameters of the coordinate system based on the new resource distribution to ensure the accuracy of traffic diversion direction determination.

[0107] The relationship between coordinate system dimensions and traffic parameters: For real-time power generation data traffic from distributed energy sources, in addition to basic network parameters (bandwidth 400Mbps, latency 15ms, packet loss rate 0.08%), relevant power service parameters are also considered. Due to the intermittent and fluctuating nature of distributed energy generation, a power generation stability parameter is introduced (e.g., stability is quantified as 0.6 based on real-time power fluctuations, with a stable state of 1 and larger fluctuations of 0-0.5). In this case, the number of traffic and security orchestration-related parameters is 6 (bandwidth, latency, packet loss rate, service priority, security level requirements, and power generation stability). Therefore, the coordinate system dimension is determined to be 6-dimensional, the security level requirement is level 3, and the service type code is 03.

[0108] The flow parameters are processed as follows:

[0109] Bandwidth quantization: Using Mbps as the unit, 400Mbps is normalized within the common bandwidth range (300-500Mbps). Assuming the numerical range mapped to the coordinates is [0.5, 0.7], its normalized value is calculated to be 0.6.

[0110] Security level quantification: According to the established quantification system, the quantification value of security level 3 is 0.6.

[0111] Business type encoding conversion: The 03 encoding corresponds to the vector representation [0,0,1] in the preset business type encoding system (assuming that a three-dimensional vector is used to distinguish different business types).

[0112] Business priority weight: set to 0.7.

[0113] The latency and packet loss rate are processed using a similar normalization method. For example, a latency of 15ms is normalized to 0.5, and a packet loss rate of 0.08% is normalized to 0.4.

[0114] Power generation stability quantification: The value is set to 0.6 according to the above settings.

[0115] These parameters determine the coordinates of the traffic in three 6-dimensional coordinate systems, with the traditional virtual security resource, Huawei Cloud, and Alibaba Cloud as the origins. For example, in the coordinate system with Alibaba Cloud as the origin, the coordinates might be (0.6, 0.5, 0.4, 0.7, 0.6, 0.6) (in the order of bandwidth, latency, packet loss rate, service priority, security level, and power generation stability).

[0116] (III) Data-driven representation of location sub-data model

[0117] Comprehensive use of multiple representation methods

[0118] For conventional power grid equipment monitoring data traffic that is close to the coordinate origin and has relatively small angle changes (such as substation equipment status monitoring data, with a bandwidth of 80Mbps and relatively stable), length is preferred as the primary representation method. The distance to the origin of the traditional virtual security resource is calculated, assuming the Manhattan distance formula is used (where is the origin coordinate and is the traffic coordinate; here, we assume a 6-dimensional coordinate system). The calculated distance value is 0.2 (after normalization).

[0119] For distributed energy control command traffic that exhibits significant angular variations along a certain coordinate axis (such as obvious variations along the business priority coordinate axis, due to varying urgency levels of different commands), the trigonometric function value of the angle is chosen as the primary representation method, supplemented by length. The sine of the angle between this command and the business priority coordinate axis is calculated to be 0.8, and its position is represented by its distance from the origin (0.3 after normalization).

[0120] Adaptive adjustment of representation model

[0121] When a large amount of high-priority traffic occurs in the network (such as emergency dispatch instructions issued by the power grid dispatching system to deal with power supply and demand imbalances), the model adjusts the representation method according to the relevant parameters of traffic priority. The traffic priority weight is increased from the original 0.7 to 0.95, and the representation position of the traffic in the coordinate system is recalculated to ensure that high-priority traffic can be more accurately represented in location so that it can be prioritized during the traffic diversion process.

[0122] (iv) Determining the direction of drainage

[0123] The direction of traffic diversion is determined based on the position and data representation in the triple coordinate system, and optimization and adjustment are made according to the load balancing and security strategies of different virtual resources.

[0124] Every 10 minutes, the load and security policy adaptability of each virtual resource are reassessed. When it is found that the Huawei Cloud load increases to 0.65 (calculated in the same way as before), and the security policy encounters bottlenecks when processing some distributed energy data (such as reduced decryption efficiency for newly encrypted distributed energy data), while the Alibaba Cloud load is 0.35 and the security policy has good compatibility with distributed energy data, the system adjusts the algorithm according to the preset traffic diversion strategy, diverting a portion of the distributed energy management system traffic originally diverted to Huawei Cloud (selecting an appropriate proportion, such as 40%, based on traffic characteristics and business needs) to Alibaba Cloud, so as to achieve effective utilization of various virtual resources and optimization of security protection.

[0125] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A power data diversion system based on cloud security technology, which constructs a computing power flow diversion system that combines security and platform efficiency in the complex environment of multi-cloud coexistence and combined operation during the construction of power grid cloud platforms, characterized by: By combining various traffic redirection solutions, including SDN traffic redirection, API traffic redirection, proxy traffic redirection, and micro-proxy traffic redirection, traffic is directed to non-cloud virtual security resources, Huawei Cloud virtual security resources, Alibaba Cloud virtual security resources, and other cloud-based virtual security resources. The various traffic redirection schemes are synergistic, automatically switching and combining based on the real-time status of the power network and service requirements: SDN traffic redirection leverages the flexibility of software-defined networks to dynamically adjust network traffic paths, guiding traffic to appropriate target virtual resources based on different virtual resource load conditions and security policies; API traffic redirection obtains detailed traffic information through interfaces with various network applications, providing data support for traffic redirection and integrating with other traffic redirection schemes; proxy traffic redirection and micro-proxy traffic redirection set up proxy nodes at the network edge and in specific areas, preprocessing and filtering traffic based on its characteristics and the requirements of the target virtual resources, and deciding to further redirect traffic to the corresponding virtual resources; It also includes constructing a multi-origin coordinate-based data diversion system, with non-cloud virtual security resources, Huawei Cloud, and Alibaba Cloud as the three coordinate origins respectively. This multi-origin coordinate-based data diversion system is based on dynamically adapting to changes in power data traffic and the expansion or adjustment of virtual resources. The correlation between coordinate system dimensions and traffic parameters is established. In the multi-origin coordinate-based data diversion system, the number of coordinate system dimensions depends on the number of parameters related to each traffic and the final security orchestration. This correlation is established by conducting in-depth analysis and classification of traffic parameters. In addition to network parameters, parameters related to power business, including the operating status parameters of power equipment and traffic priority parameters, are also referenced. The coordinate system dimensions are determined based on the complexity and interrelationship of these parameters. The mechanism for determining the location of traffic flow in a multi-origin coordinate-based data system is as follows: A-1 first categorizes traffic parameters, covering basic network parameters including bandwidth, latency, and packet loss rate, security-related parameters including security level requirements and encryption type, and service-related parameters including service type and priority. Differentiated quantification and normalization methods are then implemented for these different types of parameters. A-2 establishes a dynamic update mechanism for traffic parameters: when any parameter of the traffic changes, including network congestion leading to bandwidth reduction, power equipment failure causing increased business priority, and security policy adjustments resulting in changes in security level requirements, the data system immediately initiates the process of recalculating the coordinate position of the traffic in the coordinate system; at the same time, the data system is equipped with parameter adaptive learning capabilities: through in-depth mining of massive historical traffic data and continuous analysis of real-time monitoring data, the data system automatically identifies newly emerging parameter characteristics, including new business parameters related to distributed energy management generated as new distributed energy sources are connected to the power network. The data system can autonomously learn and update the relevant calculation rules in a timely manner, incorporating these new parameters into the coordinate position calculation system; The multi-origin coordinate-based traffic diversion data system also includes a sub-data system for constructing location data representations, used to represent the position of traffic in various coordinate systems, specifically: B-1 Comprehensive Application of Multiple Representation Methods: The constructed location data representation sub-data system includes multiple representation methods, including length from the origin of multiple coordinate systems, angle with a selected coordinate axis, coordinate plane, or hyperplane as the zero-degree angle, or the ratio of length to radian angle, trigonometric function value of angle, ratio of length to trigonometric function of angle, linear combination and product of length and angle, and linear combination or product of length and trigonometric function values ​​of angle. These representation methods are optimized and combined. According to different flow characteristics and application scenarios, the system automatically selects the most suitable representation method or combination method: for flow rates with a distance from the origin of coordinate systems less than a preset threshold and an angle change less than a preset threshold, length is preferentially selected as the primary representation method; while for flow rates with an angle change greater than a preset threshold in a certain coordinate axis direction, the trigonometric function value of angle is selected as the primary representation method and combined with length for auxiliary representation. The B-2 representation sub-data system adaptively adjusts to changes in the power network environment and traffic characteristics. The representation parameters and weights of the sub-data system are automatically adjusted: when high-priority traffic exceeding a preset amount occurs in the network, the representation method is adjusted based on service-related parameters, increasing the weight of service priority-related parameters in the representation to ensure more accurate location representation of high-priority traffic, thus enabling priority processing during traffic redirection; simultaneously, when the network topology changes, including adding or deleting a network node, the system re-evaluates the coordinate system construction and representation method to adapt to the new network environment. Ultimately, the direction of traffic diversion is determined based on the position and data representation in the triple coordinate system, and optimization and adjustment are made according to the load balancing and security strategies of different virtual resources during the process of determining the direction of traffic diversion.

2. The power data diversion system based on cloud security technology according to claim 1, characterized in that: An algorithm for constructing a security service function chain based on graph neural networks is proposed, which dynamically adjusts the construction of the security service function chain according to changes in service requirements. Specifically: Feature extraction and functional chain construction of graph neural networks: Graph neural networks are used to extract network topology features and establish a security service functional chain for the power grid cloud platform. The graph neural network extracts network topology features by learning the connection relationships and attribute information between network nodes. These features are used to construct a security service function chain. Based on different security service requirements and network topology, the node order and connection method of the security service function chain are determined: according to the security level requirements and business priorities of different areas in the network, security protection devices and services are connected in a reasonable order to form a security service function chain for the security operation of the power grid cloud platform.

3. The power data diversion system based on cloud security technology according to claim 1, characterized in that: Unified management and control of security technology measures, including centralized management and coordination of various security devices, algorithms, and strategies involved in the traffic diversion process, specifically: D-1 Unified Management and Control of Security Measures: Establish a unified security management platform to manage the configuration and status of different types of security devices, including firewalls and intrusion detection systems, while uniformly updating and optimizing traffic redirection algorithms and security policies; Evaluation and continuous improvement of D-2 capabilities: Establish a performance evaluation index system, which includes evaluation indicators for security protection effectiveness, traffic diversion efficiency, and the stability of cloud security operations; Based on the evaluation results, continuously improve security technical defense measures and traffic diversion methods: When the intrusion detection success rate is low, analyze the reasons and adjust the algorithm or configuration of the intrusion detection system; The success rate of traffic redirection is not high; therefore, it is necessary to optimize the synergy and parameter settings of the traffic redirection scheme.

Citation Information

Patent Citations

  • Scheduling method and device for cloud platform virtual diversion technology

    CN111026525A

  • Energy internet cloud platform security protection method and system

    CN111431914A