Data Security Protection System and Fragmented Encryption Method for Energy Operation Platform
By adopting multimodal feature extraction, risk assessment model of deep convolutional neural networks, fragmented encryption and dynamic access control, and multi-level security protection system on the energy operation platform, the challenges of data security on the energy operation platform are solved and efficient and reliable data protection is achieved.
Patent Information
- Application Number
- CN202510267545.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-03-07
AI Technical Summary
Energy operation platforms face severe challenges in data security, including security vulnerabilities in sensor networks, privacy risks of user energy consumption data, cyberattack threats to monitor data in grid operation, and limitations of traditional encryption algorithms and access control models.
The data security protection system for energy operation platforms is adopted, combining multimodal feature extraction, risk assessment model of deep convolutional neural networks, fragmented encryption and dynamic access control, and multi-level security protection system, including boundary protection, intrusion detection and data recovery layers to ensure the confidentiality, integrity and availability of data.
Through accurate risk assessment and dynamic encryption strategies, the risks of data leakage, tampering and loss can be effectively reduced, data processing efficiency and system performance can be improved, and data security and reliability of the energy operation platform can be ensured.
Smart Images

Figure CN119760756B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of energy operation, and particularly to a data security protection system and a fragmentation encryption method for an energy operation platform. Background Art
[0002] In today's digital age, the energy industry is undergoing profound changes, and the energy operation platform has become the core hub for realizing efficient energy management, optimized allocation, and reliable supply. This platform aggregates a vast amount of complex data, covering various aspects such as real-time operating conditions data collected from energy production equipment sensors, detailed consumption information feedback from user energy consumption record terminals, and grid status data provided by grid operation monitoring systems. These data play a crucial role in the refined operation and scientific decision-making of energy enterprises. However, with the widespread application of the energy operation platform and the increasing frequency of data interaction, its data security faces unprecedented severe challenges.
[0003] From the perspective of energy production equipment sensor data, on the one hand, the energy production environment is usually harsh, complex, and changeable. For example, the high humidity and strong electromagnetic interference environment in coal mines, and the high temperature and high pressure conditions at oil extraction sites. This makes the stability of the sensors themselves vulnerable to influence, and errors or losses are likely to occur during data transmission. On the other hand, as the "nerve endings" of energy data collection, the sensor network has openness and relatively weak security protection mechanisms, making it a potential risk point for data security. Lawbreakers may take advantage of the loopholes in the sensor network to tamper with or steal key production data, thereby interfering with the energy production process, triggering production accidents, and even endangering the safety of personnel and the environment. For example, maliciously tampering with the temperature sensor data of a nuclear power plant reactor may lead to misjudgment of the reactor status by operators, triggering a serious nuclear leakage risk.
[0004] The data of user energy consumption record terminals contains rich user personal information and consumption habit characteristics. These data not only involve user privacy but may also be related to sensitive information such as the user's economic situation. Once these data are leaked, users will face risks such as privacy infringement and targeted fraud. In addition, for energy enterprises, accurate energy consumption data is an important basis for energy supply and demand forecasting, formulating reasonable pricing strategies, and optimizing energy distribution. If the energy consumption data is maliciously tampered with, it will cause deviations in the decision-making of energy enterprises, resulting in unreasonable allocation of energy resources and economic losses, and at the same time, it will also affect the fair competition and healthy development of the energy market.
[0005] The data of the power grid operation monitoring system plays a decisive role in ensuring the safe and stable operation of the power grid. As the "main artery" of energy transmission, any subtle change in the operation state of the power grid needs to be accurately monitored and timely processed. However, with the improvement of the intelligence level of the power grid, its connection with the external network is becoming increasingly close, and the network attack surface is constantly expanding. Network attackers may interfere with the accuracy of power grid operation monitoring data and mislead the decision-making of power grid dispatching personnel through various means, such as malware injection and vulnerability exploitation, resulting in serious consequences such as power grid failures and power outages. In 2017, the power grid of a certain country was hacked, and the attacker tampered with the power data in the power grid operation monitoring system, causing the power grid in some areas to be overloaded and triggering a large-scale power outage, which brought a huge impact on the social economy.
[0006] When dealing with the data security challenges of the energy operation platform, the existing data security protection technologies have exposed many limitations. When processing energy data, traditional encryption algorithms often adopt fixed encryption strategies and are difficult to be flexibly adjusted according to the real-time characteristics of energy data (such as the dynamic changes of data sensitivity and importance over time and working conditions). For example, during the peak period of energy production, the confidentiality requirements of key production data are extremely high, but traditional encryption algorithms cannot automatically improve the encryption intensity, thus there is a risk of data leakage; while during non-critical periods, using high-intensity encryption will cause waste of computing resources and affect system performance.
[0007] In terms of access control, the common access control models based on static roles or permissions cannot adapt to the complex and changeable business scenarios of the energy operation platform. In special scenarios such as energy equipment maintenance and emergency repair, it is necessary to temporarily grant specific data access permissions to staff, but the static access control model is difficult to achieve dynamic adjustment of permissions quickly and flexibly, resulting in low work efficiency and even delaying the best opportunity for fault handling.
[0008] In the construction of the security protection system, traditional boundary protection technologies (such as simple firewall rules) can only block known network attack patterns to a limited extent and are unable to cope with new and complex network attacks (such as advanced persistent threats APT and zero-day vulnerability attacks). These attacks often have a high degree of concealment and pertinence, can lurk in the system for a long time, and steal key data without being detected. At the same time, most of the existing intrusion detection technologies rely on known attack feature libraries for matching detection and have serious deficiencies in detecting unknown attack behaviors, unable to detect and prevent new attacks in a timely manner. In addition, data recovery technologies in the energy operation platform also have problems such as long recovery time and difficulty in ensuring data consistency, and cannot meet the strict requirements of the energy industry for data real-time and integrity. After data loss or damage, it may lead to serious consequences such as interruption of energy production and suspension of business. Summary of the Invention
[0009] The object of the present invention is to provide a data security protection system and a fragmented encryption method for an energy operation platform to solve the problems raised in the above-mentioned background technology.
[0010] To achieve the above object, the present invention provides the following technical solution: A data security protection system for an energy operation platform, including:
[0011] A data acquisition module, which is used to collect various types of data from multiple data sources of the energy operation platform. The data sources include energy production equipment sensors, user energy consumption record terminals, and power grid operation monitoring systems; based on a multi-modal feature extraction method, feature extraction is performed on the collected data to obtain a data feature set; the data feature set is input into a pre-trained risk assessment model. The risk assessment model adopts a deep convolutional neural network structure, and based on a risk assessment function, the security risks faced by the data are evaluated to generate risk assessment parameters;
[0012] A data processing module, which is used to construct a data security processing model according to the risk assessment parameters. The data security processing model takes data confidentiality, integrity, and availability as protection objectives, and adopts a method combining fragmented encryption and dynamic access control to perform security processing on the data. Among them, the fragmented encryption introduces a dynamic block division strategy and a hierarchical encryption mechanism based on chaotic mapping, divides the data into multiple logically related encrypted units, and each encrypted unit independently generates a chaotic key and performs multi-dimensional encryption transformation; based on the data security processing model, the data after security processing is output;
[0013] A security protection module, which is used to establish a multi-level security protection system according to the data after security processing. The multi-level security protection system includes a boundary protection layer, an intrusion detection layer, and a data recovery layer. Among them, the boundary protection layer performs network boundary access control based on the risk assessment parameters, the intrusion detection layer performs real-time monitoring of data access behaviors based on an abnormal behavior analysis algorithm, and the data recovery layer realizes reliable recovery of data based on a redundancy backup and fast recovery mechanism; through the multi-level security protection system, the security of the data of the energy operation platform is guaranteed.
[0014] Preferably, inputting the data feature set into a pre-trained risk assessment model, the risk assessment model adopts a deep convolutional neural network structure, and based on a risk assessment function, the security risks faced by the data are evaluated to generate risk assessment parameters, including:
[0015] The object of the present invention is to provide a data security protection system and a fragmented encryption method for an energy operation platform to solve the problems raised in the above-mentioned background technology.
[0016] To achieve the above object, the present invention provides the following technical solution: A data security protection system for an energy operation platform, including:
[0017] A data acquisition module is used to collect various types of data from multiple data sources of an energy operation platform. The data sources include energy production equipment sensors, user energy consumption record terminals, and power grid operation monitoring systems. Based on a multi-modal feature extraction method, the collected data is subjected to feature extraction to obtain a data feature set. The data feature set is input into a pre-trained risk assessment model. The risk assessment model adopts a deep convolutional neural network structure and evaluates the security risks faced by the data based on a risk assessment function to generate risk assessment parameters.
[0018] A data processing module is used to construct a data security processing model according to the risk assessment parameters. The data security processing model takes data confidentiality, integrity, and availability as protection objectives and adopts a method combining fragmented encryption and dynamic access control to perform security processing on the data. Among them, the fragmented encryption introduces a dynamic block division strategy and a hierarchical encryption mechanism based on chaotic mapping, divides the data into multiple logically related encrypted units, and each encrypted unit independently generates a chaotic key and performs multi-dimensional encryption transformation. Based on the data security processing model, the data after security processing is output.
[0019] A security protection module is used to establish a multi-level security protection system according to the data after security processing. The multi-level security protection system includes a boundary protection layer, an intrusion detection layer, and a data recovery layer. Among them, the boundary protection layer performs network boundary access control based on the risk assessment parameters, the intrusion detection layer performs real-time monitoring of data access behaviors based on an abnormal behavior analysis algorithm, and the data recovery layer realizes reliable recovery of data based on a redundant backup and fast recovery mechanism. The security of the energy operation platform data is guaranteed through the multi-level security protection system.
[0020] Preferably, inputting the data feature set into a pre-trained risk assessment model, the risk assessment model adopts a deep convolutional neural network structure, and the generation of risk assessment parameters for evaluating the security risks faced by the data based on a risk assessment function includes:
[0021] The deep convolutional neural network is trained using the stochastic gradient descent method. The training sample set is expanded through data augmentation techniques, and random sampling is performed from the expanded training sample set for network training, where the parameters of the network are updated in each round of training. Based on the trained deep convolutional neural network, risk assessment parameters are output, and the risk assessment parameters include a network weight matrix, a network bias vector, feature normalization parameters, and risk level division parameters.
[0022] Preferably, a data security processing model is constructed according to the risk assessment parameters. The data security processing model aims to protect data confidentiality, integrity, and availability, and adopts a method combining fragmented encryption and dynamic access control to securely process data. The data output after security processing based on the data security processing model includes:
[0023] Construct a multi-objective function for data security processing. The multi-objective function includes a confidentiality enhancement objective function, an integrity guarantee objective function, and an availability maintenance objective function. Among them, the confidentiality enhancement objective function is calculated through the key dynamics of fragmented encryption and the hierarchical encryption depth. The integrity guarantee objective function is calculated through data block hash chain verification and logical association graph topology constraints. The availability maintenance objective function is calculated through data block redundant distribution and recovery path optimization;
[0024] Based on the multi-objective function, construct data block constraint conditions. The data block constraint conditions include semantic relevance constraints, dynamic block threshold constraints, and logical topology constraints. The semantic relevance constraints are used to ensure that the divided data blocks have resolvable semantic boundaries. The dynamic block threshold constraints dynamically adjust the block size according to data sensitivity. The logical topology constraints limit the dependency relationship between data blocks through a directed acyclic graph;
[0025] Adopt a dynamic block splitting strategy driven by chaotic mapping to split the original data. Each data block generates a unique identifier and is associated with logical position coordinates, and block splitting parameters are generated based on the iterative equation of chaotic mapping;
[0026] Construct a hierarchical encryption mechanism, which includes:
[0027] The first-layer encryption unit: Generate a chaotic initial key based on the data block identifier, generate a key sequence through Logistic mapping iteration, and perform bit-level XOR encryption on the data block;
[0028] The second-layer encryption unit: Construct a permutation matrix based on the logical position coordinates, and perform byte position permutation on the encrypted data block through matrix transformation;
[0029] The third-layer encryption unit: Generate a substitution rule based on the association relationship graph between data blocks, and perform byte substitution on the permuted data block through a non-linear S-box;
[0030] Introduce a collaborative mechanism of dynamic access control and fragmented encryption, generate a data block access policy through attribute-based encryption, bind the access policy to the logical topology constraints of the data block, and dynamically activate the decryption level based on the attribute matching degree. When the access permission meets the first-layer attribute, only the first-layer encryption unit is decrypted, and it is unlocked layer by layer until the full access permission is met.
[0031] Preferably, the boundary protection layer performs network boundary access control based on the risk assessment parameters, including:
[0032] Using state detection technology to describe the network connection state, representing the network connection state as a function of connection parameters, the value range of the connection parameters is determined according to network protocols and security policies, and the network connection state includes source IP address, destination IP address, port number, protocol type, and connection time;
[0033] Describing the network connection state based on a directed acyclic graph, representing the flow direction and dependency relationship of the network connection through the relationship between nodes and edges, the nodes of the directed acyclic graph are obtained by feature extraction of connection parameters, and the edges are determined by the conversion rules of connection states;
[0034] Constructing network access control constraint conditions, the network access control constraint conditions include source address constraint, destination address constraint, port constraint, protocol constraint, and time constraint. The source address constraint is used to limit the range of source IP addresses allowed to access, the destination address constraint is used to limit the range of destination IP addresses allowed to be accessed, the port constraint is used to limit the range of port numbers allowed to be used, the protocol constraint is used to limit the types of network protocols allowed to pass through, and the time constraint is used to limit the time period allowed to access;
[0035] Constructing a global access control policy function, the global access control policy function includes access rule matching items, risk assessment items, and security policy priority items, and performing weighted combination on each item in the global access control policy function through a weighting coefficient;
[0036] Discretizing the network connection state interval into multiple connection segments, performing discretization processing on the global access control policy function, and constructing a global discretized policy function, the global discretized policy function includes connection segment features, matching rules, and policy execution results;
[0037] Using a rule-based decision-making method to iteratively optimize the global discretized policy function, determining whether to allow access by matching access rules with connection states, and updating the access control list based on the decision result according to the risk assessment result and security policy priority;
[0038] Performing consistency check and conflict resolution on the optimized network access control policy, generating an effective network access control policy by maintaining the consistency and coherence of the policy, and controlling the access to the network boundary based on the effective network access control policy.
[0039] Preferably, the intrusion detection layer performs real-time monitoring of data access behavior based on an abnormal behavior analysis algorithm, including:
[0040] Construct a local monitoring window based on the time series, operation type, and access path of data access behaviors, adaptively adjust the size of the local monitoring window through a behavior complexity coefficient, and establish a positive correlation between the size of the local monitoring window and the complexity of the data access behaviors;
[0041] Construct a behavior model using multi-source log data, preprocess the log data to obtain standardized behavior records, update the probability distribution of the behavior pattern library based on the behavior records, and calculate the occurrence probability value of each behavior pattern through Bayesian inference methods;
[0042] Model dynamic abnormal behaviors using a hidden Markov model, predict the next state of the behavior through state transition probabilities, and update the predicted state based on the observed data to obtain the potential patterns and development trends of abnormal behaviors;
[0043] Construct an intrusion detection model, use the feature vector of the data access behavior as the state variable, where the state variable includes access time, access subject, access object, and operation type, construct state constraint conditions and behavior trend constraint conditions, where the state constraint conditions are used to limit the value range of the state variable, and the behavior trend constraint conditions are used to limit the change trend of the behavior pattern;
[0044] Construct a multi-objective detection cost function, where the multi-objective detection cost function includes a normal behavior matching term, an abnormal behavior identification term, a false alarm penalty term, and a missed alarm penalty term, and perform weighted combination on each item in the multi-objective detection cost function through a weighting coefficient;
[0045] Use the particle swarm optimization algorithm to optimize and solve the multi-objective detection cost function, calculate the gradient of the cost function with respect to the behavior features, find the optimal solution by updating the position and adjusting the velocity of the particles, evaluate the quality of the particles through a fitness function, and determine the optimal parameter combination through backtracking search.
[0046] Preferably, the data recovery layer realizes reliable data recovery based on a redundant backup and fast recovery mechanism, including:
[0047] Establish a data redundant backup model, where the data redundant backup model includes full backup, incremental backup, and differential backup strategies. The full backup regularly performs a complete backup of all data, the incremental backup only backs up the data that has changed since the last backup, and the differential backup only backs up the data that has changed since the last full backup;
[0048] Construct the data redundant backup model into a storage structure expression, where the storage vector of the storage structure expression includes backup data, backup time, backup type, and storage location, and the recovery vector of the storage structure expression includes recovery time target, recovery point target, and data consistency requirements;
[0049] Optimize the storage structure expression, calculate the trade-off relationship among the backup data volume, storage cost, and recovery time, and construct an optimized backup storage strategy;
[0050] Construct a data recovery prediction cost function, where the prediction cost function includes a recovery time term, a data loss term, and a recovery cost term, and perform weighted combination on each cost term through a weight matrix;
[0051] Construct recovery constraint conditions, where the recovery constraint conditions include storage medium availability constraints, network bandwidth constraints, and data consistency constraints, and construct recovery operation constraint conditions, where the recovery operation constraint conditions include backup data integrity check, recovery process sequence, and data verification mechanism;
[0052] Transform the prediction cost function into the standard form of a linear programming problem, calculate the linear coefficients and constant terms, and construct an inequality constraint matrix and an equality constraint matrix;
[0053] Solve the linear programming problem using the simplex method, obtain the optimal recovery strategy by solving the basic feasible solution, determine the final recovery plan based on the feasibility and optimality of the recovery strategy, perform a recovery operation on the backup data, and perform consistency check and verification on the recovered data.
[0054] Preferably, the present invention further includes a fragmented encryption method for an energy operation platform, which is applied to the above data security protection system and includes:
[0055] Divide the data to be encrypted into multiple data blocks, and each data block has a unique identifier; generate an initial key fragment based on the content and location information of the data block, and the initial key fragment is calculated through the combination of the hash value of the data block and the location index;
[0056] Perform chaotic encryption on the initial key fragment using a chaotic mapping algorithm, and the chaotic mapping algorithm performs a non-linear transformation on the key fragment through an iterative function to generate a chaotically encrypted key fragment;
[0057] Construct an association relationship graph between data blocks, where the association relationship graph takes data blocks as nodes and the semantic association or logical dependence between data blocks as edges; perform diffusion processing on the chaotically encrypted key fragment based on the association relationship graph, and generate a diffused key fragment through the propagation and mixing of the key fragment in the association relationship graph;
[0058] Classify the data blocks according to the importance and access frequency of the data blocks, and the classification method determines the category of the data blocks by defining importance indicators and access frequency thresholds; for different categories of data blocks, perform secondary encryption on the diffused key fragment using different encryption transformations;
[0059] Fuse the key fragments after secondary encryption with the corresponding data blocks, and the fusion method is implemented through exclusive-or operation or other bitwise operations; generate fragmented encrypted data based on the fused data blocks, and output the fragmented encrypted data.
[0060] Preferably, the chaotic encryption of the initial key fragments using the chaotic mapping algorithm includes:
[0061] Use the initial key fragments as the input of the chaotic mapping function, and obtain a chaotic sequence by iteratively calculating the chaotic mapping function; perform quantization processing on the chaotic sequence, map the continuous values of the chaotic sequence to the discrete key fragment space, and generate the key fragments after chaotic encryption.
[0062] Preferably, the present invention further includes an electronic device, including:
[0063] A processor;
[0064] A memory for storing instructions executable by the processor;
[0065] Wherein, the processor is configured to call the instructions stored in the memory to execute the operations of the above data security protection system.
[0066] Preferably, the present invention further includes a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the functions in the above data security protection system are implemented.
[0067] Compared with the prior art, the beneficial effects of the present invention are:
[0068] Through the data acquisition module, combined with the risk assessment model of the multi-modal feature extraction method and the deep convolutional neural network structure, the security risks faced by the energy operation platform data can be comprehensively and accurately evaluated. This model comprehensively considers multi-source information such as energy production data, user energy consumption data, and power grid operation status data, and constructs a risk assessment function covering dimensions such as data leakage, tampering, system failures, and cyberattacks. Compared with the traditional risk assessment methods based on single factors or simple rules, its assessment results are more accurate and comprehensive, and can discover potential security risks in advance. For example, by real-time monitoring of abnormal changes in data access permissions, changes in data hash values, device failure frequencies, and abnormal patterns of network traffic, risk warnings can be issued in a timely manner, enabling operation and maintenance personnel to take preventive measures in advance, effectively reducing the probability of security incidents, and avoiding serious consequences such as energy production interruptions, user information leakage, and power grid operation failures caused by data security problems.
[0069] The method of combining fragmented encryption and dynamic access control adopted by the data processing module provides strong guarantees for the data confidentiality and integrity of the energy operation platform. Based on the dynamic block strategy and hierarchical encryption mechanism of chaotic mapping, the data is divided into multiple logically related encrypted units, and each encrypted unit independently generates a chaotic key and performs multi-dimensional encryption transformation. This encryption method not only increases the complexity of encryption but also enables flexible encryption according to the sensitivity and importance of the data. Compared with traditional fixed encryption strategies, it can better adapt to the dynamic characteristics of energy data. For example, for the core energy production data with high sensitivity, finer block division and higher-level encryption are adopted to ensure the security of the data during storage and transmission. At the same time, the collaborative mechanism of dynamic access control and fragmented encryption dynamically activates the decryption level based on the attribute matching degree, and only users with corresponding permissions can unlock the corresponding encryption layer, further preventing data leakage and effectively protecting the data privacy of energy enterprises and users.
[0070] The multi-level security protection system constructed by the security protection module includes a boundary protection layer, an intrusion detection layer, and a data recovery layer, which comprehensively resist various security threats. The boundary protection layer performs network boundary access control based on risk assessment parameters, uses state detection technology and directed acyclic graphs to describe the network connection status, constructs comprehensive access control constraint conditions and global access control policy functions, and generates effective access control policies through iterative optimization and consistency checks. Compared with traditional simple firewall rules, it can more accurately identify and block illegal network access and effectively resist external malicious attacks. The intrusion detection layer performs real-time monitoring of data access behaviors based on abnormal behavior analysis algorithms. Through technologies such as constructing local monitoring windows, building behavior models with multi-source log data, and hidden Markov model modeling, it can timely detect internal and external abnormal data access behaviors, including unknown attack behaviors. Compared with traditional intrusion detection technologies that rely on known attack feature libraries, its detection ability is stronger and the false alarm rate is lower. The data recovery layer is based on the redundant backup and fast recovery mechanism, establishes a data redundant backup model including full backup, incremental backup, and differential backup strategies, and determines the optimal recovery strategy by optimizing the storage structure expression and solving linear programming problems. This ensures that when the data is lost or damaged, the data can be quickly and accurately recovered, ensuring data consistency and availability, greatly shortening the downtime of the energy operation platform caused by data problems, and improving the reliability of the system.
[0071] The technical solution of the present invention effectively improves the overall performance of the energy operation platform while ensuring data security. During the data encryption process, based on the dynamic block strategy and hierarchical encryption mechanism of chaotic mapping, by reasonably dividing blocks and optimizing the encryption process, the computational overhead of encryption and decryption is reduced, and the data processing efficiency is improved. The dynamic access control mechanism can quickly adjust user permissions according to actual business needs, avoiding the problem of untimely permission adjustment of the traditional static access control model in special scenarios and improving work efficiency. In terms of security protection, the layers of the multi-level security protection system work together to achieve rapid response and handling of security threats, reducing the impact of security incidents on system performance. For example, the boundary protection layer timely blocks illegal access, reducing the burden on the intrusion detection layer and the data recovery layer; the intrusion detection layer quickly discovers abnormal behaviors and blocks them in a timely manner to prevent the further expansion of security incidents and ensure the stable operation of the system. This enables the energy operation platform to better adapt to the complex and changeable business scenarios in the energy industry, such as seasonal fluctuations in energy production and emergency data access requirements during emergency repairs. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 is the working principle diagram of the data security protection system for the energy operation platform described in the present invention;
[0073] Figure 2 is the flowchart of the construction and training of the risk assessment model;
[0074] Figure 3 is the flowchart of the monitoring of abnormal behaviors in the intrusion detection layer of the energy operation platform. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0075] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0076] Please refer to Figures 1-3 , the present invention provides a technical solution: a data security protection system for an energy operation platform, which can efficiently and accurately monitor the stability of slopes, predict potential landslide risks, and provide timely warning information. The following will describe the specific implementation manners of the system in detail.
[0077] Data acquisition module: Collect data from multiple data sources of the energy operation platform, including energy production equipment sensors, user energy consumption record terminals, power grid operation monitoring systems, etc. Use multi-modal feature extraction methods to extract features from the collected data to obtain a data feature set. Then, input the data feature set into a pre-trained risk assessment model, which adopts a deep convolutional neural network structure and evaluates the security risks faced by the data based on a risk assessment function, and finally generates risk assessment parameters.
[0078] Data processing module: Construct a data security processing model based on the risk assessment parameters. This model aims to protect data confidentiality, integrity, and availability, and uses a method combining fragmented encryption and dynamic access control to perform security processing on the data. Fragmented encryption introduces a dynamic block strategy and a hierarchical encryption mechanism based on chaotic mapping, divides the data into multiple logically related encrypted units, and each encrypted unit independently generates a chaotic key and performs multi-dimensional encryption transformation. Finally, output the data after security processing based on the data security processing model.
[0079] Security protection module: Establish a multi-level security protection system based on the data after security processing. This system includes a boundary protection layer, an intrusion detection layer, and a data recovery layer. The boundary protection layer performs network boundary access control based on the risk assessment parameters; the intrusion detection layer monitors data access behaviors in real time based on anomaly behavior analysis algorithms; the data recovery layer realizes reliable data recovery based on a redundant backup and fast recovery mechanism, and comprehensively guarantees the security of the energy operation platform data through the multi-level security protection system.
[0080] The present invention will be further described below in conjunction with Embodiments 1 to 5:
[0081] Embodiment 1:
[0082] This embodiment details the construction and training process of the risk assessment model, which can accurately evaluate the security risks faced by the energy operation platform data, provide a key basis for subsequent data security processing and security protection, and ensure the effectiveness and pertinence of the data security protection system.
[0083] ① Data acquisition and feature construction: Obtain the collected data, which includes energy production data, user energy consumption data, power grid operation status data, equipment failure information, and network traffic data. Based on these data, construct a feature space and construct feature vectors from aspects such as data attributes, time series features, and correlation relationships. For example, for energy production data, its attributes may include production equipment types, production power, etc.; the time series features can be the change trends of production data at different times; the correlation relationship is reflected in the mutual influence with user energy consumption data and power grid operation status data.
[0084] ②Construct a multi - dimensional risk assessment function: The constructed multi - dimensional risk assessment function includes data leakage risk items, data tampering risk items, system failure risk items, and network attack risk items.
[0085] Data leakage risk item: It is calculated through the abnormal change of data access permissions. The calculation formula is: Data leakage risk item = Number of abnormal access permission changes / Total number of access permission changes. Assume that within a certain period of time, the total number of access permission changes is , and the number of abnormal access permission changes is , then the data leakage risk item is . The abnormal change of access permissions can be determined by comparing the current access permissions with the historical normal access permission range. If it exceeds the normal range, it is determined as abnormal.
[0086] Data tampering risk item: It is calculated by comparing the change of data hash value with the historical record. The calculation formula is: Data tampering risk item . Among them, is the number of data updates, is the data hash value after the th update, is the data hash value of the previous update. When data is tampered with, its hash value will change. The relative size of the hash value change is calculated to measure the data tampering risk.
[0087] System failure risk item: It is calculated through the comprehensive evaluation of equipment failure frequency and influence range. The calculation formula is: System failure risk item = Equipment failure frequency × Influence range coefficient. The equipment failure frequency can be obtained by counting the number of equipment failures within a certain period of time. Assume that within time, the equipment fails times, then the equipment failure frequency is . The influence range coefficient is determined according to factors such as the number of equipment affected by the failure and the business process. If the number of equipment affected by the failure is large and it has a great impact on the core business process, the influence range coefficient takes a larger value. Network attack risk item: It is calculated by matching the abnormal patterns of network traffic with known attack characteristics. The calculation formula is: Network attack risk item = Number of abnormal traffic patterns matched / Total number of traffic patterns. Assume that in the monitored network traffic, the total number of traffic patterns is , and the number of abnormal traffic patterns matched is , then the network attack risk item is . The known attack characteristics can be established by collecting attack samples in the field of network security and extracting their characteristics. Abnormal traffic patterns are identified by comparing real - time network traffic patterns with the characteristics in the feature library.
[0088] ③Construct a deep convolutional neural network structure and a loss function: Construct a deep convolutional neural network structure, which includes an input layer, multiple convolutional layers, pooling layers, and fully connected layers. The dimension of the input layer is the same as that of the feature space. Different-sized convolutional kernels are used in the convolutional layers to extract data features. For example , and other convolutional kernels. Different-sized convolutional kernels can capture data features at different scales. The pooling layer is used to reduce the data dimension. Common pooling methods include max pooling and average pooling to reduce the computational amount and prevent overfitting. The fully connected layer is used to integrate the extracted features. Based on this, a loss function is constructed. The loss function includes the mean square error term of the predicted risk and the actual risk, and the calculation formula is: Loss function . Among them, is the number of samples, is the actual risk value, is the predicted risk value.
[0089] Model training: Use the stochastic gradient descent method to train the deep convolutional neural network. Augment the training sample set through data augmentation techniques, such as rotating, translating, and scaling the original data to generate new data samples. Randomly sample from the augmented training sample set for network training, and the network updates parameters in each round of training. During the training process, continuously adjust the weights and biases of the network to gradually reduce the value of the loss function, thereby improving the prediction accuracy of the model. Finally, based on the trained deep convolutional neural network, output risk assessment parameters, including the network weight matrix, network bias vector, feature normalization parameters, and risk level division parameters.
[0090] Example 2:
[0091] This example specifically illustrates the construction and application process of the data security processing model. By combining fragmented encryption and dynamic access control, it effectively guarantees the confidentiality, integrity, and availability of data, and ensures the security of data during storage and transmission.
[0092] ①Construct multi-objective functions: Construct multi-objective functions for data security processing, including a confidentiality enhancement objective function, an integrity guarantee objective function, and an availability maintenance objective function.
[0093] Confidentiality enhancement objective function: Obtained through the key dynamics of fragmented encryption and the calculation of the depth of hierarchical encryption. The calculation formula is: Confidentiality enhancement objective function = key update frequency × number of hierarchical encryption layers. Assume that the key is updated once every time, and the number of hierarchical encryption layers is , then the confidentiality enhancement objective function is The higher the key update frequency and the more layers of hierarchical encryption, the greater the value of the confidentiality enhancement objective function and the stronger the data confidentiality.
[0094] Integrity guarantee objective function: Obtained through data block hash chain verification and logical association graph topology constraint calculation. The calculation formula is: Integrity guarantee objective function . Among them, is the number of data block updates, is the hash value of the data block after the th update, is the hash value of the data block in the previous update; is the number of logical association edges of the data block, is the th edge distance (which can be determined according to the relationship between nodes in the logical association graph). Data block hash chain verification detects whether the data has been tampered with by calculating the change in the hash value, and the logical association graph topology constraint guarantees the integrity of the data by restricting the dependency relationship between data blocks.
[0095] Availability maintenance objective function: Obtained through data block redundant distribution and recovery path optimization calculation. The calculation formula is: Availability maintenance objective function = Number of redundant data blocks / Total number of data blocks Shortest length of the recovery path. Assume the number of redundant data blocks is , the total number of data blocks is , and the shortest length of the recovery path is , then the availability maintenance objective function is . The more the number of redundant data blocks and the shorter the recovery path, the greater the value of the availability maintenance objective function and the higher the data availability.
[0096] ② Construct data block constraint conditions: Based on the multi-objective function, construct data block constraint conditions, including semantic relevance constraint, dynamic block threshold constraint, and logical topology constraint.
[0097] Semantic relevance constraint: Ensure that the segmented data blocks have parsable semantic boundaries. For example, for energy production data, segment according to semantic features such as production process and equipment type, so that each data block has a clear meaning, facilitating subsequent data processing and analysis.
[0098] Dynamic block threshold constraint: Dynamically adjust the block size according to data sensitivity. Data blocks with high sensitivity are divided smaller to improve the refinement and security of encryption; data blocks with low sensitivity can be divided larger to reduce the encryption and decryption overhead. Assume that the data sensitivity is measured by a sensitivity index . When ( is the set sensitivity threshold), the data block size is ; When the data block size is and .
[0099] Logical topology constraint: Restrict the dependency relationship between data blocks through a directed acyclic graph to ensure that the processing order of data blocks is logical and avoid problems such as circular dependencies. In a directed acyclic graph, nodes represent data blocks, edges represent the dependency relationship between data blocks, and the processing of data blocks can only proceed along the direction of the edges.
[0100] ③ Data chunking and key generation: Use a dynamic chunking strategy driven by chaotic mapping to split the original data. Each data block generates a unique identifier and is associated with logical position coordinates, and chunking parameters are generated based on the iterative equation of chaotic mapping. The iterative equation of chaotic mapping can use the Logistic mapping, and the formula is: . Among them, is the value of the th iteration, is the control parameter (usually taking values between 3.57 and 4). By adjusting the initial value and the control parameter , different chaotic sequences can be generated to determine the splitting position and size of data blocks.
[0101] ④ Hierarchical encryption mechanism: Build a hierarchical encryption mechanism, including the following three layers of encryption units.
[0102] The first layer of encryption unit: Generate a chaotic initial key based on the data block identifier, generate a key sequence through Logistic mapping iteration, and perform bit-level XOR encryption on the data block. Assume the data block identifier is , convert it to a numerical value through the hash function as the initial value of the Logistic mapping, that is . Then generate a key sequence through Logistic mapping iteration, perform bit-level XOR encryption on the data block , and the encrypted data block is: .
[0103] The second layer of encryption unit: Construct a permutation matrix based on the logical position coordinates, and perform byte position permutation on the encrypted data block through matrix transformation. Assume the logical position coordinates are , construct a permutation matrix according to certain rules, for example, determine the row and column transformation rules of the matrix according to the coordinate values. Perform byte position permutation on the encrypted data block , and the permuted data block is: 。
[0104] The third - layer encryption unit: generates substitution rules based on the correlation graph between data blocks, and performs byte substitution on the permuted data blocks through a non - linear S - box. According to the correlation graph between data blocks, determine the substitution rule for each byte, and substitute each byte in the permuted data block through the non - linear S - box according to the substitution rule to obtain the finally encrypted data block 。
[0105] ⑤ Dynamic access control and encryption cooperation mechanism: Introduce the cooperation mechanism of dynamic access control and fragmented encryption. Generate data block access policies through attribute - based encryption. Bind the access policies to the logical topology constraints of the data blocks, and dynamically activate the decryption levels based on the attribute matching degree. When the access permission meets the first - layer attributes, only decrypt the first - layer encryption unit, and unlock layer by layer until the full access permission is met. Assume that the access attribute of the user is , and the access policy attribute of the data block is , calculate the attribute matching degree . When ( is the attribute matching degree threshold for the first - layer decryption), unlock the first - layer encryption unit; when ( is the attribute matching degree threshold for the second - layer decryption, and ), unlock the second - layer encryption unit, and so on, until the full access permission is met, unlock all encryption layers, and obtain the original data.
[0106] Example 3:
[0107] This example details the network boundary access control process of the boundary protection layer. Through the combination of multiple technologies and strategies, it effectively prevents illegal network access, ensures the security of the network boundary of the energy operation platform, and prevents external malicious attacks and illegal data transmission.
[0108] ① Network connection status description: Use state - detection technology to describe the network connection status, represent the network connection status as a function of connection parameters. The connection parameters include source IP address, destination IP address, port number, protocol type, and connection time, and their value ranges are determined according to network protocols and security policies. For example, according to the TCP / IP protocol, the value ranges of the source IP address and the destination IP address are legal IP address segments; the value range of the port number has specific regulations according to different application protocols. For example, the default port number of the HTTP protocol is 80, and the default port number of the HTTPS protocol is 443, etc. The network connection status can be expressed as: . Among them, represents the network connection status, represents the source IP address, Represents the destination IP address, represents the port number, represents the protocol type, represents the connection time.
[0109] ② Describe the network connection status based on a directed acyclic graph: Describe the network connection status based on a directed acyclic graph, and represent the flow direction and dependency relationship of the network connection through the relationship between nodes and edges. The nodes of the directed acyclic graph are obtained by extracting the characteristics of the connection parameters. For example, the network segment information of the source IP address, the service type information of the destination IP address, etc. can be extracted as node characteristics; the edges are determined by the conversion rules of the connection status, such as the conversion conditions from one network connection status to another. Assume that node represents the connection status of a specific source IP address network segment and port number, and node represents another related connection status. When a certain conversion condition is met (such as successfully establishing a TCP connection), there is an edge from to exists.
[0110] ③ Construct network access control constraints: Construct network access control constraints, including source address constraints, destination address constraints, port constraints, protocol constraints, and time constraints.
[0111] Source address constraint: Used to limit the range of source IP addresses allowed to access. For example, allowing IP addresses from a specific network segment within the company to access the energy operation platform can be expressed as: . Among them, and are the start and end addresses of the allowed source IP address range.
[0112] Destination address constraint: Used to limit the range of destination IP addresses allowed to be accessed. For example, only allowing IP addresses that access specific services within the platform can be expressed as: . Among them, and are the start and end addresses of the allowed destination IP address range.
[0113] Port constraint: Used to limit the range of port numbers allowed to be used. For example, only allowing specific port numbers to be used for data transmission can be expressed as: . Among them, and are the start and end port numbers of the allowed port number range.
[0114] Protocol constraint: Used to limit the types of network protocols allowed to pass through. For example, only allowing TCP and UDP protocols to pass through can be expressed as: .
[0115] Time constraint: Used to limit the time period during which access is permitted. For example, access is only allowed during specific time periods on weekdays, which can be expressed as: . Among them, and are the start and end times for permitted access.
[0116] ④Construct the global access control policy function: Construct the global access control policy function, including access rule matching items, risk assessment items, and security policy priority items, and perform weighted combination on each item through weighting coefficients. Assume the access rule matching item is , the risk assessment item is , the security policy priority item is , and the weighting coefficients are , , respectively. Then the global access control policy function is . The access rule matching item is determined according to the matching degree between the network connection status and the access control constraint conditions; the risk assessment item is calculated according to the risk assessment parameters output by the risk assessment model; the security policy priority item is determined according to the pre-set security policy priority.
[0117] ⑤Discretization processing and policy optimization: Discretize the network connection status interval into multiple connection segments, perform discretization processing on the global access control policy function, and construct the global discretized policy function, including connection segment characteristics, matching rules, and policy execution results. For example, discretize the connection time at a certain time interval, discretize the port number range at a certain step size, etc. Use a rule-based decision-making method to iteratively optimize the global discretized policy function, determine whether to allow access by matching the access rule with the connection status, based on the risk assessment result and the security policy priority, and update the access control list based on the decision result. Assume that at a certain moment, the network connection status is , by matching with the access control constraint conditions, calculate the value of the access rule matching item ; at the same time, obtain the value of the risk assessment item of the current connection according to the risk assessment model, combine it with the pre-set security policy priority item , and substitute it into the global access control policy function to calculate the result. If the value of meets the threshold condition for allowing access, then allow the connection to pass, otherwise reject it, and record this decision result in the access control list, update the content of the access control list for subsequent connection judgment.
[0118] ⑥ Policy Consistency Check and Conflict Resolution: Perform consistency check and conflict resolution on the optimized network access control policy. During the consistency check, traverse the access control list to check for contradictions between different rules. For example, for the same source IP address and destination IP address, within the same time range, one rule allows access to a specific port while another rule prohibits access to that port, which results in a conflict. By analyzing the logical relationships between the rules, preferentially retain the rules with higher security policy priorities, and delete or modify the conflicting rules to maintain the consistency and coherence of the policy, generating an effective network access control policy. Based on this effective network access control policy, control the access to the network boundary. When there is a new network connection request, make a judgment according to the policy to decide whether to allow the connection to enter the energy operation platform network.
[0119] Embodiment 4:
[0120] This embodiment mainly elaborates on the specific implementation method of the intrusion detection layer for real-time monitoring of data access behavior based on the abnormal behavior analysis algorithm. By promptly detecting abnormal data access behavior, it can effectively prevent internal and external illegal data access and ensure the security and integrity of the energy operation platform data.
[0121] Construct a local monitoring window: Construct a local monitoring window based on the time series, operation type, and access path of the data access behavior. For example, take the data access behavior within a certain period of time (such as 5 minutes) as a time series range, the operation types include read, write, delete, etc., and the access path is the system path through which the data is accessed. Adaptively adjust the size of the local monitoring window through the behavior complexity coefficient, and the behavior complexity coefficient can be determined according to factors such as the diversity of operation types and the complexity of the access path. Assume the behavior complexity coefficient is , and the initial size of the local monitoring window is , then the adjusted size of the local monitoring window , establish a positive correlation between the size of the local monitoring window and the complexity of the data access behavior, that is, the more complex the behavior, the larger the monitoring window size, in order to capture abnormal behavior more comprehensively.
[0122] Construct a behavior model: Use multi-source log data to construct a behavior model. The sources of multi-source log data include system logs, application logs, security logs, etc. Preprocess the log data, such as data cleaning to remove duplicate, incorrect, or irrelevant data records; data standardization to convert log data in different formats into a unified format for subsequent analysis. After preprocessing, obtain standardized behavior records, and update the probability distribution of the behavior pattern library based on these behavior records. Assume there are types of behavior patterns , and calculate the occurrence probability value of each behavior pattern according to the Bayesian inference method , the calculation formula is: , where represents the observed behavior record, is in the behavior pattern under which the observed behavior record appears, is the prior probability of the behavior pattern . By continuously updating the probability distribution of the behavior pattern library, the behavior model can more accurately reflect the normal data access behavior pattern.
[0123] Use the Hidden Markov Model for modeling: Use the Hidden Markov Model to model dynamic abnormal behaviors. The Hidden Markov Model includes a state set, an observation set, a state transition probability matrix, and an observation probability matrix. Consider different states of data access behavior (such as login state, data reading state, data writing state, etc.) as the state set of the Hidden Markov Model; consider the actual observed data access behaviors (such as specific operation types, access times, etc.) as the observation set. Predict the next state of the behavior through the state transition probability. Assume the state transition probability matrix is , where represents the probability of transitioning from state to state . Update the predicted state based on the observed data, using algorithms such as the forward-backward algorithm or the Viterbi algorithm, to obtain the potential patterns and development trends of abnormal behaviors. For example, by analyzing the state transition situation of data access behaviors over a period of time, if it is found that there is a frequent transition from a normal login state to an abnormal data deletion state, and this transition does not conform to the normal behavior pattern probability distribution, then a potential pattern of an abnormal behavior may be detected.
[0124] Build an intrusion detection model: Build an intrusion detection model, using the feature vector of data access behavior as the state variable. The state variable includes access time, access subject, access object, and operation type. Build state constraint conditions and behavior trend constraint conditions. The state constraint conditions are used to limit the value range of the state variable. For example, the access time should be within the normal time period of the system operation, and the access subject must be a registered legitimate user, etc.
[0125] Assume the normal range of the access time is , then the state constraint condition can be expressed as access time ; The behavior trend constraint conditions are used to determine the change trend of the behavior pattern. For example, within a period of time, the frequency of data reading operations should be maintained within a certain reasonable range. If the frequency of data reading operations suddenly increases significantly and exceeds the normal change trend range, an intrusion detection alarm may be triggered.
[0126] Constructing a multi-objective detection cost function: Construct a multi-objective detection cost function, including a normal behavior matching term, an abnormal behavior recognition term, a false alarm penalty term, and a missed detection penalty term, and perform weighted combination on each term through weighted coefficients. Assume that the normal behavior matching term is , the abnormal behavior recognition term is , the false alarm penalty term is , the missed detection penalty term is , and the weighted coefficients are , , , respectively. Then the multi-objective detection cost function is: . The normal behavior matching term is used to measure the matching degree between the detection result and the normal behavior pattern; the abnormal behavior recognition term is used to measure the accurate recognition degree of abnormal behaviors; the false alarm penalty term is used to punish the situation of misjudging normal behaviors as abnormal behaviors; the missed detection penalty term is used to punish the situation of misjudging abnormal behaviors as normal behaviors.
[0127] Optimizing and solving the multi-objective detection cost function: Use the particle swarm optimization algorithm to optimize and solve the multi-objective detection cost function. In the particle swarm optimization algorithm, each particle represents a possible solution, that is, a combination of a set of behavior features. Calculate the gradient of the cost function with respect to the behavior features, and find the optimal solution by updating the position and adjusting the velocity of the particles. The position update formula of the particles is: , and the velocity update formula is: , where is the position of particle at moment, is the velocity of particle at moment, is the inertia weight, and are learning factors, and are random numbers between , is the best position experienced by particle itself, is the best position experienced by the entire particle swarm. Evaluate the quality of the particles through the fitness function, and the fitness function can use the multi-objective detection cost function , and the smaller the value, the better the particle. Determine the optimal parameter combination through backtracking search. When the best position of the particle swarm no longer changes or changes very little within a certain number of iterations, it is considered that the optimal solution has been found, that is, the optimal combination of behavior features is obtained, which is used to accurately detect abnormal situations in data access behaviors.
[0128] Example 5:
[0129] This embodiment details the specific process of the data recovery layer to achieve reliable data recovery based on redundant backup and fast recovery mechanisms. When data is lost, damaged, etc., it can ensure that the data of the energy operation platform is quickly and accurately recovered, guaranteeing the normal operation of the platform and the availability of data.
[0130] Establish a data redundant backup model: Establish a data redundant backup model, including full backup, incremental backup, and differential backup strategies. Full backup regularly makes a complete backup of all data. For example, at the early morning of every Sunday, a full backup of all data on the energy operation platform is made, and the backup frequency can be adjusted according to the importance and change frequency of the data. Incremental backup only backs up the data that has changed since the last backup. Assuming the last backup was on Monday, when making an incremental backup on Tuesday, only the data that has changed from Monday to Tuesday is backed up. Differential backup only backs up the data that has changed since the last full backup. If the last full backup was on Sunday, when making a differential backup on Wednesday, the data that has changed from Sunday to Wednesday is backed up. By comprehensively applying these three backup strategies, while ensuring data security, the amount of backup data and backup time can be reasonably controlled.
[0131] Construct a storage structure expression: Construct the data redundant backup model into a storage structure expression. The storage vector of the storage structure expression includes backup data, backup time, backup type, and storage location. Assume the storage vector is expressed as , where represents the backup data, represents the backup time, represents the backup type (full backup, incremental backup, or differential backup), represents the storage location. The recovery vector includes a recovery time target, a recovery point target, and data consistency requirements. Assume the recovery vector is expressed as , where represents the recovery time target, that is, the time when it is expected to complete data recovery; represents the recovery point target, that is, the time point corresponding to the data state that needs to be recovered to; represents the data consistency requirements, ensuring that the recovered data meets the business logic and data integrity requirements.
[0132] Optimize the storage structure expression: Optimize the storage structure expression, and calculate the trade-off relationship among the backup data volume, storage cost, and recovery time. The backup data volume is related to the backup strategy. The full backup has the largest data volume, while the incremental backup and differential backup have relatively smaller data volumes. The storage cost includes the acquisition cost and maintenance cost of storage devices, etc., and is related to the amount of data stored and the storage time. The recovery time depends on the quantity of backup data, storage location, and the complexity of the recovery operation. Construct an optimized backup storage strategy. For example, by analyzing the historical data changes and recovery requirements, determine a reasonable backup frequency and combination of backup types, and minimize the storage cost and recovery time on the premise of meeting the data recovery requirements. Assume that the backup data volumes under different backup strategies are obtained through calculation , storage cost , recovery time , a multi-objective optimization algorithm (such as a genetic algorithm) can be used to find the optimal backup strategy to optimize the comprehensive indicators of backup data volume, storage cost, and recovery time.
[0133] Construct a data recovery prediction cost function: Construct a data recovery prediction cost function, including a recovery time term, a data loss term, and a recovery cost term, and perform weighted combination on each cost term through a weight matrix. Assume that the recovery time term is , the data loss term is , the recovery cost term is , and the weight matrix is , then the data recovery prediction cost function is: . The recovery time term is calculated based on the expected time required for the recovery operation. For example, the recovery time is estimated according to the backup data volume and network bandwidth; the data loss term is evaluated based on the value of the data loss. If the lost data has a significant impact on the business, the value of the data loss term is large; the recovery cost term includes the usage cost of storage devices, network transmission cost, etc.
[0134] Construct recovery constraints: Construct recovery constraints, including storage medium availability constraints, network bandwidth constraints, and data consistency constraints. The storage medium availability constraint ensures that the storage media used for data recovery (such as disk arrays, tape libraries, etc.) are in a normal available state. For example, the remaining space of the storage medium should be sufficient to accommodate the data to be recovered. The network bandwidth constraint limits the data transmission speed during the data recovery process. Assume that the network bandwidth is , the amount of data to be transmitted for data recovery is , then the theoretically minimum recovery time is . Data consistency constraints ensure that the restored data is logically consistent and meets business rules and data integrity requirements. At the same time, recovery operation constraint conditions are constructed, including backup data integrity checks, recovery process sequences, and data verification mechanisms. Backup data integrity checks verify whether the backup data is complete and unmodified through methods such as checksums and hash values; the recovery process sequence is reasonably arranged according to the backup time sequence and backup type. For example, first restore the most recent full backup, and then sequentially restore subsequent incremental backups or differential backups; the data verification mechanism performs quality checks on the restored data after data recovery to ensure the accuracy and availability of the data.
[0135] Solve the linear programming problem: Transform the data recovery prediction cost function into the standard form of a linear programming problem, calculate the linear coefficients and constant terms, and construct the inequality constraint matrix and the equality constraint matrix. Assume that the terms in the data recovery prediction cost function are in a linear relationship and transform it into the standard form , where is the objective function value, is the linear coefficient vector, is the decision variable vector. Construct the inequality constraint matrix and the equality constraint matrix , as well as the corresponding constraint vectors and . Use the simplex method to solve this linear programming problem. The simplex method iteratively changes from one basic feasible solution to another better basic feasible solution until the optimal solution is found. Obtain the optimal recovery strategy by solving the basic feasible solution, and determine the final recovery plan based on the feasibility and optimality of the recovery strategy. For example, under the constraints of storage medium availability, network bandwidth, etc., select the recovery strategy that minimizes the data recovery prediction cost function, including selecting appropriate backup data for recovery and determining the recovery order. After determining the recovery plan, perform the recovery operation on the backup data, and perform consistency checks and verification on the restored data to ensure that the restored data is accurate and meets the business requirements of the energy operation platform.
[0136] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "including", "comprising" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.
[0137] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. Data security protection system for energy operation platform, characterized by: The system comprises: The data collection module is used to collect various types of data from multiple data sources of the energy operation platform, including energy production equipment sensors, user energy consumption recording terminals, and power grid operation monitoring systems; extract features from the collected data based on a multimodal feature extraction method to obtain a data feature set; input the data feature set into a pre-trained risk assessment model, which uses a deep convolutional neural network structure to assess the security risks faced by the data based on a risk assessment function and generate risk assessment parameters; A data processing module is used to construct a data security processing model according to the risk assessment parameters, wherein the data security processing model takes data confidentiality, integrity and availability as protection targets, and adopts a method combining fragmented encryption with dynamic access control to process data securely, wherein the fragmented encryption introduces a dynamic block strategy and a layered encryption mechanism based on chaotic mapping, divides the data into a plurality of logically associated encryption units, and each encryption unit independently generates a chaotic key and performs a multi-dimensional encryption transformation; and outputs securely processed data based on the data security processing model; A security protection module is used to establish a multi-level security protection system based on the data after security processing, wherein the multi-level security protection system includes a boundary protection layer, an intrusion detection layer and a data recovery layer, wherein the boundary protection layer performs network boundary access control based on the risk assessment parameters, the intrusion detection layer performs real-time monitoring of data access behavior based on an abnormal behavior analysis algorithm, and the data recovery layer realizes reliable data recovery based on a redundant backup and rapid recovery mechanism; the security of energy operation platform data is ensured through the multi-level security protection system; The original data is segmented by a dynamic block strategy driven by chaotic mapping. Each data block generates a unique identifier and is associated with a logical position coordinate. The block parameters are generated based on the iterative equation of chaotic mapping. Construct a layered encryption mechanism, the layered encryption mechanism comprising: The first layer encryption unit: generates a chaotic initial key based on the data block identifier, generates a key sequence through Logistic mapping iteration, and performs bit-level XOR encryption on the data block; The second-layer encryption unit: constructs a permutation matrix based on the logical position coordinates, and permutes the byte positions of the encrypted data blocks through matrix transformation; The third-layer encryption unit: Generates substitution rules based on the association relationship graph between data blocks, and performs byte substitution on the replaced data blocks through nonlinear S-boxes.
2. The data security protection system for energy operation platform according to claim 1 is characterized in that: The data feature set is input into a pre-trained risk assessment model. The risk assessment model uses a deep convolutional neural network structure to assess the security risks faced by the data based on a risk assessment function. The generated risk assessment parameters include: Acquire the collected data, including energy production data, user energy consumption data, power grid operation status data, equipment failure information, and network traffic data; construct a feature space based on the data, and construct a feature vector based on the attributes, time series characteristics, and association relationships of the data; A multidimensional risk assessment function is constructed based on the feature space and the feature vector, wherein the multidimensional risk assessment function includes a data leakage risk item, a data tampering risk item, a system failure risk item, and a network attack risk item, wherein the data leakage risk item is calculated by abnormal changes in data access rights, the data tampering risk item is calculated by comparing changes in data hash values with historical records, the system failure risk item is calculated by a comprehensive assessment of equipment failure frequency and impact range, and the network attack risk item is calculated by matching abnormal patterns of network traffic with known attack features; Constructing a deep convolutional neural network structure, the deep convolutional neural network structure includes an input layer, multiple convolutional layers, a pooling layer and a fully connected layer, the dimension of the input layer is the same as the dimension of the feature space, the convolutional layer uses convolution kernels of different sizes to extract data features, the pooling layer is used to reduce the data dimension, and the fully connected layer is used to integrate the extracted features; constructing a loss function based on the deep convolutional neural network structure, the loss function includes a mean square error term between the predicted risk and the actual risk; The deep convolutional neural network is trained by a stochastic gradient descent method, the training sample set is expanded by a data enhancement technique, random sampling is performed from the expanded training sample set for network training, wherein the network updates parameters in each round of training; risk assessment parameters are output based on the trained deep convolutional neural network, and the risk assessment parameters include a network weight matrix, a network bias vector, a feature normalization parameter, and a risk level classification parameter.
3. The data security protection system for energy operation platform according to claim 2 is characterized in that: A data security processing model is constructed according to the risk assessment parameters. The data security processing model takes data confidentiality, integrity and availability as protection targets, and uses a method combining fragmented encryption and dynamic access control to process data securely. The securely processed data output based on the data security processing model includes: Constructing a multi-objective function for data security processing, the multi-objective function includes a confidentiality enhancement objective function, an integrity assurance objective function, and an availability maintenance objective function, wherein the confidentiality enhancement objective function is obtained by calculating the key dynamics of fragmented encryption and the depth of layered encryption, the integrity assurance objective function is obtained by calculating the data block hash chain verification and the topological constraints of the logical association graph, and the availability maintenance objective function is obtained by calculating the data block redundancy distribution and the recovery path optimization; Constructing data partitioning constraints based on the multi-objective function, wherein the data partitioning constraints include semantic relevance constraints, dynamic partitioning threshold constraints, and logical topology constraints, wherein the semantic relevance constraints are used to ensure that the segmented data blocks have resolvable semantic boundaries, the dynamic partitioning threshold constraints dynamically adjust the block size according to data sensitivity, and the logical topology constraints limit the dependencies between data blocks through a directed acyclic graph; A collaborative mechanism of dynamic access control and fragmented encryption is introduced. The data block access policy is generated through attribute-based encryption. The access policy is bound to the logical topology constraints of the data block. The decryption hierarchy is dynamically activated based on the attribute matching degree. When the access permission meets the first-layer attributes, only the first-layer encryption unit is decrypted, and the encryption is unlocked layer by layer until the full access permission is met.
4. The data security protection system for energy operation platform according to claim 1 is characterized in that: The border protection layer performs network border access control based on the risk assessment parameters, including: The network connection status is described by using state detection technology, and the network connection status is expressed as a function of connection parameters. The value range of the connection parameters is determined according to the network protocol and security policy. The network connection status includes the source IP address, the destination IP address, the port number, the protocol type and the connection time. The network connection state is described based on a directed acyclic graph, and the flow direction and dependency of the network connection are represented by the relationship between nodes and edges. The nodes of the directed acyclic graph are obtained by feature extraction of connection parameters, and the edges are determined by the conversion rules of the connection state. Constructing network access control constraints, which include source address constraints, destination address constraints, port constraints, protocol constraints, and time constraints. The source address constraints are used to limit the range of source IP addresses allowed to be accessed, the destination address constraints are used to limit the range of destination IP addresses allowed to be accessed, the port constraints are used to limit the range of port numbers allowed to be used, the protocol constraints are used to limit the types of network protocols allowed to pass, and the time constraints are used to limit the time period allowed to access. Constructing a global access control policy function, the global access control policy function including an access rule matching item, a risk assessment item, and a security policy priority item, and weighting and combining each item in the global access control policy function by a weighted coefficient; Discretize the network connection state interval into multiple connection segments, discretize the global access control policy function, and construct a global discretized policy function, wherein the global discretized policy function includes connection segment features, matching rules, and policy execution results; Iteratively optimize the global discretized policy function using a rule-based decision method, determine whether to allow access based on risk assessment results and security policy priorities by matching access rules with connection status, and update the access control list based on the decision results; The optimized network access control policy is subjected to consistency check and conflict resolution, and an effective network access control policy is generated by maintaining the consistency and coherence of the policy, and access to the network boundary is controlled based on the effective network access control policy.
5. The data security protection system for energy operation platform according to claim 1 is characterized in that: The intrusion detection layer monitors data access behaviors in real time based on abnormal behavior analysis algorithms, including: A local monitoring window is constructed based on the time series, operation type and access path of the data access behavior, and the size of the local monitoring window is adaptively adjusted through the behavior complexity coefficient, so as to establish a positive correlation between the size of the local monitoring window and the complexity of the data access behavior; A behavior model is constructed using multi-source log data, the log data is preprocessed to obtain standardized behavior records, the probability distribution of the behavior pattern library is updated based on the behavior records, and the occurrence probability value of each behavior pattern is calculated using the Bayesian reasoning method; The hidden Markov model is used to model dynamic abnormal behaviors, and the next state of the behavior is predicted by the state transition probability. The predicted state is updated based on the observed data to obtain the potential pattern and development trend of the abnormal behavior. Construct an intrusion detection model, use the characteristic vector of data access behavior as a state variable, the state variable includes access time, access subject, access object and operation type, construct state constraints and behavior trend constraints, the state constraints are used to limit the value range of the state variables, and the behavior trend constraints are used to limit the change trend of the behavior pattern; Constructing a multi-target detection cost function, the multi-target detection cost function includes a normal behavior matching item, an abnormal behavior identification item, a false positive penalty item, and a false negative penalty item, and weighting and combining each item in the multi-target detection cost function by a weighting coefficient; The particle swarm optimization algorithm is used to optimize and solve the multi-target detection cost function, calculate the gradient of the cost function with respect to the behavior characteristics, find the optimal solution by updating the position and adjusting the speed of the particles, evaluate the quality of the particles by the fitness function, and determine the optimal parameter combination by backtracking search.
6. The data security protection system for energy operation platform according to claim 1 is characterized in that: The data recovery layer implements reliable data recovery based on redundant backup and fast recovery mechanisms, including: Establish a data redundancy backup model, which includes full backup, incremental backup and differential backup strategies. The full backup regularly backs up all data in full, the incremental backup only backs up data that has changed since the last backup, and the differential backup only backs up data that has changed since the last full backup; The data redundancy backup model is constructed as a storage structure expression, wherein the storage vector of the storage structure expression includes backup data, backup time, backup type and storage location, and the recovery vector of the storage structure expression includes recovery time objective, recovery point objective and data consistency requirement; Optimizing the storage structure expression, calculating the trade-off between the backup data volume, storage cost, and recovery time, and constructing an optimized backup storage strategy; Constructing a data recovery prediction cost function, wherein the prediction cost function includes a recovery time term, a data loss term, and a recovery cost term, and weighting and combining each cost term through a weight matrix; Constructing recovery constraints, including storage medium availability constraints, network bandwidth constraints, and data consistency constraints, and constructing recovery operation constraints, including backup data integrity check, recovery process sequence, and data verification mechanism; Converting the prediction cost function into a standard form of a linear programming problem, calculating linear coefficients and constant terms, and constructing an inequality constraint matrix and an equality constraint matrix; The linear programming problem is solved by the simplex method. The optimal recovery strategy is obtained by solving the basic feasible solution. The final recovery plan is determined based on the feasibility and optimality of the recovery strategy. The backup data is restored, and the restored data is checked and verified for consistency.
7. A fragmented encryption method for an energy operation platform, applied to the data security protection system of claim 1, characterized in that: include: Dividing the data to be encrypted into a plurality of data blocks, each data block having a unique identifier; Generate an initial key fragment based on the content and position information of the data block, wherein the initial key fragment is calculated by combining a hash value of the data block and a position index; The chaotic mapping algorithm is used to perform chaotic encryption on the initial key fragment, wherein the chaotic mapping algorithm performs nonlinear transformation on the key fragment through an iterative function to generate a chaotically encrypted key fragment; Constructing an association relationship graph between data blocks, wherein the association relationship graph uses data blocks as nodes and semantic associations or logical dependencies between data blocks as edges; Based on the association relationship graph, the chaotically encrypted key fragments are diffused, and the diffused key fragments are generated by propagating and mixing the key fragments in the association relationship graph; The data blocks are classified according to their importance and access frequency. The classification method determines the categories of the data blocks by defining importance indexes and access frequency thresholds. Different encryption transformations are used to re-encrypt the diffused key fragments for different categories of data blocks. The key fragment after the secondary encryption is merged with the corresponding data block, and the fusion method is realized by XOR operation or other bit operations; fragmented encrypted data is generated based on the merged data block, and the fragmented encrypted data is output.
8. The fragmentation encryption method according to claim 7, characterized in that: Using the chaotic mapping algorithm to perform chaotic encryption on the initial key fragment includes: The initial key fragment is used as the input of the chaotic mapping function, and the chaotic mapping function is iteratively calculated to obtain a chaotic sequence; the chaotic sequence is quantized, and the continuous value of the chaotic sequence is mapped to a discrete key fragment space to generate a chaotically encrypted key fragment.
9. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to perform the operation of the system described in any one of claims 1 to 6.
10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the functions of the system according to any one of claims 1 to 6 are realized.
Citation Information
Patent Citations
Power plant data safe and credible transmission method for enhancing digital watermarking technology
CN113190866A
Electric power Internet of Things industrial control equipment safety assessment method based on multi-modal large model
CN119168364A