Cloud power data security protection method and system

By implementing encryption processing, identity verification, data integrity check, abnormal detection and risk assessment on power data in the cloud, the problem of insufficient security during transmission is solved, and the efficient and secure transmission and storage of data is achieved.

CN119939617APending Publication Date: 2025-05-06YUNNAN POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411743223.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Power data is easily lost or affected by viruses during transmission, resulting in data leakage and security issues.

Method used

The cloud power data security protection method is adopted to ensure the security of data during transmission and storage by encrypting power data, identity verification and permission settings, data integrity checking, abnormal detection and early warning, and risk assessment and repair strategies.

Benefits of technology

It significantly improves the security of power data during transmission and storage, prevents data leakage and theft, ensures data integrity and reliability, reduces the probability of security threats, and improves the system's defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939617A_ABST
    Figure CN119939617A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud electric power data security protection method and system, and relates to the technical field of electric power data security, and the method comprises the steps: carrying out the encryption processing of electric power data, evaluating the security of a used encryption algorithm through the encryption strength measurement, and carrying out the identity verification and authority setting; performing integrity check on the encrypted power data, and verifying that the data is not tampered in a transmission or storage process by using a data integrity measurement technology; analyzing behaviors and modes of the power data through an anomaly detection technology, identifying abnormal data activities and performing early warning; performing quantitative evaluation on abnormal data activity of the power data by adopting a risk evaluation model and formulating corresponding repair measures in combination with encryption strength, data integrity and an anomaly detection result; and effectiveness of the measures is verified through restoration measure effectiveness evaluation. According to the cloud power data security protection method provided by the invention, the security of the data in transmission and storage processes is remarkably improved, and data leakage and stealing are effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of power data security technology, and in particular to a cloud power data security protection method and system. Background Art

[0002] Electricity is an energy source that uses electrical energy as its motive force. The invention and application of electricity has set off the second wave of industrialization. Electricity is an electricity production and consumption system composed of power generation, transmission, transformation, distribution and consumption. It converts primary energy in nature into electricity through mechanical energy devices, and then supplies electricity to various users through transmission, transformation and distribution.

[0003] When power data is being transmitted, it may be lost due to network and transmission problems, and may also be affected by viruses. In this case, the transmitted and saved power data cannot be protected, which may cause the loss and leakage of power data.

[0004] Therefore, it is necessary to propose a cloud-based power data security protection method and system to solve the above problems. Summary of the invention

[0005] In view of the above-mentioned problems, the present invention is proposed.

[0006] Therefore, the technical problem solved by the present invention is: how to ensure the security of power data during transmission.

[0007] To solve the above technical problems, the present invention provides the following technical solutions: a cloud-based power data security protection method, comprising: encrypting the power data, evaluating the security of the encryption algorithm used through encryption strength measurement, and performing identity authentication and permission setting at the same time; performing integrity check on the encrypted power data, and using data integrity measurement technology to verify that the data has not been tampered with during transmission or storage; analyzing the behavior and pattern of the power data through anomaly detection technology, identifying abnormal data activities and issuing early warnings; combining encryption strength, data integrity and anomaly detection results, using a risk assessment model to quantitatively evaluate the abnormal data activities of the power data and formulate corresponding repair measures; after implementing the repair measures, verifying the effectiveness of these measures through repair measure performance evaluation.

[0008] As a preferred solution of the cloud power data security protection method described in the present invention, the encryption processing includes collecting information related to the operation of the power system as raw data X, calculating the encryption strength metric S by integration e (X, θ), the formula is:

[0009]

[0010] Among them, θ represents the security level of the encryption algorithm or the complexity of the environment.

[0011] As a preferred solution of the cloud power data security protection method of the present invention, the identity authentication and permission setting includes: when the administrator identity authentication fails three times, the system automatically triggers the security protocol, starts the alarm processing mechanism, and locks the administrator account for 30 minutes to prevent brute force cracking attempts;

[0012] After the administrator passes the identity authentication, the data permissions are set according to the confidentiality level of the power data. The permission levels are divided into level one high confidentiality, level two medium confidentiality and level three low confidentiality. The level one high confidentiality level permissions are for high-risk operations of modification and deletion, and multiple approval processes and post-audits are carried out; the level two medium confidentiality level permissions are for controlling the modification and deletion operations of the data and recording the operation logs; the level three low confidentiality level permissions are for basic access records and operation log records.

[0013] As a preferred solution of the cloud power data security protection method described in the present invention, the integrity check includes: e The result of (X,θ) and the rate of change or stability of parameter data σ, calculate the integrity metric I v (X,σ), the formula is:

[0014]

[0015] As a preferred solution of the cloud power data security protection method described in the present invention, the anomaly detection technology includes combining integrity measurement I v (X,σ) and anomaly threshold λ, a composite function is introduced to define the anomaly detection index, and the formula is expressed as:

[0016]

[0017] Among them, the second-order derivative Indicates the rate of change of integrity measurement during data changes.

[0018] As a preferred solution of the cloud power data security protection method described in the present invention, the early warning includes: when receiving power data, when the abnormal detection index exceeds the set threshold or the packet loss rate exceeds 5%, it is determined that the network status is abnormal and an alarm is triggered;

[0019] When an alarm is triggered due to a network anomaly, the emergency processing unit is immediately activated to perform emergency backup of power data to a preset safe area and suspend all non-emergency operations until the network status returns to normal;

[0020] The backup stores the data in different security areas according to the confidentiality level of the power data. The data of the first-level high confidentiality level is stored in the high-level encryption area, the data of the second-level medium confidentiality level is stored in the low-level encryption area, and the data of the third-level low confidentiality level is stored in the general area.

[0021] When the network status returns to normal, all access and operation behaviors are recorded, and any unauthorized access attempts will trigger a security alarm and be recorded.

[0022] As a preferred solution of the cloud power data security protection method described in the present invention, the risk sensitivity φ is introduced, and the risk assessment model is expressed as:

[0023] R m (X,φ,λ,σ)=ln(1+φ·D a (X,λ,σ)

[0024] The higher the value output by the risk assessment model, the greater the risk faced. The values ​​output by the risk assessment model are sorted from high to low and divided into levels, and the critical value R1 of medium-high risk and the critical value R2 of medium-low risk are set. When R m >R1 is a high risk level, at this time, urgent patching of vulnerabilities, strengthening monitoring and alarms, and temporarily restricting access to sensitive data; when R2<R m When the risk level is less than R1, it is a medium risk level. At this time, improve security strategies and update security software. m When the risk level is lower than R2, the risk development should be monitored and important data should be backed up.

[0025] Another object of the present invention is to provide a cloud-based power data security protection system, which can solve the problem of ensuring security and confidentiality of data transmission in existing distribution network operations by building a remote security communication system for distribution network operations, and the problem that using a third-party platform is not conducive to data confidentiality.

[0026] To solve the above technical problems, the present invention provides the following technical solutions: a cloud-based power data security protection system, comprising: a data encryption module, an identity authentication and authority management module, a data integrity check module, an anomaly detection and early warning module, a risk assessment and repair strategy module, and a repair measure effectiveness evaluation; the data encryption module encrypts the original power data to ensure the security of the data during transmission and storage; the identity authentication and authority management module is used for setting user identity authentication and data access rights; the data integrity check module is used to perform integrity checks on the encrypted power data; the anomaly detection and early warning module is used to analyze the behavior and pattern of power data, identify and warn of abnormal data activities; the risk assessment and repair strategy module, combined with encryption strength, data integrity and anomaly detection results, uses a risk assessment model to quantitatively assess the security risks of power data, and formulate corresponding repair measures; the repair measure effectiveness evaluation module is used to verify the effectiveness of these measures after the implementation of the repair measures.

[0027] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above-mentioned cloud power data security protection method when executing the computer program.

[0028] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the cloud-based power data security protection method as described above.

[0029] Beneficial effects of the present invention: The cloud-based power data security protection method provided by the present invention significantly improves the security of data during transmission and storage by implementing end-to-end encryption processing on power data, effectively preventing data leakage and theft. The data integrity check ensures that the data has not been tampered with throughout the entire life cycle, maintaining the authenticity and reliability of the data. Using advanced anomaly detection technology, the system can identify and warn of abnormal data activities in real time, detect potential security threats in advance, and reduce the probability of security accidents. The risk assessment model provides a method for the system to quantify risks, so that security measures can be adjusted according to the actual risk level, enhancing the system's defense capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0031] Figure 1An overall flow chart of a cloud-based power data security protection method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0032] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0033] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0034] Example 1

[0035] Reference Figure 1 , is an embodiment of the present invention, and provides a cloud power data security protection method, comprising:

[0036] S1: Encrypt the power data, evaluate the security of the encryption algorithm used through encryption strength measurement, and perform identity authentication and permission setting;

[0037] Furthermore, the information related to the operation of the power system is collected as the original data X, and the encryption strength metric S is calculated by integration. e (X,θ), the formula is:

[0038]

[0039] Among them, θ represents the security level of the encryption algorithm or the complexity of the environment.

[0040] When the administrator's identity authentication fails three times, the system automatically triggers the security protocol, starts the alarm processing mechanism, and locks the administrator's account for 30 minutes to prevent brute force cracking attempts;

[0041] After the administrator passes the identity authentication, the data permissions are set according to the confidentiality level of the power data. The permission levels are divided into level one high confidentiality, level two medium confidentiality and level three low confidentiality. Level one high confidentiality permissions are for high-risk operations such as modification and deletion, and multiple approval processes and post-audits are carried out; level two medium confidentiality permissions are for controlling the modification and deletion of data and recording operation logs; level three low confidentiality permissions are for basic access records and operation log records.

[0042] S2: Perform integrity check on the encrypted power data and use data integrity measurement technology to verify that the data has not been tampered with during transmission or storage;

[0043] Furthermore, based on S e The result of (X,θ) and the rate of change or stability of parameter data σ, calculate the integrity metric I v (X,σ), the formula is:

[0044]

[0045] It should be noted that if the strength score of the encryption algorithm is lower than the preset threshold (such as the scoring standard for 256-bit AES encryption), the system automatically upgrades to the next level of encryption algorithm to ensure the security of data transmission and storage.

[0046] S3: Analyze the behavior and patterns of power data through anomaly detection technology, identify abnormal data activities and issue early warnings;

[0047] Furthermore, combined with the integrity metric I v (X,σ) and anomaly threshold λ, a composite function is introduced to define the anomaly detection index, and the formula is expressed as:

[0048]

[0049] Among them, the second-order derivative Indicates the rate of change of integrity measurement during data changes.

[0050] It should be noted that when receiving power data, if the abnormal detection index exceeds the set threshold or the packet loss rate exceeds 5%, the network status is determined to be abnormal and an alarm is triggered;

[0051] When an alarm is triggered due to a network anomaly, the emergency processing unit is immediately activated to perform emergency backup of power data to a preset safe area and suspend all non-emergency operations until the network status returns to normal;

[0052] The backup stores the data in different security areas according to the confidentiality level of the power data. The data with a high confidentiality level is stored in the high-level encryption area, the data with a medium confidentiality level is stored in the low-level encryption area, and the data with a low confidentiality level is stored in the common area.

[0053] When the network status returns to normal, all access and operation behaviors are recorded, and any unauthorized access attempts will trigger a security alarm and be recorded.

[0054] S4: Combining encryption strength, data integrity and anomaly detection results, a risk assessment model is used to quantitatively assess abnormal data activities of power data and formulate corresponding remediation measures;

[0055] It should be noted that, by introducing risk sensitivity φ, the risk assessment model is expressed as:

[0056] R m (X,φ,λ,σ)=ln(1+φ·D a (X,λ,σ)

[0057] The higher the value output by the risk assessment model, the greater the risk faced. The values ​​output by the risk assessment model are sorted from high to low and divided into levels. The critical value R1 for medium-high risk and the critical value R2 for medium-low risk are set. When R m >R1 is a high risk level, at this time, urgent patching of vulnerabilities, strengthening monitoring and alarms, and temporarily restricting access to sensitive data; when R2<R m When the risk level is less than R1, it is a medium risk level. At this time, improve security strategies and update security software. m When the risk level is lower than R2, the risk development should be monitored and important data should be backed up.

[0058] S5: After implementing the remediation measures, verify the effectiveness of these measures through remediation measure effectiveness evaluation.

[0059] Furthermore, by combining all parameters and previous results, a new parameter ψ (representing the effectiveness of the repair measure) is introduced to evaluate the effect of the repair strategy.

[0060]

[0061] ψ is a value from 0 to 1, where 0 indicates no effect and 1 indicates that the risk is completely eliminated. When the value is close to 0, the repair measures are executed and the calculation and evaluation are iterated until the value is close to 1 and the iteration is stopped.

[0062] It should be noted that when the modification frequency of any power data file exceeds 10 times per hour, the system marks the file as "high risk" and sends an alert to the administrator, because frequent modifications may indicate unauthorized access or data tampering.

[0063] If the number of intrusion attempts detected by the network monitoring system exceeds 5 within 5 minutes, additional network security defense measures will be automatically initiated, such as adding firewall filtering rules to prevent DDoS attacks.

[0064] Based on the risk assessment model, when the security risk score of any power data reaches the preset high-risk threshold (for example, the score exceeds 80 / 100), the emergency repair process is immediately initiated, including data backup, access restriction adjustment and detailed security inspection.

[0065] When implementing the encryption upgrade (S1) and emergency repair process (S5), the system will evaluate the current system load and performance indicators. If the system load exceeds the safe operation threshold, the encryption upgrade will be delayed until the system load returns to the normal range to avoid affecting the user experience.

[0066] Example 2

[0067] As an embodiment of the present invention, a digital construction system for typical planning scenarios of county distribution networks is provided, including:

[0068] Data encryption module, identity authentication and permission management module, data integrity check module, anomaly detection and early warning module, risk assessment and repair strategy module, and repair measure effectiveness evaluation;

[0069] The data encryption module encrypts the original power data to ensure the security of the data during transmission and storage;

[0070] The authentication and permission management module is used for setting user authentication and data access permissions;

[0071] The data integrity check module is used to perform integrity check on the encrypted power data;

[0072] The anomaly detection and warning module is used to analyze the behavior and patterns of power data, identify and warn of abnormal data activities;

[0073] The risk assessment and repair strategy module combines encryption strength, data integrity and anomaly detection results, uses a risk assessment model to quantitatively assess the security risks of power data, and formulates corresponding repair measures;

[0074] The remediation measures effectiveness evaluation module is used to verify the effectiveness of remediation measures after they are implemented.

[0075] Example 3

[0076] An embodiment of the present invention is different from the first two embodiments in that:

[0077] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program code.

[0078] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, which can be embodied in any computer-readable medium for use by an instruction execution system, apparatus or device (such as a computer-based system, a system including a processor or other system that can fetch instructions from an instruction execution system, apparatus or device and execute instructions), or used in conjunction with these instruction execution systems, apparatuses or devices. For the purpose of this specification,

[0079] A "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device.

[0080] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0081] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0082] Example 4

[0083] As an embodiment of the present invention, a cloud-based power data security protection method is provided. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through data collection comparison before and after implementation.

[0084] The index comparison table before and after the implementation of the present invention is as follows:

[0085]

[0086]

[0087] From the above table, we can intuitively see that after the introduction of the power data security protection system, the system security and efficiency have been significantly improved, as well as the user satisfaction has been improved.

[0088] In summary, compared with the prior art, the method of the present invention effectively avoids data leakage by strengthening encryption measures and implementing dynamic access control, and strengthens identity authentication mechanism and abnormal behavior monitoring to significantly reduce unauthorized access attempts. Implementing data integrity checks ensures the accuracy and integrity of data. The introduction of real-time anomaly detection technology significantly shortens the response time of security incidents. The use of advanced risk assessment models improves the accuracy of risk assessment. Optimizing the repair process and implementing automated tools significantly shortens the repair time of security vulnerabilities. Optimizing the implementation of security measures reduces the impact on system performance. Improving data security and system performance enhances user trust and satisfaction with the system.

[0089] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A cloud power data security protection method, characterized in that: include: Encrypt power data, evaluate the security of the encryption algorithm used through encryption strength measurement, and perform identity authentication and permission setting; Perform integrity checks on encrypted power data and use data integrity measurement technology to verify that the data has not been tampered with during transmission or storage; Analyze the behavior and patterns of power data through anomaly detection technology, identify abnormal data activities and issue early warnings; Combining encryption strength, data integrity and anomaly detection results, a risk assessment model is used to quantitatively evaluate abnormal data activities of power data and formulate corresponding remediation measures; After implementing the remediation measures, the effectiveness of these measures is verified through remediation measure effectiveness evaluation.

2. The cloud power data security protection method according to claim 1, characterized in that: The encryption process includes collecting information related to the operation of the power system as raw data X, and calculating the encryption strength metric S by integration. e (X,θ), the formula is: Among them, θ represents the security level of the encryption algorithm or the complexity of the environment.

3. The cloud power data security protection method according to claim 2, characterized in that: The identity authentication and permission settings include: when the administrator's identity authentication fails three times, the system automatically triggers the security protocol, starts the alarm processing mechanism, and locks the administrator's account for 30 minutes to prevent brute force cracking attempts; After the administrator passes the identity authentication, the data permissions are set according to the confidentiality level of the power data. The permission levels are divided into level one high confidentiality, level two medium confidentiality and level three low confidentiality. The level one high confidentiality level permissions are for high-risk operations of modification and deletion, and multiple approval processes and post-audits are carried out; the level two medium confidentiality level permissions are for controlling the modification and deletion operations of the data and recording the operation logs; the level three low confidentiality level permissions are for basic access records and operation log records.

4. The cloud power data security protection method according to claim 3, characterized in that: The integrity check includes: e The result of (X,θ) and the rate of change or stability of parameter data σ, calculate the integrity metric I v (X,σ), the formula is:

5. The cloud power data security protection method according to claim 4, characterized in that: The anomaly detection technique includes combining integrity measurement I v (X,σ) and anomaly threshold λ, a composite function is introduced to define the anomaly detection index, and the formula is expressed as: Among them, the second-order derivative Indicates the rate of change of integrity measurement during data changes.

6. The cloud power data security protection method according to claim 5, characterized in that: The early warning includes, when receiving power data, when the abnormal detection index exceeds the set threshold or the packet loss rate exceeds 5%, it is determined that the network status is abnormal and an alarm is triggered; When an alarm is triggered due to a network anomaly, the emergency processing unit is immediately activated to perform emergency backup of power data to a preset safe area and suspend all non-emergency operations until the network status returns to normal; The backup stores the data in different security areas according to the confidentiality level of the power data. The data of the first-level high confidentiality level is stored in the high-level encryption area, the data of the second-level medium confidentiality level is stored in the low-level encryption area, and the data of the third-level low confidentiality level is stored in the general area. When the network status returns to normal, all access and operation behaviors are recorded, and any unauthorized access attempts will trigger a security alarm and be recorded.

7. The cloud power data security protection method according to claim 6, characterized in that: Introducing risk sensitivity φ, the risk assessment model is expressed as: R m (X,φ,λ,σ)=ln(1+φ·D a (X,λ,σ)) The higher the value output by the risk assessment model, the greater the risk faced. The values ​​output by the risk assessment model are sorted from high to low and divided into levels, and the critical value R1 of medium-high risk and the critical value R2 of medium-low risk are set. When R m >R1 is a high risk level, at this time, urgent patching of vulnerabilities, strengthening monitoring and alarms, and temporarily restricting access to sensitive data; when R2<R m When the risk level is less than R1, it is a medium risk level. At this time, improve security strategies and update security software. m When the risk level is lower than R2, the risk development should be monitored and important data should be backed up.

8. A system using the cloud power data security protection method according to any one of claims 1 to 7, characterized in that: include: Data encryption module, identity authentication and permission management module, data integrity check module, anomaly detection and early warning module, risk assessment and repair strategy module, and repair measure effectiveness evaluation; The data encryption module encrypts the original power data to ensure the security of the data during transmission and storage; The identity authentication and authority management module is used for setting user identity authentication and data access authority; The data integrity check module is used to perform integrity check on the encrypted power data; The anomaly detection and warning module is used to analyze the behavior and pattern of power data, identify and warn of abnormal data activities; The risk assessment and repair strategy module uses a risk assessment model to quantitatively assess the security risks of power data by combining encryption strength, data integrity and anomaly detection results, and formulates corresponding repair measures; The remediation measures effectiveness evaluation module is used to verify the effectiveness of remediation measures after they are implemented.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the cloud-based power data security protection method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the cloud-based power data security protection method described in any one of claims 1 to 7 are implemented.