Data key dynamic adjustment method and device for electric power information security protection

By real-time acquisition of power grid operating parameters and dynamic evaluation based on multi-dimensional risk assessment model, dynamic key ageing is calculated, and the problem that fixed key ageing in the existing technology is difficult to adapt to the complex environment of the power system is achieved, and more efficient data security protection is achieved.

CN119966629AActive Publication Date: 2025-05-09BEIJING YINHU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510442499.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-05-09
Estimated Expiration
2045-04-10

AI Technical Summary

Technical Problem

The existing power information data key age setting depends on fixed values, making it difficult to adapt to the complex and changing operating environment of the power system and the diverse security needs.

Method used

By collecting grid operating parameters in real time, dynamic risk assessment is evaluated based on the multi-dimensional risk assessment model, combining the device type mapping table and preset risk threshold, dynamic key ageing is calculated, and a time adjustment command is sent to the data security terminal device through the key control center to perform multi-level checksum key ageing update.

Benefits of technology

It realizes dynamic adjustment of key ageing, and can more flexibly respond to new security threats or changes in the operating environment that may occur at any time in the power system, and improves the adaptability and response capabilities of data security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966629A_ABST
    Figure CN119966629A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric power information security, in particular to a data key dynamic adjustment method and device for electric power information security protection, which can effectively cope with challenges brought by complex and changeable operating environments of an electric power system and remarkably improve data security and system reliability. The method is applied to a data key management system comprising a key control center and data security terminal equipment. The method comprises the following steps: collecting power grid operation parameters of a target area in real time; performing dynamic risk assessment on the power grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; according to the equipment type mapping table, determining the security level and the basic key time efficiency of the target data security terminal equipment, and combining the real-time risk assessment value and a preset risk threshold value to calculate and obtain the dynamic key time efficiency; and the key control center sends an aging adjustment command containing the dynamic key aging to the target data security terminal equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power information security, and in particular to a data key dynamic adjustment method and device for power information security protection. Background Art

[0002] With the digital transformation of the power industry, power information systems are becoming increasingly complex, and the security and integrity of data have become particularly important. Data keys are the core elements to ensure data security, and their management plays a key role in power information security protection. In the power information security protection system, the timeliness of data keys directly affects the security protection effect of data.

[0003] The existing power information data key expiration settings often rely on fixed data key expiration settings. The power system operating environment is complex and changeable. The stability of power grids in different regions, load changes, and the degree of network security threats they face vary. The performance and security requirements of various data security terminal devices (such as smart meters, power monitoring terminals, etc.) are also different. When the operating environment of the power system changes or new security threats emerge, fixed data key expiration settings are difficult to adapt to the diverse application scenarios and security requirements in the power system.

[0004] Therefore, there is an urgent need to provide a data key dynamic adjustment method and device for power information security protection to solve the above technical problems. Summary of the invention

[0005] In order to effectively cope with the challenges brought by the complex and changeable operating environment of the power system, an embodiment of the present invention provides a method and device for dynamically adjusting data keys for power information security protection.

[0006] In a first aspect, the present invention provides a data key dynamic adjustment method for power information security protection, which is applied to a data key management system including a key control center and a data security terminal device, and the method includes: Collect the power grid operation parameters of the target area in real time; Performing a dynamic risk assessment on the power grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; Determine the security level and basic key validity of the target data security terminal device according to the device type mapping table, and calculate the dynamic key validity by combining the real-time risk assessment value and the preset risk threshold; The key control center sends a time limit adjustment command including the dynamic key time limit to the target data security terminal device; After receiving the time adjustment command, the target data security terminal device performs a multi-level check; In response to any level of verification failure in the multi-level verification, the target data security terminal device automatically restores to the most recently valid key validity setting; In response to all the multi-level verifications being passed, the target data security terminal device performs a key aging update operation.

[0007] On the other hand, the present application also provides a data key dynamic adjustment device for power information security protection, the device comprising: The power grid operation parameter acquisition module is used to collect the power grid operation parameters of the target area in real time; A multi-dimensional risk assessment module, based on a preset multi-dimensional risk assessment model, is used to perform a dynamic risk assessment on the power grid operation parameters and generate a real-time risk assessment value; The dynamic key validity calculation module determines the security level and basic key validity of the target data security terminal device according to the device type mapping table, and combines the real-time risk assessment value generated by the multi-dimensional risk assessment module with the preset risk threshold to calculate the dynamic key validity; A time-limit adjustment command sending module, which is arranged in the key control center and is used to send a time-limit adjustment command including the dynamic key time limit to the target data security terminal device; A multi-level verification module, disposed in the target data security terminal device, for performing a multi-level verification after receiving the time adjustment command; A key validity recovery module is provided in the target data security terminal device, and is used to automatically restore the target data security terminal device to the most recently valid key validity setting in response to the failure of any level of verification in the multi-level verification module; The key validity update module is arranged in the target data security terminal device, and is used to make the target data security terminal device perform a key validity update operation in response to all the multi-level verifications of the multi-level verification module passing.

[0008] In a third aspect, the present application provides an electronic device, comprising a bus, a transceiver, a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the transceiver, the memory, and the processor are connected via the bus, and the computer program, when executed by the processor, implements the steps of any one of the above methods.

[0009] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps in any one of the above-mentioned methods when executed by a processor.

[0010] Compared with the prior art, the present invention has the following beneficial effects: by collecting the grid operation parameters of the target area in real time, the dynamic changes of the power system operation environment can be captured in time; dynamic risk assessment is performed based on real-time parameters and the corresponding dynamic key validity is generated, so that the key validity setting no longer depends on fixed values, and can better adapt to the complex and changeable operation environment of the power system, and improve the effectiveness of data security protection in different scenarios; Determine the security level and basic key validity of the target data security terminal device according to the device type mapping table, taking into full account the differences in performance and security requirements of various types of data security terminal devices; different devices have different security levels and basic key validity, and then dynamically adjust them in combination with real-time risk assessment values ​​to ensure that the key validity setting can accurately match the actual needs of each type of device, thereby improving the pertinence and refinement of data security protection; The preset multi-dimensional risk assessment model is used to evaluate the power grid operation parameters to generate a real-time risk assessment value, and the dynamic key validity is calculated in combination with the preset risk threshold. The key validity can be dynamically adjusted based on the risk status; when the risk increases, the key validity is shortened in time, the key update frequency is increased, and the risk of data being cracked is reduced; when the risk decreases, the key validity is appropriately extended to reduce the resource consumption of key management, thereby improving the security and integrity of the data as a whole; The target data security terminal device performs multi-level verification after receiving the time adjustment command, and automatically recovers to the most recent valid key time setting when any level of verification fails; the verification and recovery mechanism can effectively avoid equipment operation abnormalities or data security issues caused by incorrect key time settings, ensure the stable operation of data security terminal devices, and thus ensure the stability and reliability of the entire power information system; This method realizes dynamic adjustment of data key validity. Compared with fixed data key validity setting, it can more flexibly respond to new security threats or operating environment changes that may appear in the power system at any time. The key control center can adjust the key validity and issue commands in time according to the real-time evaluation results, making data key management more adaptable and responsive, and better meeting the ever-changing needs of power information security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0012] Figure 1 It is a flow chart of a data key dynamic adjustment method for power information security protection provided by one embodiment of the present invention; Figure 2 is a hardware architecture diagram of an electronic device provided by an embodiment of the present invention; Figure 3 It is a structural diagram of a data key dynamic adjustment device for power information security protection provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0013] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0014] Please refer to Figure 1 The embodiment of the present invention provides a data key dynamic adjustment method for power information security protection, which is applied to a data key management system including a key control center and a data security terminal device, and specifically includes the following steps: Step S100, collecting power grid operation parameters of the target area in real time; Step S102: Performing a dynamic risk assessment on the power grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; Step S104: determining the security level and basic key validity of the target data security terminal device according to the device type mapping table, and calculating the dynamic key validity by combining the real-time risk assessment value and the preset risk threshold; Step S106: the key control center sends a time limit adjustment command including the dynamic key time limit to the target data security terminal device; Step S108: After receiving the time adjustment command, the target data security terminal device performs a multi-level check; Step S110a, in response to any level of verification failure in the multi-level verification, the target data security terminal device automatically restores to the most recently valid key validity setting; Step S110b: In response to all the multi-level verifications being passed, the target data security terminal device performs a key validity update operation.

[0015] In this embodiment, by collecting the grid operation parameters of the target area in real time, the dynamic changes of the power system operation environment can be captured in time; dynamic risk assessment is performed based on real-time parameters and corresponding dynamic key validity is generated, so that the key validity setting no longer relies on fixed values, and can better adapt to the complex and changeable operation environment of the power system, and improve the effectiveness of data security protection in different scenarios; the security level and basic key validity of the target data security terminal device are determined according to the device type mapping table, and the differences in performance and security requirements of various types of data security terminal devices are fully considered; different devices have different security levels and basic key validity, and then dynamically adjusted in combination with the real-time risk assessment value, to ensure that the key validity setting can accurately match the actual needs of each type of equipment, and improve the pertinence and refinement of data security protection; the preset multi-dimensional risk assessment model is used to evaluate the grid operation parameters to generate real-time risk assessment values, and the dynamic key validity is calculated in combination with the preset risk threshold, so that the key validity can be dynamically adjusted based on the risk situation; when the risk increases, Shorten the key validity period in time, increase the key update frequency, and reduce the risk of data cracking; when the risk is reduced, appropriately extend the key validity period to reduce the resource consumption of key management, thereby improving the security and integrity of the data as a whole; the target data security terminal device performs multi-level verification after receiving the time adjustment command, and automatically recovers to the most recent valid key time setting when any level of verification fails; the verification and recovery mechanism can effectively avoid equipment operation abnormalities or data security problems caused by incorrect key time settings, ensure the stable operation of data security terminal equipment, and thus ensure the stability and reliability of the entire power information system; this method realizes the dynamic adjustment of data key time, which can more flexibly respond to new security threats or operating environment changes that may appear in the power system at any time compared to fixed data key time settings; the key control center can adjust the key time and issue commands in time according to the real-time evaluation results, so that data key management has stronger adaptability and responsiveness, and better meets the changing needs of power information security protection.

[0016] In some embodiments of the present invention, the collection of grid operation parameters in step S100 needs to cover key operation indicators of the power system, especially factors closely related to data security, such as grid stability, network security threat level, and performance load of data security terminal equipment; Regional power grid stability indicators include power grid frequency fluctuation, which is used to reflect the stability of power grid operation. Excessive frequency fluctuation may indicate abnormal power grid operation; voltage stability, which is used to reflect the fluctuation range and stability of voltage, which directly affects the normal operation of power equipment; line load rate, which is used to reflect the load of transmission lines. Excessive load rate may increase the risk of power grid operation; equipment operation status, which is used to reflect the operation status of key equipment such as transformers and circuit breakers, and whether there is a risk of overload, aging or failure; The network security threat level is mainly reflected in the detection results of network attack events, such as malicious code injection, DDoS attack, illegal intrusion and other security events; threat intelligence data, such as regional network security threat level information obtained based on external threat intelligence platforms; security protection equipment status, such as the operating status and alarm information of firewalls, intrusion detection systems and intrusion prevention systems; The real-time performance load of the target data security terminal device includes the device resource usage, such as the CPU usage, memory occupancy, storage space usage, etc. of smart meters, power monitoring terminals and other devices; communication load, such as the network communication bandwidth occupancy rate and data transmission rate of the device; device health status, such as the device's operating temperature, battery power, communication module status, etc.

[0017] More specifically, in order to achieve efficient and accurate parameter collection, step S100 adopts the following collection methods: Sensor monitoring: Deploy sensors on power grid equipment and terminal devices to monitor the physical parameters of power grid operation (such as voltage, current, frequency, etc.) and equipment status (such as temperature, vibration, etc.) in real time; sensor data is transmitted to the key control center via wired or wireless communication; Network security monitoring system: deploy network security monitoring equipment (such as firewalls, IDS / IPS, and security information and event management systems (SIEM)) to collect network security events and threat intelligence data in real time; the network security monitoring system evaluates the current network security threat level by analyzing traffic logs, alarm information, etc. Terminal device status reporting: Data security terminal devices (such as smart meters and power monitoring terminals) regularly report their own performance load data to the key control center, including CPU usage, memory usage, communication bandwidth usage, etc.; the reporting method uses lightweight communication protocols (such as MQTT and CoAP) to reduce communication overhead; External data access: Obtain environmental data related to power grid operation (such as weather conditions and load forecast data) from external systems (such as weather forecast systems and regional power grid dispatching systems); external data access can supplement the deficiencies of internal monitoring data and improve the accuracy of risk assessment.

[0018] In this embodiment, through the real-time collection of power grid operation parameters, the system can quickly perceive the dynamic changes in power grid operation and provide accurate data support for subsequent risk assessment; the collected parameters are directly used for the calculation of the multi-dimensional risk assessment model to ensure that the dynamic adjustment of the key time can accurately match the actual needs of the power system; through real-time monitoring of the power grid operating environment and terminal equipment status, it can adapt to the complex and changeable operating environment of the power system and improve the flexibility and reliability of data security protection.

[0019] In some embodiments of the present invention, the multi-dimensional risk assessment model in step S102 performs a comprehensive analysis and quantitative assessment of multiple factors such as power grid stability, network security threat level, and performance load of data security terminal equipment to generate a real-time risk assessment value reflecting the current power system security risk; Among them, the multi-dimensional risk assessment model adopts a weight analysis model, in which the grid stability weight coefficient α, the security threat weight coefficient β and the equipment load weight coefficient γ are set; the grid stability weight coefficient α, the security threat weight coefficient β and the equipment load weight coefficient γ are not fixed values, but are dynamically adjusted based on historical data and the rich experience of experts in the power field, combined with actual application scenarios. For example, in a period when the grid operation is relatively stable and the network security situation is good, the values ​​of α and β can be appropriately reduced, and the value of γ can be correspondingly increased to highlight the impact of equipment load factors on the overall risk assessment; on the contrary, when the grid faces severe stability challenges or suffers frequent network attacks, the values ​​of α and β are increased to enhance the weight of consideration of grid stability and network security threats; The calculation formula of the multidimensional risk assessment model is: ; Among them, R represents the real-time risk assessment value, which is used to quantify the security risk of the current power system; S represents the grid stability index, which is calculated based on the parameters such as grid frequency fluctuation, voltage stability, line load rate, etc. collected in step S100; T represents the network security threat level, which is calculated based on the network attack events, threat intelligence data and security protection equipment status collected in step S100; L represents the equipment load status index, which is calculated based on the terminal equipment performance load data collected in step S100.

[0020] More specifically, the grid stability index is a comprehensive value obtained by weighted calculation of parameters such as grid frequency fluctuation, voltage stability and line load rate. The calculation formula is: f 波动 Indicates the grid frequency fluctuation value, reflecting the degree to which the frequency deviates from the rated value; v 波动 Indicates the voltage fluctuation value, reflecting the magnitude of the voltage deviation from the rated range; l 负载 Indicates the line load rate, reflecting the load condition of the transmission line; w 1 、w 2 、w 3 Respectively represent the weight coefficient of each parameter; Among them, the calculation method of the network security threat level and the equipment load status index is similar to the calculation method of the power grid stability index, and will not be repeated here.

[0021] In this embodiment, through a multi-dimensional risk assessment model, factors such as power grid stability, network security threat level, and terminal equipment performance load are comprehensively considered, and the generated risk assessment value can fully reflect the actual security status of the power system; the real-time risk assessment value provides a scientific basis for the subsequent dynamic key age calculation, ensuring that the adjustment of the key age can accurately match the actual needs of the power system; through real-time evaluation of power grid operating parameters, potential security threats can be quickly perceived, and data security protection capabilities can be improved by dynamically adjusting the key age.

[0022] In some embodiments of the present invention, since various types of data security terminal devices (such as smart meters, power monitoring terminals, etc.) play different roles, their security importance also varies. According to the device type mapping table, the security level of the target data security terminal device can be determined. The device type mapping table is formulated based on the actual operation requirements and security policies of the power system, and it specifies in detail the security levels corresponding to different types of devices.

[0023] Each security level has a corresponding basic key validity period, which is the key validity period applicable to the device under a relatively stable operating environment and risk conditions. For example, for some terminal devices with lower importance and processing general data, their security level is lower and the basic key validity period may be relatively long; while for equipment that processes critical power operation data, the security level is high and the basic key validity period may be shorter to improve data security.

[0024] Specifically, the calculation formula for the dynamic key validity is: ; in, Indicates the validity period of the dynamic key. Indicates the validity period of the basic key. represents the real-time risk assessment value, represents the preset risk threshold, k represents the equipment type sensitivity coefficient corresponding to the security level of the target data security terminal equipment, the higher the security level, the greater the equipment type sensitivity coefficient; the determination of the preset risk threshold requires comprehensive consideration of many factors; first of all, it must be based on the relevant standards and specifications of the power industry. The standards and specifications should be a summary of long-term practices and security experience in the industry, providing a basic framework for threshold setting; at the same time, combined with historical data, the frequency and severity of data security incidents at different risk levels in the past power system operation are analyzed to determine the acceptable critical value of risks in different dimensions; the actual operating environment of the power system must also be considered, such as the stability differences of power grids in different regions, common types of network security threats, etc. For environments with poor stability or high network security threats, the threshold should be appropriately lowered; in addition, experts in the power field adjust and optimize the threshold based on their professional knowledge and practical operating experience to ensure that the preset risk threshold can effectively prevent potential risks and will not affect the normal operation of the power system due to overly strict settings; In the above calculation formula, an exponential decay mechanism is used. When the real-time risk R current >R threshold When the key validity period is shortened according to the exponential law, the higher the risk, the faster the validity period decays; the sensitivity coefficient k of high-security level equipment is larger, and the risk response is more sensitive; if R current ≤R threshold , the formula degenerates to T new =T base ×e 0 =T base , maintain basic timeliness.

[0025] In this embodiment, by using the exponential decay mechanism, the key validity period can be rapidly shortened as the risk increases based on the real-time risk assessment value, thereby achieving a sensitive response to risk changes and timely enhancing data security protection; security level adaptation enables devices of different security levels to have corresponding device type sensitivity coefficients. High-security level devices are more sensitive to risks, and their key validity period adjustments are more active, ensuring that important equipment data is more strictly protected; threshold protection sets reasonable boundaries for key validity period adjustments by pre-setting risk thresholds, avoiding excessive adjustments due to risk fluctuations, and ensuring the stable operation of the power system while effectively preventing risks.

[0026] In some embodiments of the present invention, when the key control center communication interruption is detected, the data security terminal device will take a series of measures to ensure data security; the specific implementation methods are as follows: The terminal device continuously monitors the TCP heartbeat packets with the key control center. If three consecutive cycles are lost, it is considered as a communication interruption. After the interruption event is triggered, the device automatically switches to the local risk assessment mode and starts the local risk assessment cache module. A circular buffer is used to store the risk assessment values ​​of the last 24 hours, with a sampling interval of 5 minutes and a capacity of 288 records. Taking the current time point as the benchmark, 12 risk assessment values ​​within the preset time window (default 1 hour) are taken forward, and the arithmetic mean is calculated after removing the abnormal values, that is, the average risk assessment value. The local temporary key validity is calculated based on the basic key validity, average risk assessment value and preset risk threshold. The calculation formula is: ; in, Indicates the validity period of the temporary key. Represents the average risk assessment value.

[0027] In this embodiment, the average risk assessment value is calculated through a sliding window, which can avoid accidental fluctuations in a single risk assessment, such as instantaneous false alarms, and reflect changes in risk trends; the temporary key validity calculation formula and the dynamic key validity calculation formula share the basic key validity and preset risk threshold parameters to ensure that there is no conflict in policy switching after communication is restored; local cache and sliding window calculation maintain the continuity of risk perception, avoid "security blind spots" during communication interruptions, and ensure that key validity adjustments are synchronized with real-time risk trends; the triple mechanism of smoothing fluctuations through average risk assessment values, formula coefficient constraints, and resource monitoring meets the real-time requirements of power terminal equipment.

[0028] In some embodiments of the present invention, when an advanced persistent threat attack is detected, the system dynamically adjusts the device type sensitivity coefficient to enhance data security protection. The specific implementation is as follows: The system monitors the security status of target data security terminal devices in real time to identify whether they are attacked by advanced persistent threats, involving in-depth analysis of network traffic, device behavior, and system logs; Once an advanced persistent threat attack is detected, the system will dynamically adjust the device type sensitivity coefficient according to the preset sensitivity coefficient adjustment formula. The adjusted sensitivity coefficient reflects the severity of the attack. Using the adjusted sensitivity coefficient, the system recalculates the dynamic key validity period to ensure that in a high-threat environment, the key validity period can be quickly shortened, thereby enhancing data security.

[0029] Among them, advanced persistent threats refer to highly concealed and long-term cyber attacks against specific targets. The following are its core characteristics and specific threat analysis in the power system: Advanced: Attackers are usually state-sponsored or professional hacker groups; they use cutting-edge technologies such as zero-day vulnerabilities and customized malware; Persistence: The attack cycle can last for months or even years; multi-stage penetration is adopted: initial intrusion → lateral movement → persistent residence → data return; Concealment: Disguised as normal traffic (such as HTTPS encrypted communication); using legitimate tools (such as PowerShell, WMI) to carry out attacks (fileless attacks); Targeted: Specifically targeting key infrastructure such as electricity and energy; collect intelligence on target network topology and business systems in advance; Typical hazards of advanced persistent threat attacks to power systems include stealing grid operation data (such as load forecasts and dispatch instructions), obtaining equipment control protocols (such as IEC 61850 protocols), causing equipment overload by tampering with SCADA instructions, implanting logic bombs to cause substation protection systems to malfunction, encrypting power information system data for ransom, and destroying the order matching algorithm of the power market trading platform.

[0030] More specifically, the calculation formula for dynamically adjusting the device type sensitivity coefficient is: ; in, Indicates the dynamically adjusted device type sensitivity coefficient, Indicates the device type sensitivity coefficient corresponding to the target data security terminal device, Indicates the number of attacks detected during the past preset time period.

[0031] In this embodiment, advanced persistent threat attacks usually rely on long-term penetration to test system weaknesses, and the sublinear growth of k′ forces the attacker to launch exponentially more attacks to achieve the same destructive effect (for example, increasing k′ from 10 to 1000 attacks can increase k′ by 4 times), which greatly increases the cost of the attack; this adjustment mechanism can quickly respond to high-threat environments, shorten the key validity period by increasing the sensitivity coefficient, thereby enhancing data security, which not only improves the system's defense capabilities, but also enhances its flexibility and adaptability; by quickly adapting to threat changes, it can more effectively protect critical data and prevent potential security vulnerabilities from being exploited.

[0032] In some embodiments of the present invention, after receiving the time adjustment command sent by the key control center, the target data security terminal device will perform multi-level verification to ensure the validity and security of the command, which is specifically implemented as follows: Verify the time format compliance of the dynamic key validity period: the device first checks the format of the received dynamic key validity period; the device has preset standard time format specifications, for example, the time format may be specified as a positive integer in seconds, or a format that complies with the time representation rules of a specific power system; the device will compare the received dynamic key validity period with these specifications; if the received dynamic key validity period appears in a decimal form (assuming it is not allowed), a negative number, or a confusing format, it is determined that the time format does not meet the requirements, the verification fails, the subsequent verification stops, and the operation of step S110a is triggered; only when the format of the dynamic key validity period fully complies with the preset specifications will the next verification be entered; Verify whether the dynamic key validity period meets the maximum tolerance validity period and minimum security validity period corresponding to the device security level: Each device has a corresponding maximum tolerance validity period and minimum security validity period range according to its security level; the device will obtain these thresholds from the security policy information stored in itself; for example, the maximum tolerance validity period of a low-security level device may be longer and the minimum security validity period may be relatively short; while the opposite is true for a high-security level device; the device will compare the received dynamic key validity period with these thresholds; if the dynamic key validity period is less than the minimum security validity period, it may lead to frequent key replacement, affecting device performance and data processing efficiency; if it is greater than the maximum tolerance validity period, data security cannot be effectively guaranteed; once the dynamic key validity period exceeds this range, the verification fails, triggering step S110a; if it is within the range, proceed to the next verification; Verify the matching degree between the dynamic key validity period and the current data processing cycle of the device: the device will identify its current data processing cycle, which is the time period for the device to perform operations such as data collection, processing and transmission; for example, a smart meter may collect and upload electricity consumption data at regular intervals, and this time interval is its data processing cycle; the device will determine whether the dynamic key validity period matches the data processing cycle; if the dynamic key validity period is set unreasonably, the key needs to be replaced during the critical stage of data processing (such as data encryption or transmission), which may interrupt the data processing process and cause data loss or errors; if such a mismatch exists, the verification fails and step S110a is triggered; if it matches, all multi-level verifications pass and step S110b is entered.

[0033] When any level of the multi-level verification fails, the device will immediately trigger the recovery mechanism, that is, step S110a; the device stores the most recently valid key validity setting information internally, and this information will be recorded and updated each time the key validity is successfully updated; once the verification fails, the device quickly calls the stored information to restore the key validity to the previously successfully set state; it can ensure that when the device receives an inapplicable dynamic key validity, it will not fall into a state of data security risk or abnormal operation, and ensure that the device can continue to perform data security protection with reliable key validity and maintain the stable operation of the power information system.

[0034] If all the multi-level checks are passed, it means that the received dynamic key validity meets the requirements of the device in terms of format, security level adaptability and matching degree with the data processing cycle. At this time, the device will update its own key validity according to the received dynamic key validity, that is, step S110b. The device writes the new dynamic key validity information into the corresponding storage area, overwriting the original key validity setting. Thereafter, the device will perform key management and data encryption operations according to the new key validity, ensuring that under the current power system operating environment and security risk conditions, the data can obtain the most appropriate security protection, thereby improving the security and integrity of the data.

[0035] In this implementation, through multi-level verification, the dynamic key validity is strictly reviewed from multiple dimensions such as format, security level and data processing cycle to ensure that the new key validity can adapt to the operation needs and security requirements of the equipment; the automatic recovery mechanism when the verification fails can avoid abnormal equipment operation or data security accidents caused by incorrect key validity settings; and the update operation after the verification is successful enables the equipment to adjust the key validity in time according to changes in system risks, enhance data protection capabilities, greatly improve the stability and reliability of the power information security protection system, and ensure the security and integrity of power data in a complex and changing environment.

[0036] like Figure 2 , Figure 3 As shown, an embodiment of the present invention provides a data key dynamic adjustment device for power information security protection. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. From the hardware level, Figure 2 As shown, it is a hardware architecture diagram of an electronic device where a data key dynamic adjustment device for power information security protection provided by an embodiment of the present invention is located, except Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown, the electronic device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing messages, etc. Taking software implementation as an example, Figure 3As shown, as a device in a logical sense, the CPU of the electronic device in which it is located reads the corresponding computer program in the non-volatile memory into the internal memory and runs it.

[0037] like Figure 3 As shown, this embodiment provides a data key dynamic adjustment device for power information security protection, including: The power grid operation parameter acquisition module is used to collect the power grid operation parameters of the target area in real time; A multi-dimensional risk assessment module, based on a preset multi-dimensional risk assessment model, is used to perform a dynamic risk assessment on the power grid operation parameters and generate a real-time risk assessment value; The dynamic key validity calculation module determines the security level and basic key validity of the target data security terminal device according to the device type mapping table, and combines the real-time risk assessment value generated by the multi-dimensional risk assessment module with the preset risk threshold to calculate the dynamic key validity; A time-limit adjustment command sending module, which is arranged in the key control center and is used to send a time-limit adjustment command including the dynamic key time limit to the target data security terminal device; A multi-level verification module, disposed in the target data security terminal device, for performing a multi-level verification after receiving the time adjustment command; A key validity recovery module is provided in the target data security terminal device, and is used to automatically restore the target data security terminal device to the most recently valid key validity setting in response to the failure of any level of verification in the multi-level verification module; The key validity update module is arranged in the target data security terminal device, and is used to make the target data security terminal device perform a key validity update operation in response to all the multi-level verifications of the multi-level verification module passing.

[0038] It is understandable that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on a data key dynamic adjustment device for power information security protection. In other embodiments of the present invention, a data key dynamic adjustment device for power information security protection may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0039] The information interaction, execution process and other contents between the modules in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention. For the specific contents, please refer to the description in the embodiment of the method of the present invention, and no further description is given here.

[0040] An embodiment of the present invention also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, a data key dynamic adjustment method for power information security protection in any embodiment of the present invention is implemented.

[0041] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes a data key dynamic adjustment method for power information security protection in any embodiment of the present invention.

[0042] Specifically, a system or device equipped with a storage medium can be provided, on which software program code that implements the functions of any of the above-mentioned embodiments is stored, and a computer (or CPU or MPU) of the system or device can be enabled to read and execute the program code stored in the storage medium.

[0043] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute a part of the present invention.

[0044] The storage medium embodiments for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer via a communication network.

[0045] In addition, it should be clear that the functions of any of the above embodiments can be implemented not only by executing the program code read by the computer, but also by enabling an operating system operating on the computer to complete part or all of the actual operations based on instructions from the program code.

[0046] In addition, it can be understood that the program code read from the storage medium is written to a memory provided in an expansion board inserted into the computer or to a memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or expansion module is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above-mentioned embodiments.

[0047] It should be noted that, in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.

[0048] A person of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, etc., various media that can store program codes.

[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data key dynamic adjustment method for power information security protection, applied to a data key management system including a key control center and a data security terminal device, characterized in that: The method comprises: Real-time collection of power grid operation parameters in the target area; Performing a dynamic risk assessment on the power grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; Determine the security level and basic key validity of the target data security terminal device according to the device type mapping table, and calculate the dynamic key validity by combining the real-time risk assessment value and the preset risk threshold; The key control center sends a time limit adjustment command including the dynamic key time limit to the target data security terminal device; After receiving the time adjustment command, the target data security terminal device performs a multi-level check; In response to any level of verification failure in the multi-level verification, the target data security terminal device automatically restores to the most recently valid key validity setting; In response to all the multi-level verifications being passed, the target data security terminal device performs a key aging update operation.

2. The data key dynamic adjustment method for power information security protection according to claim 1 is characterized in that: The multi-level verification includes: Verify the time format compliance of the dynamic key validity period; Verify whether the dynamic key validity period meets the maximum tolerance validity period and minimum security validity period corresponding to the device security level; Verify the matching degree between the dynamic key validity and the current data processing cycle of the device.

3. The data key dynamic adjustment method for power information security protection according to claim 2 is characterized in that: The power grid operation parameters include at least regional power grid stability indicators, network security threat levels, and real-time performance loads of target data security terminal equipment; The multi-dimensional risk assessment model is provided with a power grid stability weight coefficient, a security threat weight coefficient and an equipment load correction factor.

4. The data key dynamic adjustment method for power information security protection according to claim 1 is characterized in that: The calculation formula of the dynamic key validity is: ; in, Indicates the validity period of the dynamic key. Indicates the validity period of the basic key. Represents the real-time risk assessment value, represents the preset risk threshold, k represents the device type sensitivity coefficient corresponding to the security level of the target data security terminal device, and the higher the security level, the greater the device type sensitivity coefficient.

5. The data key dynamic adjustment method for power information security protection according to claim 4 is characterized in that: In response to detecting that the key control center communication is interrupted, the data security terminal device executes: Enable the local risk assessment cache module and use the average risk assessment value in the most recent preset time window to calculate the temporary key validity period; The calculation formula for the temporary key validity is: ; in, Indicates the validity period of the temporary key. Represents the average risk assessment value.

6. The data key dynamic adjustment method for power information security protection according to claim 4 is characterized in that: In response to detecting that the target data security terminal device is attacked by an advanced persistent threat, the device type sensitivity coefficient is dynamically adjusted, and the dynamic key validity is calculated using the dynamically adjusted device type sensitivity coefficient.

7. The data key dynamic adjustment method for power information security protection according to claim 6 is characterized in that: in, The dynamic adjustment formula of the equipment type sensitivity coefficient is: ; in, Indicates the dynamically adjusted device type sensitivity coefficient, Indicates the device type sensitivity coefficient corresponding to the target data security terminal device, Indicates the number of attacks detected during the past preset time period.

8. A data key dynamic adjustment device for power information security protection, characterized in that: The device comprises: The power grid operation parameter acquisition module is used to collect the power grid operation parameters of the target area in real time; A multi-dimensional risk assessment module, based on a preset multi-dimensional risk assessment model, is used to perform a dynamic risk assessment on the power grid operation parameters and generate a real-time risk assessment value; The dynamic key validity calculation module determines the security level and basic key validity of the target data security terminal device according to the device type mapping table, and combines the real-time risk assessment value generated by the multi-dimensional risk assessment module with the preset risk threshold to calculate the dynamic key validity; A time-limit adjustment command sending module, which is arranged in the key control center and is used to send a time-limit adjustment command including the dynamic key time limit to the target data security terminal device; A multi-level verification module, disposed in the target data security terminal device, for performing a multi-level verification after receiving the time adjustment command; A key validity recovery module is provided in the target data security terminal device, and is used to automatically restore the target data security terminal device to the most recently valid key validity setting in response to the failure of any level of verification in the multi-level verification module; The key validity update module is arranged in the target data security terminal device, and is used to make the target data security terminal device perform a key validity update operation in response to all the multi-level verifications of the multi-level verification module passing.

9. An electronic device, comprising a bus, a transceiver, a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the transceiver, the memory, and the processor are connected via the bus, wherein: When the computer program is executed by the processor, the steps in the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps in the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Communication information security risk early warning management and control method and system based on big data

    CN117955712A

  • Secure data storage system based on cloud computing

    CN119135445A

  • Communication timeout exception handling method for intelligent electric energy meter

    CN119766696A

  • Video conference data security encryption method, system, device, and storage medium

    CN119788808A

  • Variable epoch scheduler for proactive cryptography systems

    US8817988B1

Cited By

  • Network and information security encryption system and method

    CN120546908A

  • A network and information security encryption system and method

    CN120546908B

  • Key dynamic activity maintaining method and device for complex power network topology

    CN121125172A