Data Key Dynamic Adjustment Method and Device for Power Information Security Protection

By collecting power grid operating parameters and multi-dimensional risk assessment models in real time, and calculating dynamic key ageing combined with equipment type mapping tables and preset risk thresholds, the problem of insufficient adaptability caused by fixed key ageing in power information systems is solved, and more efficient data security protection is achieved.

CN119966629BActive Publication Date: 2025-07-11BEIJING YINHU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510442499.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-07-11
Estimated Expiration
2045-04-10

AI Technical Summary

Technical Problem

In the existing power information system, the data key age setting depends on fixed time value, which is difficult to adapt to the complex and changing operating environment of the power system and the diversified security needs, resulting in poor data security protection.

Method used

By collecting grid operation parameters in real time, using a multi-dimensional risk assessment model to generate real-time risk assessment values, calculating dynamic key aging based on the device type mapping table and preset risk thresholds, and performing multi-level checksum key aging update on the target data security terminal device to ensure dynamic key aging adjustment.

Benefits of technology

It realizes dynamic adjustment of key ageing, can better adapt to the complex and changing environment of the power system, improve the pertinence and flexibility of data security protection, and enhance the stability and security of the power information system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966629B_ABST
    Figure CN119966629B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of power information security, and particularly to a method and device for dynamically adjusting data keys for power information security protection, which can effectively cope with the challenges brought by the complex and changeable operation environment of the power system and significantly improve data security and system reliability; the method is applied to a data key management system including a key control center and data security terminal devices, and the method includes: collecting the grid operation parameters of the target area in real time; dynamically evaluating the risks of the grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; determining the security level and the basic key aging period of the target data security terminal device according to the device type mapping table, and calculating the dynamic key aging period by combining the real-time risk assessment value with a preset risk threshold; the key control center sends an aging adjustment command including the dynamic key aging period to the target data security terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electric power information security, and particularly to a method and device for dynamically adjusting data keys for electric power information security protection. Background Art

[0002] With the digital transformation of the power industry, power information systems are becoming increasingly complex, and the security and integrity of data have become particularly important; data keys, as the core elements for ensuring data security, play a key role in the security protection of electric power information; in the electric power information security protection system, the timeliness of data keys directly affects the security protection effect of data.

[0003] The existing timeliness settings of electric power information data keys often rely on fixed data key timeliness settings. The operating environment of the power system is complex and changeable, and the stability of different regional power grids, load changes, and the degree of network security threats faced are different. The performance and security requirements of various data security terminal devices (such as smart meters, power monitoring terminals, etc.) are also different. When the operating environment of the power system changes or new security threats appear, fixed data key timeliness settings are difficult to adapt to the diverse application scenarios and security requirements in the power system.

[0004] Therefore, there is an urgent need to provide a method and device for dynamically adjusting data keys for electric power information security protection to solve the above technical problems. Summary of the Invention

[0005] In order to effectively cope with the challenges brought by the complex and changeable operating environment of the power system, embodiments of the present invention provide a method and device for dynamically adjusting data keys for electric power information security protection.

[0006] In a first aspect, the present invention provides a method for dynamically adjusting data keys for electric power information security protection, which is applied to a data key management system including a key control center and data security terminal devices. The method includes:

[0007] Collecting the grid operation parameters of the target area in real time;

[0008] Performing dynamic risk assessment on the grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value;

[0009] Determining the security level and basic key timeliness of the target data security terminal device according to the device type mapping table, and calculating the dynamic key timeliness in combination with the real-time risk assessment value and a preset risk threshold;

[0010] The key control center sending a timeliness adjustment command including the dynamic key timeliness to the target data security terminal device;

[0011] After receiving the aging adjustment command, the target data security terminal device performs multi-level verification;

[0012] When any level of verification in the multi-level verification fails, the target data security terminal device automatically reverts to the last valid key aging setting;

[0013] When all levels of the multi-level verification pass, the target data security terminal device performs a key aging update operation.

[0014] On the other hand, the present application also provides a data key dynamic adjustment device for power information security protection, and the device includes:

[0015] A power grid operation parameter acquisition module for real-time acquisition of power grid operation parameters in a target area;

[0016] A multi-dimensional risk assessment module, based on a preset multi-dimensional risk assessment model, for dynamically assessing the risk of the power grid operation parameters and generating a real-time risk assessment value;

[0017] A dynamic key aging calculation module for determining the security level and basic key aging of the target data security terminal device according to the device type mapping table, and combining the real-time risk assessment value generated by the multi-dimensional risk assessment module with a preset risk threshold to calculate the dynamic key aging;

[0018] An aging adjustment command sending module, disposed in the key control center, for sending an aging adjustment command including the dynamic key aging to the target data security terminal device;

[0019] A multi-level verification module, disposed in the target data security terminal device, for performing multi-level verification after receiving the aging adjustment command;

[0020] A key aging recovery module, disposed in the target data security terminal device, in response to any level of verification failure in the verification by the multi-level verification module, for automatically reverting the target data security terminal device to the last valid key aging setting;

[0021] A key aging update module, disposed in the target data security terminal device, in response to all levels of the multi-level verification by the multi-level verification module passing, for causing the target data security terminal device to perform a key aging update operation.

[0022] In a third aspect, the present application provides an electronic device, including a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. The transceiver, the memory, and the processor are connected through the bus. When the computer program is executed by the processor, the steps in any one of the above methods are implemented.

[0023] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in any one of the above methods are implemented.

[0024] Compared with the prior art, the beneficial effects of the present invention are as follows: By collecting the grid operation parameters of the target area in real time, the dynamic changes in the operation environment of the power system can be captured in a timely manner; Based on the real-time parameters, a dynamic risk assessment is carried out and the corresponding dynamic key aging is generated, so that the key aging setting no longer depends on fixed values, and it can better adapt to the complex and changeable operation environment of the power system, and improve the effectiveness of data security protection in different scenarios;

[0025] Determine the security level and the basic key aging of the target data security terminal device according to the device type mapping table, fully considering the differences in the performance and security requirements of various data security terminal devices; Different devices have different security levels and basic key aging, and then dynamically adjust them in combination with the real-time risk assessment value to ensure that the key aging setting can accurately match the actual needs of each type of device, and improve the pertinence and refinement degree of data security protection;

[0026] Use a preset multi-dimensional risk assessment model to evaluate the grid operation parameters to generate a real-time risk assessment value, and calculate the dynamic key aging in combination with a preset risk threshold, so that the key aging can be dynamically adjusted based on the risk situation; When the risk increases, shorten the key aging in a timely manner, increase the key update frequency, and reduce the risk of data being cracked; When the risk decreases, appropriately extend the key aging and reduce the resource consumption of key management, so as to improve the security and integrity of data as a whole;

[0027] The target data security terminal device performs multi-level verification after receiving the aging adjustment command, and automatically restores to the most recent valid key aging setting when any level of verification fails; The verification and recovery mechanism can effectively avoid abnormal device operation or data security problems caused by incorrect key aging settings, ensure the stable operation of the data security terminal device, and then ensure the stable and reliable operation of the entire power information system;

[0028] This method realizes the dynamic adjustment of the data key validity period. Compared with the fixed setting of the data key validity period, it can more flexibly cope with new security threats or changes in the operating environment that may occur at any time in the power system. The key control center can adjust the key validity period in a timely manner according to the real-time evaluation results and issue commands, making the data key management have stronger adaptability and response capabilities, and better meeting the changing requirements of power information security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0030] Figure 1 is a flowchart of a method for dynamically adjusting data keys for power information security protection provided by an embodiment of the present invention;

[0031] Figure 2 is a hardware architecture diagram of an electronic device provided by an embodiment of the present invention;

[0032] Figure 3 is a structural diagram of a device for dynamically adjusting data keys for power information security protection provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0034] Please refer to Figure 1 , an embodiment of the present invention provides a method for dynamically adjusting data keys for power information security protection, which is applied to a data key management system including a key control center and data security terminal devices, and specifically includes the following steps:

[0035] Step S100, collect the grid operation parameters of the target area in real time;

[0036] Step S102, perform dynamic risk assessment on the grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value;

[0037] Step S104: Determine the security level and the basic key aging period of the target data security terminal device according to the device type mapping table, and calculate the dynamic key aging period by combining the real-time risk assessment value with the preset risk threshold;

[0038] Step S106: The key control center sends an aging adjustment command containing the dynamic key aging period to the target data security terminal device;

[0039] Step S108: After receiving the aging adjustment command, the target data security terminal device performs multi-level verification;

[0040] Step S110a: When any level of verification in the multi-level verification fails, the target data security terminal device automatically reverts to the last valid key aging period setting;

[0041] Step S110b: When all levels of verification in the multi-level verification pass, the target data security terminal device performs a key aging period update operation.

[0042] In this embodiment, by collecting the power grid operation parameters of the target area in real time, the dynamic changes in the operation environment of the power system can be captured in a timely manner; based on the real-time parameters, dynamic risk assessment is carried out and corresponding dynamic key timeliness is generated, so that the key timeliness setting no longer depends on fixed values, and it can better adapt to the complex and changeable operation environment of the power system, and improve the effectiveness of data security protection in different scenarios; according to the device type mapping table, the security level and basic key timeliness of the target data security terminal device are determined, fully considering the differences in the performance and security requirements of various data security terminal devices; different devices have different security levels and basic key timeliness, and then combined with the real-time risk assessment value for dynamic adjustment to ensure that the key timeliness setting can accurately match the actual needs of each type of device, and improve the pertinence and refinement degree of data security protection; using a preset multi-dimensional risk assessment model to evaluate the power grid operation parameters to generate a real-time risk assessment value, and combining with a preset risk threshold to calculate the dynamic key timeliness, the key timeliness can be dynamically adjusted based on the risk situation; when the risk increases, the key timeliness is shortened in a timely manner, the key update frequency is increased, and the risk of data being cracked is reduced; when the risk decreases, the key timeliness is appropriately extended, and the resource consumption of key management is reduced, thereby improving the security and integrity of data as a whole; after receiving the timeliness adjustment command, the target data security terminal device performs multi-level verification, and automatically restores to the most recent valid key timeliness setting when any level of verification fails; the verification and recovery mechanism can effectively avoid abnormal device operation or data security problems caused by incorrect key timeliness settings, ensure the stable operation of the data security terminal device, and then ensure the stable and reliable operation of the entire power information system; this method realizes the dynamic adjustment of data key timeliness, and compared with the fixed data key timeliness setting, it can more flexibly cope with new security threats or operation environment changes that may occur at any time in the power system; the key control center can adjust the key timeliness in a timely manner according to the real-time evaluation results and issue commands, making the data key management have stronger adaptability and response ability, and better meeting the ever-changing requirements of power information security protection.

[0043] In some embodiments of the present invention, for the power grid operation parameter collection in step S100, it is necessary to cover the key operation indicators of the power system, especially the factors closely related to data security, such as power grid stability, network security threat level, and performance load of data security terminal devices, etc.;

[0044] The regional power grid stability indicators include power grid frequency fluctuation, which is used to reflect the stability of the power grid operation. Excessive frequency fluctuation may indicate abnormal power grid operation; voltage stability, which is used to directly affect the normal operation of power equipment due to the voltage fluctuation range and stability; line load rate, which is used to indicate the load situation of transmission lines. Excessive load rate may lead to an increase in power grid operation risk; device operation status, which is used to indicate the operation status of key devices such as transformers and circuit breakers, and whether there are risks of overload, aging or failure;

[0045] The network security threat level is mainly reflected in the detection results of network attack events, such as security events like malicious code injection, DDoS attacks, and illegal intrusions; threat intelligence data, such as the regional network security threat level information obtained from external threat intelligence platforms; the status of security protection devices, such as the operating status and alarm information of firewalls, intrusion detection systems, and intrusion prevention systems.

[0046] The real-time performance load of the target data security terminal device includes the device resource usage, such as the CPU usage rate, memory occupancy rate, and storage space usage rate of devices like smart meters and power monitoring terminals; the communication load, such as the network communication bandwidth occupancy rate and data transmission rate of the device; the device health status, such as the operating temperature, battery power, and communication module status of the device.

[0047] More specifically, in order to achieve efficient and accurate parameter collection, step S100 adopts the following several collection methods:

[0048] Sensor monitoring: Deploy sensors on power grid devices and terminal devices to monitor the physical parameters of power grid operation (such as voltage, current, frequency, etc.) and device status (such as temperature, vibration, etc.) in real time; the sensor data is transmitted to the key control center through wired or wireless communication methods.

[0049] Network security monitoring system: Deploy network security monitoring devices (such as firewalls, IDS / IPS, security information and event management system SIEM) to collect network security events and threat intelligence data in real time; the network security monitoring system evaluates the current network security threat level by analyzing traffic logs, alarm information, etc.

[0050] Terminal device status reporting: Data security terminal devices (such as smart meters and power monitoring terminals) regularly report their own performance load data, including CPU usage rate, memory occupancy rate, communication bandwidth occupancy rate, etc., to the key control center; the reporting method adopts lightweight communication protocols (such as MQTT, CoAP) to reduce communication overhead.

[0051] External data access: Obtain environmental data related to power grid operation (such as weather conditions, load prediction data) from external systems (such as weather forecasting systems, regional power grid dispatching systems); the access of external data can supplement the deficiencies of internal monitoring data and improve the accuracy of risk assessment.

[0052] In this embodiment, by collecting the real-time operation parameters of the power grid, the system can quickly perceive the dynamic changes in the operation of the power grid and provide accurate data support for subsequent risk assessment; the collected parameters are directly used for the calculation of the multi-dimensional risk assessment model to ensure that the dynamic adjustment of the key validity can accurately match the actual needs of the power system; by monitoring the real-time operation environment of the power grid and the status of terminal devices, it can adapt to the complex and changeable operation environment of the power system and improve the flexibility and reliability of data security protection.

[0053] In some embodiments of the present invention, the multi-dimensional risk assessment model in step S102 comprehensively analyzes and quantitatively evaluates various factors such as the stability of the power grid, the level of network security threats, and the performance load of data security terminal devices, and generates a real-time risk assessment value reflecting the current security risks of the power system;

[0054] Among them, the multi-dimensional risk assessment model adopts a weight analysis model, in which a power grid stability weight coefficient α, a security threat weight coefficient β, and a device load weight coefficient γ are set; the power grid stability weight coefficient α, the security threat weight coefficient β, and the device load weight coefficient γ are not fixed values, but are dynamically adjusted according to historical data and the rich experience of power experts, combined with the actual application scenario. For example, during a period when the power grid operation is relatively stable and the network security situation is good, the values of α and β can be appropriately reduced, and the value of γ can be increased accordingly to highlight the impact of the device load factor on the overall risk assessment; on the contrary, when the power grid faces severe stability challenges or suffers frequent cyberattacks, the values of α and β are increased to enhance the consideration weight of power grid stability and network security threats;

[0055] The calculation formula of the multi-dimensional risk assessment model is:

[0056] ;

[0057] Among them, R represents the real-time risk assessment value, which is used to quantify the security risks of the current power system; S represents the power grid stability index, which is calculated based on parameters such as the power grid frequency fluctuation, voltage stability, and line load rate collected in step S100; T represents the level of network security threats, which is calculated based on network attack events, threat intelligence data, and the status of security protection devices collected in step S100; L represents the device load status index, which is calculated based on the terminal device performance load data collected in step S100.

[0058] More specifically, the power grid stability index is a comprehensive value calculated by weighting parameters such as the power grid frequency fluctuation, voltage stability, and line load rate. The calculation formula is:

[0059]

[0060] f 波动 represents the grid frequency fluctuation value, reflecting the degree of frequency deviation from the rated value; v 波动 represents the voltage fluctuation value, reflecting the amplitude of voltage deviation from the rated range; l 负载 represents the line load rate, reflecting the load condition of the transmission line; w 1 、w 2 、w 3 respectively represent the weight coefficients of each parameter;

[0061] Among them, the calculation methods of the network security threat level and the device load status index are similar to those of the grid stability index, and will not be elaborated here one by one.

[0062] In this embodiment, through the multi-dimensional risk assessment model, comprehensively considering factors such as grid stability, network security threat level, and terminal device performance load, the generated risk assessment value can comprehensively reflect the actual security status of the power system; the real-time risk assessment value provides a scientific basis for the subsequent dynamic key aging calculation, ensuring that the adjustment of the key aging can accurately match the actual needs of the power system; through the real-time assessment of the grid operation parameters, potential security threats can be quickly perceived, and the data security protection ability can be improved by dynamically adjusting the key aging.

[0063] In some embodiments of the present invention, since various data security terminal devices (such as smart meters, power monitoring terminals, etc.) play different roles, their security importance also varies. According to the device type mapping table, the security level of the target data security terminal device can be determined. The device type mapping table is formulated based on the actual operation requirements and security policies of the power system, and it details the security levels corresponding to different types of devices.

[0064] Each security level has a corresponding basic key aging. The basic key aging is the effective time of the key applicable to the device under a relatively stable operating environment and risk situation. For example, for some terminal devices with relatively low importance and processing general data, their security level is relatively low, and the basic key aging may be relatively long; while for devices processing critical power operation data, the security level is high, and the basic key aging may be relatively short to improve data security.

[0065] Specifically, the calculation formula of the dynamic key aging is:

[0066] ;

[0067] Among them, represents the dynamic key aging, Indicates the basic key aging period, Indicates the real-time risk assessment value, Indicates the preset risk threshold. k represents the device type sensitivity coefficient corresponding to the security level of the target data security terminal device. The higher the security level, the greater the device type sensitivity coefficient. The determination of the preset risk threshold needs to consider multiple factors. First, it is necessary to rely on relevant standards and specifications in the power industry. The standards and specifications should be the summary of long-term practices and safety experiences in the industry, providing a basic framework for threshold setting. At the same time, combined with historical data, analyze the occurrence frequency and severity of data security incidents under different risk levels in the past operation of the power system to determine the acceptable critical values of risks in different dimensions. Also, consider the actual operating environment of the power system, such as the stability differences of different regional power grids and common types of network security threats. For environments with poor stability or high network security threats, appropriately lower the threshold. In addition, power domain experts adjust and optimize the threshold based on professional knowledge and practical operation experience to ensure that the preset risk threshold can effectively prevent potential risks without affecting the normal operation of the power system due to overly strict settings.

[0068] In the above calculation formula, an exponential decay mechanism is adopted. When the real-time risk R current >R threshold , the key aging period shortens according to the exponential law, and the higher the risk, the faster the aging decay. The sensitivity coefficient k of high-security-level devices is larger, and the risk response is more sensitive. If R current ≤R threshold , the formula degenerates to T new =T base ×e 0 =T base , maintaining the basic aging period.

[0069] In this embodiment, by means of the exponential decay mechanism, according to the real-time risk assessment value, the key aging period can be quickly shortened as the risk increases, achieving a sensitive response to risk changes and enhancing data security protection in a timely manner. The security level adaptation enables devices with different security levels to have corresponding device type sensitivity coefficients. High-security-level devices are more sensitive to risks, and their key aging period adjustments are more active, ensuring that important device data is more strictly protected. The threshold protection sets a reasonable boundary for key aging period adjustment by presetting the risk threshold, avoiding excessive adjustment due to risk fluctuations, and ensuring the stable operation of the power system while effectively preventing risks.

[0070] In some embodiments of the present invention, when a communication interruption of the key control center is detected, the data security terminal device will take a series of measures to ensure data security. The specific implementation methods are as follows:

[0071] The terminal device continuously monitors the TCP heartbeat packets with the key control center. If 3 consecutive cycles are lost, it is determined that the communication is interrupted. After triggering the interruption event, the device automatically switches to the local risk assessment mode and starts the local risk assessment cache module.

[0072] Use a circular buffer to store the risk assessment values for the last 24 hours, with a sampling interval of 5 minutes and a capacity of 288 records. Based on the current time point, take 12 risk assessment values within a preset time window (default 1 hour) forward, remove the outliers, and calculate the arithmetic mean, which is the average risk assessment value.

[0073] Calculate the local temporary key aging based on the basic key aging, the average risk assessment value, and the preset risk threshold. The calculation formula is:

[0074] ;

[0075] Where, represents the temporary key aging, represents the average risk assessment value.

[0076] In this embodiment, the average risk assessment value is calculated through a sliding window, which not only avoids the accidental fluctuations of a single risk assessment, such as instantaneous false alarms, but also can reflect the change of the risk trend. The calculation formula of the temporary key aging shares the basic key aging and the preset risk threshold parameters with the calculation formula of the dynamic key aging to ensure that there is no conflict in the policy switch after the communication is restored. The local cache and the sliding window calculation maintain the continuity of risk perception, avoid the "security blind area" during the communication interruption, and ensure that the key aging adjustment is synchronized with the real-time risk trend. Through the triple mechanisms of smoothing fluctuations by the average risk assessment value, formula coefficient constraint, and resource monitoring, it meets the real-time requirements of power terminal devices.

[0077] In some embodiments of the present invention, when detecting an advanced persistent threat attack, the system will dynamically adjust the device type sensitivity coefficient to enhance data security protection. The specific implementation method is as follows:

[0078] The system continuously monitors the security status of the target data security terminal device, identifies whether it is under an advanced persistent threat attack, which involves in-depth analysis of network traffic, device behavior, and system logs.

[0079] Once an advanced persistent threat attack is detected, the system will dynamically adjust the device type sensitivity coefficient according to the preset adjustment formula of the sensitivity coefficient. The adjusted sensitivity coefficient reflects the severity of the attack.

[0080] Using the adjusted sensitivity coefficient, the system recalculates the dynamic key aging to ensure that in a high-threat environment, the key aging can be quickly shortened, thereby enhancing the data security.

[0081] Among them, an advanced persistent threat refers to a highly concealed and long-term network attack behavior targeting specific targets. The following are its core characteristics and specific threat analysis in the power system:

[0082] Advanced nature: Attackers usually have the background of national support or professional hacker organizations; they use cutting-edge technologies such as zero-day vulnerabilities and customized malware;

[0083] Persistence: The attack cycle lasts for months or even years; it adopts multi-stage penetration: initial intrusion → lateral movement → persistent residence → data exfiltration;

[0084] Concealment: Disguised as normal traffic (such as HTTPS encrypted communication); using legitimate tools (such as PowerShell, WMI) to carry out attacks (fileless attacks);

[0085] Targeted: Specifically targeting critical infrastructures such as power and energy; pre-collecting intelligence on the target network topology and business systems;

[0086] Typical harms of advanced persistent threat attacks to the power system include stealing power grid operation data (such as load forecasting, dispatching instructions), obtaining device control protocols (such as IEC 61850 protocol), causing equipment overload by tampering with SCADA instructions, implanting logic bombs to cause misoperation of substation protection systems, encrypting power information system data to extort ransom, and destroying the order matching algorithm of the power market trading platform, etc.

[0087] More specifically, the calculation formula for dynamically adjusting the sensitivity coefficient of device types is:

[0088] ;

[0089] Among them, represents the sensitivity coefficient of the device type after dynamic adjustment, represents the sensitivity coefficient of the device type corresponding to the target data security terminal device, represents the number of attacks detected in the past preset time period.

[0090] In this embodiment, advanced persistent threat attacks usually rely on long-term penetration to probe system weaknesses, and the sublinear growth of k′ forces attackers to initiate exponentially more attack times to achieve the same destructive effect (such as increasing from 10 attacks to 1000 attacks to increase k′ to 4 times), significantly increasing the attack cost; this adjustment mechanism can quickly respond to a high-threat environment, shorten the key validity period by increasing the sensitivity coefficient, thereby enhancing data security, not only improving the system's defense ability, but also enhancing its flexibility and adaptability; by quickly adapting to threat changes, it can more effectively protect critical data and prevent potential security vulnerabilities from being exploited.

[0091] In some embodiments of the present invention, after receiving the aging adjustment command sent by the key control center, the target data security terminal device will perform multi-level verification to ensure the effectiveness and security of the command. The specific implementation is as follows:

[0092] Verify the compliance of the time format of the dynamic key aging: The device first checks the format of the received dynamic key aging. There is a preset standard time format specification inside the device. For example, the time format may be specified as a positive integer represented in seconds, or a format that conforms to the time representation rules of a specific power system. The device will compare the received dynamic key aging with these specifications. If the received dynamic key aging appears in a form such as a decimal (assuming it is not allowed), a negative number, or a chaotic format, it is determined that the time format does not meet the requirements, this verification fails, the subsequent verification stops, and the operation of step S110a is triggered. Only when the format of the dynamic key aging completely conforms to the preset specifications will it enter the next verification;

[0093] Verify whether the dynamic key aging meets the maximum tolerance aging and the minimum security aging corresponding to the device security level: Each device has corresponding maximum tolerance aging and minimum security aging ranges according to its security level. The device will obtain these thresholds from the security policy information stored in itself. For example, the maximum tolerance aging of a device with a low security level may be longer, and the minimum security aging is relatively shorter. While for a device with a high security level, it is the opposite. The device compares the received dynamic key aging with these thresholds. If the dynamic key aging is less than the minimum security aging, it may lead to frequent key replacement, affecting the device performance and data processing efficiency. If it is greater than the maximum tolerance aging, the data security cannot be effectively guaranteed. Once the dynamic key aging exceeds this range, this verification fails and step S110a is triggered. If it is within the range, the next verification continues;

[0094] Verify the matching degree between the dynamic key aging and the current data processing cycle of the device: The device will clarify its current data processing cycle, which is the time cycle rule for the device to perform operations such as data collection, processing, and transmission. For example, an intelligent electricity meter may collect electricity consumption data and upload it every certain period of time, and this time interval is its data processing cycle. The device will determine whether the dynamic key aging matches this data processing cycle. If the dynamic key aging is set unreasonably, resulting in the need to replace the key during the critical stage of data processing (such as during data encryption or transmission), it may interrupt the data processing process, causing data loss or errors. If there is such a mismatch, the verification fails and step S110a is triggered. If it matches, all multi-level verifications pass and step S110b is entered.

[0095] When any level of multi-level verification fails, the device will immediately trigger the recovery mechanism, i.e., step S110a; the device internally stores the information of the most recent valid key aging setting, which is recorded and updated each time the key aging is successfully updated; once the verification fails, the device quickly calls this stored information and restores the key aging to the previously successfully set state; this can ensure that when the device receives an inapplicable dynamic key aging, it will not fall into a state of data security risk or abnormal operation, guaranteeing that the device can continue to perform data security protection work with a reliable key aging and maintaining the stable operation of the power information system.

[0096] If all levels of multi-level verification pass, it indicates that the received dynamic key aging meets the device's requirements in terms of format, security level adaptability, and matching degree with the data processing cycle, etc.; at this time, the device will update its own key aging according to the received dynamic key aging, i.e., step S110b; the device writes the new dynamic key aging information into the corresponding storage area, overwriting the original key aging setting; thereafter, the device will perform operations such as key management and data encryption based on the new key aging to ensure that data can obtain the most appropriate security protection under the current power system operation environment and security risk situation, improving the security and integrity of the data.

[0097] In this embodiment, through multi-level verification, the dynamic key aging is strictly reviewed from multiple dimensions such as format, security level, and data processing cycle to ensure that the new key aging can adapt to the device's operation requirements and security requirements; the automatic recovery mechanism when the verification fails avoids abnormal device operation or data security accidents caused by incorrect key aging settings; and the update operation after the verification is successful enables the device to adjust the key aging in a timely manner according to system risk changes, enhancing the data protection ability, greatly improving the stability and reliability of the power information security protection system, and guaranteeing the security and integrity of power data in a complex and changeable environment.

[0098] As Figure 2 、 Figure 3 shown, the embodiment of the present invention provides a data key dynamic adjustment device for power information security protection. The device embodiment can be implemented through software, or through hardware or a combination of software and hardware. From the hardware level, as Figure 2 shown, it is a hardware architecture diagram of an electronic device where the data key dynamic adjustment device for power information security protection provided by the embodiment of the present invention is located. In addition to Figure 2 the shown processor, memory, network interface, and non-volatile memory, the electronic device where the device is located in the embodiment usually may also include other hardware, such as a forwarding chip responsible for processing packets, etc. Taking software implementation as an example, as Figure 3As shown, as a device in a logical sense, it is formed by reading the corresponding computer program in the non-volatile memory into the memory and running it through the CPU of the electronic device where it is located.

[0099] As Figure 3 shown, a data key dynamic adjustment device for power information security protection provided in this embodiment includes:

[0100] A power grid operation parameter acquisition module, configured to acquire power grid operation parameters of a target area in real time;

[0101] A multi-dimensional risk assessment module, based on a preset multi-dimensional risk assessment model, configured to perform dynamic risk assessment on the power grid operation parameters and generate a real-time risk assessment value;

[0102] A dynamic key aging calculation module, configured to determine the security level and basic key aging of the target data security terminal device according to the device type mapping table, and combine the real-time risk assessment value generated by the multi-dimensional risk assessment module and a preset risk threshold to calculate the dynamic key aging;

[0103] An aging adjustment command sending module, disposed in the key control center, configured to send an aging adjustment command including the dynamic key aging to the target data security terminal device;

[0104] A multi-level verification module, disposed in the target data security terminal device, configured to perform multi-level verification after receiving the aging adjustment command;

[0105] A key aging recovery module, disposed in the target data security terminal device, in response to any level of verification failure of the multi-level verification module during verification, configured to automatically restore the target data security terminal device to the most recent valid key aging setting;

[0106] A key aging update module, disposed in the target data security terminal device, in response to all levels of multi-level verification of the multi-level verification module passing, configured to enable the target data security terminal device to perform a key aging update operation.

[0107] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on a data key dynamic adjustment device for power information security protection. In other embodiments of the present invention, a data key dynamic adjustment device for power information security protection may include more or fewer components than those shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure can be implemented in hardware, software, or a combination of software and hardware.

[0108] For the information interaction, execution process, etc. between the modules in the above device, since they are based on the same concept as the method embodiments of the present invention, the specific content can be referred to the description in the method embodiments of the present invention, and will not be elaborated here.

[0109] An embodiment of the present invention further provides an electronic device, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, a data key dynamic adjustment method for power information security protection in any embodiment of the present invention is implemented.

[0110] An embodiment of the present invention further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the processor is enabled to execute a data key dynamic adjustment method for power information security protection in any embodiment of the present invention.

[0111] Specifically, a system or device equipped with a storage medium can be provided. Software program codes for implementing the functions in any one of the above embodiments are stored on the storage medium, and the computer (or CPU or MPU) of the system or device reads and executes the program codes stored on the storage medium.

[0112] In this case, the program code read from the storage medium itself can implement the functions in any one of the above embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of the present invention.

[0113] Embodiments of the storage medium for providing program codes include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code can be downloaded from a server computer via a communication network.

[0114] In addition, it should be clear that not only can the actual operations be completed in part or in whole by executing the program code read by the computer, but also by means of instructions based on the program code to make the operating system, etc. operating on the computer, so as to implement the functions in any one of the above embodiments.

[0115] In addition, it can be understood that the program code read from the storage medium is written into the memory provided in the expansion board inserted into the computer or into the memory provided in the expansion module connected to the computer. Subsequently, based on the instructions of the program code, the CPU, etc. installed on the expansion board or the expansion module execute part and all of the actual operations, so as to implement the functions in any one of the above embodiments.

[0116] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device.

[0117] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including those of the above method embodiments; and the foregoing storage medium includes various media that can store program codes, such as ROM, RAM, magnetic disks or optical discs.

[0118] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data key dynamic adjustment method for power information security protection, which is applied to a data key management system including a key control center and data security terminal devices, and is characterized in that The method includes: Collecting the power grid operation parameters of the target area in real time; Performing dynamic risk assessment on the power grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; Determining the security level and basic key validity period of the target data security terminal device according to the device type mapping table, and calculating the dynamic key validity period by combining the real-time risk assessment value and the preset risk threshold; The key control center sends a validity period adjustment command containing the dynamic key validity period to the target data security terminal device; After receiving the validity period adjustment command, the target data security terminal device performs multi-level verification; In response to any level of verification failure in the multi-level verification, the target data security terminal device automatically reverts to the last valid key validity period setting; In response to all levels of verification passing, the target data security terminal device performs a key validity period update operation; The calculation formula for the dynamic key validity period is: ; Among them, represents the dynamic key aging,[ represents the basic key aging,[ represents the real-time risk assessment value,[ represents the preset risk threshold, and k represents the device type sensitivity coefficient corresponding to the security level of the target data security terminal device. The higher the security level, the greater the device type sensitivity coefficient; In response to detecting a communication interruption of the key control center, the data security terminal device performs: Enabling the local risk assessment cache module and calculating the temporary key validity period using the average risk assessment value within the most recent preset time window; The calculation formula for the temporary key validity period is: ; Among them, represents the temporary key expiration time, represents the average risk assessment value; The temporary key validity period calculation formula shares the basic key validity period and preset risk threshold parameters with the dynamic key validity period calculation formula to ensure conflict-free policy switching after communication is restored.

2. The data key dynamic adjustment method for power information security protection according to claim 1, characterized in that, The multi-level verification includes: Verifying the compliance of the time format of the dynamic key validity period; Verifying whether the dynamic key validity period meets the maximum tolerable validity period and minimum security validity period corresponding to the device security level; Verifying the matching degree between the dynamic key validity period and the current data processing cycle of the device.

3. The data key dynamic adjustment method for power information security protection according to claim 2, characterized in that, The power grid operation parameters at least include the regional power grid stability index, the network security threat level, and the real-time performance load of the target data security terminal device; The multi-dimensional risk assessment model is set with a power grid stability weight coefficient, a security threat weight coefficient, and a device load correction factor.

4. The data key dynamic adjustment method for power information security protection according to claim 1, wherein In response to detecting that the target data security terminal device is under an advanced persistent threat attack, dynamically adjust the device type sensitivity coefficient and calculate the dynamic key validity period using the dynamically adjusted device type sensitivity coefficient.

5. The data key dynamic adjustment method for power information security protection according to claim 4, characterized in that, Wherein, The dynamic adjustment formula for the device type sensitivity coefficient is: ; Among them, represents the device type sensitivity coefficient after dynamic adjustment, represents the device type sensitivity coefficient corresponding to the target data security terminal device, represents the number of attacks detected in the past preset time period.

6. A data key dynamic adjustment device for power information security protection, the device is applied to the data key dynamic adjustment method for power information security protection as described in claim 1, and is characterized in that, The device includes: A power grid operation parameter acquisition module for collecting the power grid operation parameters of the target area in real time; A multi-dimensional risk assessment module for performing dynamic risk assessment on the power grid operation parameters based on a preset multi-dimensional risk assessment model to generate a real-time risk assessment value; A dynamic key validity period calculation module for determining the security level and basic key validity period of the target data security terminal device according to the device type mapping table, and calculating the dynamic key validity period by combining the real-time risk assessment value generated by the multi-dimensional risk assessment module and the preset risk threshold; A validity period adjustment command sending module provided in the key control center for sending a validity period adjustment command containing the dynamic key validity period to the target data security terminal device; The multi-level verification module is disposed in the target data security terminal device and is used to perform multi-level verification after receiving the aging adjustment command; The key aging recovery module is disposed in the target data security terminal device. In response to any level of verification failure of the multi-level verification module during verification, it is used to automatically restore the target data security terminal device to the last effective key aging setting; The key aging update module is disposed in the target data security terminal device. In response to all levels of multi-level verification of the multi-level verification module passing, it is used to make the target data security terminal device perform a key aging update operation.

7. An electronic device, comprising a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the transceiver, the memory, and the processor are connected through the bus, and is characterized in that, When the computer program is executed by the processor, it implements the steps in the method according to any one of claims 1-5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps in the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Communication information security risk early warning management and control method and system based on big data

    CN117955712A

  • Secure data storage system based on cloud computing

    CN119135445A

Cited By

  • Power information dynamic encryption collaborative protection method and system

    CN121309221A

  • A power information dynamic encryption cooperative protection method and system

    CN121309221B