Load regulation and control safety protection method and system based on privacy calculation

Through the method based on privacy calculation, certificate information is collected and verified, trusted equipment is screened and target edge equipment is determined, which solves the problem of data authenticity and regulation behavior deviation during load regulation, and achieves more efficient and accurate load regulation and grid optimization.

CN119994929APending Publication Date: 2025-05-13STATE GRID ELECTRIC POWER RES INST +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411785433.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing load regulation safety protection methods cannot guarantee the authenticity of data during load regulation, resulting in the deviation of regulation behavior from expectations, seriously affecting the safety and stability of distributed power systems.

Method used

The load regulation security protection method based on privacy calculation is adopted, and a list of trusted devices is established by collecting and verifying certificate information, a trusted device is selected and a data transmission channel is established with them, and the target edge device is determined based on the data verification matrix and model, and the target regulation information is generated and applied.

Benefits of technology

Effectively identify trusted equipment, prevent access to unauthorized equipment, ensure the credibility and accuracy of data analysis, improve the efficiency and accuracy of load regulation, optimize power grid operation, and reduce the risk of load imbalance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119994929A_ABST
    Figure CN119994929A_ABST
Patent Text Reader

Abstract

The invention discloses a load regulation and control safety protection method and system based on privacy calculation, and relates to the technical field of information security, and the method comprises the steps: collecting certificate information, carrying out the identity verification of the certificate information, obtaining an identity verification result, obtaining load regulation and control information based on the identity verification result, and carrying out the safety protection of the load regulation and control. Establishing a data verification matrix and determining a verification vector according to the load regulation and control information, determining a target edge device through a data verification model, determining the load regulation and control information, generating target regulation and control information, and carrying out load regulation and control on the target edge device. According to the method, the security of the system is improved, the privacy of data is enhanced, the accuracy of load control is improved, and distributed load regulation and control are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and specifically to a load regulation security protection method and system based on privacy computing. Background Art

[0002] In a distributed power system, when edge devices are regulating power loads, they can send load regulation information to the cloud platform, seeking the cloud platform to regulate loads based on the load regulation information. When regulating, usually the cloud platform and edge devices perform separate verification, that is, the cloud platform or edge device independently verifies the source of information. When the information transmitted by the edge device is tampered with or hijacked, the regulation behavior will deviate from expectations, seriously affecting the security of the distributed power system and being detrimental to the stable operation of the power system.

[0003] The above contents are only used to assist in understanding the technical solution of the present application and do not constitute an admission that the above contents are prior art. Summary of the invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by the present invention is: the existing load control safety protection method has the technical problem that the control information during load control cannot guarantee the authenticity of the data, and how to solve the problem that the control behavior deviates from expectations.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: a load regulation and security protection method based on privacy computing, comprising:

[0007] As a preferred solution of the load regulation security protection method based on privacy computing described in the present invention, wherein: collecting first feature data of a first object, verifying the first feature data of the first object, and obtaining a first verification result;

[0008] Based on the first verification result, the first target is screened, a trusted first object is obtained, and a transmission is established with the trusted first object to obtain the first target information;

[0009] Performing a first adjustment process on the first object according to the first target information, and determining the first target object through the first adjustment process;

[0010] While obtaining first target effect data according to the first target, self-checking is performed on the first target object.

[0011] As a preferred solution of the load regulation security protection method based on privacy computing described in the present invention, the first verification process includes collecting the first feature data of each first object and comparing the first feature data of each first object.

[0012] As a preferred solution of the load regulation and security protection method based on privacy computing described in the present invention, the obtaining of the first target information includes establishing a verification matrix to determine a trusted first object, and obtaining the first target information by screening the first verification result and the matrix.

[0013] As a preferred solution of the load regulation security protection method based on privacy computing described in the present invention, the first target screening includes: sending the first target parameter to each of the target first objects so that the first target model of the target first object is updated to the first target parameter.

[0014] As a preferred solution of the load regulation and security protection method based on privacy computing described in the present invention, wherein: the first adjustment processing includes optimizing the first object parameter by comparing it with the first target parameter to determine the first target object parameter.

[0015] As a preferred solution of the load regulation and security protection method based on privacy computing described in the present invention, wherein: obtaining the first target object parameters includes sending data to each first target object and obtaining feedback, optimizing the first object parameters through feedback, and obtaining the first target object parameters.

[0016] As a preferred solution of the load regulation and security protection method based on privacy computing described in the present invention, the self-check process includes, when information monitoring shows an abnormal state, disconnecting the data connection with the first object, connecting the first object with the backup, and synchronizing the update information.

[0017] As a preferred solution of the load regulation and security protection system based on privacy computing described in the present invention, it includes: an identity authentication module, a channel connection module, a device verification module, and a load regulation module.

[0018] The identity authentication module is used to receive the certificate information of the cloud platform and each edge device, authenticate the certificate information of the cloud platform and each edge device, and obtain the identity authentication result.

[0019] A channel connection module is used to determine a trusted edge device based on the identity authentication result of the cloud platform when the identity authentication result of the cloud platform is normal, establish a data transmission channel with the trusted edge device, and obtain load regulation information sent by the edge device to the cloud platform based on the data transmission channel.

[0020] The device verification module is used to establish a data verification matrix according to the load regulation information, determine the verification vector of each of the trusted edge devices according to the data verification matrix, verify the verification vector based on the data verification model, and determine the target edge device.

[0021] The load control module is used to determine the load control information of the target edge device, generate target control information according to the load control information based on the load control model, and perform load control on the target edge device based on the target control information.

[0022] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement a load regulation and security protection method and system based on privacy computing.

[0023] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a load regulation and security protection method and system based on privacy computing.

[0024] Beneficial effects of the present invention: The load regulation security protection method based on privacy computing provided by the present invention collects certificate information, authenticates the certificate information, and obtains an authentication result. Through the identity authentication mechanism based on digital certificates in this scheme, it is possible to effectively identify trusted devices, prevent unauthorized devices from accessing the system, and ensure the security and reliability of the system from the source.

[0025] Based on the identity authentication result, load regulation information is obtained; through this solution, load regulation information of the device is collected only when the identity authentication is passed, avoiding interference from illegal device data and ensuring the credibility and accuracy of subsequent data analysis.

[0026] A data verification matrix is ​​established based on the load control information and the verification vector is determined. The target edge device is determined through the data verification model. The optimal target device is dynamically screened through the data verification matrix and model of this solution, which realizes the intelligent evaluation and selection of edge device performance and improves the efficiency and accuracy of load control.

[0027] Determine load control information, generate target control information, and perform load control on the target edge device; through this solution, a refined control strategy for the target device is generated, which can dynamically adjust load distribution, optimize the overall performance of power grid operation, reduce the risk of load imbalance, and improve the economy and stability of the system. The present invention achieves better results in equipment screening, control, control accuracy and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0029] Figure 1 An overall flow chart of a load regulation and security protection method based on privacy computing provided for the first embodiment of the present invention.

[0030] Figure 2 A schematic diagram of trusted edge device authentication for a load regulation security protection method based on privacy computing provided in the second embodiment of the present invention.

[0031] Figure 3 A connection relationship diagram between a cloud platform and a backup cloud platform of a load regulation and security protection method based on privacy computing provided in the second embodiment of the present invention.

[0032] Figure 4 A schematic diagram of the module structure of a load regulation and security protection system based on privacy computing provided in the fourth embodiment of the present invention.

[0033] Figure 5 A schematic diagram of the device structure of a load regulation and security protection method based on privacy computing provided in the second embodiment of the present invention. DETAILED DESCRIPTION

[0034] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0035] Example 1, reference Figure 1 , which is an embodiment of the present invention, provides a load regulation security protection method based on privacy computing, including:

[0036] S1: Collect first feature data of a first object, verify the first feature data of the first object, and obtain a first verification result.

[0037] Specifically: the first characteristic data includes various parameters of the first object itself. In this embodiment: the first object is specifically a cloud platform and each edge device, and the first characteristic data is the certificate information of the cloud platform and each edge device. The certificate information of the cloud platform and each edge device is collected, and the certificate information of the cloud platform and each edge device is authenticated to obtain the authentication result.

[0038] In this embodiment, the first object refers to the cloud platform and each edge device. Furthermore, the first characteristic data includes the certificate information and identity verification result of the first object. The certificate information includes the device ID, device type, device authorization code, etc. The identity verification result includes the verification status, verification time, verification method, etc.

[0039] In an optional embodiment, the first object may also be an IoT device or a sensor. For these two devices, their quantitative characteristic data may include the following operating state parameters and design parameters: IoT device, operating state parameters: network connection state, device temperature, device load, signal strength, etc. Design parameters: communication protocol type, transmission rate, battery life, etc. Sensor, operating state parameters: acquisition frequency, sensor output, data quality, operating temperature, etc. Design parameters: range, accuracy, resolution, response time, etc.

[0040] S2: Screen the first target based on the first verification result, obtain the trusted first object and establish transmission with the trusted first object to obtain the first target information.

[0041] Specifically: the first target information includes information required by the first object to achieve the first target. In this embodiment: the first target information is specifically load regulation information, and the first verification result is the above-mentioned identity authentication result. When the identity authentication result of the cloud platform is normal, a trusted edge device is determined based on the identity authentication result, and a data transmission channel is established with the trusted edge device, and the load regulation information sent by the edge device to the cloud platform is obtained based on the data transmission channel.

[0042] In this embodiment, the first target refers to load regulation. Furthermore, the first target information includes load demand data and regulation strategy data of the load regulation information. The load demand data includes real-time load demand, expected load change trend, historical load data, etc. The regulation strategy data includes regulation target, regulation mode, priority strategy, regulation time window, etc.

[0043] In an optional embodiment, the first target information may also be load regulation information or safety monitoring information. For these two types of target information, the quantitative characteristic data may include the following performance parameters and operating status parameters: Load regulation information, performance parameters: load adjustment rate, load stability, load change response time, etc. Operating status parameters: current load, equipment power consumption, regulating equipment status, etc. Safety monitoring information, performance parameters: fault detection response time, system safety index, alarm trigger rate, etc. Operating status parameters: sensor status, alarm record, system load status, etc.

[0044] S3: performing a first adjustment process on the first object according to the first target information, and determining the first target object through the first adjustment process.

[0045] Specifically: the first target object includes the object that the first object determines to complete the first target through the first adjustment process. In this embodiment: the first adjustment process is specifically to verify the verification vector based on the data verification model, and the first target object is the edge device determined by the data verification matrix. A data verification matrix is ​​established according to the load control information, and the verification vector of each of the trusted edge devices is determined according to the data verification matrix. The verification vector is verified based on the data verification model to determine the target edge device.

[0046] In this embodiment, the first target information refers to load regulation information. Furthermore, the first adjustment process includes model construction of the data verification model and verification of the verification vector. Model construction includes verification algorithm, model parameter setting, data input format, etc. Verification of the verification vector includes verification process, verification result, verification timestamp, etc.

[0047] In an optional embodiment, the first target information may also be load forecast information or power distribution information. For these two types of target information, the quantitative characteristic data may include the following performance parameters and operating status parameters: Load forecast information, performance parameters: forecast load error, forecast accuracy, forecast update frequency, etc. Operating status parameters: actual load, load change rate, load regulation response time, etc. Power distribution information, performance parameters: power distribution ratio, power balance error, response speed, etc. Operating status parameters: power system load, power transmission efficiency, system stability, etc.

[0048] S4: performing a self-check on the first target object while obtaining the first target effect data according to the first target.

[0049] Specifically: the obtaining of the first target effect data includes generating the first target information according to the first object information. In the present embodiment: the first target effect data is specifically the load control information of the target edge device, the load control information of the target edge device is determined, the target control information is generated according to the load control information based on the load control model, and the target edge device is load controlled based on the target control information. The self-check process is specifically: the self-check information is detected, and when the self-check information is abnormal status information, the data connection between the cloud platform and each of the edge devices is disconnected, and the data connection between the backup cloud platform and each of the edge devices is restored. The backup cloud platform and the cloud platform are connected through a backup data channel. When the data of the cloud platform or the backup cloud platform is updated, a data update log is generated, and the data update log is synchronized when the data channel between the cloud platform and the backup cloud platform is normally connected.

[0050] In this embodiment, the first target effect data refers to the load regulation information of the target edge device. Further, the load regulation information includes the regulation strategy and regulation status of the target edge device. The regulation strategy includes device power, operation mode, etc. The regulation status includes expected regulation, whether it is effective, etc.

[0051] In an optional embodiment, the first target effect data may also be heating effect data or pressure regulation effect data. For these two types of data, the quantitative characteristic data may include the following performance parameters and performance parameters: Heating effect data, performance parameters: heating rate, target temperature reaching time, uniformity parameters, etc. Operating state parameters: power consumption, heat loss, equipment state, etc. of the heating equipment. Pressure regulation effect data, performance parameters: pressure stability, regulation time, pressure relief efficiency, etc. Operating state parameters: pipeline pressure difference, valve opening degree, system load state, etc.

[0052] Embodiment 2 is an embodiment of the present invention, which provides an algorithm implementation process of a load regulation security protection method for privacy computing, including:

[0053] S1: The cloud platform is a cloud server used to centrally process various edge devices. It is the data processing center of the distributed power system. The edge device refers to the power load end. The cloud platform and each edge device contain CA certificates issued by a third-party CA organization. The certificate information includes the issuer, validity period, owner and other information. The identity authentication result refers to the verification result of the CA certificate.

[0054] It can be understood that the load regulation and security protection equipment based on privacy computing can be deployed inside the cloud platform or outside the cloud platform, and data can be transmitted between the load regulation and security protection equipment based on privacy computing and the cloud platform and / or between each edge device through wired and / or wireless means.

[0055] In the specific implementation, information for obtaining certificates can be sent to the cloud platform and each edge device corresponding to the cloud platform, so that the cloud platform and each edge device can send their own CA certificate information based on the information for obtaining their certificates. At this time, the obtained CA certificate information can be authenticated. First, the issuer is detected to determine whether it is a trusted issuer. After determining that the issuer is trustworthy, the validity period can be confirmed according to the current time, and the cloud platform or each edge device corresponding to the CA certificate that is still within the validity period can be determined as a trusted device, and the result of identity authentication passing is output. When the verification fails in any link, the result of identity authentication failure is output.

[0056] In a feasible implementation manner, the steps of receiving the certificate information of the cloud platform and each edge device, performing identity authentication on the cloud platform and each edge device certificate information, and obtaining the identity authentication result include:

[0057] Establishing an identity authentication channel with the cloud platform and each edge device, and obtaining certificate information of the cloud platform and each edge device based on the identity authentication channel;

[0058] Comparing the certificate information with pre-stored trusted entity information to obtain a comparison result;

[0059] When the comparison result is a comparison failure, the certificate information is verified online to obtain a verification result;

[0060] The comparison result is combined with the verification result to obtain an identity verification result.

[0061] It should be noted that the authentication channel refers to the data transmission channel used to connect the cloud platform and various edge devices, and the information transmission channel is dedicated to transmitting certificate information. The trusted entity information refers to the loaded CA certificate information that records the cloud platform and various edge devices.

[0062] In a specific implementation, a request message for establishing an authentication channel is sent to the cloud platform and each edge device. The cloud platform and each edge device can verify the received request message for establishing an authentication channel. After successful verification, the information of agreeing to establish an authentication channel can be fed back to the load regulation and security protection device based on privacy computing. After receiving the information of agreeing to establish an authentication channel from the load regulation and security protection device based on privacy computing, the authentication channel can be established with the cloud platform and each edge device, and the CA certificate information of the cloud platform or each edge device can be sent in the authentication channel. The certificate information is compared with the pre-stored trusted entity information to obtain a comparison result. The pre-stored trusted entity information is the valid certificate information of the CA certificate that has been obtained and verified before. When the obtained certificate information is consistent with the trusted entity information after comparison, a successful comparison result can be obtained. If the obtained certificate information is inconsistent with the trusted entity information after comparison, the CA certificate information can be verified in the form of online verification to obtain a verification result. The comparison result is combined with the verification result to obtain the identity authentication result. That is to say, if the verification based on the trusted entity information is successful, the identity authentication is successful. If the verification based on the trusted entity information fails, the CA certificate is verified online. If the online verification is successful, the information of successful identity authentication is output. If the online verification fails, the information of failed identity authentication is output.

[0063] It should be noted that the certificate information of the cloud platform and each edge device is received, and identity authentication is performed on the certificate information of the cloud platform and each edge device to obtain an identity authentication result.

[0064] S2: A trusted edge device refers to an edge device that has passed identity authentication. A data transmission channel refers to a data channel dedicated to transmitting load control information between the cloud platform and each edge device. The load control information is the load control information generated by each edge device based on local data or the load control information sent by the cloud platform based on the control information of each edge device.

[0065] In a specific implementation, the identity authentication result of the cloud platform can be verified. When the identity authentication result of the cloud platform is normal, the edge device with a successfully authenticated identity authentication result is identified as a trusted edge device, and a data transmission channel is established with the trusted edge device. Based on the data transmission channel, the load regulation information sent by the edge device to the cloud platform is obtained.

[0066] It should be noted that when the identity authentication result of the cloud platform is normal, a trusted edge device is determined based on the identity authentication result, and a data transmission channel is established with the trusted edge device, and the load control information sent by the edge device to the cloud platform is obtained based on the data transmission channel.

[0067] S3: The data verification matrix is ​​a collection used to record load regulation information. The verification vector is used to measure the authentication results of the current trusted edge device for other trusted edges. The target edge device refers to the edge device that is finally determined to perform load regulation.

[0068] In a specific implementation, when load regulation information is received, the received load regulation information can be added to a data verification matrix. For ease of explanation, four trusted edge nodes can be taken as an example to establish a data verification matrix as shown in Table 1 based on the load regulation information of each trusted edge node.

[0069] Table 1

[0070] Device 1 Device 2 Device 3 Device 4 Device 1 X1 X1 X1 a Device 2 X2 X2 X2 b Device 3 X3 X3 X3 c Device 4 d e f g

[0071] The data verification matrix shown in Table 1 can be obtained, and the verification vectors of each trusted edge device can be obtained in sequence, such as the verification vector of trusted edge device 2 can be expressed as (X2, X2, X2, b). The verification vectors of all trusted edge devices are obtained in a similar manner, and the target edge device is determined based on the verification vectors of all trusted edge devices.

[0072] In a feasible implementation manner, the step of establishing a data verification matrix according to the load regulation information, determining a verification vector of each of the trusted edge devices according to the data verification matrix, verifying the verification vector based on a data verification model, and determining a target edge device includes:

[0073] Determine a first trusted edge device and a second trusted edge device based on the load regulation information, wherein the second trusted edge device is all trusted edge devices except the first trusted edge device;

[0074] Acquire first verification data sent by the first trusted edge device to the cloud platform and second verification data sent by the first trusted edge device and received by the second trusted device;

[0075] Establishing a data verification matrix according to the first verification data and the second verification data, and obtaining verification vectors of each of the trusted edge devices based on the data verification matrix;

[0076] Verifying the verification vector, determining vector features of the verification vector, and determining the number of features of the same vector features in the vector features;

[0077] When the number of features is greater than a preset number, the trusted authentication device corresponding to the same vector feature is determined as the target edge device.

[0078] It should be noted that the first trusted edge device refers to the currently verified trusted edge device, and the second trusted edge device refers to all edge devices except the currently verified trusted edge device. The first verification data refers to the verification data sent by the first trusted edge device to the cloud platform, and the second verification data refers to the verification data sent by the first trusted edge device to the second trusted edge device.

[0079] In a specific implementation, after the cloud platform receives the load regulation information sent by each trusted edge device, it can form an information pair from the obtained load regulation information and each trusted edge device, and form a load regulation information with the information pair, and randomly select an information pair from the load regulation information as the first trusted edge device, so that other trusted edge devices except the first trusted edge device are used as the second trusted edge device. At this time, the first verification data A sent by the first trusted edge device to the cloud platform can be obtained. When the first trusted edge device sends the first verification data A to the cloud platform, it can also send the second verification data X1~Xn to each second edge device, where n is the number of second edge devices. Take n=3 as an example for explanation. At this time, assuming that the first trusted edge device is S1, the second trusted devices are S2~S4. Since the proportion of malicious edge devices and faulty edge devices M in all edge devices N is N>>3M, when making a judgment, it can ensure that the correct data can occupy a dominant position. Therefore, at this time, it can be assumed that the trusted edge device S4 is a malicious edge device or a faulty edge device, and the second trusted edge device S2~S4 receives the second verification data X1~X3 sent by the first trusted edge device. The second verification data sent by the first edge device and received by the cloud platform is Y1~Y3. Therefore, the obtained data verification matrix can be expressed as Table 2:

[0080] Table 2

[0081] S1 S2 S3 S4 A Y1 Y2 Y3

[0082] If the trusted edge device is a normal edge device, the first verification data or the second verification data sent is consistent, and if the trusted edge device is a malicious or faulty edge device, the first verification data or the second verification data sent is chaotic. Therefore, when the first edge device is normal, the obtained first verification data A and the second verification data X1~X3 are the same. When the second trusted edge device sends the second verification data sent by the first trusted edge device to the cloud platform, since S1 and S2 are normal edge devices, it can be determined that the sent Y1 and Y2 are also A, and when S3 is a malicious or faulty edge device, the Y3 it sends is not A, but any other value, represented by a here. Therefore, for the cloud platform, the data verification matrix of the first edge device it obtains is shown in Table 3.

[0083] Table 3

[0084]

[0085]

[0086] At this time, the verification vector of the first edge device can be obtained as (A, A, A, a). The verification vectors of all trusted edge devices can be obtained in the same way. Figure 2 , Figure 2 The schematic diagram of trusted edge device authentication is shown in Table 4.

[0087] Table 4

[0088] Cloud Platform S1 S2 S3 S4 S1 A - A A a S2 B B - B b S3 C C C - c S4 d e f g -

[0089] At this time, the verification vector can be verified to determine the vector features of the verification vector. Specifically, the vector eigenvalue can be determined according to the formula, where is the vector eigenvalue, is the unit matrix, and A is the verification vector. At the same time, the number of identical vector features in a verification vector can be determined. When the number of features is greater than the preset number, the trusted authentication device corresponding to the identical vector features is the target edge device.

[0090] It should be noted that a data verification matrix is ​​established according to the load regulation information, and a verification vector of each of the trusted edge devices is determined according to the data verification matrix. The verification vector is verified based on a data verification model to determine the target edge device.

[0091] S4: Target control information refers to the load control information generated by the cloud platform based on the load control information of the target edge device. The target control information is the actual scheduling information of the cloud platform for the edge device.

[0092] In a specific implementation, when determining the target control information, the target control information can be generated based on the load control information of the target edge device and based on the load control model. Specifically, the load control information is the local data of the edge device processed by the model, and the load control information of the current edge device is calculated.

[0093] In a feasible implementation manner, the step of determining the load control information of the target edge device, generating target control information according to the load control information based on a load control model, and performing load control on the target edge device based on the target control information also includes:

[0094] Obtaining a load scheduling parameter of the target edge device, where the load scheduling parameter is a model parameter of a load scheduling model trained based on local data of the target edge device;

[0095] Acquire encrypted sample data of each of the target edge devices, and optimize the load scheduling parameters based on the encrypted sample data to obtain target load scheduling parameters;

[0096] The target load scheduling parameters are sent to each of the target edge devices, so that the load regulation model in the target edge device is updated to the target load scheduling parameters.

[0097] It should be noted that the load scheduling parameters refer to the model parameters that determine the load control information in the edge device based on the local data. They can be obtained by training the local data or by the parameters sent back by the cloud platform. The encrypted sample data is the data obtained by encrypting the local data of the edge device, and the target load scheduling parameters are generated by the cloud platform based on the encrypted sample data provided by each target edge device.

[0098] In a specific implementation, the target edge device includes a training model, which can obtain load scheduling parameters based on local sample data. Therefore, the load scheduling parameters of the target edge device can be obtained. The load scheduling parameters are model parameters of the load scheduling model obtained by training based on the local data of the target edge device. At the same time, the encrypted sample data of each target edge device is obtained, and the load scheduling parameters are optimized based on the encrypted sample data. The target load scheduling parameters are obtained through a gradient descent algorithm, and the target load scheduling parameters are sent to each target edge device to update the load control model in the target edge device to the target load scheduling parameters.

[0099] In a feasible implementation manner, the step of obtaining the encrypted sample data of each of the target edge devices, optimizing the load scheduling parameters based on the encrypted sample data, and obtaining the target load scheduling parameters includes:

[0100] Obtaining encrypted sample data of each of the target edge devices;

[0101] Determining a loss value of the encrypted sample data based on a preset loss function;

[0102] By back-propagating the loss value, a gradient value corresponding to the loss value is obtained.

[0103] The gradient values ​​are screened, the encrypted sample data whose gradient values ​​are greater than the preset gradient values ​​are used as optimization values, and the load scheduling parameters are optimized according to the optimization values ​​to obtain target load scheduling parameters.

[0104] In the specific implementation, sample data is collected from each target edge device and encrypted to ensure data security and privacy. A loss function MSE is defined to evaluate the prediction performance of the model under the current load scheduling parameters. The encrypted sample data and the current load scheduling parameters are used to calculate the loss value through the model. The loss value is used to back-propagate the model and calculate the gradient value of each parameter. The weight gradient can be expressed as:

[0105]

[0106] The bias gradient is expressed as:

[0107]

[0108] Among them, z is the input of the current layer, x is the activation value of the previous layer, It is the gradient of the loss function with respect to the input of the current layer, which needs to be obtained by multiplying the gradient passed from the next layer with the derivative of the activation function of the current layer.

[0109] The back propagation algorithm is an algorithm used to learn parameters in neural networks. It updates parameters based on the partial derivative of the loss function for each parameter. The obtained gradient values ​​are screened, and sample data with gradient values ​​greater than the preset threshold are retained. The encrypted sample data after screening is used to update the load scheduling parameters according to their corresponding gradient values. At this time, the Adam algorithm can be used to apply the updated load scheduling parameters to the model to complete a round of optimization. The above process is repeated until the model converges or reaches the predetermined number of iterations.

[0110] In a feasible implementation manner, the step of obtaining the encrypted sample data of each of the target edge devices includes:

[0111] Sending a data acquisition instruction to each of the target edge devices, so that each of the target edge devices retrieves a homomorphic encryption key based on the data acquisition instruction, and homomorphically encrypts local data based on the homomorphic encryption key to obtain encrypted sample data and feed it back;

[0112] Receive the encrypted sample data fed back by each of the target edge devices.

[0113] It should be noted that the homomorphic encryption key is a tool for data encryption. Homomorphic encryption, including additive encryption and multiplicative encryption, is an encryption method that can obtain homomorphic encrypted data for data processing without affecting the original data.

[0114] In the specific implementation, a data acquisition instruction is sent to each target edge device, so that each target edge device retrieves the homomorphic encryption key based on the data acquisition instruction, wherein the homomorphic encryption keys between the cloud platform and each edge device are different from each other. When it is determined that the homomorphic encryption key is obtained, the edge device can encrypt the local data to obtain encrypted sample data. At the same time, the load scheduling parameters obtained by the edge device can also be homomorphically encrypted and fed back.

[0115] In a feasible implementation manner, the load regulation security protection method based on privacy computing further includes:

[0116] Obtain self-check information of the cloud platform;

[0117] The self-test information is detected. When the self-test information is abnormal status information, the data connection between the cloud platform and each of the edge devices is disconnected, and the data connection between the backup cloud platform and each of the edge devices is restored. The backup cloud platform and the cloud platform are connected through a backup data channel. When the data of the cloud platform or the backup cloud platform is updated, a data update log is generated, and the data update log is synchronized when the data channel between the cloud platform and the backup cloud platform is normally connected.

[0118] It should be noted that self-check information refers to the cloud platform's detection information on its own operating status. The backup cloud platform and the cloud platform have consistent functions and data. When the cloud platform performs load regulation normally, the relevant data generated are transmitted to the backup cloud platform through the backup data channel between the backup cloud platform and the backup cloud platform. The update log refers to the data change information.

[0119] In the specific implementation, refer to Figure 3 , Figure 3 This is a connection diagram between the cloud platform and the backup cloud platform. When the cloud platform is operating normally, the data generated by the cloud platform can be transmitted to the backup cloud platform through the backup data channel for backup. When the cloud platform fails, the data connection between the cloud platform and each edge device can be disconnected, and the data connection between the backup cloud platform and each edge device can be restored. At this time, it is transformed into providing control services for the backup cloud platform. At this time, the data change information generated by the backup cloud platform is saved in the form of an update log. When the cloud platform is restored to normal, the data update log can be synchronized when the data channel between the cloud platform and the backup cloud platform is normally connected, thereby improving the redundant fault tolerance capability of the platform.

[0120] It should be noted that the load regulation information of the target edge device is determined, target regulation information is generated according to the load regulation information based on a load regulation model, and load regulation is performed on the target edge device based on the target regulation information.

[0121] refer to Figure 5 , which shows a schematic diagram of the structure of a load regulation safety protection device based on privacy computing suitable for implementing the embodiment of the present application. The load regulation safety protection device based on privacy computing in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The load regulation safety protection device based on privacy computing shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0122] like Figure 5 As shown, the load regulation safety protection device based on privacy computing may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 to the random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the load regulation safety protection device based on privacy computing are also stored. The processing device 1001, ROM1002 and RAM1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 1003 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 1009. The communication device 1009 can allow the load regulation safety protection device based on privacy computing to communicate wirelessly or wired with other devices to exchange data. Although the figure shows a load regulation safety protection device based on privacy computing with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or have instead.

[0123] Example 3 is an embodiment of the present invention, which provides a load regulation and security protection method based on privacy computing. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0124] First, in order to verify the innovation and practicality of the invention, an experimental study was conducted on the load regulation security protection method. The experiment was conducted in a simulated industrial smart grid environment, and the equipment used included a cloud platform server, multiple edge devices (numbered E1 to E5), and an identity authentication module and a load regulation module. The test scenario simulates the security of data interaction and the efficiency of load regulation during the collaborative work of multiple devices, focusing on verifying the impact of identity authentication, data verification, and load regulation strategy generation on system stability and reliability.

[0125] The test process is as follows:

[0126] Each edge device and cloud platform is simulated to have unique digital certificate information (formatted in accordance with the X.509 standard), which contains the device number, encryption public key and related features. After receiving the certificate, the server authenticates each certificate through the authentication module based on the PKI (public key infrastructure) system, generates verification results, and screens out trusted devices. The screening of trusted devices is completed by checking whether the certificate is expired, revoked, and whether it meets the expected device list.

[0127] For trusted devices that have passed identity authentication (such as E1, E3, and E5), the system obtains their real-time operating data based on an encrypted transmission channel, including voltage, current, equipment load and other control parameters. Devices that have not passed identity authentication (such as E2 and E4) are isolated and cannot participate in subsequent data processing.

[0128] According to the collected load control information, a data verification matrix is ​​established. The eigenvalue vector of each device (including load offset, response time, etc.) is extracted through the verification matrix, and the data verification model is used to verify the credibility. The verification model is used to select devices with better response capabilities as target edge devices (finally determined to be E1 and E5).

[0129] The load control information of the target device is calculated, and the control strategy is generated based on the load control model. During the generation process, the adjustable capacity, response characteristics and global load distribution balance requirements of the device are considered, and the control information is finally generated and sent to the target device to achieve dynamic optimization of load control.

[0130] In order to verify the innovation and practicality of the invention, an experimental study was conducted on the load regulation security protection method. The experiment was conducted in a simulated industrial smart grid environment, and the equipment used included a cloud platform server, multiple edge devices (numbered E1 to E5), and an identity authentication module and a load regulation module. The test scenario simulates the security of data interaction and the efficiency of load regulation during the collaborative work of multiple devices, focusing on verifying the impact of identity authentication, data verification, and load regulation strategy generation on system stability and reliability.

[0131] The test process is as follows:

[0132] Each edge device and cloud platform is simulated to have unique digital certificate information (formatted in accordance with the X.509 standard), which contains the device number, encryption public key and related features. After receiving the certificate, the server authenticates each certificate through the authentication module based on the PKI (public key infrastructure) system, generates verification results, and screens out trusted devices. The screening of trusted devices is completed by checking whether the certificate is expired, revoked, and whether it meets the expected device list.

[0133] For trusted devices that have passed identity authentication (such as E1, E3, and E5), the system obtains their real-time operating data based on an encrypted transmission channel, including voltage, current, equipment load and other control parameters. Devices that have not passed identity authentication (such as E2 and E4) are isolated and cannot participate in subsequent data processing.

[0134] According to the collected load control information, a data verification matrix is ​​established. The eigenvalue vector of each device (including load offset, response time, etc.) is extracted through the verification matrix, and the data verification model is used to verify the credibility. The verification model is used to select devices with better response capabilities as target edge devices (finally determined to be E1 and E5).

[0135] The load control information of the target device is calculated, and the control strategy is generated based on the load control model. During the generation process, the adjustable capacity, response characteristics and global load distribution balance requirements of the device are considered, and the control information is finally generated and sent to the target device to achieve dynamic optimization of load control.

[0136] Table 5: Experimental data records

[0137]

[0138] It can be observed from the tabular data that the designed load control method based on privacy computing has significant advantages in equipment screening, load control efficiency and security.

[0139] Data shows that the edge devices that passed the authentication include E1, E3 and E5, with authentication pass rates of 100%, 85% and 100% respectively. Compared with the devices E2 and E4 that failed the authentication, it can be seen that the authentication module effectively shields possible abnormal or illegal devices, ensuring the reliability of the system data source.

[0140] Among the trusted devices, the load offsets of E1 and E5 are 5.2kW and 4.9kW respectively, and the response times are 150ms and 130ms respectively, which are significantly better than E3 (6.7kW, 220ms). This shows that the data verification model can accurately identify target devices with excellent load regulation performance.

[0141] In terms of control efficiency, the load control efficiency of target devices E5 and E1 reached 95.2% and 92.3%, and the load balance errors were 1.8% and 2.1%, respectively, which were better than other devices. In traditional methods, due to the inability to accurately identify the target device, the control efficiency is usually less than 85%, and the load balance error is usually higher than 5%.

[0142] Compared with traditional load control methods, the present invention achieves the security and accuracy of data interaction and load control process through privacy computing technology. Traditional methods often rely on fixed rules for load distribution, which is difficult to dynamically adjust or consider performance differences between devices. In the present invention, devices are dynamically screened through verification matrices and verification models, and refined strategies are generated using control models, which significantly improves control efficiency and system stability.

[0143] To sum up, the technical solution of the present invention makes full use of privacy computing technology to ensure data security, and at the same time combines dynamic verification and control models to effectively improve the accuracy and response efficiency of load control, and solves the problems of inaccurate equipment screening and inflexible control strategies in the prior art. It has strong creativity and significant technological advancement.

[0144] Example 4, reference Figure 4 , as an embodiment of the present invention, provides a load regulation security protection system based on privacy computing, including an identity authentication module, a channel connection module, a device verification module, and a load regulation module.

[0145] The identity authentication module is used to receive the certificate information of the cloud platform and each edge device, authenticate the certificate information of the cloud platform and each edge device, and obtain an identity authentication result.

[0146] A channel connection module is used to determine a trusted edge device based on the identity authentication result of the cloud platform when the identity authentication result of the cloud platform is normal, establish a data transmission channel with the trusted edge device, and obtain load regulation information sent by the edge device to the cloud platform based on the data transmission channel.

[0147] The device verification module is used to establish a data verification matrix according to the load regulation information, determine the verification vector of each of the trusted edge devices according to the data verification matrix, verify the verification vector based on the data verification model, and determine the target edge device.

[0148] The load control module is used to determine the load control information of the target edge device, generate target control information according to the load control information based on the load control model, and perform load control on the target edge device based on the target control information.

[0149] When implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program code.

[0150] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.

[0151] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0152] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc. It should be noted that the above embodiments are only used to illustrate the technical solution of the present invention and are not limited. Although the present invention is described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention, which should be included in the scope of the claims of the present invention.

[0153] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A load control security protection method based on privacy computing, characterized in that: include: Collecting first feature data of a first object, verifying the first feature data of the first object, and obtaining a first verification result; Based on the first verification result, the first target is screened, a trusted first object is obtained, and a transmission is established with the trusted first object to obtain the first target information; Performing a first adjustment process on the first object according to the first target information, and determining the first target object through the first adjustment process; While obtaining first target effect data according to the first target, self-checking is performed on the first target object.

2. The load regulation and security protection method based on privacy computing according to claim 1 is characterized in that: The first verification process includes collecting first feature data of each first object and performing comparison processing on the first feature data of each first object.

3. The load regulation and security protection method based on privacy computing as claimed in claim 2, characterized in that: The obtaining of the first target information includes establishing a verification matrix to determine a credible first object, and obtaining the first target information by screening the first verification result and the matrix.

4. The load regulation and security protection method based on privacy computing as claimed in claim 3 is characterized by: The first target screening includes: sending a first target parameter to each of the target first objects, so that the first target model of the target first object is updated to the first target parameter.

5. The load regulation and security protection method based on privacy computing as claimed in claim 4 is characterized by: The first adjustment process includes optimizing the first object parameter by comparing it with the first target parameter to thereby determine the first target object parameter.

6. The load regulation and security protection method based on privacy computing according to claim 5 is characterized in that: The obtaining of the first target object parameters includes sending data to each first target object and obtaining feedback, and optimizing the first object parameters through the feedback to obtain the first target object parameters.

7. The load regulation and security protection method based on privacy computing according to claim 6 is characterized in that: The self-checking process includes, when information monitoring shows an abnormal state, disconnecting the data connection with the first object, connecting the first object with the backup, and synchronizing the update information.

8. A system using the load regulation and security protection method based on privacy computing as described in any one of claims 1 to 7, characterized in that: Identity verification module, channel connection module, equipment verification module, load control module; An identity authentication module is used to receive the certificate information of the cloud platform and each edge device, authenticate the certificate information of the cloud platform and each edge device, and obtain an identity authentication result; A channel connection module is used to determine a trusted edge device based on the identity authentication result of the cloud platform when the identity authentication result of the cloud platform is normal, establish a data transmission channel with the trusted edge device, and obtain load regulation information sent by the edge device to the cloud platform based on the data transmission channel; A device verification module, used to establish a data verification matrix according to the load regulation information, determine the verification vector of each of the trusted edge devices according to the data verification matrix, verify the verification vector based on a data verification model, and determine the target edge device; The load control module is used to determine the load control information of the target edge device, generate target control information according to the load control information based on the load control model, and perform load control on the target edge device based on the target control information.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.