Power grid data security protection method and device, electronic equipment and storage medium
By embedding digital watermarks in the measurement data of the power system, combined with similarity measurement algorithms and timestamp analysis, the problem of difficult to identify AGC system tampering data and replay attacks in the prior art is solved, and efficient network security protection of the power system is achieved.
Patent Information
- Application Number
- CN202510160158.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to accurately identify tampered data and playback attacks in automatic power generation control (AGC) systems without affecting the performance of the power system.
By embedding digital watermarks in the measurement data of the power system, combined with similarity metric algorithms and timestamp analysis, the receiver can identify data tampering attacks and replay attacks, trigger security alerts and refuse further processing.
It realizes accurate identification of tampering data and playback attacks in the AGC system without affecting the system performance, enhancing the network security of the power system.
Smart Images

Figure CN120012054A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system network security, and in particular to a power grid data security protection method, device, electronic equipment and storage medium. Background Art
[0002] Modern power systems rely on wide area networks (WANs) for real-time data transmission and control. However, the integration of WANs exposes power systems to the risk of external attacks. Attackers can exploit vulnerabilities to affect the operation of power systems by modifying or replaying control signals. This can lead to inaccurate dispatch decisions, which may eventually cause grid instability. In particular, the Automatic Generation Control (AGC) system, as an important part of power balance, is a high-risk area for cyber attacks because it is highly dependent on remote signal transmission.
[0003] Traditional network security mechanisms, such as encryption, multi-factor authentication, and anti-virus software, are often not effectively applied due to the real-time requirements and resource constraints of power systems. Therefore, there is an urgent need for a lightweight and efficient network security mechanism that can accurately identify tampered data in the AGC system and implement replay attack detection without affecting system performance. Summary of the invention
[0004] The present invention provides a power grid data security protection method, device, electronic device and storage medium, which are used to solve or partially solve the technical problem that existing related algorithms cannot accurately identify tampered data and replayed data in an AGC system.
[0005] The present invention provides a power grid data security protection method, which is applied to a receiving end. The power grid data security protection method comprises:
[0006] receiving watermarked measurement data of the power system transmitted by a transmitter;
[0007] Extracting the digital watermark to be identified embedded in the watermarked measurement data; the digital watermark to be identified includes a timestamp to be identified;
[0008] Based on the digital watermark to be identified, combined with a similarity measurement algorithm, data tampering attacks are identified through watermark distance calculation;
[0009] Identify the replay attack by comparing the time difference of the timestamp to be identified;
[0010] When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is rejected.
[0011] Optionally, the identifying of data tampering attacks based on the digital watermark to be identified and in combination with a similarity measurement algorithm through watermark distance calculation includes:
[0012] Acquire a unique original digital watermark corresponding to the watermarked measurement data from the sending end; the original digital watermark includes an original timestamp related to the time when the watermark was generated;
[0013] Determine the first number of characters of the digital watermark to be identified and the second number of characters of the original digital watermark, and initialize an edit distance matrix according to the first number of characters and the second number of characters;
[0014] According to the edit distance matrix, using a similarity measurement algorithm to calculate the edit distance between the digital watermark to be identified and the original digital watermark;
[0015] If the minimum edit distance is less than or equal to the preset edit distance threshold, it is determined that the watermarked measurement data has not been subjected to a data tampering attack;
[0016] If the minimum edit distance is greater than a preset edit distance threshold, it is determined that the watermarked measurement data has been subjected to a data tampering attack.
[0017] Optionally, the edit distance between the to-be-identified digital watermark and the original digital watermark is calculated by the following recursive formula:
[0018]
[0019] in, Represents the original digital watermark of the string and the digital watermark to be identified In Location (corresponding to characters) and (corresponding to The edit distance is composed of four basic operations: insertion, deletion, substitution and exchange. min means the minimum value solution. and Represents the original digital watermark of the string and the digital watermark to be identified No. and characters; Indicates character and Are they equal? If they are equal, it is 0; if they are not equal, it is 1.
[0020] Optionally, the identifying a replay attack by comparing the time difference of the timestamp to be identified includes:
[0021] Obtain the current system time, and perform a time difference calculation between the timestamp to be identified and the current system time to obtain a time difference;
[0022] If the time difference is less than or equal to a preset time difference threshold, it is determined that the watermarked measurement data has not been subjected to a replay attack;
[0023] If the time difference is greater than a preset time difference threshold, it is determined that the watermarked measurement data has been subjected to a replay attack.
[0024] The present invention also provides a power grid data security protection method, which is applied to a sending end, and the power grid data security protection method comprises:
[0025] Acquire original measurement data of the power system, and generate a unique original digital watermark for the original measurement data; the original digital watermark includes an original timestamp related to the time when the watermark was generated;
[0026] embedding the original digital watermark into the original measurement data to generate watermarked measurement data;
[0027] The watermarked measurement data is transmitted to a receiving end so that the receiving end can extract a digital watermark from the watermarked measurement data, identify data tampering attacks through watermark distance calculation in combination with a similarity measurement algorithm, and identify replay attacks through time difference comparison. When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is refused.
[0028] Optionally, embedding the original digital watermark into the original measurement data to generate watermarked measurement data includes:
[0029] The original digital watermark is combined with the original measurement data through a weighted superposition method to generate watermarked measurement data.
[0030] The present invention also provides a power grid data security protection device, which is applied to a receiving end, and the power grid data security protection device comprises:
[0031] A data receiving module, used for receiving watermarked measurement data of the power system transmitted by a sending end;
[0032] A watermark extraction module, used to extract the digital watermark to be identified embedded in the watermarked measurement data; the digital watermark to be identified includes a timestamp to be identified;
[0033] A data tampering attack identification module, used to identify data tampering attacks based on the digital watermark to be identified and in combination with a similarity measurement algorithm, by calculating the watermark distance;
[0034] A replay attack identification module, used to identify a replay attack by comparing the time difference of the timestamp to be identified;
[0035] The security alarm triggering module is used to trigger a security alarm and refuse further processing of the watermarked measurement data when a data tampering attack and / or a replay attack is identified.
[0036] The present invention also provides a power grid data security protection device, which is applied to a transmitting end, and the power grid data security protection device comprises:
[0037] A watermark generation module, used for acquiring original measurement data of the power system and generating a unique original digital watermark for the original measurement data; the original digital watermark includes an original timestamp related to the watermark generation time;
[0038] A watermark embedding module, used for embedding the original digital watermark into the original measurement data to generate watermarked measurement data;
[0039] The data transmission module is used to transmit the watermarked measurement data to a receiving end so that the receiving end can extract the digital watermark from the watermarked measurement data, identify the data tampering attack by watermark distance calculation in combination with a similarity measurement algorithm, and identify the replay attack by time difference comparison. When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is refused.
[0040] The present invention also provides an electronic device, the device comprising a processor and a memory:
[0041] The memory is used to store program code and transmit the program code to the processor;
[0042] The processor is used to execute the power grid data security protection method as described in any one of the above items according to the instructions in the program code.
[0043] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and the program code is used to execute the power grid data security protection method as described in any one of the above items.
[0044] It can be seen from the above technical solutions that the present invention has the following advantages:
[0045] A method for protecting power grid data security is provided. The transmitting end obtains the original measurement data of the power system, generates a unique original digital watermark and embeds it into the original measurement data, and then transmits it to the receiving end; the receiving end receives the measurement data with the watermark, extracts the digital watermark to be identified containing the timestamp to be identified, and identifies the data tampering attack through watermark distance calculation based on the digital watermark to be identified, combined with the similarity measurement algorithm, and identifies the replay attack through timestamp comparison analysis. When the data tampering attack and / or replay attack are identified, a security alarm is triggered and further data processing is rejected. Therefore, by combining the digital watermark, the similarity measurement algorithm and the timestamp analysis, it is possible to effectively detect the data tampering and replay attack behaviors that may exist in the transmission process of the measurement data without affecting the system performance, so as to accurately identify the tampered data and realize the replay attack detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0047] Figure 1 A flowchart of the steps of a power grid data security protection method;
[0048] Figure 2 A flowchart of another method for protecting power grid data security;
[0049] Figure 3 It is a schematic diagram of the overall process of a power grid data security protection method;
[0050] Figure 4 A structural block diagram of a power grid data security protection device
[0051] Figure 5 The structure block diagram of another power grid data security protection device. DETAILED DESCRIPTION
[0052] The embodiments of the present invention provide a power grid data security protection method, device, electronic device and storage medium, which are used to solve or partially solve the technical problem that the existing related algorithms cannot accurately identify tampered data and replayed data in the AGC system.
[0053] In order to make the purpose, features and advantages of the present invention more obvious and easy to understand, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described below are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0054] As an example, traditional network security mechanisms, such as encryption, multi-factor authentication, and anti-virus software, are often not effectively applied due to the real-time requirements and resource constraints of the power system. Therefore, there is an urgent need for a lightweight and efficient network security mechanism that can accurately identify tampered data in the AGC system and implement replay attack detection without affecting system performance.
[0055] Therefore, one of the core invention points of the embodiment of the present invention is to provide an efficient and reliable power grid data security protection method based on a digital watermark similarity measurement algorithm. First, the sending end embeds a dynamic digital watermark in the key measurement data of the power system, and transmits the measurement data embedded with the digital watermark to the receiving end through a wide area network; the receiving end extracts the embedded digital watermark from the received measurement data, and compares the extracted digital watermark with the original generated digital watermark through a similarity measurement algorithm to detect whether the data has been tampered with, so as to verify the integrity of the data and improve the accuracy of tampering detection. At the same time, through timestamp comparison and analysis, it is detected whether the data is subject to a replay attack. Thus, by combining digital watermarks, similarity measurement algorithms and timestamp analysis, it is possible to effectively detect data tampering and replay attack behaviors that may exist in the transmission process of measurement data, and try to ensure the integrity and timeliness of data transmission, enhance the network security of the power system, and maintain the safe and stable operation of the power system. In addition, the embedding and extraction process of the digital watermark adopted by the present invention is simple and efficient, does not affect the real-time performance of the system, is suitable for power systems of various sizes, and has good application prospects.
[0056] On the one hand, the sending end is used as the data processing end, referring to Figure 1 , shows a flowchart of another method for protecting power grid data security provided by an embodiment of the present invention, which may include the following steps:
[0057] Step 101, obtaining original measurement data of the power system, and generating a unique original digital watermark for the original measurement data;
[0058] This step mainly realizes the dynamic embedding of digital watermarks with timestamps into the measurement data of the power system. The measurement data of the power system can mainly include voltage, current, power, frequency, etc. In order to distinguish the measurement data after the digital watermark is embedded, the measurement data before the digital watermark is embedded is defined as the original measurement data, and the measurement data after the digital watermark is embedded is defined as the watermarked measurement data.
[0059] More specifically, the measurement data that may be attacked in the embodiments of the present invention are applicable to various key measurement data including voltage, power, frequency, etc. of the AGC system. They may mainly include:
[0060] (1) Voltage data: used to monitor the voltage level of each node. An attacker can cause overvoltage or undervoltage events by tampering with the voltage data.
[0061] (2) Power data: Real-time monitoring of system power flow. Tampering with power data may lead to improper system scheduling.
[0062] (3) Frequency data: The AGC system relies on frequency data to maintain the stability of the power grid. Tampering with frequency data may disrupt the frequency balance of the power grid.
[0063] (4) Current data: In actual situations, attackers may cause equipment overload or other failures by modifying current measurement data.
[0064] For the original measurement data, a unique original digital watermark can be generated The original digital watermark Contains the original timestamp relative to the current time (i.e. the time when the watermark was generated) .
[0065] In order to distinguish the digital watermark obtained by the receiving end through watermark extraction, the digital watermark generated by the sending end is defined as the original digital watermark. , the corresponding timestamp is defined as the original timestamp The digital watermark obtained by extracting the watermarked measurement data at the receiving end is defined as the digital watermark to be identified , the corresponding timestamp is defined as the timestamp to be identified .
[0066] Step 102, embedding the original digital watermark into the original measurement data to generate watermarked measurement data;
[0067] In a specific implementation, the original digital watermark is embedded into the original measurement data to generate the watermarked measurement data. The original digital watermark is combined with the original measurement data by weighted superposition method to generate the watermarked measurement data. The calculation formula is as follows:
[0068]
[0069] in, Represents raw measurement data (such as power, frequency, voltage, etc.); Indicates at time The watermark generated at the moment is the original digital watermark; A control parameter representing the watermark strength, which is used to control the amount of watermark embedding; Represents the measurement data after embedding the watermark, that is, the watermarked measurement data.
[0070] Step 103, the watermarked measurement data is transmitted to the receiving end, so that the receiving end can extract the digital watermark from the watermarked measurement data, identify the data tampering attack by watermark distance calculation in combination with the similarity measurement algorithm, and identify the replay attack by time difference comparison. When the data tampering attack and / or replay attack are identified, a security alarm is triggered, and further processing of the watermarked measurement data is refused.
[0071] Finally, the watermarked measurement data can be transmitted to the receiving end through the wide area network, so that the receiving end can perform the next step of data tampering attack and replay attack processing. The specific data processing process on the receiving end side can be performed with reference to the following related embodiments, which will not be described here.
[0072] In an embodiment of the present invention, a power grid data security protection method is proposed with the sending end as the data processing end. The sending end embeds a dynamic digital watermark in the key measurement data of the power system, and transmits the measurement data embedded with the digital watermark to the receiving end through a wide area network, so that the receiving end can perform attack detection related processing. Combined with the relevant data processing flow of the receiving end, based on digital watermarks, similarity measurement algorithms and timestamp analysis, it is possible to effectively detect data tampering and replay attacks that may exist in the transmission process of the measurement data, and try to ensure the integrity and timeliness of data transmission, enhance the network security of the power system, and maintain the safe and stable operation of the power system.
[0073] On the other hand, the receiving end is used as the data processing end. Figure 2 , shows a flowchart of another method for protecting power grid data security provided by an embodiment of the present invention, which may include the following steps:
[0074] Step 201, receiving watermarked measurement data of a power system transmitted by a transmitting end;
[0075] The receiving end first needs to receive the watermarked measurement data of the power system transmitted by the sending end through the wide area network for subsequent data processing.
[0076] Step 202, extracting the digital watermark to be identified embedded in the watermarked measurement data; the digital watermark to be identified includes a timestamp to be identified;
[0077] The receiving end can then extract the digital watermark to be identified embedded in the watermarked measurement data . Digital watermark to be identified The corresponding timestamp contains the time stamp to be identified .
[0078] Step 203, based on the digital watermark to be identified, combined with a similarity measurement algorithm, and through watermark distance calculation, identify data tampering attacks;
[0079] In a specific implementation, based on the digital watermark to be identified, combined with the similarity measurement algorithm, the process of identifying the data tampering attack through watermark distance calculation may include the following sub-steps S01 to S04:
[0080] Step S01: Obtain a unique original digital watermark corresponding to the watermarked measurement data from a sending end; the original digital watermark includes an original timestamp related to the time when the watermark was generated.
[0081] Step S02: Determine the first character number of the digital watermark to be identified and the second character number of the original digital watermark, and initialize the edit distance matrix according to the first character number and the second character number.
[0082] Step S02 mainly implements initialization of the edit distance matrix .in, Original digital watermark The number of characters in The received digital watermark to be identified In order to distinguish the number of characters in the two digital watermarks, the digital watermark to be identified The number of characters in is defined as the number of first characters, and the original digital watermark The number of characters in is defined as the second character number.
[0083] The first line is initialized as: . Indicates conversion from an empty string to The first column is initialized as: . Indicates that from The cost of converting to an empty string.
[0084] Step S03: According to the edit distance matrix, a similarity measurement algorithm is used to calculate the edit distance between the digital watermark to be identified and the original digital watermark.
[0085] Specifically, the edit distance between the digital watermark to be identified and the original digital watermark is calculated by the following recursive formula:
[0086]
[0087] in, Represents the original digital watermark of the string and the digital watermark to be identified In Location (corresponding to characters) and (corresponding to The edit distance is composed of four basic operations: insertion, deletion, substitution and exchange. min means the minimum value solution. and Represents the original digital watermark of the string and the digital watermark to be identified No. and characters; Indicates character and Are they equal? If they are equal, it is 0; if they are not equal, it is 1.
[0088] After the recursive calculation is completed, the last element of the matrix The original digital watermark of the string Convert to digital watermark to be identified Minimum required edit distance.
[0089] Step S04: if the minimum edit distance is less than or equal to the preset edit distance threshold, it is determined that the watermarked measurement data has not been attacked by data tampering; if the minimum edit distance is greater than the preset edit distance threshold, it is determined that the watermarked measurement data has been attacked by data tampering.
[0090] If the minimum edit distance Does not exceed the predetermined edit distance threshold ,Right now , it is determined that the watermarked measurement data has not been attacked by data tampering, that is, the data has not been tampered with.
[0091] If the minimum edit distance Exceeding a predefined edit distance threshold ,Right now , it is determined that the watermarked measurement data has been subjected to a data tampering attack, that is, the data has been tampered with.
[0092] Step 204, identifying a replay attack by comparing the time difference of the timestamp to be identified;
[0093] In a specific implementation, the process of identifying a replay attack by comparing the time difference of the timestamp to be identified may include the following sub-steps S11 to S12:
[0094] Step S11: Obtain the current system time, and perform a difference calculation between the timestamp to be identified and the current system time to obtain the time difference.
[0095] Get the current system time , compared with the received timestamp to be identified With the current system time If the time difference exceeds the allowed range, a replay attack is considered to have occurred:
[0096]
[0097] in, is the timestamp to be identified; is the current system time; is the time difference.
[0098] Step S12: If the time difference is less than or equal to the preset time difference threshold, it is determined that the watermarked measurement data has not been subjected to a replay attack; if the time difference is greater than the preset time difference threshold, it is determined that the watermarked measurement data has been subjected to a replay attack.
[0099] If the time difference The predetermined time difference threshold is not exceeded ,Right now , it is determined that the watermarked measurement data has not been subjected to replay attacks.
[0100] If the time difference Exceeded the predetermined time difference threshold ,Right now , it is determined that the watermarked measurement data has been subjected to a replay attack and the processing of the data packet is rejected.
[0101] Step 205: When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is rejected.
[0102] Specifically, if watermark inconsistency or timestamp anomaly is detected, that is, as long as watermark inconsistency or timestamp anomaly occurs, a security alarm is triggered and further processing of the relevant data is rejected.
[0103] Furthermore, after detecting a replay attack or data tampering attack, the system can automatically adjust the attack response strategy and implement countermeasures such as network isolation and signal recovery.
[0104] In an embodiment of the present invention, another power grid data security protection method is proposed with the receiving end as the data processing end. The receiving end receives the measurement data with watermarks transmitted by the sending end, extracts the embedded digital watermark from it, and compares the extracted digital watermark with the originally generated digital watermark through a similarity measurement algorithm to detect whether the data has been tampered with, so as to verify the integrity of the data and improve the accuracy of tampering detection. At the same time, through timestamp comparison and analysis, it is detected whether the data is subject to replay attacks. Combined with the relevant data processing flow of the sending end, based on digital watermarks, similarity measurement algorithms and timestamp analysis, it is possible to effectively detect data tampering and replay attacks that may exist in the transmission process of the measurement data, and try to ensure the integrity and timeliness of data transmission, enhance the network security of the power system, and maintain the safe and stable operation of the power system.
[0105] For better explanation, refer to Figure 3 , showing an overall flow diagram of a power grid data security protection method provided by an embodiment of the present invention. It should be pointed out that this embodiment only briefly describes the general process of power grid data security protection, and the specific implementation process of each step can be understood by referring to the relevant content in the aforementioned embodiment, which will not be described here. It can be understood that the present invention does not limit this.
[0106] Processing on the sender side:
[0107] The original measurement data of the power system is read, and a unique original digital watermark with an original timestamp is generated for the original measurement data.
[0108] The original digital watermark is embedded into the original measurement data to generate watermarked measurement data.
[0109] The watermarked measurement data is transmitted to the receiving end via a wide area network.
[0110] Processing on the sender side:
[0111] Receive the watermarked measurement data transmitted by the sender.
[0112] The digital watermark to be identified embedded in the watermarked measurement data is extracted, and the digital watermark to be identified includes a timestamp to be identified.
[0113] Combined with the original digital watermark, an attack detection model is constructed. Specifically, based on the digital watermark to be identified and combined with the similarity measurement algorithm, the watermark distance is calculated to detect whether there is a data tampering attack; by comparing the time difference of the timestamp to be identified, it is detected whether there is a replay attack.
[0114] When a data tampering attack and / or a replay attack is detected, a security alarm is triggered and further processing of the watermarked measurement data is rejected.
[0115] If no data tampering attack or replay attack is detected (i.e., neither case is detected), the data is determined to be consistent and the watermarked measurement data continues to be processed normally.
[0116] In combination with the above-introduced contents, in order to enable those skilled in the art to better understand the technical solution of the present invention, an embodiment of the present invention is described below through a specific example.
[0117] Take the IEEE 14-node system as an example. First, collect the measurement data of key nodes, such as voltage amplitude, phase angle, frequency, and active power. Assume that the following active power data is collected from node 1:
[0118]
[0119] Table 1: Active power data of node 1
[0120] (1) The sender generates a digital watermark
[0121] Generate a digital watermark containing a timestamp for each time point As shown in Table 2 below:
[0122]
[0123] Table 2: Digital watermark generation results
[0124] (2) The sender embeds the digital watermark into the measurement data
[0125] Use weighted superposition to add digital watermark Embedding raw measurement data:
[0126]
[0127] in, Represents the measurement data after embedding the digital watermark; Represents the original active power data; Indicates the watermark strength control parameter (the value is 0.001 in this example); It means converting the digital watermark string into digital representation, converting the digital watermark string into ASCII code and summing them.
[0128] For example, the ASCII code sum of the digital watermark "W202309151000" is as follows.
[0129] String: "W202309151000";
[0130] ASCII code sequence: [87,50,48,50,48,51,48,57,49,53,49,48,48,48];
[0131] Sum: ;
[0132] thereby .
[0133] Similarly, the data at other time points are calculated as shown in Table 3 below:
[0134]
[0135] Table 3: Watermark embedding results of each node power
[0136] The measurement data embedded with digital watermark Transmitted to the control center or receiving end via a wide area network.
[0137] (3) The receiving end extracts the watermark and performs attack detection on the received watermarked measurement data
[0138] (a) Watermark extraction
[0139] The receiving end receives the measurement data embedded with the digital watermark Finally, extract the embedded digital watermark:
[0140]
[0141] in, The estimated raw power value can be obtained through historical data or prediction models.
[0142] (b) Data tampering attack identification
[0143] Convert the extracted digital watermark value back to a string. Then compare the received watermark With the original digital watermark .
[0144] The similarity measurement algorithm is used to calculate the edit distance between the two If the edit distance If it is greater than the threshold 2, it is determined that the data has been tampered with.
[0145] Assume that during the transmission, the attacker sends the data at time 10:02 Modified to 150.000 MW.
[0146] First, the digital watermark can be extracted:
[0147]
[0148] According to the original digital watermark value 765 and the extracted digital watermark value 1000, using the similarity measurement algorithm, we can calculate , greater than the threshold 2, the data is determined to be tampered with and a security alarm is triggered.
[0149] (c) Replay attack identification
[0150] Compare received timestamps With the current system time , calculate the time difference :
[0151]
[0152] like If the duration is greater than the threshold of 2 minutes, it is considered a replay attack.
[0153] Assume that the attacker replays the data at time 10:00 at time 10:05 .
[0154] Since the received timestamp , current system time , calculate the time difference If the attack time is greater than the threshold of 2 minutes, it is considered a replay attack and a security alarm is triggered.
[0155] Take the sending end as the data processing end, refer to Figure 4 , shows a structural block diagram of a power grid data security protection device provided by an embodiment of the present invention, which may specifically include:
[0156] The watermark generation module 401 is used to obtain the original measurement data of the power system and generate a unique original digital watermark for the original measurement data; the original digital watermark includes an original timestamp related to the watermark generation time;
[0157] A watermark embedding module 402, configured to embed the original digital watermark into the original measurement data to generate watermarked measurement data;
[0158] The data transmission module 403 is used to transmit the watermarked measurement data to the receiving end so that the receiving end can extract the digital watermark from the watermarked measurement data, identify the data tampering attack by watermark distance calculation in combination with the similarity measurement algorithm, and identify the replay attack by time difference comparison. When the data tampering attack and / or replay attack are identified, a security alarm is triggered and further processing of the watermarked measurement data is refused.
[0159] In an optional embodiment, the watermark embedding module 402 is specifically used for:
[0160] The original digital watermark is combined with the original measurement data through a weighted superposition method to generate watermarked measurement data.
[0161] Take the receiving end as the data processing end, refer to Figure 5 , shows a structural block diagram of another power grid data security protection device provided by an embodiment of the present invention, which may specifically include:
[0162] The data receiving module 501 is used to receive the watermarked measurement data of the power system transmitted by the sending end;
[0163] The watermark extraction module 502 is used to extract the digital watermark to be identified embedded in the watermarked measurement data; the digital watermark to be identified includes a timestamp to be identified;
[0164] A data tampering attack identification module 503 is used to identify data tampering attacks based on the digital watermark to be identified and in combination with a similarity measurement algorithm by calculating watermark distance;
[0165] A replay attack identification module 504, configured to identify a replay attack by comparing the time difference of the timestamp to be identified;
[0166] The security alarm triggering module 505 is used to trigger a security alarm and refuse further processing of the watermarked measurement data when a data tampering attack and / or a replay attack is identified.
[0167] In an optional embodiment, the data tampering attack identification module 503 includes:
[0168] An original digital watermark acquisition module, used to acquire a unique original digital watermark corresponding to the watermarked measurement data from the sending end; the original digital watermark includes an original timestamp related to the watermark generation time;
[0169] An edit distance matrix initialization module, used to determine the first character number of the digital watermark to be identified and the second character number of the original digital watermark, and initialize the edit distance matrix according to the first character number and the second character number;
[0170] A minimum edit distance calculation module, used to calculate the edit distance between the digital watermark to be identified and the original digital watermark using a similarity measurement algorithm according to the edit distance matrix;
[0171] A first data tampering attack determination module, configured to determine that the watermarked measurement data has not been subjected to a data tampering attack when the minimum edit distance is less than or equal to a preset edit distance threshold;
[0172] The second data tampering attack determination module is used to determine that the watermarked measurement data has been subjected to a data tampering attack when the minimum edit distance is greater than a preset edit distance threshold.
[0173] In an optional embodiment, the edit distance between the to-be-identified digital watermark and the original digital watermark is calculated by the following recursive formula:
[0174]
[0175] in, Represents the original digital watermark of the string and the digital watermark to be identified In Location (corresponding to characters) and (corresponding to The edit distance is composed of four basic operations: insertion, deletion, substitution and exchange. min means the minimum value solution. and Represents the original digital watermark of the string and the digital watermark to be identified No. and characters; Indicates character and Are they equal? If they are equal, it is 0; if they are not equal, it is 1.
[0176] In an optional embodiment, the replay attack identification module 504 includes:
[0177] A time difference calculation module is used to obtain the current system time, and perform a difference calculation between the timestamp to be identified and the current system time to obtain the time difference;
[0178] A first replay attack determination module, configured to determine that the watermarked measurement data is not subjected to a replay attack when the time difference is less than or equal to a preset time difference threshold;
[0179] The second replay attack determination module is used to determine that the watermarked measurement data is subjected to a replay attack when the time difference is greater than a preset time difference threshold.
[0180] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the aforementioned method embodiment.
[0181] It should be noted that, in order to enable those skilled in the art to better distinguish data of the same type but with different actual meanings, the foregoing embodiments of the present invention use the first and second to distinguish some technical features. The first and second are only used for data distinction and have no other special meanings. It can be understood that the present invention is not limited to this.
[0182] An embodiment of the present invention further provides an electronic device, the device comprising a processor and a memory:
[0183] The memory is used to store the program code and transmit the program code to the processor;
[0184] The processor is used to execute the power grid data security protection method of any embodiment of the present invention according to the instructions in the program code.
[0185] An embodiment of the present invention further provides a computer-readable storage medium, which is used to store program codes, and the program codes are used to execute the power grid data security protection method of any embodiment of the present invention.
[0186] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0187] In the several embodiments provided by the present invention, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0188] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0189] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0190] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program codes.
[0191] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for protecting power grid data security, characterized in that: Applied to the receiving end, the power grid data security protection method includes: receiving watermarked measurement data of the power system transmitted by a transmitter; Extracting the digital watermark to be identified embedded in the watermarked measurement data; the digital watermark to be identified includes a timestamp to be identified; Based on the digital watermark to be identified, combined with a similarity measurement algorithm, data tampering attacks are identified through watermark distance calculation; Identify the replay attack by comparing the time difference of the timestamp to be identified; When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is rejected.
2. The power grid data security protection method according to claim 1, characterized in that: The method of identifying data tampering attacks based on the digital watermark to be identified and combining a similarity measurement algorithm and calculating watermark distance includes: Acquire a unique original digital watermark corresponding to the watermarked measurement data from the sending end; the original digital watermark includes an original timestamp related to the time when the watermark was generated; Determine the first number of characters of the digital watermark to be identified and the second number of characters of the original digital watermark, and initialize an edit distance matrix according to the first number of characters and the second number of characters; According to the edit distance matrix, using a similarity measurement algorithm to calculate the edit distance between the digital watermark to be identified and the original digital watermark; If the minimum edit distance is less than or equal to the preset edit distance threshold, it is determined that the watermarked measurement data has not been subjected to a data tampering attack; If the minimum edit distance is greater than a preset edit distance threshold, it is determined that the watermarked measurement data has been subjected to a data tampering attack.
3. The power grid data security protection method according to claim 2, characterized in that: The edit distance between the digital watermark to be identified and the original digital watermark is calculated by the following recursive formula: in, Represents the original digital watermark of the string and the digital watermark to be identified In Location (corresponding to characters) and (corresponding to The edit distance is composed of four basic operations: insertion, deletion, substitution and exchange. min means the minimum value solution. and Represents the original digital watermark of the string and the digital watermark to be identified No. and characters; Indicates character and Are they equal? If they are equal, it is 0; if they are not equal, it is 1.
4. The power grid data security protection method according to any one of claims 1 to 3, characterized in that: The identifying the replay attack by comparing the time difference of the timestamp to be identified includes: Obtain the current system time, and perform a time difference calculation between the timestamp to be identified and the current system time to obtain a time difference; If the time difference is less than or equal to a preset time difference threshold, it is determined that the watermarked measurement data has not been subjected to a replay attack; If the time difference is greater than a preset time difference threshold, it is determined that the watermarked measurement data has been subjected to a replay attack.
5. A method for protecting power grid data security, characterized in that: Applied to the transmitting end, the power grid data security protection method includes: Acquire original measurement data of the power system, and generate a unique original digital watermark for the original measurement data; the original digital watermark includes an original timestamp related to the time when the watermark was generated; embedding the original digital watermark into the original measurement data to generate watermarked measurement data; The watermarked measurement data is transmitted to a receiving end so that the receiving end can extract a digital watermark from the watermarked measurement data, identify data tampering attacks through watermark distance calculation in combination with a similarity measurement algorithm, and identify replay attacks through time difference comparison. When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is refused.
6. The method for protecting power grid data security according to claim 5, characterized in that: The step of embedding the original digital watermark into the original measurement data to generate watermarked measurement data includes: The original digital watermark is combined with the original measurement data through a weighted superposition method to generate watermarked measurement data.
7. A power grid data security protection device, characterized in that: Applied to the receiving end, the power grid data security protection device comprises: A data receiving module, used for receiving watermarked measurement data of the power system transmitted by a sending end; A watermark extraction module, used to extract the digital watermark to be identified embedded in the watermarked measurement data; the digital watermark to be identified includes a timestamp to be identified; A data tampering attack identification module, used to identify data tampering attacks based on the digital watermark to be identified and in combination with a similarity measurement algorithm, by calculating the watermark distance; A replay attack identification module, used to identify a replay attack by comparing the time difference of the timestamp to be identified; The security alarm triggering module is used to trigger a security alarm and refuse further processing of the watermarked measurement data when a data tampering attack and / or a replay attack is identified.
8. A power grid data security protection device, characterized in that: Applied to the transmitting end, the power grid data security protection device comprises: A watermark generation module, used for acquiring original measurement data of the power system and generating a unique original digital watermark for the original measurement data; the original digital watermark includes an original timestamp related to the watermark generation time; A watermark embedding module, used for embedding the original digital watermark into the original measurement data to generate watermarked measurement data; The data transmission module is used to transmit the watermarked measurement data to a receiving end so that the receiving end can extract the digital watermark from the watermarked measurement data, identify the data tampering attack by watermark distance calculation in combination with a similarity measurement algorithm, and identify the replay attack by time difference comparison. When a data tampering attack and / or a replay attack is identified, a security alarm is triggered and further processing of the watermarked measurement data is refused.
9. An electronic device, characterized in that: The device comprises a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is used to execute the power grid data security protection method according to any one of claims 1-6 according to the instructions in the program code.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store program code, and the program code is used to execute the power grid data security protection method according to any one of claims 1-6.