Power terminal data protection method and system

By hierarchical encryption and dynamic key management of power terminal data, combined with instruction protection mechanism, the security risks faced by power terminal data are solved, and efficient, flexible and reliable data protection is achieved.

CN120034351APending Publication Date: 2025-05-23YUNNAN POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411842887.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Power terminal data faces many security risks and challenges in power transmission, substation, distribution, and power consumption, including network attacks and illegal access, resulting in data tampering and sensitive information theft, which may in turn cause power system failure or major security accidents.

Method used

By layering the power terminal data and dynamically adjusting the data level with the settings of indicators and thresholds, different encryption strategies are adopted for each layer of data, including lightweight encryption algorithms, asymmetric encryption algorithms and instruction-level protection mechanisms, and layered key generation is carried out through the dynamic key management module, a periodic rotation mechanism and key life cycle management are introduced, combining instruction flow obfuscation, randomization and dynamic instruction decryption to achieve comprehensive protection of power terminal data.

Benefits of technology

Through dynamic hierarchical mechanism and multi-level encryption strategy, data protection levels can be automatically adjusted according to real-time security requirements and environmental changes of data, improving the flexibility and adaptability of the system, effectively preventing key leakage and cracking, enhancing data security and confidentiality, and improving the system's response speed and accuracy to security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034351A_ABST
    Figure CN120034351A_ABST
Patent Text Reader

Abstract

The invention discloses a power terminal data protection method and system, and relates to the technical field of power data protection, and the method comprises the following steps: layering power terminal data, and carrying out the dynamic adjustment of a data grade through the setting of an index and a threshold value; encrypting each layer of power terminal data; and comprehensive protection of the power terminal data is realized in combination with an instruction protection mechanism. The data layering mechanism has dynamic adaptability, the layering structure of the data can be automatically adjusted according to the real-time safety requirement of the data and the environment change condition, and the flexibility and adaptability of the system are improved. And meanwhile, the data is layered more finely, so that the security and availability requirements of different data in the power system can be better met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power data protection, and in particular to a power terminal data protection method and system. Background Art

[0002] With the construction of smart grid, power Internet of Things and digital grid, the power industry has generated massive amounts of data in various links such as transmission, transformation, distribution and consumption. These data are of great significance to the intelligent perception of the power grid, internal control capabilities and the improvement of user service efficiency.

[0003] However, at the same time, power terminal data also faces many security risks and challenges. As power is a key national infrastructure, its information system and data resources are vulnerable to cyber attacks and illegal access. Attackers may cause power system failures or major safety accidents by tampering with key data and stealing sensitive information.

[0004] In the power system, the security and integrity of data are crucial to the stable operation of the system. Different power data needs to be protected by different encryption measures due to their different importance and sensitivity. In particular, the integrity and authenticity of key instructions are crucial to the security of the power system. Summary of the invention

[0005] In view of the problems existing in the existing power terminal data protection and system, the present invention is proposed.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, an embodiment of the present invention provides a method for protecting data of a power terminal, which comprises the following steps:

[0008] The power terminal data is layered and the data level is dynamically adjusted by setting indicators and thresholds;

[0009] Encrypt the power terminal data of each layer separately;

[0010] Combined with the instruction protection mechanism, comprehensive protection of power terminal data can be achieved.

[0011] As a preferred solution of the power terminal data protection method of the present invention, the step of stratifying the circuit terminal data includes:

[0012] By analyzing the frequency, method and pattern of user operations, combined with behavior analysis and pattern recognition of API interface calls, the preliminary classification level of the data can be determined;

[0013] Monitor special information such as data operation paths, API interface usage, and access patterns;

[0014] The data level can be adjusted in real time based on the number of accesses, whether sensitive path thresholds or indicators are accessed.

[0015] As a preferred solution of the power terminal data protection method of the present invention, the step of encrypting each layer of power terminal data separately includes:

[0016] Each layer of power terminal data includes common data, sensitive data, and key command data;

[0017] The encryption strategy adopted for ordinary data is lightweight encryption algorithm;

[0018] The encryption strategy adopted for sensitive data is asymmetric encryption algorithm;

[0019] The encryption strategy adopted for key instruction data is an instruction-level protection mechanism;

[0020] The instruction-level protection mechanism includes generating obfuscated stream data and adding randomization processing to generate the data stream.

[0021] As a preferred solution of the power terminal data protection method of the present invention, after encrypting each layer of power terminal data, hierarchical key generation is performed through a dynamic key management module, and the specific steps include:

[0022] For each layer of power terminal data, a different key generation algorithm is used to generate the corresponding key;

[0023] Generate a master key based on a hash function, derive a master key into multiple subkeys, each subkey corresponds to a data level;

[0024] The normal data subkey is based on the MD5 value of the source IP address and is connected to the subkey with the @ symbol;

[0025] The sensitive data subkey generates an MD5 value based on the source MAC address and connects it to the subkey with the @ symbol;

[0026] The key instruction data subkey generates a SHA256 value based on the source IP address and source MAC address and connects it to the subkey through the @ symbol.

[0027] As a preferred solution of the power terminal data protection method of the present invention, a periodic rotation mechanism is introduced to enhance data security. The specific steps include:

[0028] The rotation frequency is set based on the sensitivity and security of the data level, where:

[0029] The basic setting for normal data is to rotate the key every 180 minutes;

[0030] The basic setting for sensitive data is to rotate keys every 120 minutes;

[0031] The basic setting for key instruction data is to rotate the key every 30 minutes;

[0032] When rotating keys, the old key is used as KEY and the new key is used as VALUE. When updating, the device obtains the new key through the old key and ensures a smooth transition between the new key and the old key.

[0033] As a preferred solution of the power terminal data protection method of the present invention, when managing the key, the key life cycle management is adopted, which is specifically expressed as follows:

[0034] When the key is generated, a unique identifier is assigned to each key, and corresponding key metadata is established to record the key's generation time, usage, and rotation history.

[0035] As a preferred solution of the power terminal data protection method of the present invention, wherein: the operation steps of the instruction protection mechanism include instruction stream obfuscation, introduction of randomization, and dynamic instruction decryption;

[0036] The instruction stream obfuscation is expressed as:

[0037] The data values ​​of the instruction data are exchanged in the front and back positions, that is, the first position is exchanged with the last position, the second position is exchanged with the second to last position, and so on;

[0038] Continue to add virtual instructions or invalid instructions to the initial obfuscated stream data, and add them in the following way: introduce the instructions to the first three bits at the same time, forming the final instruction data obfuscated stream;

[0039] The introduction of randomization is expressed as:

[0040] Introducing random factors to produce different results each time a key instruction is executed, making the execution results of the instructions uncertain;

[0041] The dynamic instruction decryption is expressed as:

[0042] The key instructions are encrypted and stored, and the instruction content is dynamically decrypted and parsed during execution, and the plaintext instruction content is obtained during the execution stage.

[0043] In a second aspect, an embodiment of the present invention provides a power terminal data protection system, which includes a data layering module, a data encryption module, a dynamic key management module, and an instruction protection mechanism module;

[0044] The data stratification module determines the preliminary classification level of the data by analyzing the frequency, method and pattern of user operations and performing behavior analysis and pattern recognition in combination with the call status of the API interface;

[0045] The data encryption module encrypts each layer of power terminal data separately, including ordinary data, sensitive data and key instruction data;

[0046] The dynamic key management module generates corresponding keys for each layer of power terminal data using different key generation algorithms;

[0047] The instruction protection mechanism module includes instruction stream obfuscation, introduction of randomization, and dynamic instruction decryption.

[0048] In a third aspect, an embodiment of the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, wherein: when the processor executes the computer program, any step of the above-mentioned power terminal data protection method is implemented.

[0049] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the above-mentioned power terminal data protection method is implemented.

[0050] The beneficial effects of the present invention are:

[0051] The data stratification mechanism is dynamically adaptable and can automatically adjust the data stratification structure according to the real-time security requirements of the data and environmental changes, thus improving the flexibility and adaptability of the system. At the same time, by making the data more refined, it can better meet the security and availability requirements of different data in the power system.

[0052] The dynamic key management mechanism, through a unique algorithm and management method, can timely update the key and implement key rotation, effectively preventing key leakage and cracking, and improving the security and confidentiality of data. At the same time, multi-level encryption is adopted, and each data level uses different encryption algorithms and keys, which increases the difficulty for attackers to crack.

[0053] The dynamic key management mechanism has established a complete key lifecycle management mechanism, including key generation, distribution, use, rotation and destruction, which can fully ensure the security and controllability of keys and improve the system's response speed and accuracy to security incidents.

[0054] The instruction protection method combines obfuscation with the introduction of randomization, which increases the difficulty for attackers to predict the instruction execution process and results, and improves the security and integrity of the instructions. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:

[0056] Figure 1 The figure is a flow chart of a method for protecting data of a power terminal.

[0057] Figure 2 The data layering flow chart of the power terminal data protection method.

[0058] Figure 3 The hierarchical encryption data flow chart of the power terminal data protection method.

[0059] Figure 4 The present invention is a flow chart of dynamic key management for the power terminal data protection method.

[0060] Figure 5 The flowchart of the key instruction protection mechanism of the power terminal data protection method is shown in FIG. DETAILED DESCRIPTION

[0061] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0062] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0063] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0064] The present invention is described in detail with reference to schematic diagrams. When describing the embodiments of the present invention, for the sake of convenience, the cross-sectional diagrams showing the device structure will not be partially enlarged according to the general scale, and the schematic diagrams are only examples, which should not limit the scope of protection of the present invention. In addition, in actual production, the three-dimensional dimensions of length, width and depth should be included.

[0065] At the same time, in the description of the present invention, it should be noted that the directions or positional relationships indicated by the terms "upper, lower, inner and outer" are based on the directions or positional relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore cannot be understood as limiting the present invention. In addition, the terms "first, second or third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0066] In the present invention, unless otherwise clearly specified and limited, the terms "install, connect, connect" should be understood in a broad sense, for example: it can be a fixed connection, a detachable connection or an integral connection; it can also be a mechanical connection, an electrical connection or a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0067] Example 1

[0068] Reference Figure 1 to Figure 5 , which is the first embodiment of the present invention, and provides a method for protecting data of a power terminal, comprising the following steps:

[0069] S1. Layer the power terminal data and dynamically adjust the data level by setting indicators and thresholds.

[0070] The steps for stratifying circuit terminal data include:

[0071] By analyzing the frequency, method and pattern of user operations, combined with behavior analysis and pattern recognition of API interface calls, the preliminary classification level of the data can be determined;

[0072] Monitor special information such as data operation paths, API interface usage, and access patterns;

[0073] The data level can be adjusted in real time based on the number of accesses, whether sensitive path thresholds or indicators are accessed.

[0074] like Figure 2As shown in the figure, according to the Instant Data Analysis Algorithm method (data instant analysis method), the power terminal data can be dynamically classified and adjusted according to the real-time data situation and environmental changes. Including data flow, user access mode, network security threats, user operation behavior, external network connection, access frequency, data type and other factors, the data is automatically classified into layers (ordinary data, sensitive data, key instruction data), and the data level is dynamically adjusted through the setting of indicators and thresholds, so as to more accurately realize the protection of data at different levels.

[0075] S2. Encrypt the data of each layer of power terminals separately.

[0076] The steps of encrypting each layer of power terminal data separately include:

[0077] like Figure 3 As shown, each layer of power terminal data includes common data, sensitive data, and key instruction data;

[0078] The encryption strategy adopted for ordinary data is a lightweight encryption algorithm; its data characteristics are general power terminal data, such as log information, basic parameters, basic information of user login, etc. The specific encryption process is to encrypt ordinary data using the AES algorithm and add the device MAC address that conforms to the format of this data to the end of each data for verification.

[0079] The encryption strategy adopted for sensitive data is an asymmetric encryption algorithm; its data characteristics include data flow, user access patterns, network security threats, external network connections, access frequency, data types, etc. The specific encryption method is to use the RSA algorithm to perform public key encryption on the data to ensure the confidentiality of the data and ensure that only legitimate users holding the private key can decrypt the data.

[0080] The encryption strategy adopted for key instruction data is an instruction-level protection mechanism; its data features are some key operations such as control commands, firmware updates, and user operations.

[0081] The instruction-level protection mechanism includes generating obfuscated stream data and adding randomization processing to generate the data stream.

[0082] like Figure 4 As shown, after encrypting the data of each layer of power terminals, hierarchical keys are generated through the dynamic key management module. The specific steps include:

[0083] For each layer of power terminal data, a different key generation algorithm is used to generate the corresponding key;

[0084] Generate a master key based on a hash function, derive a master key into multiple subkeys, each subkey corresponds to a data level;

[0085] The normal data subkey is based on the MD5 value of the source IP address and is connected to the subkey with the @ symbol;

[0086] The sensitive data subkey generates an MD5 value based on the source MAC address and connects it to the subkey with the @ symbol;

[0087] The key instruction data subkey generates a SHA256 value based on the source IP address and source MAC address and connects it to the subkey through the @ symbol.

[0088] Introduce a regular rotation mechanism to enhance data security. The specific steps include:

[0089] The rotation frequency is set based on the sensitivity and security of the data level, where:

[0090] The basic setting for normal data is to rotate the key every 180 minutes;

[0091] The basic setting for sensitive data is to rotate keys every 120 minutes;

[0092] The basic setting for key instruction data is to rotate the key every 30 minutes;

[0093] When rotating keys, the old key is used as KEY and the new key is used as VALUE. When updating, the device obtains the new key through the old key and ensures a smooth transition between the new key and the old key.

[0094] When managing keys, key lifecycle management is used, which is specifically expressed as follows:

[0095] When the key is generated, a unique identifier is assigned to each key, and corresponding key metadata is established to record the key's generation time, usage, and rotation history.

[0096] S3. Combined with the instruction protection mechanism, comprehensive protection of power terminal data can be achieved.

[0097] The operation steps of the instruction protection mechanism include instruction stream obfuscation, introduction of randomization, and dynamic instruction decryption;

[0098] like Figure 5 As shown, the instruction stream obfuscation is expressed as:

[0099] The data values ​​of the instruction data are exchanged in the front and back positions, that is, the first position is exchanged with the last position, the second position is exchanged with the second to last position, and so on;

[0100] Continue to add virtual instructions or invalid instructions to the initial obfuscated stream data (the virtual instruction here refers to 0, and the invalid instruction refers to all other values). The adding method is: introduce this instruction to the first three bits at the same time to form the final instruction data obfuscated stream; it is to confuse the key instructions to make its execution process complicated, increasing the difficulty for attackers to crack and tamper with it.

[0101] The introduction of randomization is expressed as:

[0102] Introducing random factors to produce different results each time a key instruction is executed, making the execution results of the instructions uncertain;

[0103] Suppose there is a program code int a=10; int b=20; int c; c=a+b; before the introduction of randomization, the execution flow of this program is fixed, first the value 10 is stored in variable a, then the value 20 is stored in variable b, and finally the result of adding a and b is stored in variable c. After the introduction of randomization, the execution order or operands of the program may change randomly, for example, the assignment operation of variable b may be executed first, and then the assignment operation of variable a. The calculation operation of variable c may occur at any time after the assignment of variables a and b. Or adding some irrelevant execution commands will not affect the final execution result or action.

[0104] The dynamic instruction decryption is expressed as:

[0105] The key instructions are encrypted and stored, and the instruction content is dynamically decrypted and parsed during execution, and the plaintext instruction content is obtained during the execution stage.

[0106] In summary, the data stratification mechanism has dynamic adaptability and can automatically adjust the hierarchical structure of data according to the real-time security requirements of data and environmental changes, thereby improving the flexibility and adaptability of the system. At the same time, by making the data more refined, it can better meet the security and availability requirements of different data in the power system; the dynamic key management mechanism, through a unique algorithm and management method, can timely update the key and implement key rotation, effectively prevent key leakage and cracking, and improve the security and confidentiality of the data. At the same time, multi-level encryption is adopted, and each data level uses different encryption algorithms and keys, which increases the difficulty for attackers to crack; the dynamic key management mechanism establishes a complete key life cycle management mechanism, including key generation, distribution, use, rotation and destruction, which can fully guarantee the security and controllability of the key and improve the system's response speed and accuracy to security incidents; the instruction protection method combines obfuscation with the introduction of randomization, which increases the difficulty for attackers to predict the instruction execution process and results, and improves the security and integrity of the instruction.

[0107] Example 2

[0108] On the basis of the first embodiment, this embodiment further provides a power terminal data protection system, including a data layering module, a data encryption module, a dynamic key management module, and an instruction protection mechanism module;

[0109] The data stratification module determines the preliminary classification level of the data by analyzing the frequency, method and pattern of user operations and performing behavior analysis and pattern recognition in combination with the call status of the API interface;

[0110] The data encryption module encrypts each layer of power terminal data separately, including ordinary data, sensitive data and key instruction data;

[0111] The dynamic key management module generates corresponding keys for each layer of power terminal data using different key generation algorithms;

[0112] The instruction protection mechanism module includes instruction stream obfuscation, introduction of randomization, and dynamic instruction decryption.

[0113] This embodiment also provides a computer device, which is suitable for the case of the power terminal data protection method, including a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute computer executable instructions to implement the power terminal data protection method proposed in the above embodiment.

[0114] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.

[0115] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the method for protecting power terminal data as proposed in the above embodiment is implemented.

[0116] The storage medium proposed in this embodiment and the data storage method proposed in the above embodiment belong to the same inventive concept. The technical details not fully described in this embodiment can be found in the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.

[0117] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for protecting power terminal data, characterized in that: The following steps are included: The power terminal data is layered and the data level is dynamically adjusted by setting indicators and thresholds; Encrypt the power terminal data of each layer separately; Combined with the instruction protection mechanism, comprehensive protection of power terminal data can be achieved.

2. The power terminal data protection method according to claim 1, characterized in that: The steps for stratifying circuit terminal data include: By analyzing the frequency, method and pattern of user operations, combined with behavior analysis and pattern recognition of API interface calls, the preliminary classification level of the data can be determined; Monitor special information such as data operation paths, API interface usage, and access patterns; The data level can be adjusted in real time based on the number of accesses, whether sensitive path thresholds or indicators are accessed.

3. The power terminal data protection method according to claim 2, characterized in that: The steps of encrypting each layer of power terminal data separately include: Each layer of power terminal data includes common data, sensitive data, and key command data; The encryption strategy adopted for ordinary data is lightweight encryption algorithm; The encryption strategy adopted for sensitive data is asymmetric encryption algorithm; The encryption strategy adopted for key instruction data is an instruction-level protection mechanism; The instruction-level protection mechanism includes generating obfuscated stream data and adding randomization processing to generate the data stream.

4. The power terminal data protection method according to claim 3, characterized in that: After encrypting the data of each layer of power terminals, hierarchical keys are generated through the dynamic key management module. The specific steps include: For each layer of power terminal data, a different key generation algorithm is used to generate the corresponding key; Generate a master key based on a hash function, derive a master key into multiple subkeys, each subkey corresponds to a data level; The normal data subkey is based on the MD5 value of the source IP address and is connected to the subkey with the @ symbol; The sensitive data subkey generates an MD5 value based on the source MAC address and connects it to the subkey with the @ symbol; The key instruction data subkey generates a SHA256 value based on the source IP address and source MAC address and connects it to the subkey through the @ symbol.

5. The power terminal data protection method according to claim 4, characterized in that: Introduce a regular rotation mechanism to enhance data security. The specific steps include: The rotation frequency is set based on the sensitivity and security of the data level, where: The basic setting for normal data is to rotate the key every 180 minutes; The basic setting for sensitive data is to rotate keys every 120 minutes; The basic setting for key instruction data is to rotate the key every 30 minutes; When rotating keys, the old key is used as KEY and the new key is used as VALUE. When updating, the device obtains the new key through the old key and ensures a smooth transition between the new key and the old key.

6. The power terminal data protection method according to claim 5, characterized in that: When managing keys, key lifecycle management is used, which is specifically expressed as follows: When the key is generated, a unique identifier is assigned to each key, and corresponding key metadata is established to record the key's generation time, usage, and rotation history.

7. The power terminal data protection method according to claim 6, characterized in that: The operation steps of the instruction protection mechanism include instruction stream obfuscation, introduction of randomization, and dynamic instruction decryption; The instruction stream obfuscation is expressed as: The data values ​​of the instruction data are exchanged in the front and back positions, that is, the first position is exchanged with the last position, the second position is exchanged with the second to last position, and so on; Continue to add virtual instructions or invalid instructions to the initial obfuscated stream data, and add them in the following way: introduce this instruction to the first three bits at the same time, so as to form the final instruction data obfuscated stream; The introduction of randomization is expressed as: Introducing random factors to produce different results each time a key instruction is executed, making the execution results of the instructions uncertain; The dynamic instruction decryption is expressed as: The key instructions are encrypted and stored, and the instruction content is dynamically decrypted and parsed during execution, and the plaintext instruction content is obtained during the execution stage.

8. A power terminal data protection system, based on the power terminal data protection method according to any one of claims 1 to 7, characterized in that: It includes data layering module, data encryption module, dynamic key management module, and instruction protection mechanism module; The data stratification module determines the preliminary classification level of the data by analyzing the frequency, method and pattern of user operations and performing behavior analysis and pattern recognition in combination with the call status of the API interface; The data encryption module encrypts each layer of power terminal data separately, including ordinary data, sensitive data and key instruction data; The dynamic key management module generates corresponding keys for each layer of power terminal data using different key generation algorithms; The instruction protection mechanism module includes instruction stream obfuscation, introduction of randomization, and dynamic instruction decryption.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the power terminal data protection method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the power terminal data protection method according to any one of claims 1 to 7 are implemented.