Power data cross-domain dynamic trust evaluation and access control method

By introducing a zero-trust architecture and dynamic trust evaluation method in power data access control, combining random forest algorithms and large language models, the shortcomings of traditional access control mechanisms in complex environments are solved, and high security and reliability of cross-domain access of power data are achieved.

CN120145351APending Publication Date: 2025-06-13ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510211774.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The traditional power data access control mechanism is based on static identity authentication and fixed permission allocation, and it is difficult to cope with complex and changeable converged access environments. It lacks dynamic trust evaluation and real-time response capabilities, and cannot effectively ensure the security and integrity of power data in cross-domain access.

Method used

A cross-domain dynamic trust evaluation and access control method of power data is proposed. Based on the zero-trust architecture, the context information between users and devices is collected in real time, the trust value and risk value are generated using a random forest algorithm, and the trust degree is calculated dynamically. Combined with product quantization technology and large language model, access authorization strategy is generated to realize fine-grained dynamic access control and user abnormal behavior recognition.

Benefits of technology

It realizes dynamic adaptability and real-time response capabilities, effectively prevents malicious attacks and abuse of permissions, improves the security and reliability of cross-domain access of power data, and ensures the integrity and security of data during transmission and sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145351A_ABST
    Figure CN120145351A_ABST
Patent Text Reader

Abstract

The invention discloses a power data cross-domain dynamic trust evaluation and access control method, and belongs to the field of power data security management and control. The method comprises the following steps: S1, dynamic trust evaluation: acquiring context information of a user and equipment in real time, generating a trust value and a risk value by using a random forest algorithm, and dynamically calculating a trust degree; s2, adapting to a sequence recommendation algorithm of a large language model based on a product quantization technology: generating an access authorization strategy through behavior sequence embedding generation and vector quantization in combination with credibility; s3, fine-grained dynamic access control: dynamically adjusting permission distribution according to the sensitivity of the power data and a real-time trust evaluation result; and S4, user abnormal behavior identification: monitoring user behaviors in real time based on a TextCNN model, identifying abnormity and triggering a safety protection mechanism. According to the method, the safety and reliability of cross-domain access of the power data can be effectively improved, data abuse is effectively prevented, and the method has wide industrial application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of power data security control, and particularly relates to a method for cross-domain dynamic trust evaluation and access control of power data. Background Art

[0002] Under the background of the rapid development of informatization and intelligentization in the current power industry, the wide access of power Internet of Things, new energy facilities, third-party special charging platforms, etc. makes the power data show an obvious trend of cross-regional and cross-system interaction and sharing.

[0003] With the increasing connection of the power system to external networks, power data in a low-trust environment is facing many severe risks. On the one hand, there is a possibility that the data can be illegally obtained. Malicious attackers may obtain sensitive data in the power system, such as power grid operation parameters, user electricity consumption information, etc. through network vulnerabilities, eavesdropping and other means. On the other hand, the risk of data tampering cannot be underestimated. Once the key power data is tampered with, it may lead to incorrect control instructions of the power system, thus affecting the normal operation of the power system. In addition, the problem of data abuse is gradually emerging. Unauthorized entities may use the obtained power data for improper business activities or other illegal acts. These risks seriously threaten the stable operation of the power system.

[0004] Traditional power data access control mechanisms are based on static identity authentication and fixed permission allocation. When facing the current complex and changeable integrated access environment, these mechanisms show many limitations.

[0005] Firstly, it relies on static identity authentication and fixed permission allocation, and it is difficult to cope with the rapidly changing access environment in the power system, lacking flexibility and adaptability. Secondly, it lacks a dynamic trust evaluation mechanism, cannot monitor the behavior changes of users and devices in real time, and cannot adjust access control policies according to the changes in the security situation, resulting in the inability to respond in time when facing network attacks or security vulnerabilities. Thirdly, traditional mechanisms fail to effectively handle complex problems in cross-domain access of power data, such as trust evaluation and permission adjustment between different regions and systems. In addition, its response speed is slow, and it cannot quickly modify permissions and policies when security events occur, thus increasing the risk of data leakage or tampering. Finally, the permission management of traditional mechanisms lacks an auditing function and cannot track access behaviors in real time, increasing the difficulty of accountability and repair afterwards. These limitations make traditional mechanisms unable to effectively guarantee the security and integrity of power data in complex environments. Summary of the Invention

[0006] Aiming at the problems mentioned in the background art, the present invention proposes a method for cross-domain dynamic trust evaluation and access control of power data, which is constructed based on the zero-trust architecture and aims to solve the security and precise authorization problems in cross-domain access of power data.

[0007] Technical solution: To solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0008] A cross-domain dynamic trust evaluation and access control method for power data, comprising the following steps:

[0009] S1: Dynamic trust evaluation: By collecting the context information of users and devices in real time, using the random forest algorithm to generate trust values and risk values, and dynamically calculating the trust degree;

[0010] S2: Sequence recommendation algorithm for adapting large language models based on product quantization technology: By generating behavioral sequence embeddings and vector quantization, and combining the trust degree to generate access authorization policies;

[0011] S3: Fine-grained dynamic access control: Dynamically adjust the permission allocation according to the sensitivity of power data and the results of real-time trust evaluation;

[0012] S4: User abnormal behavior recognition: Based on the TextCNN model, monitor user behavior in real time, identify abnormalities and trigger the security protection mechanism.

[0013] Preferably, the specific process of S1 is as follows:

[0014] S11: Multidimensional data collection: Use embedded devices to collect behavioral data and transmit the collected data to the edge computing device in real time;

[0015] S12: Trust value generation: Construct a trust model through the random forest algorithm;

[0016] S13: Historical trust value generation: Calculate the historical trust value by analyzing the historical behavior of users ;

[0017] S14: Risk value calculation: Generate a risk value according to the deviation of user operation behavior;

[0018] S15: Dynamic trust degree update: Combine the trust value , historical trust value and risk value to calculate the final dynamic trust degree.

[0019] Preferably, in S12, the trust value generation: The specific process of constructing a trust model through the random forest algorithm is as follows:

[0020] S121: Input feature vector , where, represents multi-dimensional features, represents the dimension of vector X;

[0021] S122: Construct A decision tree that uses information gain to select the optimal splitting node and outputs the trust value of each tree ;

[0022] S123: Combine the trust values T output by each decision tree. The specific calculation formula is:

[0023] ,

[0024] where K represents the number of decision trees.

[0025] Preferably, in S13, the historical trust value is generated: Calculate the historical trust value by analyzing the user's historical behavior The specific process is:

[0026] S131: Feature extraction: Extract the average login frequency, data access type distribution, and abnormal behavior ratio from the user's historical behavior records;

[0027] S132: Assign weights to each feature ;

[0028] S133: Trust value calculation: Combine the feature values and weights to calculate the historical trust value. The specific calculation formula is:

[0029]

[0030] where represents the value of the th feature, represents the weight of the th feature;

[0031] S134: Time decay adjustment: To reflect the time correlation of historical behaviors, apply time decay to earlier behaviors. The adjustment formula is:

[0032]

[0033] where is the time decay coefficient, is the time interval from the feature to the current time, represents the value of the th feature, represents the weight of the th feature.

[0034] Preferably, the specific process of S2 is:

[0035] S21: Use a large language model to perform embedding representation on the text information in the user behavior sequence to generate high-dimensional embedding vectors, expressed as:

[0036]

[0037] Among them, is the embedding vector, is the user interaction behavior, and LLM represents the large language model;

[0038] S22: Use product quantization technology to reduce the dimension of the high-dimensional embedding vector;

[0039] S23: Use the quantized embedding vector to model the user behavior sequence through the multi-head attention mechanism and generate a recommendation score.

[0040] Preferably, in S22, the specific process of using product quantization technology to reduce the dimension of the high-dimensional embedding vector is as follows:

[0041] S221: Split the embedding vector into multiple sub-vectors, specifically:

[0042] ,

[0043] Among them, represents the high-dimensional embedding vector, represents the number of sub-vectors;

[0044] S222: Use K-means clustering to generate the codebook of the sub-vectors, and the optimization objective is:

[0045] ,

[0046] Among them, represents the number of samples, represents the number of sub-vectors, represents the th sub-vector, represents the clustering centroid, represents the clustering label;

[0047] S223: Quantize the sub-vectors to generate low-dimensional feature vectors, specifically:

[0048] ,

[0049] Among them, represents the index of the centroid corresponding to the th sample of the th sub-vector, argmin represents the value of the variable when a certain function reaches the minimum, represents the th sub-vector, represents the clustering centroid;

[0050] The compressed embedding vector is expressed as:

[0051] ,

[0052] Among them, represents the low-dimensional vector after quantization of the th sample, and m represents the dimension of the compressed embedded vector.

[0053] Preferably, the specific process of S3 is as follows:

[0054] S31: Data classification strategy: Divide power data into ordinary monitoring data, core operation parameters, and highly sensitive data based on data sensitivity;

[0055] S32: Trust level and permission allocation: When the trust level exceeds the threshold corresponding to the sensitive data , access is allowed, otherwise access is denied;

[0056] S33: Dynamic threshold adjustment: Dynamically adjust the threshold according to data access behavior and business scenarios. The calculation formula is:

[0057]

[0058] Among them, is the adjustment parameter, is the data sensitivity level, and Threshold s represents the dynamic threshold;

[0059] S34: During the access control process, whenever a user or device completes a trust assessment, the system reallocates permissions according to the latest trust level.

[0060] Preferably, the specific process of S4 is as follows:

[0061] S41: Real-time monitor the deviation degree between the user's access behavior and the recommended authorization behavior, such as whether the user accesses sensitive data frequently within a short period of time, whether the user accesses sensitive data frequently within a short period of time, and check whether the user behavior sequence conforms to the normal business logic;

[0062] S42: Detect abnormal behaviors based on the TextCNN model;

[0063] S43: If the probability of abnormal behavior exceeds the preset threshold, trigger an alarm and restrict the access permission, and at the same time link the security protection device for in-depth investigation.

[0064] Preferably, in S42, the specific process of detecting abnormal behaviors based on the TextCNN model is as follows:

[0065] S421: Construct a behavior feature embedding matrix: Generate a word vector matrix by performing word embedding on the user behavior sequence according to the Word2vec pre-trained model;

[0066] S422: Extract behavioral feature vectors using convolutional kernels of different sizes: Extract key behavioral features through one-dimensional convolution calculation;

[0067] S423: Max pooling for dimensionality reduction: Reduce the dimensionality of the features extracted by the convolutional layer, reduce the computational complexity, and prevent overfitting;

[0068] S424: Output the probability of abnormal behavior: Output the probability distribution of abnormal behavior through the fully connected layer.

[0069] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0070] (1) The present invention has dynamic adaptability and real-time response capabilities. Traditional methods usually rely on fixed permission settings and static authentication, while the present invention can perform real-time evaluation of the trust status of devices and users at each data access link by introducing a real-time trust evaluation mechanism. This dynamic evaluation not only considers the identity information of devices and users, but also comprehensively considers multiple factors such as device status and network environment, enabling each access control decision to be made based on the latest security situation, thereby effectively preventing malicious attacks and permission abuse.

[0071] (2) The technical solution of the present invention innovates in cross-domain access control and can effectively solve the complexity of access permission management between different systems and regions. By constructing a flexible trust evaluation system, it not only improves security, but also ensures that the system can operate efficiently in the face of a complex multi-system and multi-device environment. This improvement makes the cross-domain access of power data more controllable and can adjust security policies in real time to ensure the integrity and security of power data during transmission and sharing.

[0072] (3) The cross-domain dynamic trust evaluation and access control method for power data of the present invention breaks the traditional static management and control mode, continuously performs dynamic identity authentication on power devices and users throughout the process, re-evaluates the trust status at each data access link, and ensures that only the subjects that pass the trust verification can enter the access process, thereby establishing a safe, controllable, and adaptive cross-domain access channel for power data.

[0073] (4) The present invention fundamentally solves the problem of cross-domain management and control of power data, builds a solid data security defense line for the digital transformation of the power industry, has extremely high practical value and broad promotion prospects, and is expected to become a new support technology in the field of power data security. Brief description of the drawings

[0074] Figure 1 It is the system architecture diagram of the embodiment of the present invention. Detailed implementation manners

[0075] The present invention will be further illustrated below in conjunction with specific embodiments. The embodiments are implemented on the premise of the technical solution of the present invention. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.

[0076] As Figure 1 shown, the power data cross-domain dynamic trust evaluation and access control method provided in this embodiment mainly includes the following steps:

[0077] S1: Dynamic trust evaluation: By collecting the context information of users and devices in real time, including user login behavior, operation frequency, data access type, and operation coherence, use the random forest algorithm to generate trust values and risk values, and dynamically calculate the trust degree;

[0078] The dynamic trust evaluation module is deployed in a software and hardware combined manner to achieve real-time trust evaluation of users and devices. The module is divided into a data collection layer, an edge computing layer, and a background processing layer. The specific implementation is as follows:

[0079] S11: Multidimensional data collection;

[0080] Deployed on user terminals and power equipment, use embedded devices to collect behavior data, including user login time, operation frequency, data access type, operation coherence, etc.; use the MQTT (Message Queuing Telemetry Transport) protocol to transmit the collected data to the edge computing device in real time.

[0081] S12: Background processing, trust value generation: Build a trust model through the random forest algorithm, specifically:

[0082] S121: Input feature vector ,

[0083] wherein, represents multi-dimensional features, n represents the dimension of the vector X, and the multi-dimensional features include login frequency, operation coherence, data access type, etc.;

[0084] S122: Build decision trees, use information gain to select the optimal splitting node, and output the trust value of each tree ;

[0085] Run the random forest model on the server side, build decision trees, and calculate the trust value of each tree ;

[0086] S123: Integrate the trust values T output by each decision tree. The specific calculation formula is: ,

[0087] wherein, K represents the number of decision trees;

[0088] S13: Historical Trust Value Calculation: Calculate the historical trust value by analyzing the user's historical behavior ;

[0089] S131: Feature Extraction: Extract the average login frequency, data access type distribution, and abnormal behavior ratio from the user's historical behavior records;

[0090] S132: Assign weights to each feature and the sum of the weights is 1;

[0091] S133: Trust Value Calculation: Calculate the historical trust value by combining the feature values and weights. The calculation formula is:

[0092]

[0093] where, represents the value of the th feature, represents the th feature's weight;

[0094] S134: Time Decay Adjustment: To reflect the time correlation of historical behavior, apply time decay to earlier behaviors. The adjustment formula is:

[0095]

[0096] where, is the time decay coefficient, is the time interval from the feature to the current time, represents the value of the th feature, represents the th feature's weight, represents the natural exponential function.

[0097] S14: Risk Value Calculation: Generate a risk value based on the deviation of the user's operation behavior. The specific calculation formula is:

[0098]

[0099] where, R represents the risk value, M represents the number of risk indicators, represents the weight of the risk indicator, is the risk indicator value, is the safe range of the risk indicator;

[0100] S15: Dynamic Trust Degree Update: Combine the trust value , historical trust value and risk value to calculate the final dynamic trust degree. The specific calculation formula is:

[0101]

[0102] Among them, and are adjustment parameters, indicating the final dynamic trust level;

[0103] The server side uses WebSocket to feedback the trust evaluation results to the user terminal and the power device terminal in real time.

[0104] S2: Sequence recommendation algorithm for adapting large language models based on product quantization technology: generating sum vectors through behavior sequence embedding and vector quantization, and combining trust levels to generate access authorization policies;

[0105] This module optimizes the recommendation process through behavior sequence embedding and product quantization technology, and is implemented by combining a recommendation engine and distributed computing technology. The specific implementation steps are as follows:

[0106] S21: Behavior sequence embedding: Use a large language model to perform embedding representation on the text information in the user behavior sequence to generate high-dimensional embedding vectors, expressed as:

[0107]

[0108] Among them, is the embedding vector, is the user interaction behavior, and LLM represents the large language model;

[0109] In this embodiment, the Transformer model is used to implement the embedding of the behavior sequence using the PyTorch framework to generate high-dimensional vectors:

[0110] ,

[0111] S22: Quantization and dimensionality reduction: Use product quantization technology to reduce the dimensionality of the high-dimensional embedding vectors;

[0112] Deploy the Faiss tool for efficient vector retrieval and quantization. The specific implementation steps are:

[0113] S221: Split the embedding vector into multiple sub-vectors:

[0114] ,

[0115] Among them, represents the high-dimensional embedding vector, represents the number of sub-vectors;

[0116] S222: Use K-means clustering to generate the codebook of the sub-vectors, and the optimization objective is:

[0117] ,

[0118] Among them, represents the number of samples, represents the number of sub-vectors, represents the -th sub-vector, represents the clustering centroid, is the clustering label;

[0119] S223: Generate low-dimensional feature vectors by sub-vector quantization:

[0120] ,

[0121] Among them, represents the index of the centroid corresponding to the -th sample's -th sub-vector. argmin represents the value of the variable when a certain function reaches its minimum value, represents the -th sub-vector, represents the clustering centroid;

[0122] S224: The compressed embedded vector is represented as:

[0123] ,

[0124] Among them, represents the quantized low-dimensional vector of the -th sample, and m represents the dimension of the compressed embedded vector;

[0125] S23: Recommendation generation: Use the quantized embedded vector, model the user behavior sequence through the multi-head attention mechanism, and generate a recommendation score. The specific calculation formula is:

[0126]

[0127] Among them, score represents the recommendation score, represents the normalization exponential function, represents the query vector, represents the transpose of the key vector, represents the dimension of the key vector K, represents the value vector;

[0128] The system generates the optimal access permission policy according to the recommendation score to achieve precise and flexible permission allocation.

[0129] S3: Fine-grained dynamic access control: Dynamically adjust the permission allocation based on the sensitivity of power data and the real-time trust evaluation results, based on the TBAC model;

[0130] Implement fine-grained dynamic access control based on the zero-trust architecture and the TBAC model (Task-Based Access Control Model), and dynamically adjust the permission policy by combining the sensitivity level of power data and the trust value.

[0131] S31: Module deployment, data classification strategy;

[0132] Deploy an access control management server, which is responsible for the real-time calculation and distribution of permission policies; the definition of data sensitivity levels is stored in the relational database MySQL, and power data is divided into (ordinary monitoring data), (core operating parameters), and (highly sensitive data) based on data sensitivity;

[0133] S32: Trust level and permission allocation: When the trust level exceeds the threshold corresponding to the sensitive data access is allowed, otherwise access is denied;

[0134] S33: Dynamic threshold adjustment: Dynamically adjust the threshold according to data access behavior and business scenarios. The formula is:

[0135]

[0136] where is the adjustment parameter, is the data sensitivity level, and Threshold s represents the dynamic threshold.

[0137] Use the open-source Keycloak (authentication and access management) tool to build a permission management service; configure RESTful API (RESTful API is an application programming interface (API) based on the REST (Representational State Transfer) architectural style), and update the permission allocation policy in real time and interact with the front-end terminal.

[0138] S34: During the access control process, whenever a user or device completes the trust assessment, the system reallocates permissions according to the latest trust level and performs the following steps:

[0139] S341: Initialize permission and role allocation;

[0140] S342: Perform user authentication to verify whether the user or device meets the initial trust requirements;

[0141] S343: Trust value calculation: Dynamically evaluate the trust value based on historical behavior and current behavior;

[0142] S344: Permission verification: If the trust value is lower than the current trust threshold, immediately terminate the access permission.

[0143] S4: User abnormal behavior recognition: Based on the TextCNN (Text Convolutional Neural Network) model, monitor user behavior in real time, identify abnormalities, and trigger the security protection mechanism.

[0144] The user abnormal behavior recognition module detects abnormal operations through a deep learning model and is deployed in the user terminal and the background server.

[0145] S41: Real-time monitor the deviation degree between the user access behavior and the recommended authorization behavior, such as whether the user accesses sensitive data frequently in a short period of time, whether the user accesses sensitive data frequently in a short period of time, and check whether the user behavior sequence conforms to the normal business logic;

[0146] S42: Detect abnormal behavior based on the TextCNN model. The specific process is as follows:

[0147] S421: Construct a behavior feature embedding matrix: Generate a word vector matrix by performing word embedding on the user behavior sequence according to the Word2vec pre-trained model;

[0148] S422: Extract behavior feature vectors using convolutional kernels of different sizes: Extract key behavior features through one-dimensional convolution calculation;

[0149] S423: Max pooling for dimensionality reduction: Reduce the dimensionality of the features extracted by the convolutional layer, reduce the computational complexity, and prevent overfitting;

[0150] S424: Output the probability of abnormal behavior: Output the probability distribution of abnormal behavior through the fully connected layer;

[0151] Use TensorFlow (an open-source machine learning framework) to implement the TextCNN model to extract features and calculate the probability of abnormality.

[0152] S43: If the probability of abnormal behavior exceeds the preset threshold, trigger a warning and restrict the access permission. At the same time, link with the security protection device for in-depth investigation, configure the Apache Kafka (an open-source distributed stream processing platform) message queue, and interface with the real-time monitoring system.

[0153] The present invention can effectively improve the security and reliability of cross-domain access to power data, effectively prevent data abuse, and has wide industrial application value.

[0154] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for cross-domain dynamic trust assessment and access control of power data, characterized by: The following steps are involved: S1: Dynamic trust assessment: By collecting the contextual information of users and devices in real time, the trust value and risk value are generated using the random forest algorithm, and the trust degree is dynamically calculated; S2: Sequence recommendation algorithm based on product quantization technology adapted to large language models: Through behavior sequence embedding generation and vector quantization, access authorization strategy is generated in combination with trust; S3: Fine-grained dynamic access control: Dynamically adjust permission allocation based on the sensitivity of power data and real-time trust assessment results; S4: Abnormal user behavior identification: Based on the TextCNN model, user behavior is monitored in real time, anomalies are identified and security protection mechanisms are triggered.

2. The method for cross-domain dynamic trust assessment and access control of power data according to claim 1 is characterized in that: The specific process of S1 is: S11: Multi-dimensional data collection: Use embedded devices to collect behavioral data and transmit the collected data to edge computing devices in real time; S12: Trust value generation: building a trust model through random forest algorithm; S13: Historical trust value generation: Calculate historical trust value by analyzing user historical behavior ; S14: Risk value calculation: Generate risk value based on user operation behavior deviation; S15: Dynamic trust update: combined with trust value , Historical Trust Value and risk value Calculate the final dynamic trust.

3. The method for cross-domain dynamic trust assessment and access control of power data according to claim 2 is characterized in that: In S12, trust value generation: The specific process of building a trust model through the random forest algorithm is: S121: Input feature vector ,in, Represents multidimensional features, n represents the dimension of vector X; S122: Build decision trees, use information gain to select the optimal split node, and output the trust value of each tree ; S123: The trust value T output by each decision tree is calculated using the following formula: ; Here, K represents the number of decision trees.

4. The method for cross-domain dynamic trust assessment and access control of power data according to claim 2 is characterized in that: In S13, historical trust value generation: historical trust value is calculated by analyzing user historical behavior The specific process is: S131: Feature extraction: extract the average login frequency, data access type distribution, and abnormal behavior ratio from the user's historical behavior records; S132: Assign weights to each feature ; S133: Trust value calculation: Calculate the historical trust value by combining the characteristic value and the weight. The specific calculation formula is: ; in, Indicates The value of the feature, Indicates The weight of each feature; S134: Time decay adjustment: To reflect the temporal relevance of historical actions, time decay is applied to earlier actions. The adjustment formula is: ; in, is the time attenuation coefficient, Features The time interval from the current time, Indicates The value of the feature, Indicates The weight of a feature.

5. The method for cross-domain dynamic trust assessment and access control of power data according to claim 1 is characterized in that: The specific process of S2 is: S21: Use a large language model to embed the text information in the user behavior sequence and generate a high-dimensional embedding vector, which is expressed as: ; in, is the embedding vector, For user interaction behavior, LLM stands for Large Language Model; S22: Reduce the dimensionality of high-dimensional embedding vectors using product quantization techniques; S23: Use the quantized embedding vector to model the user behavior sequence through the multi-head attention mechanism and generate the recommendation score.

6. The method for cross-domain dynamic trust assessment and access control of power data according to claim 5 is characterized in that: In S22, the specific process of using the product quantization technique to reduce the dimensionality of the high-dimensional embedding vector is as follows: S221: Split the embedding vector into multiple sub-vectors, specifically: ; in, represents a high-dimensional embedding vector, represents the number of sub-vectors; S222: Generate a codebook of subvectors using K-means clustering, with the optimization goal being: ; in, represents the number of samples, represents the number of sub-vectors, Indicates sub-vectors, represents the cluster centroid, represents the cluster label; S223: Sub-vector quantization generates a low-dimensional feature vector, specifically: ; in, Indicates The sample The index of the centroid corresponding to the sub-vector, argmin represents the value of the variable when a function reaches the minimum value, Indicates sub-vectors, represents the cluster centroid; S224: The compressed embedding vector is expressed as: ; in, Indicates The low-dimensional vector of samples is quantized, and m represents the dimension of the compressed embedding vector.

7. The method for cross-domain dynamic trust assessment and access control of power data according to claim 1 is characterized in that: The specific process of S3 is: S31: Data classification strategy: divide power data into general monitoring data, core operating parameters and highly sensitive data based on data sensitivity; S32: Trust and authority allocation: When trust Exceeding the threshold for sensitive data If yes, access is allowed, otherwise access is denied; S33: Dynamic threshold adjustment: Dynamically adjust the threshold according to data access behavior and business scenarios. The calculation formula is: ; in, To adjust the parameters, is the data sensitivity level, Threshold s represents a dynamic threshold; S34: During the access control process, each time a user or device completes a trust evaluation, the system reallocates permissions based on the latest trust level.

8. The method for cross-domain dynamic trust assessment and access control of power data according to claim 1 is characterized in that: The specific process of S4 is: S41: Real-time monitoring of the deviation between user access behavior and recommended authorization behavior, such as whether the user frequently accesses sensitive data in a short period of time, whether the user frequently accesses sensitive data in a short period of time, and whether the user behavior sequence conforms to normal business logic; S42: Detect abnormal behavior based on TextCNN model; S43: If the probability of abnormal behavior exceeds the preset threshold, an early warning is triggered and access rights are restricted. At the same time, security protection equipment is linked to conduct in-depth inspections.

9. The method for cross-domain dynamic trust assessment and access control of power data according to claim 8 is characterized in that: In S42, the specific process of detecting abnormal behavior based on the TextCNN model is as follows: S421: Constructing a behavior feature embedding matrix: Generate a word vector matrix by embedding the user behavior sequence according to the Word2vec pre-training model; S422: Extracting behavior feature vectors using convolution kernels of different sizes: extracting key behavior features through one-dimensional convolution calculation; S423: Max pooling dimensionality reduction: Reduce the dimensionality of features extracted by the convolutional layer to reduce computational complexity and prevent overfitting; S424: Output abnormal behavior probability: output the probability distribution of abnormal behavior through the fully connected layer.

Citation Information

Cited By

  • Automatic driving vehicle control method based on driving style and dynamic trust evaluation

    CN120534387A

  • Electronic purchase approval method based on zero-trust model

    CN120763976A