Sandbox-based electric power agent process isolation protection method and system
Through sandbox-based granular matrix modeling and multi-objective optimization, dynamically divide the memory space of the power intelligent body, solving the problem of mismatch in memory allocation in traditional process isolation, and achieving precise protection of power intelligent body memory access and improving system stability.
Patent Information
- Application Number
- CN202510839427.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-23
AI Technical Summary
In the memory protection of traditional process isolation, there is a problem that the memory allocation granularity does not match the actual needs, resulting in waste of resources and the inability to effectively prevent particle-sized memory attacks.
Through a sandbox-based method, combining granularity matrix modeling and multi-objective optimization, the memory space of the power intelligent body is dynamically divided, the DTW algorithm and NSGA-III evolution algorithm are used to optimize the memory allocation granularity, and the memory capacity of the isolation area is optimized through the quantum annealing algorithm to generate isolation barriers to achieve safe isolation.
It realizes precise protection of memory access for power intelligent bodies, dynamically adjusts memory resource allocation, improves the security and stability of the system, and prevents attacks such as cross-regional read and write and cache injection.
Smart Images

Figure CN120337206A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power intelligent agent process isolation and protection, and more specifically, to a method and system for power intelligent agent process isolation and protection based on a sandbox. Background Art
[0002] In the current power system, with the wide application of artificial intelligence technology, power intelligent agents have gradually become an important part of the system operation. At the same time, power intelligent agents highly rely on computing resources and complex data interactions during operation, resulting in increasingly severe security threats, especially at the memory level. Traditional process isolation mechanisms mostly adopt static memory allocation or coarse-grained strategies based on permission control, which are difficult to cope with high-frequency and multi-variant attack means, such as memory traversal, buffer overflow, malicious process hijacking, etc. In addition, although the current sandbox technology has been widely used in information system security, in the power system environment, its isolation ability and resource adaptability are insufficient and cannot meet the requirements of power intelligent agents for real-time performance, high reliability, and refined protection.
[0003] For example, the method, device, and electronic device for protecting intelligent contracts based on a sandbox disclosed in the invention patent announcement with the publication number of CN118153035A, the method includes: determining that a data sandbox accesses an intelligent contract, obtaining a security value of the intelligent contract, the security value including a confidentiality value and an integrity value, the confidentiality value indicating the level of read permission, and the integrity value being used to represent the level of write permission; updating the security value of the intelligent contract when the security value of the intelligent contract and the security value of the data sandbox meet a preset condition. The present disclosure can ensure the safe execution of the intelligent contract process in a controlled and protected environment by updating the security value of the intelligent contract when the security value of the intelligent contract and the security value of the data sandbox meet a preset condition.
[0004] In the above-disclosed technical solutions, there are at least the following technical problems: Traditional process isolation generally adopts a static allocation mechanism with a fixed granularity in process memory protection, that is, the memory is divided into partitions with predefined sizes, without considering the time-varying and different memory access patterns of processes during operation, resulting in a mismatch between the memory allocation granularity and the actual requirements. For example, some frequently accessed process areas may be allocated too few resources, leading to frequent page swapping and even the risk of information leakage; while low-active areas occupy more memory resources, causing resource waste. In addition, such methods lack the ability to model dynamic behaviors and cannot optimally adjust according to the memory usage characteristics of power intelligent agents at different running times and different task stages, resulting in rough isolation area division and fuzzy boundaries, and it is difficult to effectively prevent fine-grained memory attacks such as cross-region reading and writing, cache injection, etc. In response to the above problems, the present invention proposes a solution. Summary of the Invention
[0005] To overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a power intelligent agent process isolation and protection method and system based on a sandbox. By combining granularity matrix modeling with multi-objective optimization, dynamic granularity division and optimal capacity allocation of the power intelligent agent's memory space are achieved to solve the problem of micro-granularity memory attacks such as cross-region reading and writing and cache injection caused by the mismatch between the memory allocation granularity and the actual required memory resource capacity in traditional process isolation.
[0006] To achieve the above object, the present invention provides the following technical solutions: A power intelligent agent process isolation and protection method based on a sandbox, comprising the following steps: obtaining power system power frequency time series data, extracting the current frequency fluctuation curve to construct a first query sequence; using the DTW algorithm to perform sequence screening on the first query sequence to obtain a reference sequence; constructing a frequency feature vector based on the reference sequence and performing Fourier transform to obtain a granularity matrix; inputting the granularity matrix into a preset multi-objective optimization function, and using the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity; dividing the process memory space of the intelligent agent into several isolation regions according to the evaluation result, and performing quantum annealing optimization on the memory capacity of each isolation region to obtain the optimal memory capacity; deploying the optimal memory capacity to the memory protection unit to generate an isolation barrier, and integrating the isolation barrier into the sandbox to achieve secure isolation.
[0007] In a preferred embodiment, the extracting the current frequency fluctuation curve to construct a first query sequence is specifically: based on the power system power frequency time series data, extracting the frequency fluctuation curve through an adaptive sliding window; performing multi-scale decomposition on the frequency fluctuation curve to obtain several long-range dependent components; constructing a first query sequence based on the several long-range dependent components.
[0008] In a preferred embodiment, the using the DTW algorithm to perform sequence screening on the first query sequence to obtain a reference sequence is specifically: obtaining a candidate sequence set from the historical frequency fluctuation database; using the DTW algorithm to calculate the DTW distance between each candidate sequence and the first query sequence, and performing sequence screening on the first query sequence according to the DTW distance to obtain a reference sequence.
[0009] In a preferred embodiment, the constructing a frequency feature vector based on the reference sequence and performing Fourier transform to obtain a granularity matrix is specifically: dividing the reference sequence into several sequence segments, using the DTW algorithm to calculate the DTW distance between each sequence segment; constructing a graph structure with the sequence segments as nodes and the DTW distance as edge weights; performing feature aggregation on the graph structure through a preset graph convolutional layer to generate a first feature vector; performing Fourier transform on the first feature vector to output a spectrum matrix; performing probability fusion on the frequency matrix, and constructing a granularity matrix based on a preset convolutional neural network.
[0010] In a preferred embodiment, the probability fusion of the frequency matrix and the construction of the granularity matrix based on a preset convolutional neural network are specifically as follows: Obtain the historical access logs of the power agent, extract the page access frequencies of the same process in different time slices, and construct an access probability vector; Align the spectrum matrix and the access probability vector according to a preset time window, and calculate the frequency domain energy features of each time window; Construct a second feature vector based on the frequency domain energy features and the access probability vector; Input the second feature vector into a preset convolutional neural network to obtain the granularity matrix.
[0011] In a preferred embodiment, the input of the granularity matrix into a preset multi-objective optimization function and the evaluation of the memory allocation granularity using the NSGA-III evolutionary algorithm are specifically as follows: Perform singular value decomposition on the granularity matrix to extract the singular value vector; Slice the granularity matrix according to the singular value vector to generate several memory block mapping structure matrices; Construct a multi-objective optimization function for each memory block mapping structure matrix and encode it as an individual of the initial population of the NSGA-III algorithm; Iteratively execute the crossover and mutation operations, and calculate the multi-objective optimization function values of each individual; Output the Pareto front solution set based on the non-dominated sorting and multi-objective optimization function value mechanism to obtain the optimal memory allocation granularity.
[0012] In a preferred embodiment, the division of the process memory space of the agent into several isolated regions according to the evaluation result is specifically as follows: Based on the optimal memory allocation granularity, obtain the page access frequency sequence of the agent process in a preset historical time slice and construct an access density vector; Use the sliding window mechanism to segment the access density vector to generate the first access density sub-vectors of several windows; Perform clustering analysis on the first access density vector and calculate the mean and standard deviation of the page access frequencies of each clustering cluster; Divide the process memory space of the agent into several isolated regions based on the ratio of the mean and standard deviation of the access frequencies.
[0013] In a preferred embodiment, the quantum annealing optimization of the memory capacity of each isolated region to obtain the optimal memory capacity is specifically as follows: Define a Hamiltonian model for each isolated region, use the quantum annealing algorithm to solve the Hamiltonian ground state in the solution space of the Hamiltonian model to obtain the first candidate capacity solution set; Construct a Voroni diagram based on the first candidate capacity solution set, and divide the solution space into several spaces based on the Voroni diagram; Calculate the solution density of each space, and perform random perturbation on the first candidate capacity solution set based on the solution density to obtain the second candidate capacity solution set; Apply the second candidate capacity solution set to the next round of quantum annealing optimization and jump out of the local optimal solution through the tunneling effect to output the optimal memory capacity.
[0014] In a preferred embodiment, the steps of deploying the optimal memory capacity to the memory protection unit, generating an isolation barrier, and integrating the isolation barrier into the sandbox to achieve secure isolation are as follows: loading the optimal memory capacity vector into the memory protection unit, and configuring the base address register and the boundary register; generating a hardware isolation barrier based on the mapping of the base address register and the boundary register; embedding the hardware isolation barrier in the sandbox kernel to monitor the memory access requests of the agent process in real time; when an illegal cross-region access is detected, triggering a security interrupt and redirecting it to the sandbox isolation log pool.
[0015] Technical effects and advantages of the method and system for isolating and protecting power agent processes based on a sandbox according to the present invention: 1. By introducing the DTW algorithm and multi-scale analysis, the present invention realizes the screening and modeling of frequency sequences, further combines the Fourier transform and the convolutional neural network to generate a granularity matrix, and fully excavates the time-frequency characteristics of agent behavior. In addition, the NSGA-III evolutionary algorithm is used to perform multi-objective optimization on the memory allocation granularity to ensure the scientificity and rationality of memory partitioning. On this basis, the isolation area of the process is divided based on the access density vector, and the memory capacity of each isolation area is optimized by the quantum annealing algorithm to obtain the optimal memory capacity. This optimal capacity is deployed to the memory protection unit in a hardware configuration manner to form a dynamic isolation barrier, and real-time monitoring and protection are implemented in the sandbox kernel. When an illegal access behavior occurs, the system can quickly respond and isolate the risk to ensure the integrity of the running environment of the core process. This method takes the optimal memory capacity as the core driving force to build an accurate protection mechanism for agent memory access, breaks through the limitations of the traditional coarse-grained isolation of the sandbox, and provides an efficient and adaptable technical path for the secure operation of agents in the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic flowchart of the method for isolating and protecting power agent processes based on a sandbox according to the present invention.
[0017] Figure 2 It is a schematic structural diagram of the system for isolating and protecting power agent processes based on a sandbox according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0019] Embodiment 1 Figure 1The present invention provides a sandbox-based power intelligent body process isolation protection method, which includes the following steps: S1, obtaining the power system power frequency time series data, extracting the current frequency fluctuation curve to construct the first query sequence; In this example, the power system power frequency time series data is obtained, specifically: In order to realize the dynamic perception and memory isolation configuration of the power intelligent body's operating environment, the power frequency time series data is first obtained from the power system's data acquisition equipment (such as PMU-synchronous phasor measurement device, SCADA system). The power frequency time series data is the continuously recorded power grid frequency value, and the sampling frequency can be set to 50Hz, 100Hz or higher to meet the high-resolution requirements. The data is usually stored in the form of timestamp-frequency pairs.
[0020] Power system power frequency time series data mainly refers to the data that continuously samples and records the power frequency components of physical quantities such as voltage and current in the power grid over time, usually around the system frequency. This type of data has time series characteristics and is important basic information for describing the stability of power system operation, load changes, abnormal disturbances, etc. Specifically, it includes: system frequency, timestamp, voltage phase angle, voltage amplitude, current amplitude, sampling point number or sequence number, etc.
[0021] In this example, the current frequency fluctuation curve is extracted to construct the first query sequence, specifically: Based on the power system power frequency time series data, the frequency fluctuation curve is extracted through an adaptive sliding window; Perform multi-scale decomposition on the frequency fluctuation curve to obtain several long-range correlation components; A first query sequence is constructed based on a plurality of long correlation components.
[0022] It should be noted that, first, the system obtains real-time power grid frequency time series data from power monitoring equipment (such as PMU or dispatching master station), and uses an adaptive sliding window algorithm to extract the current frequency fluctuation curve. The length of the sliding window is dynamically adjusted according to the intensity of historical frequency fluctuations. For example, when the fluctuation is severe, the window length is shortened to enhance the response sensitivity, and when it is running stably, the window can be extended to improve the accuracy of steady-state modeling. Then, the extracted frequency fluctuation curve is decomposed at multiple scales, such as decomposing the original fluctuation curve into several long-correlated components representing different time scales through wavelet transform or empirical mode decomposition (EMD). These components can better reveal the different periodic or trend characteristics in system operation and avoid misjudgment due to local disturbances.
[0023] Next, a first query sequence is constructed based on multiple long correlation components, and a large set of candidate sequences is extracted from the historical frequency fluctuation database. These candidate sequences are derived from historical records such as different typical load scenarios, fault disturbances, frequency jumps, or regional power flow changes during the operation of the power grid. After that, the DTW algorithm is used to calculate the DTW distance between each candidate sequence and the current first query sequence one by one. The DTW algorithm can accurately measure the similarity between two sequences in the presence of time offset and rate changes. Finally, according to the DTW distance, a set of sequences with the smallest DTW distance is selected as the reference sequence, which will be used as the basic input for subsequent frequency behavior modeling and granularity matrix generation.
[0024] S2. Use the DTW algorithm to perform sequence screening on the first query sequence to obtain the reference sequence. In this example, use the DTW algorithm to perform sequence screening on the first query sequence to obtain the reference sequence, specifically: Obtain a set of candidate sequences from the historical frequency fluctuation database. Use the DTW algorithm to calculate the DTW distance between each candidate sequence and the first query sequence, and perform sequence screening on the first query sequence according to the DTW distance to obtain the reference sequence.
[0025] S3. Construct a frequency feature vector based on the reference sequence and perform Fourier transform to obtain the granularity matrix. In this example, construct a frequency feature vector based on the reference sequence and perform Fourier transform to obtain the granularity matrix, specifically: Divide the reference sequence into several sequence segments, and use the DTW algorithm to calculate the DTW distance between each sequence segment. Use the sequence segments as nodes and the DTW distance between each sequence segment as edge weights to construct a graph structure. Perform feature aggregation on the graph structure through a preset graph convolutional layer to obtain the first feature vector. Perform Fourier transform on the first feature vector to obtain the spectrum matrix. Perform probability fusion on the frequency matrix and construct the granularity matrix based on a preset convolutional neural network.
[0026] It should be noted that assume the reference sequence is a time series data with a length of 1000 and a sampling frequency of 50Hz, representing the frequency change within 20 seconds. The reference sequence is equally divided into 10 segments, each segment contains 100 sampling points, calculate the DTW distance between these 10 segments pairwise, and generate a 10×10 distance matrix. For example, the DTW distance between segment 1 and segment 2 is 15.2, and the DTW distance between segment 1 and segment 3 is 30.8, and so on, to obtain the distance matrix.
[0027] In this example, the frequency matrix is probabilistically fused, and a granularity matrix is constructed based on a preset convolutional neural network, specifically as follows: Obtain the historical access logs of the power agent, extract the page access frequencies of the same process in different time slices, and construct an access probability vector; Align the spectrum matrix and the access probability vector according to a preset time window, and calculate the frequency-domain energy features of each time window; Construct a second feature vector based on the frequency-domain energy features and the access probability vector; Input the second feature vector into a preset convolutional neural network to obtain a granularity matrix.
[0028] Exemplarily, the page access frequencies of a certain power agent process in the past 6 time slices (1 second per time slice) are shown in the following table: (unit: number of accesses):
[0029] Normalize the page access frequencies in each time slice to construct an access probability vector. For example, the access probability vector for time slice 1 is [0.5, 0.2, 0.1, 0.05, 0.15].
[0030] S4. Input the granularity matrix into a preset multi-objective optimization function, and use the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity; In this example, input the granularity matrix into a preset multi-objective optimization function, and use the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity, specifically as follows: Perform singular value decomposition on the granularity matrix to obtain a singular value vector, and perform slicing processing on the granularity matrix based on the singular value vector to obtain several memory block mapping structure matrices; Construct a multi-objective optimization function for each memory block mapping structure matrix and encode it as an individual in the initial population of the NSGA-III algorithm; Iteratively perform crossover and mutation operations, and calculate the multi-objective optimization function values of each individual in the initial population; Output the Pareto front solution set based on the non-dominated sorting and multi-objective optimization function value mechanism to obtain the optimal memory allocation granularity.
[0031] It should be noted that first, the granularity matrix is subjected to singular value decomposition (SVD) to extract the singular value vectors to reflect the core features and structural information of the matrix. Then, based on the singular value vectors, the granularity matrix is sliced to generate multiple memory block mapping structure matrices, with each matrix corresponding to a different memory allocation unit. For each block matrix, a multi-objective optimization function is constructed and encoded as an individual in the initial population of the NSGA-III algorithm. By iteratively performing crossover and mutation operations, the multi-objective function values of each individual are calculated, and the Pareto front solution set is selected using the non-dominated sorting mechanism. Finally, the optimal memory allocation granularity that can both meet the resource utilization efficiency and ensure the security isolation effect is obtained. This method realizes the accurate modeling and dynamic adjustment of complex memory access behaviors, improving the intelligence and refinement level of the process isolation protection of power agents.
[0032] S5. Divide the process memory space of the agent into several isolation areas according to the evaluation results, and perform quantum annealing optimization on the memory capacity of each isolation area to obtain the optimal memory capacity. In this example, divide the process memory space of the agent into several isolation areas according to the evaluation results, specifically: Based on the optimal memory allocation granularity, obtain the page access frequency of the agent's process within a preset number of historical time slices and construct an access density vector. Use the sliding window mechanism to segment the access density vector to obtain the first access density vectors of several windows. Perform clustering analysis on the first access density vectors of several windows, and calculate the average value and standard deviation of the page access frequency of each clustering cluster. Divide the process memory space of the agent into several isolation areas based on the ratio of the average value and standard deviation of the page access frequency of each clustering cluster.
[0033] Among them, the calculation formula for the average value of the page access frequency of the clustering cluster is as follows:
[0034] Among them, is the average access density of the kth clustering cluster, is the access imbalance index of the kth clustering cluster, is the access frequency of the tth memory page per unit time.
[0035] Among them, the calculation formula for the standard deviation of the page access frequency of the clustering cluster is as follows:
[0036] Among them, is the standard deviation of the access density of the kth clustering cluster.
[0037] It should be noted that, first, based on the optimal memory allocation granularity, page access frequency data of the agent process within multiple historical time slices is collected to construct an access density vector. Here, the "first access density vector" refers to the local access density feature obtained by segmenting continuous access frequency data through a sliding window mechanism, which is used to reflect the dynamic changes in memory access behavior. Then, clustering analysis is performed on these segmented access density vectors to identify sets of memory pages with similar access patterns, calculate the mean and standard deviation of the page access frequencies of each clustering cluster, and then judge the access stability and concentration through the ratio of the mean to the standard deviation. Finally, based on these statistical features, the memory space of the agent process is divided into several "isolation regions", that is, a group of memory blocks that are similar and independent in access behavior. These isolation regions are physically or logically separated, which can effectively limit the spread of abnormal access and achieve refined and dynamically adjustable security isolation. Through this method, the system can dynamically divide memory regions based on the actual access behavior pattern, making memory protection more accurate and efficient, and significantly improving the security protection ability of the power agent process.
[0038] In this example, quantum annealing optimization is performed on the memory capacity of each isolation region to obtain the optimal memory capacity, specifically as follows: Define a Hamiltonian model for each isolation region, and use the quantum annealing algorithm to solve the Hamiltonian ground state in the solution space of the Hamiltonian model to obtain a first candidate capacity solution set; Construct a Voroni diagram based on the first candidate capacity solution set, and divide the solution space into several spaces based on the Voroni diagram; Calculate the solution density of each space, and perform random perturbation on the first candidate capacity solution set based on the solution density to obtain a second candidate capacity solution set; Apply the second candidate capacity solution set to the next round of quantum annealing optimization, and jump out of the local optimal solution through the tunneling effect to output the optimal memory capacity.
[0039] Among them, the specific calculation formula of the Hamiltonian model is as follows:
[0040] Among them, is the Hamiltonian of the i-th isolation region, is the current memory capacity configuration value of the i-th isolation region, is the target capacity recommended for the current region, is the variance of memory access within the region, is the communication weight between region i and region j, is the current memory capacity configuration value of the j-th isolation region, is the set of other regions that have a shared boundary or adjacent relationship with the i-th region.
[0041] It should be noted that, first, a Hamiltonian model is constructed for each isolation region. The Hamiltonian is used to describe the energy state of a system in quantum computing. The quantum annealing algorithm searches for the ground state solution with the lowest energy, i.e., the optimal memory capacity configuration scheme, in the solution space defined by the Hamiltonian by simulating the quantum tunneling effect. The multiple candidate capacity solutions obtained are used to construct a Voronoi diagram, which is a spatial partitioning method that divides the solution space into several regions, each region being controlled by the corresponding candidate solution point, facilitating the analysis of the distribution and density of the solutions. Based on the Voronoi diagram, the density of the solutions within each region is further calculated, and the candidate solutions are adjusted in combination with the random perturbation technique to avoid falling into a local optimum. By continuously iterating the quantum annealing process, a global search and optimization of the memory capacity are achieved, and finally, the optimal memory capacity configuration that satisfies both functional requirements and has good defense capabilities is output. This optimization method combining quantum annealing and Voronoi diagram effectively improves the intelligent level of memory capacity allocation in isolation regions and the security protection effect.
[0042] S5. Deploy the optimal memory capacity to the memory protection unit to obtain an isolation barrier, and integrate the isolation barrier into the sandbox to achieve secure isolation.
[0043] In this example, deploying the optimal memory capacity to the memory protection unit to obtain an isolation barrier and integrating the isolation barrier into the sandbox to achieve secure isolation is specifically as follows: Load the optimal memory capacity vector into the memory protection unit, and configure the base address register and the boundary register; Generate a hardware isolation barrier based on the mapping of the base address register and the boundary register; Embed the hardware isolation barrier in the sandbox kernel to monitor the memory access requests of the agent process in real time; When an illegal cross-region access is detected, trigger a security interrupt and redirect it to the sandbox isolation log pool.
[0044] It should be noted that the calculated optimal memory capacity vector is loaded into the memory protection unit, and the start address and size of each isolation region are specified by configuring the base address register and the boundary register, thereby generating an isolation barrier for physical memory at the hardware level. This isolation barrier is embedded in the sandbox kernel, which can monitor the memory access requests of the agent process in real time. Once an illegal cross-region access behavior is detected, the system immediately triggers a security interrupt and redirects the event to the sandbox isolation log pool for recording and processing. In this way, seamless integration from the optimal allocation of memory capacity to the hardware isolation barrier is achieved, constructing a dynamic, precise, and efficient memory access protection mechanism, which greatly improves the security protection ability of the power agent process and the overall stability of the system.
[0045] Embodiment 2 Figure 2The present invention provides a sandbox-based process isolation protection system for power intelligent agents, including a sequence generation module, a sequence screening module, a matrix generation module, an optimization decision module, a capacity optimization module, and a process isolation module: The sequence generation module is used to obtain the power system power frequency time series data and extract the current frequency fluctuation curve to construct the first query sequence; The sequence screening module is used to screen the first query sequence by using the DTW algorithm to obtain the reference sequence; The matrix generation module is used to construct a frequency feature vector based on the reference sequence and perform Fourier transform to obtain the granularity matrix; The optimization decision module is used to input the granularity matrix into a preset multi-objective optimization function and use the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity; The capacity optimization module is used to divide the process memory space of the intelligent agent into several isolation areas according to the evaluation results and perform quantum annealing optimization on the memory capacity of each isolation area to obtain the optimal memory capacity; The process isolation module is used to deploy the optimal memory capacity to the memory protection unit, generate an isolation barrier, and integrate the isolation barrier into the sandbox to achieve secure isolation.
[0046] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula that is closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0047] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product.
[0048] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0049] In addition, the functional modules in each embodiment of the present application can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.
[0050] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.
[0051] Finally: The above description is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. Sandbox-based process isolation and protection method for power intelligent agents, characterized in that It includes the following steps: Obtain power system power frequency time series data, extract the current frequency fluctuation curve to construct the first query sequence; Use the DTW algorithm to perform sequence screening on the first query sequence to obtain a reference sequence; Construct a frequency feature vector based on the reference sequence and perform Fourier transform to obtain a granularity matrix; Input the granularity matrix into a preset multi-objective optimization function, and use the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity; According to the evaluation results, divide the process memory space of the intelligent agent into several isolated regions, and perform quantum annealing optimization on the memory capacity of each isolated region to obtain the optimal memory capacity; Deploy the optimal memory capacity to the memory protection unit to generate an isolation barrier, and integrate the isolation barrier into the sandbox to achieve secure isolation.
2. The method for isolating and protecting the power intelligent agent process based on a sandbox according to claim 1, characterized in that, The specific method for extracting the current frequency fluctuation curve to construct the first query sequence is as follows: Based on the power system power frequency time series data, extract the frequency fluctuation curve through an adaptive sliding window; Perform multi-scale decomposition on the frequency fluctuation curve to obtain several long-range dependent components; Construct the first query sequence based on several long-range dependent components.
3. The method for isolating and protecting the power intelligent agent process based on the sandbox according to claim 2, wherein, The specific method for using the DTW algorithm to perform sequence screening on the first query sequence to obtain a reference sequence is as follows: Obtain a candidate sequence set from the historical frequency fluctuation database; Use the DTW algorithm to calculate the DTW distance between each candidate sequence and the first query sequence, and perform sequence screening on the first query sequence according to the DTW distance to obtain a reference sequence.
4. The method for isolating and protecting the power intelligent agent process based on a sandbox according to claim 3, wherein, The specific method for constructing a frequency feature vector based on the reference sequence and performing Fourier transform to obtain a granularity matrix is as follows: Divide the reference sequence into several sequence segments, and use the DTW algorithm to calculate the DTW distance between each sequence segment; Construct a graph structure with sequence segments as nodes and DTW distances as edge weights; Perform feature aggregation on the graph structure through a preset graph convolutional layer to generate a first feature vector; Perform Fourier transform on the first feature vector and output a spectrum matrix; Perform probability fusion on the frequency matrix and construct a granularity matrix based on a preset convolutional neural network.
5. The method for isolating and protecting the power intelligent agent process based on a sandbox according to claim 4, wherein The specific method for performing probability fusion on the frequency matrix and constructing a granularity matrix based on a preset convolutional neural network is as follows: Obtain the historical access logs of the power intelligent agent, extract the page access frequencies of the same process in different time slices, and construct an access probability vector; Align the spectrum matrix and the access probability vector according to a preset time window, and calculate the frequency domain energy feature of each time window; Construct a second feature vector based on the frequency domain energy feature and the access probability vector; Input the second feature vector into a preset convolutional neural network to obtain a granularity matrix.
6. The method for isolating and protecting the power intelligent agent process based on sandbox according to claim 5, wherein, The specific method for inputting the granularity matrix into a preset multi-objective optimization function and using the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity is as follows: Perform singular value decomposition on the granularity matrix to extract a singular value vector; Perform slicing processing on the granularity matrix according to the singular value vector to generate several memory block mapping structure matrices; Construct a multi-objective optimization function for each memory block mapping structure matrix and encode it as an individual of the initial population of the NSGA-III algorithm; Iteratively perform crossover and mutation operations, and calculate the multi-objective optimization function values of each individual; Output the Pareto front solution set based on non-dominated sorting and the multi-objective optimization function value mechanism to obtain the optimal memory allocation granularity.
7. The method for isolating and protecting the power intelligent agent process based on the sandbox according to claim 6, wherein, Partition the process memory space of the agent into several isolated regions according to the evaluation results, specifically: Based on the optimal memory allocation granularity, obtain the page access frequency sequence of the agent process within the preset historical time slice, and construct an access density vector; Use the sliding window mechanism to segment the access density vector to generate the first access density sub-vectors of several windows; Perform clustering analysis on the first access density vector, and calculate the mean and standard deviation of the page access frequency of each clustering cluster; Partition the process memory space of the agent into several isolated regions based on the ratio of the mean and standard deviation of the access frequency.
8. The sandbox-based power intelligent agent process isolation and protection method according to claim 7, wherein, Perform quantum annealing optimization on the memory capacity of each isolated region to obtain the optimal memory capacity, specifically: Define a Hamiltonian model for each isolated region, and use the quantum annealing algorithm to solve the Hamiltonian ground state in the solution space of the Hamiltonian model to obtain the first candidate capacity solution set; Construct a Voroni diagram based on the first candidate capacity solution set, and divide the solution space into several spaces based on the Voroni diagram; Calculate the solution density of each space, and perform random perturbation on the first candidate capacity solution set based on the solution density to obtain the second candidate capacity solution set; Apply the second candidate capacity solution set to the next round of quantum annealing optimization, and jump out of the local optimal solution through the tunneling effect to output the optimal memory capacity.
9. The method for isolating and protecting the power intelligent agent process based on the sandbox according to claim 8, characterized in that, Deploy the optimal memory capacity to the memory protection unit to generate an isolation barrier, and integrate the isolation barrier into the sandbox to achieve secure isolation, specifically: Load the optimal memory capacity vector into the memory protection unit, and configure the base address register and the boundary register; Generate a hardware isolation barrier based on the mapping of the base address register and the boundary register; Embed the hardware isolation barrier in the sandbox kernel to monitor the memory access requests of the agent process in real time; When an illegal cross-region access is detected, trigger a security interrupt and redirect it to the sandbox isolation log pool.
10. A sandbox-based power intelligent agent process isolation and protection system, which is applied to the sandbox-based power intelligent agent process isolation and protection method described in any one of claims 1-9, and is characterized in that, Includes a sequence generation module, a sequence screening module, a matrix generation module, an optimization decision module, a capacity optimization module, and a process isolation module: The sequence generation module is used to obtain the power system power frequency time series data, extract the current frequency fluctuation curve to construct the first query sequence; The sequence screening module is used to perform sequence screening on the first query sequence using the DTW algorithm to obtain a reference sequence; The matrix generation module is used to construct a frequency feature vector based on the reference sequence and perform Fourier transform to obtain a granularity matrix; The optimization decision module is used to input the granularity matrix into a preset multi-objective optimization function, and use the NSGA-III evolutionary algorithm to evaluate the memory allocation granularity; The capacity optimization module is used to partition the process memory space of the agent into several isolated regions according to the evaluation results, and perform quantum annealing optimization on the memory capacity of each isolated region to obtain the optimal memory capacity; The process isolation module is used to deploy the optimal memory capacity to the memory protection unit to generate an isolation barrier, and integrate the isolation barrier into the sandbox to achieve secure isolation.
Citation Information
Patent Citations
Smart contract protection method and device based on sandbox and electronic equipment
CN118153035A
Containerized resource dynamic allocation method for power distribution network system and electronic equipment
CN119127388A
Power grid fault waveform identification and intelligent relay protection rapid control method and system
CN119965775A
Zonal energy management and optimization systems for smart grids applications
US20150058061A1
Platform and method for power grid frequency regulation with participation of large-scale energy storage based on maddpg
US20250096600A1