An electric power data security convergence communication method based on attack and defense integration

By adopting a power data security aggregation and communication method based on integrated offense and defense, and utilizing quantum fingerprinting and dynamic key obfuscation technology, real-time and secure aggregation and communication of power data is achieved. This solves the problem that traditional passive defense is unable to cope with complex attacks and improves the security and stability of the power system.

CN120415718BActive Publication Date: 2026-01-27GUANGXI POWER GRID CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510687808.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2026-01-27
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

Traditional network security protection mainly focuses on passive defense, which is difficult to deal with increasingly complex attack methods. Existing technologies are also unable to achieve efficient and secure power data aggregation and communication.

Method used

A power data security convergence communication method based on integrated offense and defense is adopted. Through technologies such as edge terminal access authentication anchored by quantum fingerprint, anti-tampering data preprocessing with dynamic key obfuscation, initial key generation by quantum communication technology, virtual node simulated attack, and edge node federated learning detection, a three-dimensional authentication vector and dynamic key obfuscation mechanism are constructed to realize real-time behavior verification and dynamic adjustment of encryption strategy.

Benefits of technology

It enables real-time and secure aggregation and communication of power data, reduces computing power consumption, adapts to changes in equipment operating status, enhances the ability to defend against complex attacks, and improves the security and stability of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415718B_ABST
    Figure CN120415718B_ABST
Patent Text Reader

Abstract

The application discloses a power data security convergence communication method based on attack and defense integration, which comprises the following steps: A01, quantum fingerprint anchored edge terminal access authentication; A02, anti-tampering data preprocessing of dynamic key confusion; A03, confidence dynamic filtering based on anti-tampering data preprocessing; A04, generating an initial key by using quantum communication technology; A05, simulating a real device by using a virtual node, luring attacks and collecting intelligence; and A06, automatically optimizing a defense strategy through data driving and adapting to new attacks. The application has the beneficial effect that a three-dimensional authentication vector is constructed in combination with dynamic biological characteristics, real-time behavior verification of an access request is realized through a lightweight space-time attention model, the algorithm power consumption is reduced compared with a traditional model, cross-domain fusion authentication of quantum noise fingerprints and power equipment operation characteristics breaks through the single authentication mode of traditional digital certificates or hardware IDs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power data aggregation and communication, specifically to a power data security aggregation and communication method based on integrated offense and defense. Background Technology

[0002] With the evolution of power grid towards intelligence, digitalization, and informatization, the Internet of Things in the power sector is developing rapidly. A large number of intelligent devices and sensors have been connected to the power system, generating massive amounts of data. Efficient and secure converged communication methods are needed to support the transmission and processing of data. The power grid can be regarded as a cyber-physical system, with the communication network as its nerve center. In recent years, malicious attacks against the power grid have gradually shifted from traditional physical damage to cyber attacks, posing a huge challenge to the secure transmission of power data and the stable operation of the power grid.

[0003] Traditional network security protection mainly focuses on passive defense, which is difficult to cope with increasingly complex attack methods. The concept of integrated offense and defense emphasizes combining attack and defense. By proactively understanding the attacker's methods and strategies, defense planning and optimization can be carried out in advance. At the same time, it has the ability to trace the source of attacks and respond quickly, so as to improve the overall level of security protection. Against this background, the power data security aggregation and communication method based on integrated offense and defense has emerged. It aims to design a more efficient and secure data aggregation and communication solution by comprehensively considering attack and defense factors, so as to ensure the safe and stable operation of the power system. Summary of the Invention

[0004] The purpose of this invention is to address the problem that traditional network security protection mainly focuses on passive defense and is unable to cope with increasingly complex attack methods, and to propose a power data security aggregation and communication method based on integrated offense and defense.

[0005] The objective of this invention can be achieved through the following technical solution: a power data security aggregation and communication method based on integrated offense and defense, comprising the following steps:

[0006] A01: Quantum fingerprint-anchored edge terminal access authentication utilizes the noise signal generated by the quantum tunneling effect inside the device, which is encoded by SHA-3 as a unique identifier. Combined with dynamic biometric features, a three-dimensional authentication vector is constructed. Through a spatiotemporal attention model, real-time behavior verification of access requests is achieved.

[0007] A02: Tamper-resistant data preprocessing for dynamic key obfuscation;

[0008] A03: Dynamic confidence filtering based on tamper-resistant data preprocessing;

[0009] A04: Utilize quantum communication technology to generate an initial key, generate random parameters every 15 seconds using a chaotic algorithm, change the encryption rules, define a security controller to globally manage the encryption strategy, and synchronize the key and parameters to all devices in real time to ensure encryption consistency.

[0010] A05: Use virtual nodes to simulate real devices, lure attacks and collect intelligence, record attack behavior and extract malicious code characteristics, update the threat database, and provide real-time intelligence for defense.

[0011] A06: By using data-driven automatic optimization of defense strategies to adapt to new attacks, it uses a contrastive learning algorithm to automatically label unknown attack samples from massive amounts of data, and utilizes self-supervised learning technology to dynamically adjust edge detection parameters. The optimized strategy is then injected back into each defense link.

[0012] Furthermore, the method for constructing a three-dimensional authentication vector by combining dynamic biometrics is as follows: a three-dimensional authentication vector is constructed by fusing quantum noise fingerprints, hardware-running biometric entropy values, and harmonic energy distribution entropy. The specific algorithm is as follows:

[0013] Quantum noise fingerprint generation first dimension The thermal noise signal n(t) is collected using the internal quantum tunneling device and then generated as a quantum fingerprint through 256-bit SHA-3 hash encoding. ;

[0014] in: It represents an XOR operation; UUID is a globally unique identifier for a device. and Indicates the start and end times of a time interval, used to define the time range for data analysis or processing. That is, a secure hash algorithm. It is time The function represents time. Data features at time of day are obtained by analyzing their characteristics at time of day. arrive Integrating over a time period yields the cumulative value of relevant data characteristics within that time period. Represents the function In time interval Perform integration on the data to obtain the cumulative result of the data within that time period;

[0015] The second dimension E of the hardware operation biometric entropy value calculation is the voltage signal during device operation. Perform a Fast Fourier Transform to extract the first 10 harmonic components. , This indicates the result obtained after calculation. The amplitude of each frequency component, For the Fast Fourier Transform algorithm, Indicates time The changing original time-domain signal;

[0016] Calculate the entropy of harmonic energy distribution , Entropy represents the harmonic energy distribution, used to measure the uniformity of harmonic energy distribution across different frequency components. and These are all harmonic orders, ranging from 1 to 10, representing the analysis of the first 10 harmonics. Indicates the first The amplitude of the second harmonic. Indicates the first The amplitude of each harmonic is quantified by the ratio of the square of the amplitude of each harmonic to the sum of the squares of the total harmonic amplitudes.

[0017] The hardware ID is hashed to generate the third dimension H, and the device hardware ID is then subjected to a two-factor hash. In the formula, This uses a hash message authentication code algorithm, where ID is the device's hardware identifier. This refers to the 8 bytes of the quantum key prefix, which are XORed with the hardware identifier. This indicates the key possessed by the device, which serves as the key input for the HMAC-SHA-512 algorithm;

[0018] The three-dimensional authentication vector is constructed and normalized by concatenating and normalizing the features of the three dimensions to form the final authentication vector. , ,in, This represents a vector of power load data in the power data. This represents a data vector representing the equipment operating status in the power data. This represents a data vector representing the power grid topology in the power data. The norm of a vector is used to normalize the vector so that its length is 1. It is due to the , , The normalized vectors form a new vector, which is used for subsequent data security aggregation and communication processing.

[0019] Real-time verification algorithm for access requests, defining real-time acquisition vectors With registration vector The cosine similarity is expressed by the formula: , This represents a similarity metric between two vectors. Represents the target vector. Represents the reference vector. Representing vectors and The dot product operation is used to measure the consistency of two vectors in direction. The Euclidean norm of a vector is used to normalize the vector, eliminating the influence of vector length on similarity calculations. Authentication will pass on the first attempt; otherwise, secondary verification will be triggered. This is a preset threshold.

[0020] Furthermore, the tamper-proof data preprocessing process for dynamic key obfuscation involves obtaining real-time latitude and longitude coordinates through a built-in GPS / BeiDou module, quantizing them, and then calculating the geographic location entropy. The formula reflecting the uncertainty of the device's spatial location is as follows:

[0021] , Geographic information entropy is used to measure the degree of uncertainty or disorder in the distribution of geospatial data. The total number of categories for classifying geospatial data. Indicates the first The probability of geospatial data appearing in the population.

[0022] According to geographic entropy generate 3D dynamic offset matrix It updates every 5 seconds, and the formula is expressed as follows: ;

[0023] in, The chaotic mapping function performs complex nonlinear transformations on the input data. For timestamps, Yes and Perform bitwise logical operations. For modulo operation, The function's output is modulo 256, mapping the value to the 0-255 range to suit the representation range of byte data.

[0024] Generate master key In the formula, KDF includes the geographic location entropy, the first dimension Q value of the device quantum fingerprint, and a random number, and DKCA_KDF is a key derived from multiple parameter combinations based on the key derivation function.

[0025] based on pass Standard functions combined with dynamic offset matrix Generate 32 rounds of dynamic wheel keys. , Indicates the first The wheel key, Indicates the first The wheel key, It is a key expansion function based on the Chinese national cryptographic algorithm SM4, used to generate the current round key from the previous round key;

[0026] Geographic location pre-obfuscation involves XORing the hash values ​​of the current grid number and MAC address of data group P, using the following formula: ,in, This is the original data. , The raw data representing the power data acquisition nodes. This represents the ciphertext data after encryption. This is the data after being decrypted and verified at the receiving end. This is represented by the current grid number. The original data is preprocessed by XORing the current grid number with the MAC address hash value.

[0027] Dynamic key encryption, , Represents the SM4 encryption algorithm. Parameters obtained from geolocation pre-obfuscation. The round encryption key used by the SM4 encryption algorithm is used to transform plaintext data in multiple rounds during the encryption process to achieve data encryption.

[0028] Chained hash verification construction, , ciphertext timestamp The quantum fingerprint Q and the previous round of hash value The hash value is calculated after XORing.

[0029] Furthermore, the tamper-resistant data preprocessing also includes constructing an edge node federated learning detection model, training a malicious payload detection feature library in real time, converting network traffic into a 224×224 grayscale image, and extracting features using the following formula: ;

[0030] in, In time step The output features represent the processed power data feature vector, which integrates information from the current time step and historical information from the previous time step, and is used for subsequent security analysis. Long Short-Term Memory (LSTM) networks are used to capture long-term dependencies in sequential data over time. Convolutional neural networks are used to process input data Feature extraction is performed, using convolution and pooling operations to extract key spatial features of the power data. This provides power data at time step t, including voltage, current, and power. The output features at time step t-1 are used as input to the LSTM network to pass information from the previous time step to the current time step. The formula extracts spatial features through CNN and captures temporal series dependencies through LSTM.

[0031] based on Update gradients using the obtained model parameters , according to Update and combine with federated learning aggregation formula This allows the global model to learn the characteristics of malicious loads throughout the entire power data network, where, This represents the final calculated aggregate value. Represents the number of data groups or categories. This represents the weight of the i-th data set. This represents the parameter value corresponding to the i-th data group;

[0032] eigenvectors Input the federated learning model, through the formula Generate confidence scores. This is a federated learning model.

[0033] Furthermore, the confidence level dynamic filtering method is as follows:

[0034]

[0035] When the confidence level is below the threshold If the data is deemed high-risk, deep detection is immediately triggered and transmission is blocked; if the confidence level is greater than or equal to... and less than When the data is entered into the sandbox environment for behavioral analysis, and the confidence level is greater than or equal to... At that time, the data was deemed secure, and direct access was allowed.

[0036] Compared with the prior art, the beneficial effects of the present invention are:

[0037] 1. A hardware fingerprint generation technology based on quantum physics characteristics is proposed. The noise signal hash code generated by the quantum tunneling effect inside the device is used as a unique identifier. A three-dimensional authentication vector is constructed by combining dynamic biometrics. Real-time behavior verification of access requests is achieved through a lightweight spatiotemporal attention model. Compared with the traditional model, the computing power consumption is reduced. The cross-domain fusion authentication of quantum noise fingerprint and power equipment operation characteristics breaks through the single authentication mode of traditional digital certificates or hardware IDs.

[0038] 2. A two-factor dynamic key obfuscation algorithm is designed. Based on SM4 encryption, a dynamic offset based on the device's geographic location entropy is introduced. The malicious payload detection feature library is trained in real time through an edge node federated learning model. Combined with data integrity hash chain technology, a chain hash value containing timestamps and device fingerprints is generated for each data group. This achieves pre-screening of attack features and data tamper-proofing before transmission. The geographic location entropy-driven dynamic key obfuscation mechanism is different from traditional fixed parameter encryption or single federated learning detection schemes.

[0039] 3. Design a hybrid encryption system with periodic parameter perturbation. The quantum channel generates the initial session key, and the classical channel dynamically switches the encryption mode every 15 seconds to generate a key confusion factor. The encryption parameters are dynamically synchronized across the entire network by defining a security controller. The quantum key and the chaotic dynamic encryption mechanism are integrated into the solution.

[0040] 4. Real-time behavior verification of access requests is achieved through a spatiotemporal attention model. The verification involves multi-dimensional anomaly capture, covering cloning attacks, parameter tampering, and abnormal behavior. Feature weights are adjusted in real time to adapt to changes in device operating status. Depthwise separable convolution technology is used to reduce computational load, lowering the model's computational complexity without sacrificing too much accuracy. This makes the model easier to run quickly on resource-constrained edge devices, aligning with the goal of lightweight design to reduce computational resource consumption. Based on extracted spatiotemporal features, information is filtered by dynamically focusing on key time steps and feature dimensions. In the time dimension, key time steps are dynamically focused to avoid performing equally complex calculations on all time steps, reducing unnecessary computations. In the spatial dimension, key feature dimensions are filtered, and only important feature dimensions are processed subsequently, reducing data processing volume and computational overhead. Lightweighting is achieved from the computational process perspective. The lightweight detection and authentication design meets the computing power limitations of edge devices such as smart meters and sensors, and is suitable for power IoT scenarios. Attached Figure Description

[0041] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.

[0042] Figure 1 This is a flowchart of a power data security aggregation and communication method based on integrated offense and defense according to the present invention. Detailed Implementation

[0043] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0044] Please see Figure 1 As shown, a power data security aggregation and communication method based on integrated offense and defense includes the following steps:

[0045] A power data security aggregation and communication method based on integrated offense and defense includes the following steps:

[0046] A01: Quantum fingerprint-anchored edge terminal access authentication utilizes the noise signal generated by the quantum tunneling effect inside the device, which is encoded by SHA-3 as a unique identifier. Combined with dynamic biometric features, a three-dimensional authentication vector is constructed. Through a spatiotemporal attention model, real-time behavior verification of access requests is achieved.

[0047] A02: Tamper-resistant data preprocessing for dynamic key obfuscation;

[0048] A03: Dynamic confidence filtering based on tamper-resistant data preprocessing;

[0049] A04: Utilize quantum communication technology to generate an initial key, generate random parameters every 15 seconds using a chaotic algorithm, change the encryption rules, define a security controller to globally manage the encryption strategy, and synchronize the key and parameters to all devices in real time to ensure encryption consistency.

[0050] A05: Use virtual nodes to simulate real devices, lure attacks and collect intelligence, record attack behavior and extract malicious code characteristics, update the threat database, and provide real-time intelligence for defense.

[0051] A06: Automatically optimize defense strategies through data-driven approaches to adapt to new attacks. Use contrastive learning algorithms to automatically label unknown attack samples from massive amounts of data. Utilize self-supervised learning techniques to dynamically adjust edge detection parameters. The optimized strategies are then injected back into each defense stage.

[0052] This solution uses trusted access authentication to ensure the legitimacy and compliance of access devices from the source. It ensures the security and integrity of data before transmission through data preprocessing, preventing data from being maliciously tampered with or injected with malicious content. It uses dynamic encrypted communication to realize the dynamism and collaboration of the encryption process, improving the confidentiality of data transmission. It has proactive defense and intelligence gathering functions, transforming passive defense into proactive defense, providing real-time and effective information support for subsequent defense. It also has intelligent defense optimization functions, realizing the self-evolution and dynamic adaptation of the defense system to cope with constantly changing attack methods.

[0053] In this scheme, the method of constructing a three-dimensional authentication vector by combining dynamic biometrics is as follows: a three-dimensional authentication vector is constructed by fusing quantum noise fingerprint, hardware-running biometric entropy value, and harmonic energy distribution entropy. The specific algorithm is as follows: Quantum noise fingerprint generates the first dimension. The thermal noise signal n(t) is collected using the internal quantum tunneling device and then generated as a quantum fingerprint through 256-bit SHA-3 hash encoding. ;

[0054] in: It represents an XOR operation; UUID is a globally unique identifier for a device. and Indicates the start and end times of a time interval, used to define the time range for data analysis or processing. That is, a secure hash algorithm. It is time The function represents time. Data features at time of day are obtained by analyzing their characteristics at time of day. arrive Integrating over a time period yields the cumulative value of relevant data characteristics within that time period. Represents the function In time interval Perform integration on the data to obtain the cumulative result of the data within that time period;

[0055] The second dimension E of the hardware operation biometric entropy value calculation is the voltage signal during device operation. Perform a Fast Fourier Transform to extract the first 10 harmonic components. , This indicates the result obtained after calculation. The amplitude of each frequency component, For the Fast Fourier Transform algorithm, Indicates time The changing original time-domain signal;

[0056] Calculate the entropy of harmonic energy distribution , Entropy represents the harmonic energy distribution, used to measure the uniformity of harmonic energy distribution across different frequency components. and These are all harmonic orders, ranging from 1 to 10, representing the analysis of the first 10 harmonics. Indicates the first The amplitude of the second harmonic. Indicates the first The amplitude of each harmonic is quantified by the ratio of the square of the amplitude of each harmonic to the sum of the squares of the total harmonic amplitudes.

[0057] The hardware ID is hashed to generate the third dimension H, and the device hardware ID is then subjected to a two-factor hash. In the formula, This uses a hash message authentication code algorithm, where ID is the device's hardware identifier. This refers to the 8 bytes of the quantum key prefix, which are XORed with the hardware identifier. This indicates the key possessed by the device, which serves as the key input for the HMAC-SHA-512 algorithm;

[0058] The three-dimensional authentication vector is constructed and normalized by concatenating and normalizing the features of the three dimensions to form the final authentication vector. , ,in, This represents a vector of power load data in the power data. This represents a data vector representing the equipment operating status in the power data. This represents a data vector representing the power grid topology in the power data. The norm of a vector is used to normalize the vector so that its length is 1. It is due to the , , The normalized vectors form a new vector, which is used for subsequent data security aggregation and communication processing.

[0059] Real-time verification algorithm for access requests, defining real-time acquisition vectors With registration vector The cosine similarity is expressed by the formula: , This represents a similarity metric between two vectors. Represents the target vector. Represents the reference vector. Representing vectors and The dot product operation is used to measure the consistency of two vectors in direction. The Euclidean norm of a vector is used to normalize the vector, eliminating the influence of vector length on similarity calculations. Authentication will pass on the first attempt; otherwise, secondary verification will be triggered. Based on preset thresholds, the following table compares traditional access authentication with quantum fingerprint 3D authentication:

[0060]

[0061] The aforementioned authentication scheme constructs the digital DNA of power edge terminals through cross-domain fusion of quantum physical properties and dynamic characteristics of device operation. It cuts off the attack path of illegal devices from the source of access and provides a reliable trust anchor for subsequent data encryption, transmission protection, and aggregation security. It is the primary barrier to achieve integrated attack and defense of power data security, blocking illegal device access from the source and establishing a root of trust for end-to-end security.

[0062] In this scheme, the tamper-proof data preprocessing process for dynamic key obfuscation involves obtaining real-time latitude and longitude coordinates through a built-in GPS / BeiDou module, quantizing the coordinates, and then calculating the geographic location entropy. The formula reflecting the uncertainty of the device's spatial location is as follows:

[0063] , Geographic information entropy is used to measure the degree of uncertainty or disorder in the distribution of geospatial data. The total number of categories for classifying geospatial data. Indicates the first The probability of geospatial data appearing in the population.

[0064] According to geographic entropy generate 3D dynamic offset matrix It updates every 5 seconds, and the formula is expressed as follows: ;

[0065] in, The chaotic mapping function performs complex nonlinear transformations on the input data. For timestamps, Yes and Perform bitwise logical operations. For modulo operation, The function's output is modulo 256, mapping the value to the 0-255 range to suit the representation range of byte data.

[0066] Generate master key In the formula, KDF includes the geographic location entropy, the first dimension Q value of the device quantum fingerprint, and a random number, and DKCA_KDF is a key derived from multiple parameter combinations based on the key derivation function.

[0067] based on pass Standard functions combined with dynamic offset matrix Generate 32 rounds of dynamic wheel keys. , Indicates the first The wheel key, Indicates the first The wheel key, It is a key expansion function based on the Chinese national cryptographic algorithm SM4, used to generate the current round key from the previous round key;

[0068] Geographic location pre-obfuscation involves XORing the hash values ​​of the current grid number and MAC address of data group P, using the following formula: ,in, This is the original data. , The raw data representing the power data acquisition nodes. This represents the ciphertext data after encryption. This is the data after being decrypted and verified at the receiving end. This is represented by the current grid number. The original data is preprocessed by XORing the current grid number with the MAC address hash value.

[0069] Dynamic key encryption, , Represents the SM4 encryption algorithm. Parameters obtained from geolocation pre-obfuscation. The round encryption key used by the SM4 encryption algorithm is used to transform plaintext data in multiple rounds during the encryption process to achieve data encryption.

[0070] Chained hash verification construction, , ciphertext timestamp The quantum fingerprint Q and the previous round of hash value The hash value is calculated after XORing.

[0071] In this scheme, the tamper-resistant data preprocessing also includes constructing an edge node federated learning detection model, training a malicious payload detection feature library in real time, converting network traffic into a 224×224 grayscale image, and performing feature extraction, using the formula: ;

[0072] in, In time step The output features represent the processed power data feature vector, which integrates information from the current time step and historical information from the previous time step, and is used for subsequent security analysis. Long Short-Term Memory (LSTM) networks are used to capture long-term dependencies in sequential data over time. Convolutional neural networks are used to process input data Feature extraction is performed, using convolution and pooling operations to extract key spatial features of the power data. This provides power data at time step t, including voltage, current, and power. The output features at time step t-1 are used as input to the LSTM network to pass information from the previous time step to the current time step. The formula extracts spatial features through CNN and captures temporal series dependencies through LSTM.

[0073] based on Update gradients using the obtained model parameters , according to Update and combine with federated learning aggregation formula This allows the global model to learn the characteristics of malicious loads throughout the entire power data network, where, This represents the final calculated aggregate value. Represents the number of data groups or categories. This represents the weight of the i-th data set. This represents the parameter value corresponding to the i-th data group;

[0074] eigenvectors Input the federated learning model, through the formula Generate confidence scores. For federated learning models;

[0075] The confidence level dynamic filtering method is as follows:

[0076]

[0077] When the confidence level is below the threshold If the data is deemed high-risk, deep detection is immediately triggered and transmission is blocked; if the confidence level is greater than or equal to... and less than When the data is entered into the sandbox environment for behavioral analysis, and the confidence level is greater than or equal to... At that time, the data was deemed secure, and direct access was permitted.

[0078] The confidence-based dynamic filtering mechanism, combined with federated learning, enables distributed detection of malicious code across nodes, providing a basis for dynamic filtering. It complements the data grouping and obfuscation process. The former focuses on real-time detection and interception of traffic, while the latter defends against attacks from the perspective of data encryption and integrity verification through dynamic key obfuscation and hash chain integrity verification. Together, they ensure the security of power data during the aggregation and communication process, effectively preventing risks such as data tampering and malicious attacks.

[0079] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A power data security aggregation and communication method based on integrated offense and defense, characterized in that, Includes the following steps: A01: Quantum fingerprint-anchored edge terminal access authentication utilizes the noise signal generated by the quantum tunneling effect inside the device, which is encoded by SHA-3 as a unique identifier. Combined with dynamic biometric features, a three-dimensional authentication vector is constructed. Through a spatiotemporal attention model, real-time behavior verification of access requests is achieved. A02: Tamper-resistant data preprocessing for dynamic key obfuscation; A03: Dynamic confidence filtering based on tamper-resistant data preprocessing; A04: Utilize quantum communication technology to generate an initial key, generate random parameters every 15 seconds using a chaotic algorithm, change the encryption rules, define a security controller to globally manage the encryption strategy, and synchronize the key and parameters to all devices in real time to ensure encryption consistency. A05: Use virtual nodes to simulate real devices, lure attacks and collect intelligence, record attack behavior and extract malicious code characteristics, update the threat database, and provide real-time intelligence for defense. A06: By using data-driven automatic optimization of defense strategies to adapt to new attacks, it uses a contrastive learning algorithm to automatically label unknown attack samples from massive amounts of data, and utilizes self-supervised learning technology to dynamically adjust edge detection parameters. The optimized strategy is then injected back into each defense link.

2. The power data security aggregation and communication method based on integrated offense and defense as described in claim 1, characterized in that, The method of constructing a three-dimensional authentication vector by combining dynamic biometrics is as follows: a three-dimensional authentication vector is constructed by fusing quantum noise fingerprints, hardware-running biometric entropy values, and harmonic energy distribution entropy. The specific algorithm is as follows: Quantum noise fingerprint generation first dimension The thermal noise signal n(t) is collected using the internal quantum tunneling device and then generated as a quantum fingerprint through 256-bit SHA-3 hash encoding. ; in: It represents an XOR operation; UUID is a globally unique identifier for a device. and Indicates the start and end times of a time interval, used to define the time range for data analysis or processing. That is, a secure hash algorithm. It is time The function represents time. Data features at time of day are obtained by analyzing their characteristics at time of day. arrive Integrating over a time period yields the cumulative value of relevant data characteristics within that time period. Represents the function In the time interval Perform integration on the data to obtain the cumulative result of the data within that time period; The second dimension E of the hardware operation biometric entropy value calculation is the voltage signal during device operation. Perform a Fast Fourier Transform to extract the first 10 harmonic components. , This indicates the result obtained after calculation. The amplitude of each frequency component, For the Fast Fourier Transform algorithm, Indicates time The changing original time-domain signal; Calculate the entropy of harmonic energy distribution , Entropy represents the harmonic energy distribution, used to measure the uniformity of harmonic energy distribution across different frequency components. and These are all harmonic orders, ranging from 1 to 10, representing the analysis of the first 10 harmonics. Indicates the first The amplitude of the second harmonic. Indicates the first The amplitude of each harmonic is quantified by the ratio of the square of the amplitude of each harmonic to the sum of the squares of the total harmonic amplitudes. The hardware ID is hashed to generate the third dimension H, and the device hardware ID is then subjected to a two-factor hash. In the formula, This uses a hash message authentication code algorithm, where ID is the device's hardware identifier. This refers to the 8 bytes of the quantum key prefix, which are XORed with the hardware identifier. This indicates the key possessed by the device, which serves as the key input for the HMAC-SHA-512 algorithm; The three-dimensional authentication vector is constructed and normalized by concatenating and normalizing the features of the three dimensions to form the final authentication vector. , ,in, This represents a vector of power load data in the power data. This represents a data vector representing the equipment operating status in the power data. This represents a data vector representing the power grid topology in the power data. The norm of a vector is used to normalize the vector so that its length is 1. It is due to the , , The normalized vectors form a new vector, which is used for subsequent data security aggregation and communication processing. Real-time verification algorithm for access requests, defining real-time acquisition vectors With registration vector The cosine similarity is expressed by the formula: , This represents a similarity metric between two vectors. Represents the target vector. Represents the reference vector. Representing vectors and The dot product operation is used to measure the consistency of two vectors in direction. The Euclidean norm of a vector is used to normalize the vector, eliminating the influence of vector length on similarity calculations. Authentication will pass on the first attempt; otherwise, secondary verification will be triggered. This is a preset threshold.

3. The power data security aggregation and communication method based on integrated offense and defense as described in claim 1, characterized in that, The tamper-proof data preprocessing process for dynamic key obfuscation involves obtaining real-time latitude and longitude coordinates through a built-in GPS / BeiDou module, quantizing them, and then calculating the geographic location entropy. The formula reflecting the uncertainty of the device's spatial location is as follows: , Geographic information entropy is used to measure the degree of uncertainty or disorder in the distribution of geospatial data. The total number of categories for classifying geospatial data. Indicates the first The probability of geospatial data appearing in the population. According to geographic entropy generate 3D dynamic offset matrix It updates every 5 seconds, and the formula is expressed as follows: ; in, The chaotic mapping function performs complex nonlinear transformations on the input data. For timestamps, Yes and Perform bitwise logical operations. For modulo operation, The function's output is modulo 256, mapping the value to the 0-255 range to suit the representation range of byte data. Generate master key In the formula, KDF includes the geographic location entropy, the first dimension Q value of the device quantum fingerprint, and a random number, and DKCA_KDF is a key derived from multiple parameter combinations based on the key derivation function. based on pass Standard functions combined with dynamic offset matrix Generate 32 rounds of dynamic wheel keys. , Indicates the first The wheel key, Indicates the first The wheel key, It is a key expansion function based on the Chinese national cryptographic algorithm SM4, used to generate the current round key from the previous round key; Geographic location pre-obfuscation involves XORing the hash values ​​of the current grid number and MAC address of data group P, using the following formula: ,in, The original data, , The raw data representing the power data acquisition nodes. This refers to the ciphertext data after encryption. This is the data after being decrypted and verified at the receiving end. This is represented by the current grid number. The original data is preprocessed by XORing the current grid number with the MAC address hash value. Dynamic key encryption, , Represents the SM4 encryption algorithm. Parameters obtained from geolocation pre-obfuscation. The round encryption key used by the SM4 encryption algorithm is used to transform plaintext data in multiple rounds during the encryption process to achieve data encryption. Chained hash verification construction, , ciphertext timestamp The quantum fingerprint Q and the previous round of hash value The hash value is calculated after XORing.

4. The power data security aggregation and communication method based on integrated offense and defense as described in claim 3, characterized in that, The tamper-resistant data preprocessing also includes constructing an edge node federated learning detection model, training a malicious payload detection feature library in real time, converting network traffic into 224×224 grayscale images, and extracting features using the following formula: ; in, In time step The output features represent the processed power data feature vector, which integrates information from the current time step and historical information from the previous time step, and is used for subsequent security analysis. Long Short-Term Memory (LSTM) networks are used to capture long-term dependencies in sequential data over time. Convolutional neural networks are used to process input data Feature extraction is performed, using convolution and pooling operations to extract key spatial features of the power data. This provides power data at time step t, including voltage, current, and power. The output features at time step t-1 are used as input to the LSTM network to pass information from the previous time step to the current time step. The formula extracts spatial features through CNN and captures temporal series dependencies through LSTM. based on Update gradients using the obtained model parameters , according to Update and combine with federated learning aggregation formula This allows the global model to learn the characteristics of malicious loads throughout the entire power data network, where, This represents the final calculated aggregate value. Represents the number of data groups or categories. This represents the weight of the i-th data set. This represents the parameter value corresponding to the i-th data group; eigenvectors Input the federated learning model, through the formula Generate confidence scores. This is a federated learning model.

5. The power data security aggregation and communication method based on integrated offense and defense as described in claim 4, characterized in that, The confidence level dynamic filtering method is as follows: ; When the confidence level is below the threshold If the data is deemed high-risk, deep detection is immediately triggered and transmission is blocked; if the confidence level is greater than or equal to... and less than When the data is entered into the sandbox environment for behavioral analysis, and the confidence level is greater than or equal to... At that time, the data was deemed secure, and direct access was allowed.

Citation Information

Patent Citations

  • Archive data protection method based on block chain

    CN118228312A

  • Electronic signature generation and anti-counterfeiting system based on multi-source information fusion

    CN119885294A