Access security management and control system and method for gateway equipment of power grid Internet of Things platform
Through two-way identity authentication, hierarchical permission model and LSTM prediction model, the problems of low resource allocation efficiency and untimely response to security vulnerabilities in the security management and control of gateway device access on the power grid IoT platform are solved, the legitimacy and security of device access are achieved, resource utilization is optimized, and the stability and business continuity of the platform are ensured.
Patent Information
- Application Number
- CN202511071650.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-01
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-08-01
AI Technical Summary
The existing gateway device access security management method for power grid IoT platforms lacks flexible dynamic adjustment and intelligent prediction capabilities, resulting in inefficient resource allocation and untimely response to security vulnerabilities, affecting platform stability and business continuity.
It adopts two-way identity authentication, hierarchical permission model and LSTM prediction model, generates a unique digital certificate for device identity authentication, divides permission levels based on device type and business data, dynamically adjusts resource allocation, and monitors abnormal behavior in real time to trigger session reset or suspension operations.
It improves the legality and security of device access, optimizes resource utilization efficiency, ensures platform stability and business continuity, responds to emergencies in a timely manner, and improves security and efficiency.
Smart Images

Figure CN120639504A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security management and control, and in particular to a system and method for securely managing and controlling access of gateway equipment to a power grid Internet of Things platform. Background Art
[0002] With the rapid development of smart grid and IoT technologies, the digital transformation of the power industry is accelerating. Grid IoT platforms have become a core component of power systems. The integration of IoT devices makes grid monitoring, management, and optimization more efficient, but it also brings challenges in device access security and data security.
[0003] Current methods for securing access to gateway devices on power grid IoT platforms typically rely on static identity authentication and permission management, lacking flexible dynamic adjustments and intelligent predictive capabilities. These methods often manage device access through simple authentication and permission allocation, making them incapable of addressing complex and ever-changing device access requirements. Due to a lack of historical data analysis and prediction, it is impossible to accurately assess future access needs or promptly identify potential access bottlenecks, resulting in inefficient resource allocation and a tendency for the platform to become overloaded or wasteful. Furthermore, traditional methods often rely on manual or rule-driven approaches to address anomalies in device behavior, lacking real-time monitoring and intelligent anomaly detection. This results in delayed responses to security vulnerabilities, potentially significantly impacting platform stability and business continuity. Summary of the Invention
[0004] In order to improve the existing systems and methods, a system and method for secure access management of gateway devices on a power grid Internet of Things platform is provided. This method implements secure access management of the power grid Internet of Things platform through two-way identity authentication, a hierarchical permission model, and LSTM prediction, optimizes resource allocation, and effectively responds to sudden traffic and abnormal behavior, thereby improving the security and efficiency of the platform.
[0005] In order to achieve the above objects, the technical solution adopted by the present invention is:
[0006] A method for secure access control of gateway devices on a power grid Internet of Things platform, comprising:
[0007] Submit the device's unique identifier and hardware signature to the IoT platform to generate a unique digital certificate binding the device's identity.
[0008] When a device is connected, the gateway and the device perform two-way identity authentication based on digital certificates. After the authentication is passed, the service type and operation instructions requested by the device are obtained;
[0009] Based on device type and access business data, a hierarchical permission model is used to divide the device into different levels of operation permissions, add hierarchical labels, and securely encapsulate real-time business data.
[0010] Based on historical gateway device access data, an LSTM neural network model is trained to build a gateway device access prediction model. Real-time access data is input into the prediction model to output the number of device accesses and service type distribution at each permission level in the future time period.
[0011] Based on the number of access devices and service type distribution at each level, the physical interface resource allocation ratio corresponding to each permission level is dynamically adjusted to meet the service access requirements of different levels.
[0012] When the IoT platform detects abnormal device behavior, it extracts the unique identifier and hardware feature code of the abnormal device to locate the device, triggering a forced session reset or access suspension operation.
[0013] Preferably, the step of submitting the device unique identifier and hardware feature code of the gateway device to be connected to the Internet of Things platform to generate a unique digital certificate bound to the device identity specifically includes:
[0014] Obtain the serial number or MAC address of the gateway device to be connected as a unique identifier, package it with the device hardware feature code into request data and send a request to the IoT platform;
[0015] After receiving the device request, the IoT platform verifies the validity of the device's unique identifier and hardware feature code;
[0016] Based on the device that passes the authentication, the IoT platform generates a unique digital certificate to identify the device and stores it locally on the device.
[0017] Preferably, when the device is connected, the gateway and the device perform two-way identity authentication based on a digital certificate, and after the authentication is passed, obtaining the service type and operation instruction requested by the device specifically includes:
[0018] The access device sends the obtained digital certificate to the gateway for identity authentication. The gateway verifies the validity period, issuing authority, and device identifier consistency of the digital certificate.
[0019] The device verifies the validity and credibility of the certificate based on the digital certificate provided by the gateway;
[0020] After the gateway and the device have verified each other's identities, two-way identity authentication is completed. The device sends a request, and the gateway parses the request sent by the device to identify the specific business type and operation instructions requested by the device.
[0021] Preferably, the steps of dividing the device into operation permission levels based on the device type and access service data through a hierarchical permission model, adding hierarchical labels, and securely encapsulating the real-time service data specifically include:
[0022] Classify devices based on their functions and characteristics, and divide data into different types based on the business operations involved in the devices;
[0023] Based on the device type and access service, a hierarchical permission model is constructed, which includes at least three permission levels: device control layer, data collection layer, and system management layer;
[0024] Add labels to each permission level;
[0025] Based on business needs and data sensitivity, real-time business data is securely encapsulated and encrypted.
[0026] Preferably, the LSTM neural network model is trained based on historical gateway device access data to construct a gateway device access prediction model, real-time access data is input into the prediction model, and the output of the number of device accesses and service type distribution of each permission level in the future time period specifically includes:
[0027] Obtain historical gateway device access data and perform feature extraction on the pre-processed data;
[0028] Divide historical data into training and validation sets, perform model training based on the LSTM neural network model, and build a gateway device access prediction model;
[0029] Based on the trained gateway device access prediction model, real-time access data is input into the prediction model to obtain the number of device accesses and business type distribution data of each permission level in the future time period predicted by the model.
[0030] Preferably, the dynamically adjusting the physical interface resource allocation ratio corresponding to each authority level based on the obtained number of device accesses and service type distributions at each level to meet service access requirements at different levels specifically includes:
[0031] Based on the predicted number of device accesses and service type distribution at each layer, the resource requirements of each layer are evaluated and the resource load of each layer is calculated.
[0032] Based on the resource requirements and resource load of each layer, the allocation ratio is divided for each layer and the physical interface resources are allocated;
[0033] Based on the actual number of devices connected at each layer and the distribution of service types, the allocation ratio of physical interface resources is adjusted dynamically in real time;
[0034] Allocate high-priority resources to high-priority businesses, and adopt traffic limiting or resource allocation strategies for low-priority businesses.
[0035] By reserving 5% of physical interface resources as redundant resources, you can cope with sudden surges in device access or sudden changes in business needs.
[0036] Preferably, when the IoT platform detects abnormal device behavior, extracting the unique identifier and hardware feature code of the abnormal device to locate the device, and triggering a forced session reset or access suspension operation specifically includes:
[0037] Real-time monitoring of device sensor data, operation logs, and communication behavior data to determine whether device behavior is abnormal;
[0038] For detecting abnormal situations, the abnormal device is identified by extracting the device's unique identifier and hardware feature code, and the device is located;
[0039] Based on the abnormal device positioning, the abnormal risk level is judged. For low-risk abnormalities, a forced session reset is actively triggered. For high-risk abnormalities, the device access suspension operation is triggered, and all communication and data exchange between the device and the IoT platform are stopped.
[0040] Furthermore, a power grid IoT platform gateway device access security management and control system is proposed, including:
[0041] Device identity authentication module: The device identity authentication module is responsible for receiving the unique identifier and hardware feature code of the device, and performing two-way identity authentication through digital certificates to ensure the legitimacy of the identity of the access device;
[0042] Access request parsing module: The access request parsing module parses the authenticated device request, identifies the service type and operation instruction of the device request, and processes it according to the permission model;
[0043] Permission hierarchy module: The permission hierarchy module builds a hierarchical permission model based on device type and business requirements, assigns different operation permissions to devices, and ensures the secure encapsulation and encryption of real-time business data;
[0044] Access data prediction module: The access data prediction module uses historical gateway device access data to train the LSTM neural network model to predict the number of access devices at each permission level and the distribution of service types in the future;
[0045] Resource allocation and scheduling module: The resource allocation and scheduling module dynamically adjusts the allocation ratio of physical interface resources according to the predicted access data and responds to sudden surges in device access;
[0046] Anomaly Detection Module: This module monitors the sensor data, operation logs, and communication behavior of devices in real time, detects and locates abnormal devices, and triggers forced session resets or access suspension operations to ensure platform security.
[0047] Processor: The processor is used to process the calculation process of each formula and the construction calculation process of each model.
[0048] Compared with the prior art, the advantages of the present invention are:
[0049] A two-way identity authentication mechanism ensures the legitimacy and security of devices, preventing unauthorized device access. Secondly, a hierarchical permission model allows for granular resource allocation and management of different devices based on business needs and permissions, improving the efficiency of platform resource utilization. Furthermore, historical data analysis and prediction using an LSTM neural network model provides real-time insights into access status at each permission level, allowing for pre-estimated access needs and providing a scientific basis for platform resource scheduling. Especially in response to emergencies, dynamic adjustments to access traffic and the reservation of redundant resources ensure platform stability and business continuity. Finally, the abnormal behavior detection system, by monitoring device operating status in real time, can quickly identify and address potential security threats, effectively ensuring the security and reliability of the platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 A schematic diagram of the method proposed in the present invention;
[0051] Figure 2 A schematic diagram of generating a unique digital certificate proposed by the present invention;
[0052] Figure 3 This is a schematic diagram of the two-way identity authentication proposed by the present invention;
[0053] Figure 4 This is a schematic diagram of the hierarchical division of operating permissions proposed by the present invention;
[0054] Figure 5 This is a schematic diagram of the predicted number of device accesses and service type distribution proposed by the present invention;
[0055] Figure 6 This is a schematic diagram of the dynamic resource adjustment proposed by the present invention;
[0056] Figure 7 This is a schematic diagram of the abnormality of the processing equipment proposed by the present invention. DETAILED DESCRIPTION
[0057] The following description is intended to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are merely examples, and those skilled in the art may conceive of other obvious variations.
[0058] A power grid Internet of Things platform gateway device access security management and control system, comprising:
[0059] Device identity authentication module: The device identity authentication module is responsible for receiving the unique identifier and hardware feature code of the device, and performing two-way identity authentication through digital certificates to ensure the legitimacy of the identity of the access device;
[0060] Access request parsing module: The access request parsing module parses the authenticated device request, identifies the service type and operation instruction of the device request, and processes it according to the permission model;
[0061] Permission hierarchy module: The permission hierarchy module builds a hierarchical permission model based on device type and business requirements, assigns different operation permissions to devices, and ensures the secure encapsulation and encryption of real-time business data;
[0062] Access data prediction module: The access data prediction module uses historical gateway device access data to train the LSTM neural network model to predict the number of access devices at each permission level and the distribution of service types in the future;
[0063] Resource allocation and scheduling module: The resource allocation and scheduling module dynamically adjusts the allocation ratio of physical interface resources according to the predicted access data and responds to sudden surges in device access;
[0064] Anomaly Detection Module: This module monitors the sensor data, operation logs, and communication behavior of devices in real time, detects and locates abnormal devices, and triggers forced session resets or access suspension operations to ensure platform security.
[0065] Processor: The processor is used to process the calculation process of each formula and the construction calculation process of each model.
[0066] See Figure 1 As shown, a method for secure access control of gateway devices on a power grid IoT platform includes:
[0067] Step 1: Submit the device's unique identifier and hardware signature to the IoT platform to generate a unique digital certificate bound to the device's identity.
[0068] Step 2: When the device is connected, the gateway and the device perform two-way identity authentication based on digital certificates. After the authentication is passed, the service type and operation instructions requested by the device are obtained;
[0069] Step 3: Based on the device type and access business data, the hierarchical permission model is used to divide the device into different levels of operation permissions, add hierarchical labels, and securely encapsulate the real-time business data.
[0070] Step 4: Train the LSTM neural network model based on historical gateway device access data to build a gateway device access prediction model. Input the real-time access data into the prediction model to output the number of device accesses and service type distribution at each permission level in the future time period.
[0071] Step 5: Based on the obtained number of device accesses and service type distribution at each level, dynamically adjust the physical interface resource allocation ratio corresponding to each permission level to meet the service access requirements of different levels;
[0072] Step 6: When the IoT platform detects abnormal device behavior, it extracts the unique identifier and hardware feature code of the abnormal device to locate the device, triggering a forced session reset or access suspension operation.
[0073] See Figure 2 As shown, the gateway device to be connected submits the device's unique identifier and hardware feature code to the IoT platform to generate a unique digital certificate bound to the device's identity. Specifically, the following steps are involved:
[0074] Obtain the serial number or MAC address of the gateway device to be connected as a unique identifier, package it with the device hardware feature code into request data and send a request to the IoT platform;
[0075] After receiving the device request, the IoT platform verifies the validity of the device's unique identifier and hardware feature code;
[0076] Based on the device that passes the authentication, the IoT platform generates a unique digital certificate to identify the device and stores it locally on the device.
[0077] Specifically, the device hardware signature is a unique feature of the device hardware. It is a hash value generated by the device's hardware components, including the processor model, memory size, and storage type. The device hardware information is processed using a hash algorithm to obtain a signature code of fixed length.
[0078] The device's unique identifier and hardware signature are packaged into request data and sent to the IoT platform for verification. The platform queries the database based on the received ID to confirm whether the device is legitimate, recalculates the device's hardware signature, and compares it with the signature code sent by the device.
[0079] Once verification is successful, the IoT platform generates a unique digital certificate for the device. This certificate includes the device's ID, hardware signature, and public key, and is stored locally on the device.
[0080] See Figure 3 As shown, when a device is connected, the gateway and the device perform two-way identity authentication based on a digital certificate. After the authentication is passed, the service type and operation instructions requested by the device are obtained, including:
[0081] The access device sends the obtained digital certificate to the gateway for identity authentication. The gateway verifies the validity period, issuing authority, and device identifier consistency of the digital certificate.
[0082] The device verifies the validity and credibility of the certificate based on the digital certificate provided by the gateway;
[0083] After the gateway and the device have verified each other's identities, two-way identity authentication is completed. The device sends a request, and the gateway parses the request sent by the device to identify the specific business type and operation instructions requested by the device.
[0084] Specifically, after receiving the digital certificate of the device, the gateway verifies the validity period of the digital certificate, the validity of the certificate authority, and the consistency of the device identifier and the hardware feature code;
[0085] After receiving the gateway's certificate, the device performs certificate public key verification, extracts the public key from the gateway's certificate, and verifies its validity;
[0086] When both the device and the gateway pass their respective authentications, the two-way authentication is successful. The device sends a service request to the gateway. After receiving the device's request, the gateway first decrypts the request content and then identifies the specific service type and operation instructions requested by the device.
[0087] See Figure 4 As shown in the figure, based on the device type and access business data, a hierarchical permission model is used to divide the operation permission levels for the devices, add hierarchical labels, and securely encapsulate the real-time business data. Specifically, the following are included:
[0088] Classify devices based on their functions and characteristics, and divide data into different types based on the business operations involved in the devices;
[0089] Based on the device type and access service, a hierarchical permission model is constructed, which includes at least three permission levels: device control layer, data collection layer, and system management layer;
[0090] Add labels to each permission level;
[0091] Based on business needs and data sensitivity, real-time business data is securely encapsulated and encrypted.
[0092] Specifically, devices are classified according to their functions and characteristics. Devices can be divided into multiple categories, including control devices, acquisition devices, communication devices, and management devices. Data is classified according to the specific business operations involved in the devices, including real-time data, control instructions, log data, and configuration data.
[0093] Based on device type and business requirements, a hierarchical permission model is built to ensure that each device or user can only perform operations within their authorized scope. The device control layer allows users or systems to control the status of the device. The data collection layer allows users or systems to access the data collected by the device. The system management layer allows management operations such as configuration, update, and maintenance of the device.
[0094] Each permission level is labeled according to the actual permission requirements of the operation, so that the system can easily identify and manage permissions at each level;
[0095] Based on business needs and data sensitivity, real-time business data is securely encapsulated and encrypted to ensure the confidentiality, integrity, and availability of data transmission and storage. The encryption method can be selected based on the data type and business needs, such as using symmetric encryption for sensitive data and public key encryption for transmitted data.
[0096] See Figure 5 As shown in the figure, based on the historical gateway device access data, the LSTM neural network model is trained to build a gateway device access prediction model. The real-time access data is input into the prediction model, and the output of the number of device accesses and the distribution of service types at each permission level in the future time period is as follows:
[0097] Obtain historical gateway device access data and perform feature extraction on the pre-processed data;
[0098] Divide historical data into training and validation sets, perform model training based on the LSTM neural network model, and build a gateway device access prediction model;
[0099] Based on the trained gateway device access prediction model, real-time access data is input into the prediction model to obtain the number of device accesses and business type distribution data of each permission level in the future time period predicted by the model.
[0100] Specifically, access data is collected from gateway devices, including device ID, access time, permission level, and service type. The data is normalized or standardized so that all features are at the same level, and feature extraction is performed.
[0101] The historical data is divided into a training set and a validation set, with 70% used as the training set and 30% as the validation set. Through LSTM model training, a model capable of predicting future device access is obtained. The training process continuously adjusts the LSTM network weights to minimize prediction errors.
[0102] Real-time access data is input into the trained LSTM model. The historical data of each time step is input into the network through the input layer. The LSTM layer learns the long-term dependencies of the time series, and the output layer obtains predictions of future access quantity and service types. Based on the results of the access quantity prediction, the distribution of different service types is further predicted.
[0103] See Figure 6 As shown, based on the obtained number of device accesses and service type distribution at each level, the physical interface resource allocation ratio corresponding to each permission level is dynamically adjusted to meet the service access requirements of different levels. Specifically, the following are included:
[0104] Based on the predicted number of device accesses and service type distribution at each layer, the resource requirements of each layer are evaluated and the resource load of each layer is calculated.
[0105] Based on the resource requirements and resource load of each layer, the allocation ratio is divided for each layer and the physical interface resources are allocated;
[0106] Based on the actual number of devices connected at each layer and the distribution of service types, the allocation ratio of physical interface resources is adjusted dynamically in real time;
[0107] Allocate high-priority resources to high-priority businesses, and adopt traffic limiting or resource allocation strategies for low-priority businesses.
[0108] By reserving 5% of physical interface resources as redundant resources, you can cope with sudden surges in device access or sudden changes in business needs.
[0109] Specifically, resource requirements and load are evaluated based on the number of devices connected at each level and the distribution of service types. Each device will occupy a certain amount of resources when connected, and different service types have different resource requirements. The resource requirement formula is:
[0110]
[0111] in, is the total resource demand of level i, is the number of devices of type j accessed at level i, is the resource demand of the j-th type of equipment, is the total type;
[0112] The resource load calculation formula is:
[0113]
[0114] in, is the resource load of the i-th level, is the total resource capacity of level i;
[0115] Based on the resource requirements and load of each level, calculate the resource ratio that should be allocated to each level. The formula is:
[0116]
[0117] in, is the resource allocation ratio of the i-th level, is the total number of all levels;
[0118] The number of devices connected to each layer and the distribution of service types will change over time. Resource allocation ratios should be adjusted based on real-time data. Priority allocation should be ensured for high-priority services, while a flow control strategy can be adopted for low-priority services.
[0119] To cope with sudden traffic or sudden changes in business demand, a certain proportion of resources should be reserved as redundancy. The reserved resources are set to 5% of the total resources. By reserving redundant resources, it is possible to cope with emergencies such as a sudden surge in device access or sudden changes in business demand.
[0120] See Figure 7 As shown in the figure, when the IoT platform detects abnormal device behavior, it extracts the unique identifier and hardware feature code of the abnormal device to locate the device, triggering a forced session reset or access suspension operation. Specifically, the following operations are performed:
[0121] Real-time monitoring of device sensor data, operation logs, and communication behavior data to determine whether device behavior is abnormal;
[0122] For detecting abnormal situations, the abnormal device is identified by extracting the device's unique identifier and hardware feature code, and the device is located;
[0123] Based on the abnormal device positioning, the abnormal risk level is judged. For low-risk abnormalities, a forced session reset is actively triggered. For high-risk abnormalities, the device access suspension operation is triggered, and all communication and data exchange between the device and the IoT platform are stopped.
[0124] Specifically, it acquires the device's sensor data, operation logs, and communication behavior data in real time to determine whether the device has abnormal behavior. Once abnormal behavior is detected, it identifies the abnormal device by extracting the device's unique identifier and hardware feature code.
[0125] Based on the identified abnormal devices, the device is located and the danger level is determined according to the severity of the abnormality. For low-risk abnormalities, the system actively triggers a session reset and reinitializes the device connection. For high-risk abnormalities, the system needs to suspend the device access operation and stop the communication and data exchange between the device and the IoT platform.
[0126] It should be noted that the order in which the embodiments of the present invention are described above is for illustrative purposes only and does not necessarily represent the superiority or inferiority of the embodiments. Furthermore, the foregoing descriptions of specific embodiments of this specification are provided. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential sequence shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0127] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.
[0128] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for secure access control of gateway devices on a power grid Internet of Things platform, characterized in that: include: Submit the device's unique identifier and hardware signature to the IoT platform to generate a unique digital certificate binding the device's identity. When a device is connected, the gateway and the device perform two-way identity authentication based on digital certificates. After the authentication is passed, the service type and operation instructions requested by the device are obtained; Based on device type and access business data, a hierarchical permission model is used to divide the device into different levels of operation permissions, add hierarchical labels, and securely encapsulate real-time business data. Based on historical gateway device access data, an LSTM neural network model is trained to build a gateway device access prediction model. Real-time access data is input into the prediction model to output the number of device accesses and service type distribution at each permission level in the future time period. Based on the number of access devices and service type distribution at each level, the physical interface resource allocation ratio corresponding to each permission level is dynamically adjusted to meet the service access requirements of different levels. When the IoT platform detects abnormal device behavior, it extracts the unique identifier and hardware feature code of the abnormal device to locate the device, triggering a forced session reset or access suspension operation.
2. A method for secure access control of gateway devices on a power grid Internet of Things platform according to claim 1, characterized in that: The step of submitting the device's unique identifier and hardware feature code to the IoT platform to generate a unique digital certificate for the device's identity is as follows: Obtain the serial number or MAC address of the gateway device to be connected as a unique identifier, package it with the device hardware feature code into request data and send a request to the IoT platform; After receiving the device request, the IoT platform verifies the validity of the device's unique identifier and hardware feature code; Based on the device that passes the authentication, the IoT platform generates a unique digital certificate to identify the device and stores it locally on the device.
3. A method for secure access control of gateway devices on a power grid Internet of Things platform according to claim 1, characterized in that: When the device is connected, the gateway and the device perform two-way identity authentication based on the digital certificate. After the authentication is passed, the service type and operation instructions requested by the device are obtained, which specifically include: The access device sends the obtained digital certificate to the gateway for identity authentication. The gateway verifies the validity period, issuing authority, and device identifier consistency of the digital certificate. The device verifies the validity and credibility of the certificate based on the digital certificate provided by the gateway; After the gateway and the device have verified each other's identities, two-way identity authentication is completed. The device sends a request, and the gateway parses the request sent by the device to identify the specific business type and operation instructions requested by the device.
4. A method for secure access control of gateway devices on a power grid Internet of Things platform according to claim 1, characterized in that: The hierarchical permission model is used to divide the device into different levels of operation permissions based on the device type and access service data, add hierarchical labels, and securely encapsulate the real-time service data. Specifically, the following steps are involved: Classify devices based on their functions and characteristics, and divide data into different types based on the business operations involved in the devices; Based on the device type and access service, a hierarchical permission model is constructed, which includes at least three permission levels: device control layer, data collection layer, and system management layer; Add labels to each permission level; Based on business needs and data sensitivity, real-time business data is securely encapsulated and encrypted.
5. A method for secure access control of gateway devices on a power grid Internet of Things platform according to claim 1, characterized in that: The LSTM neural network model is trained based on historical gateway device access data to build a gateway device access prediction model. The real-time access data is input into the prediction model to output the number of device accesses and service type distribution of each permission level in the future time period. Specifically, the following are included: Obtain historical gateway device access data and perform feature extraction on the pre-processed data; Divide historical data into training and validation sets, perform model training based on the LSTM neural network model, and build a gateway device access prediction model; Based on the trained gateway device access prediction model, real-time access data is input into the prediction model to obtain the number of device accesses and business type distribution data of each permission level in the future time period predicted by the model.
6. A method for secure access control of gateway devices on a power grid Internet of Things platform according to claim 1, characterized in that: The method of dynamically adjusting the physical interface resource allocation ratio corresponding to each permission level based on the obtained number of device accesses and service type distribution at each level to meet the service access requirements at different levels specifically includes: Based on the predicted number of device accesses and service type distribution at each layer, the resource requirements of each layer are evaluated and the resource load of each layer is calculated. Based on the resource requirements and resource load of each layer, the allocation ratio is divided for each layer and the physical interface resources are allocated; Based on the actual number of devices connected at each layer and the distribution of service types, the allocation ratio of physical interface resources is adjusted dynamically in real time; Allocate high-priority resources to high-priority businesses, and adopt traffic limiting or resource allocation strategies for low-priority businesses. By reserving 5% of physical interface resources as redundant resources, you can cope with sudden surges in device access or sudden changes in business needs.
7. A method for secure access control of gateway devices on a power grid Internet of Things platform according to claim 1, characterized in that: When the IoT platform detects abnormal device behavior, it extracts the unique identifier and hardware feature code of the abnormal device to locate the device, and triggers a forced session reset or access suspension operation, specifically including: Real-time monitoring of device sensor data, operation logs, and communication behavior data to determine whether device behavior is abnormal; For detecting abnormal situations, the abnormal device is identified by extracting the device's unique identifier and hardware feature code, and the device is located; Based on the abnormal device positioning, the abnormal risk level is judged. For low-risk abnormalities, a forced session reset is actively triggered. For high-risk abnormalities, the device access suspension operation is triggered, and all communication and data exchange between the device and the IoT platform are stopped.
8. A power grid Internet of Things platform gateway device access security management and control system, used to implement a power grid Internet of Things platform gateway device access security management and control method according to any one of claims 1 to 7, characterized in that: include: Device identity authentication module: The device identity authentication module is responsible for receiving the unique identifier and hardware feature code of the device, and performing two-way identity authentication through digital certificates to ensure the legitimacy of the identity of the access device; Access request parsing module: The access request parsing module parses the authenticated device request, identifies the service type and operation instruction of the device request, and processes it according to the permission model; Permission hierarchy module: The permission hierarchy module builds a hierarchical permission model based on device type and business requirements, assigns different operation permissions to devices, and ensures the secure encapsulation and encryption of real-time business data; Access data prediction module: The access data prediction module uses historical gateway device access data to train the LSTM neural network model to predict the number of access devices at each permission level and the distribution of service types in the future; Resource allocation and scheduling module: The resource allocation and scheduling module dynamically adjusts the allocation ratio of physical interface resources according to the predicted access data and responds to sudden surges in device access; Anomaly Detection Module: This module monitors the sensor data, operation logs, and communication behavior of devices in real time, detects and locates abnormal devices, and triggers forced session resets or access suspension operations to ensure platform security. Processor: The processor is used to process the calculation process of each formula and the construction calculation process of each model.
Citation Information
Patent Citations
Network security access method and device, equipment and storage medium
CN116405262A
Internet of Things equipment security access method based on mobile communication network
CN119485284A
Real-time hierarchical distribution method for power cloud resources of digital power grid
CN119603304A
Industrial Internet of Things security authentication method and system based on zero-knowledge proof
CN119743270A
Network demand prediction method based on multi-feature fusion
CN120128492A