A power grid data extension access control method and system
By using a combination of static and dynamic tags in power grid data interaction, the security rules of the data caller are verified and contract authorization is established, which solves the problem of power grid data extension access control across regions and business areas and realizes secure and controllable data propagation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2026-04-07
AI Technical Summary
How to effectively control extended access in power grid data interaction across geographical regions and business areas, and solve security risks in scenarios with blurred boundaries.
Static tags are used to provide access control, while dynamic tags provide propagation rules. By verifying the security rule information of the data caller, contract authorization is established and populated into the dynamic tags, enabling cross-regional and cross-business domain propagation monitoring of target power grid data.
It implements secure constraint access control for target power grid data, ensures that data propagation follows predetermined rules, prevents data leakage, and provides an effective solution for extended access control of power grid data.
Smart Images

Figure CN120729575B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power grid data cross-region and cross-domain sharing, and particularly relates to a power grid data extension access control method and system. BACKGROUND
[0002] The interaction of power grid data across geographical regions and across business fields is a key link in the development of smart grids, involving data circulation, business collaboration and resource optimization, and many other aspects. Among them, the cross-geographical region interaction refers to the sharing and collaboration of power grid data between different administrative regions (such as provinces, cities, and counties) or power grid partitions (such as East China Power Grid and North China Power Grid), such as the interaction of inter-provincial power transmission line load data and cross-region new energy grid-connected data; the cross-business field interaction refers to the data connection of different business links in the power system, such as power generation, power transmission, power distribution, power consumption, dispatching, and marketing, such as the fusion of power distribution automation data and power consumption information collection data.
[0003] At present, unlike the access control of the boundary of the traditional enterprise internal network, the focus is on the access management of external entities (such as different power grid institutions across geographical regions and across business fields) to power grid data, and the security risks in the "boundary fuzzification" scenario need to be solved. How to control the extension access is a technical problem to be solved. SUMMARY
[0004] The present application provides a power grid data extension access control method and system, the main purpose of which is to provide constraint access control to data callers by using static labels and to provide propagation access control to the next data caller by using dynamic labels, and then to realize the propagation monitoring of target power grid data in cross-geographical regions and / or cross-business fields by using the static labels and the constantly updated dynamic labels associated with the target power grid data when there are multiple iterative data callers, thereby providing an effective solution to the power grid data extension access control.
[0005] In order to achieve the above purpose, the present application mainly provides the following technical solutions:
[0006] The first aspect of the present application provides a power grid data extension access control method, which comprises:
[0007] determining a target power grid data to be called, the target power grid data corresponding to associated static labels and dynamic labels, the static labels being used to provide security rule information for accessing the target power grid data, and the dynamic labels being used to provide propagation rule information for propagating the target power grid data in cross-geographical regions and / or cross-business fields;
[0008] when receiving a first data calling request of a first data caller to the target power grid data, verifying whether the first data caller meets the security rule information in the static labels;
[0009] If the condition is met, if the verification is passed, and the first data caller is authorized to obtain the target grid data;
[0010] At the same time when the first data caller obtains the target grid data, a first contract authorization is established with the first data caller, and the dimensions of the propagation constraint conditions provided in the first contract authorization at least include attribute information of the next data caller, data propagation valid duration, and data propagation valid times;
[0011] The first contract authorization is filled into the dynamic label of the target grid data to obtain an updated dynamic label;
[0012] According to the static label and the updated dynamic label corresponding to the target grid data, the target grid data is monitored to be obtained by a second data caller in a cross-geographical area and / or a cross-business field.
[0013] The second aspect of the application provides a grid data extension access control system, which comprises:
[0014] A determination unit is configured to determine target grid data to be called, the target grid data corresponding to an associated static label and a dynamic label, the static label being configured to provide security rule information for accessing the target grid data, and the dynamic label being configured to provide propagation rule information for propagating the target grid data in a cross-geographical area and / or a cross-business field;
[0015] A verification unit is configured to verify whether a first data caller satisfies the security rule information in the static label when receiving a first data calling request of the first data caller for the target grid data;
[0016] An authorization unit is configured to, if the condition is met, if the verification is passed, and the first data caller is authorized to obtain the target grid data;
[0017] An establishment unit is configured to, at the same time when the first data caller obtains the target grid data, establish a first contract authorization with the first data caller, and the dimensions of the propagation constraint conditions provided in the first contract authorization at least include attribute information of the next data caller, data propagation valid duration, and data propagation valid times;
[0018] A filling unit is configured to fill the first contract authorization into the dynamic label of the target grid data to obtain an updated dynamic label;
[0019] The monitoring unit is configured to monitor whether the target power grid data is obtained by a second data invoker according to the static label corresponding to the target power grid data and the updated dynamic label.
[0020] The third aspect of the present application provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the power grid data extension access control method.
[0021] The fourth aspect of the present application provides an electronic device, which comprises at least one processor, at least one memory connected to the processor, and a bus;
[0022] The processor, the memory and the bus are in communication with each other.
[0023] The processor is configured to call program instructions in the memory to execute the power grid data extension access control method.
[0024] The technical solution provided by the present application has at least the following advantages:
[0025] The present application provides a power grid data extension access control method and system. In the interaction of power grid data across geographical regions and across business fields, for the target power grid data to be called, the present application associates a static label and a dynamic label with the target power grid data. The static label is used to provide security rule information for accessing the target power grid data, and the dynamic label is used to provide propagation rule information for propagating the target power grid data when crossing geographical regions and / or crossing business fields. When a data invoker initiates a data calling request for the target power grid data, the present application first verifies whether the data invoker meets the security rule information by using the static label. If yes, the data invoker is authorized to obtain the target power grid data, and a contract authorization is established with the data invoker and filled into the dynamic label. Since the contract authorization provides the dimension of the propagation constraint condition, although the data invoker has obtained the target power grid data, it still needs to judge whether the target power grid data can be shared and transmitted to the next data invoker according to the static label corresponding to the target power grid data and the updated dynamic label (filled with the contract authorization).
[0026] Compared with the demand of the prior art for extension access control of power grid data in the interaction across geographical areas and across business fields, the application provides constraint access control of data calling party by using static labels, and provides propagation access control of next data calling party by using dynamic labels, and then when there are multiple iterative data calling parties, the static labels and the dynamic labels that are constantly updated and associated with target power grid data are used to realize the propagation monitoring of the target power grid data across geographical areas and / or across business fields, thereby providing an effective solution of extension access control of power grid data.
[0027] The above description is only a summary of the technical scheme of the application, in order to enable the technical means of the application to be more clearly understood and implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the application to be more apparent and easy to understand, the following specific embodiments of the application are described. BRIEF DESCRIPTION OF DRAWINGS
[0028] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are included to provide a description of the preferred embodiments and are not meant to limit the present application. Furthermore, the same reference numerals are intended to denote the same components throughout the accompanying drawings. In the drawings:
[0029] Figure 1 A flow chart of a power grid data extension access control method provided for an embodiment of the application;
[0030] Figure 2 A flow chart of a power grid data extension access control method provided for an embodiment of the application;
[0031] Figure 3 A composition block diagram of a power grid data extension access control system provided for an embodiment of the application;
[0032] Figure 4 A composition block diagram of another power grid data extension access control system provided for an embodiment of the application. DETAILED DESCRIPTION
[0033] Exemplary embodiments of the present application will be described herein below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that the present application can be more thoroughly and completely understood, and so that the scope of the present application can be accurately conveyed to those skilled in the art.
[0034] The interaction of power grid data across geographical regions and business sectors is a key aspect of smart grid development, involving multiple levels such as data flow, business collaboration, and resource optimization. Cross-geographical interaction refers to the sharing and collaboration of power grid data between different administrative regions (such as provinces, cities, and counties) or power grid sub-regions (such as the East China Power Grid and the North China Power Grid), for example, the exchange of load data for inter-provincial transmission lines and data on cross-regional renewable energy grid connection. Cross-business sector interaction refers to the integration of data from different business segments within the power system, such as generation, transmission, distribution, consumption, dispatching, and marketing, for example, the fusion of distribution automation data and electricity consumption information collection data.
[0035] Through such cross-regional and cross-domain interactions, the following key values can be achieved, but are not limited to:
[0036] (1) Optimized resource allocation: Through cross-regional data interaction, the cross-regional consumption of renewable energy (such as wind power and photovoltaic) can be realized, reducing the curtailment rate. For example, the data linkage between the Northwest New Energy Base and the Eastern Load Center can dynamically adjust the cross-regional power transmission plan.
[0037] (2) Improved efficiency through business collaboration: Cross-business data fusion can support integrated scheduling of power generation, grid, load and storage. For example, the dispatching department can combine distribution-side load data and generation-side output data to optimize the grid operation mode and reduce the peak-valley difference.
[0038] (3) Intelligent decision support: Integrate multi-dimensional data (such as equipment status, meteorological data, and user electricity consumption behavior) to support scenarios such as power grid fault early warning and precise user services. For example, by interacting with distribution area data and user electricity consumption data, optimize the dispatch path for power outage repair.
[0039] However, unlike access control at the boundaries of traditional enterprise internal networks, the focus on managing access to power grid data by external entities (such as different power grid organizations across geographical regions and business areas) requires addressing security risks in scenarios with "blurred boundaries." How to control external access is a pressing technical problem that needs to be solved.
[0040] Based on the above considerations, embodiments of this application provide a power grid data extension access control method, such as... Figure 1 As shown, the following specific steps are provided in this embodiment of the invention:
[0041] 101. Determine the target power grid data to be invoked. The target power grid data is associated with static and dynamic tags. Static tags are used to provide security rule information for accessing the target power grid data, while dynamic tags are used to provide propagation rule information for propagating the target power grid data across geographical regions and / or business areas.
[0042] In this embodiment, a tagging system is established to track the origin of data, such as associating static and dynamic tags with the target power grid data to be accessed. Static tags provide security rules for accessing the target power grid data. These security rules may include, but are not limited to, key information such as: the data's sensitivity level (e.g., public, internal, confidential), usage permissions (e.g., viewing / editing / transmission only), flow rules (e.g., cross-regional transmission prohibited / approval required), and responsible parties (e.g., data provider / recipient). Thus, static tags enable constrained access control of the target power grid data, i.e., precise authorization of permissions before access.
[0043] Dynamic tags are used to provide propagation rule information for target power grid data across geographical regions and / or business domains. The dimensions of this propagation rule information include at least: the attributes of the next data caller, the effective duration of data propagation, the number of effective data propagations, and the data flow path, etc. Furthermore, as the name suggests, unlike static tags, dynamic tags can be dynamically populated during the propagation of target power grid data. Static tags, on the other hand, are defined at the origin of the target power grid data, or only the originator has the authority to modify them. This prevents any data caller from tampering with the data during propagation, thus ensuring the security of the target power grid data.
[0044] 102. Upon receiving a first data call request for target power grid data from the first data caller, verify whether the first data caller meets the security rule information in the static label.
[0045] 103a. If the verification shows that the first data caller meets the security rule information in the static label, then if the verification passes, the first data caller is authorized to obtain the target power grid data.
[0046] 103b. If the verification of the first data caller does not meet the security rule information in the static tag, the verification fails and the first data call request is rejected.
[0047] It should be noted that, in order to distinguish between different data callers, different data call requests initiated, and different contract authorizations established, the embodiments of this application use the terms "first" and "second" for identification, which will not be explained further below.
[0048] Besides the original origin of the target power grid data (i.e., the geographical area where the data was generated and the power grid system within the business domain), when a data request is received from any data caller, this application embodiment first uses the static tag of the target power grid data to verify the identity of the data caller, thereby determining whether the target power grid data can be authorized for use, to ensure data security. However, if the verification of the data caller's identity does not meet the authorization requirement, the data caller's data request is rejected.
[0049] 104a. While the first data caller obtains the target power grid data, a first contract authorization is established with the first data caller. The dimensions of the propagation constraints provided in the first contract authorization include at least: the attribute information of the next data caller, the effective duration of data propagation, and the effective number of data propagations.
[0050] Once 103a verifies and authorizes the data caller to obtain the target power grid data, a contract authorization is established with the data caller. The dimensions of the propagation constraints provided in the contract authorization include at least: the attribute information of the next data caller, the effective duration of data propagation, and the effective number of data propagations.
[0051] The attribute information of the next data caller can be, but is not limited to, attribute information in geographical region or business domain. For example, if the attribute information is "Beijing", it indicates that the propagation constraint is that the data can continue to be propagated to the power grid agency in "Beijing" to call the target power grid data. Accordingly, in the embodiments of this application, the "attribute information of the next data caller" can be further refined into different attribute dimensions to provide diverse constraints.
[0052] Among them, the effective duration of data propagation imposes a "timeliness" constraint on the target power grid data. The effective number of data propagations imposes a "limit on the number of times" constraint on the target power grid data.
[0053] In the above embodiments of this application, after a data caller obtains the target power grid data, the restrictions on the propagation of the target power grid data from the "data caller" are limited according to the established contract authorization.
[0054] 105a. Fill the dynamic tag of the target power grid data with the first contract authorization to obtain the updated dynamic tag.
[0055] In this embodiment of the application, after the contract authorization is established, it is populated into a dynamic tag, thereby using the dynamic tag to monitor the contract authorization.
[0056] 106a. Based on the static tags and updated dynamic tags corresponding to the target power grid data, monitor the target power grid data being obtained by the second data caller across geographical regions and / or business domains.
[0057] In this embodiment, after a data caller obtains the target power grid data, the target power grid data can be propagated from this "data caller", and this "data caller" can be the "new data owner". However, the propagation process is constrained by static and dynamic tags. For example, if another data caller wants to call the target power grid data from this "new data owner", it needs to perform the steps as described in 102-106a again. Thus, the power grid data extension access control method provided in this embodiment is an iterative process, which stops when constrained by static tags or continuously updated dynamic tags.
[0058] The above embodiments of this application provide a method for power grid data extension access control. Compared with the prior art's requirement for extension access control in the interaction of power grid data across geographical regions and business domains, the embodiments of this application use static tags to provide constraint access control for data callers and dynamic tags to provide propagation access control for the next data caller. Then, when there are multiple iterative data callers, the static tags associated with the target power grid data and the continuously updated dynamic tags are used to realize the propagation monitoring of the target power grid data across geographical regions and / or business domains, thereby providing an effective solution for power grid data extension access control.
[0059] To explain in more detail the aforementioned "power grid data extension access control method is an iterative process," this application embodiment also provides another power grid data extension access control method, such as... Figure 2 As shown, the following specific steps are provided in this embodiment of the invention:
[0060] 201. When the first data caller receives the second data caller's second data call request for target power grid data, verify whether the second data caller meets the security rule information in the static label.
[0061] It should be noted that in the embodiments of this application, the "first data caller" is the party that has already obtained the target power grid data from the data origin location, the "second data caller" is the party that wants to obtain the target power grid data from the "first data caller", and the "third data caller" is the party that obtains the target power grid data from the "second data caller" after the "second data caller" has been able to obtain the target power grid data.
[0062] In addition, the embodiments of this application use the terms "first" and "second" as identifiers to distinguish the data call requests and contract authorizations corresponding to different data callers, namely: "first data caller" corresponds to "first call request" and "first contract authorization"; "second data caller" corresponds to "second call request" and "second contract authorization", which will not be described in detail below.
[0063] Since the target power grid data is associated with static and dynamic tags at the data origin location, when the first data caller receives the second data caller's second data call request for the target power grid data, the static tag is used first to verify whether the second data caller meets the security rule information in the static tag.
[0064] For a detailed explanation of static and dynamic tags, please refer to 101; it will not be repeated here.
[0065] 202a. If the security rule information is not met, the second data access request is rejected.
[0066] 202b. If the security rule information is satisfied, then verify whether the second data caller meets the constraints in the first contract authorization.
[0067] When the first data caller receives a second data caller's request for the target power grid data, it first uses the static tag of the target power grid data to verify the identity of the second data caller, thereby determining whether the target power grid data can be authorized to be called. If the verification fails, the data caller's request for the second data caller is directly rejected.
[0068] However, if the verification passes, since the first data caller establishes a first contract authorization when obtaining the target power grid data from the data origin location, and since the first contract authorization is filled into the dynamic tag, then the second data caller can be further verified based on this first contract authorization in the dynamic tag to see if it meets the requirements.
[0069] It should be noted that, as explained in 104a, "the dimensions of the propagation constraints provided in the first contract authorization shall at least include: the attribute information of the next data caller, the effective duration of data propagation, and the effective number of data propagations."
[0070] In this application embodiment, we still take the "dimension of propagation constraint" as an example. For the "effective duration of data propagation and the effective number of data propagation", in fact, when the first contract authorization is established, these two dimensions are triggered in the mode of "countdown" and "countdown".
[0071] For example, if the "effective duration of data transmission" in the first contract authorization is 30 days, it means that the "timeliness" of the target power grid data is 30 days and the "countdown" mode has been activated; if the "effective number of data transmissions" is 10 times, it means that the "limited number of calls" for the target power grid data is 10 times and the "countdown" mode has been activated.
[0072] 203bc. If the constraints in the first contract authorization are not met, the second data call request is rejected.
[0073] 203bd. If the constraints in the first contract authorization are met, the second data caller is authorized to obtain the target power grid data from the first data caller.
[0074] 204bd. While the second data caller obtains the target power grid data, a second contract authorization is established with the second data caller. The dimensions of the propagation constraints of the second contract authorization are the same as those of the first contract authorization.
[0075] The second contract authorization has the same dimensions of propagation constraints as the first contract authorization. As illustrated in 202b, the "effective duration of data propagation" and "effective number of data propagations" are actually triggered in a "countdown" and "count-down" mode when the first contract authorization is established.
[0076] When establishing a second contract authorization, the above example continues. Since this "countdown" and "count-down" mode is triggered, the "effective duration" in the "effective duration of data propagation" dimension and the "limited number of calls" in the "effective number of data propagation" dimension are re-determined based on the current time to establish the second contract authorization.
[0077] For example, if the "effective duration of data transmission" in the first contract authorization is 30 days and the "effective number of data transmissions" is 10, then since 2 days have passed, the "effective duration of data transmission" is redefined as 28 days. And since the second data caller can be authorized to obtain the target power grid data, the "effective number of data transmissions" is redefined as 9. Based on this, the second contract authorization is established to include at least: the attribute information of the next data caller, the effective duration of data transmission of 28 days, and the effective number of data transmissions of 9.
[0078] 205bd. The second contract authorization is filled into the dynamic tag of the target power grid data in a way that covers the first contract authorization, so as to obtain the updated dynamic tag again.
[0079] To avoid storing redundant data in the dynamic tags, the second contract authorization is filled into the dynamic tags of the target power grid data in a way that overrides the first contract authorization.
[0080] 206bd. Based on the static tags corresponding to the target power grid data and the updated dynamic tags, monitor the target power grid data being obtained by a third-party data caller across geographical regions and / or business domains.
[0081] Following steps 201-205bd, the second data caller has obtained the target power grid data and established a second contract authorization, acting as the "owner" of the target power grid data. In cross-geographical regions and / or cross-business domains, a third data caller may initiate a data call request to this "owner" to obtain the target power grid data. Whether the target power grid data can be obtained by the third data caller is determined iteratively by executing steps 201-205bd above. Therefore, the power grid data extension access control method provided in this application is an iterative process that stops when constrained by a static tag or a continuously updated dynamic tag. That is, the target power grid data is rejected from being called because the security rule information in the static tag is not satisfied, or the target power grid data is rejected from being called because the contract authorization in the "continuously updated dynamic tag" is not satisfied.
[0082] In some modified embodiments, for the target contract authorization established between the previous data caller and the next data caller, a timestamp can be added to each target contract authorization in this application embodiment, so as to control the use of the newly added target contract authorization to cover the previous time-adjacent target contract authorization in the dynamic tag according to the timestamp corresponding to each target contract authorization.
[0083] As explained in 205bd above, "the second contract authorization is filled into the dynamic tag of the target power grid data in a way that overwrites the first contract authorization, so as to obtain the updated dynamic tag again," if the target power grid data is propagated among multiple data callers, resulting in multiple target contract authorizations being established during this propagation process, then the embodiments of this application can use the timestamp corresponding to the contract authorization to avoid errors when overwriting the previous invalid target contract authorization and improve accuracy.
[0084] In some modified embodiments, during the propagation of target power grid data across geographical regions and / or business areas, as explained in 201-206bd, it is evident that the power grid data extension access control method provided in this application is an iterative process. Therefore, how to terminate this iterative process, besides based on static tags, can also be based on continuously updated dynamic tags. Specific implementation methods include the following:
[0085] A1. Based on the current target contract authorization stored in the dynamic tag, determine the remaining effective duration and number of remaining effective data propagation times;
[0086] A2. If the remaining effective time for data propagation is less than the first preset threshold, then the acquisition operation of the target power grid data corresponding to the next data caller will be rejected.
[0087] A3. If the remaining valid number of data propagation attempts is less than the second preset threshold, then the acquisition operation of the target power grid data corresponding to the next data caller will be rejected.
[0088] As shown in A1A2 above, the determination of whether to continue authorizing the target power grid data to be obtained by the next data caller is based on the "effective duration of data transmission" dimension in the target contract authorization. As explained in 204bd above, in fact, when the first contract authorization is established, these two dimensions are triggered in the mode of "countdown" and "count-down".
[0089] Therefore, for the current target contract authorization, by combining the data value in the "effective duration of data propagation" dimension with the time difference between the current moment and the current time, the "remaining effective duration of data propagation" can be further determined. Furthermore, based on the value in the "effective number of times data propagation is valid" dimension of the current target contract authorization, the "remaining effective number of times data propagation is valid" can be obtained. Therefore, this application embodiment can pre-set a "first preset threshold" as a boundary constraint. When the "remaining effective duration of data propagation is less than the first preset threshold," the acquisition operation of the target power grid data corresponding to the next data caller is rejected.
[0090] As A1A3 is a parallel scheme of A1A2, the embodiments of this application can pre-set a "second preset threshold" as a boundary constraint. When the "remaining number of valid data propagation attempts is less than the second preset threshold", the acquisition operation of the target power grid data corresponding to the next data caller is rejected.
[0091] It should be noted that once either of the two parallel solutions mentioned above is selected, the iterative process should terminate.
[0092] In some modified embodiments, during the propagation of target power grid data across geographical regions and / or business domains, when the previous data caller establishes a target contract authorization with the next data caller, this application embodiment also provides an operation to obtain the identification information corresponding to the next data caller, and adds the identification information, carrying a corresponding timestamp, to the dynamic tag corresponding to the target power grid data. It should be noted that the "identification information carrying a timestamp" will not be overwritten in the continuously updated dynamic tag. Therefore, as the target power grid data propagates among multiple data callers, the propagation path of the target power grid data can be constructed based on each "identification information carrying a timestamp," realizing the monitoring and traceability of the target power grid data along the propagation path, thereby providing more diverse management methods for the extended access control of power grid data.
[0093] Furthermore, as a response to the above Figure 1 , Figure 2The implementation of the method shown in this application provides a power grid data extension access control system. This system embodiment corresponds to the foregoing method embodiment. For ease of reading, this system embodiment will not repeat the details of the foregoing method embodiment, but it should be understood that the system in this embodiment can implement all the contents of the foregoing method embodiment. This system is applied to perform access control on power grid data extensions across geographical regions and / or across business domains, specifically as follows... Figure 3 As shown, the device includes:
[0094] The determining unit 31 is used to determine the target power grid data to be invoked. The target power grid data is associated with a static tag and a dynamic tag. The static tag is used to provide security rule information for accessing the target power grid data. The dynamic tag is used to provide propagation rule information corresponding to the propagation of the target power grid data across geographical regions and / or across business domains.
[0095] Verification unit 32 is used to verify whether the first data caller meets the security rule information in the static tag when it receives a first data caller's first data call request for the target power grid data;
[0096] The authorization unit 33 is used to authorize the first data caller to obtain the target power grid data if the verification is successful, provided that the conditions are met.
[0097] Establishment unit 34 is used to establish a first contract authorization with the first data caller while the first data caller obtains the target power grid data. The dimensions of the propagation constraints provided in the first contract authorization include at least: the attribute information of the next data caller, the effective duration of data propagation, and the effective number of data propagation.
[0098] The filling unit 35 is used to fill the first contract authorization into the dynamic tag of the target power grid data to obtain the updated dynamic tag;
[0099] The monitoring unit 36 is used to monitor the target power grid data being obtained by the second data caller in cross-geographical regions and / or cross-business domains based on the static tag and the updated dynamic tag corresponding to the target power grid data.
[0100] Furthermore, such as Figure 4 As shown, the monitoring unit 36 includes:
[0101] The first verification module 361 is used to verify whether the second data caller meets the security rule information in the static tag when the first data caller receives the second data caller's second data call request for the target power grid data;
[0102] The rejection module 362 is used to reject the second data access request if the security rule information is not met.
[0103] The second verification module 363 is used to verify whether the second data caller meets the constraints in the first contract authorization if the security rule information is satisfied.
[0104] The rejection module 362 is further configured to reject the second data call request if the constraints in the first contract authorization are not met.
[0105] The authorization module 364 is used to authorize the second data caller to obtain the target power grid data from the first data caller if the constraints in the first contract authorization are met.
[0106] Module 365 is established to establish a second contract authorization with the second data caller while the second data caller obtains the target power grid data. The second contract authorization has the same dimension of propagation constraint conditions as the first contract authorization.
[0107] The filling module 366 is used to fill the dynamic tag of the target power grid data with the second contract authorization in a manner that overrides the first contract authorization, so as to obtain the updated dynamic tag again;
[0108] The monitoring module 367 is used to monitor the target power grid data being obtained by a third data caller in cross-geographical regions and / or cross-business domains, based on the static tag corresponding to the target power grid data and the updated dynamic tag.
[0109] Furthermore, such as Figure 4 As shown, the system also includes an adding unit 37, used for:
[0110] For each target contract authorization established between the previous data caller and the next data caller, a timestamp is added to each target contract authorization;
[0111] Based on the timestamp corresponding to each target contract authorization, control the dynamic tag to overwrite the previous target contract authorization with the most recently added target contract authorization.
[0112] Furthermore, such as Figure 4 As shown, during the propagation of the target power grid data across geographical regions and / or across business areas, the monitoring unit 36 is further specifically used for:
[0113] Based on the current target contract authorization stored in the dynamic tag of the target power grid data, determine the remaining effective duration and the remaining effective number of data propagation attempts;
[0114] If the remaining data propagation duration is less than a first preset threshold, then the acquisition operation of the target power grid data corresponding to the next data caller is rejected; or,
[0115] If the number of valid data propagation attempts is less than the second preset threshold, the acquisition operation of the target power grid data by the next data caller will be rejected.
[0116] Furthermore, such as Figure 4 As shown, during the propagation of the target power grid data across geographical regions and / or across business areas, the monitoring unit 36 is further specifically used for:
[0117] When the previous data caller establishes a target contract authorization with the next data caller, obtain the identification information corresponding to the next data caller;
[0118] The identification information, carrying the corresponding timestamp, is added to the dynamic tag corresponding to the target power grid data.
[0119] In summary, the power grid data extension access control system includes a processor and a memory. The aforementioned determination unit, verification unit, authorization unit, establishment unit, filling unit, and monitoring unit are all stored as program units in the memory, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0120] The processor contains a kernel that retrieves the corresponding program units from memory. One or more kernels can be configured. By adjusting kernel parameters, static tags are used to provide constrained access control for data callers, while dynamic tags provide propagation access control for subsequent data callers. Furthermore, when multiple iterative data callers exist, the static tags associated with the target power grid data and the continuously updated dynamic tags enable monitoring of the propagation of target power grid data across geographical regions and / or business domains, thus providing an effective solution for extended access control of power grid data.
[0121] This application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the power grid data extensional access control method as described above.
[0122] This application provides an electronic device, which includes at least one processor, at least one memory and a bus connected to the processor; wherein the processor and the memory communicate with each other through the bus; the processor is used to share program instructions in the memory to execute the power grid data extension access control method as described above.
[0123] This application also provides a computer program product that, when executed on a data processing device, is suitable for performing the steps of initializing a power grid data extension access control method.
[0124] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0125] In a typical configuration, the device includes one or more processors (CPUs), memory, and a bus. The device may also include input / output interfaces, network interfaces, etc.
[0126] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and memory includes at least one memory chip. Memory is an example of computer-readable media.
[0127] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0128] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0129] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0130] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for controlling extended access to power grid data, characterized in that, The method includes: The target power grid data to be invoked is determined. The target power grid data is associated with static and dynamic tags. The static tags are used to provide security rule information for accessing the target power grid data, and the dynamic tags are used to provide propagation rule information for propagating the target power grid data across geographical regions and / or business areas. Upon receiving a first data call request for the target power grid data from a first data caller, verify whether the first data caller meets the security rule information in the static tag; If the conditions are met, and the verification passes, the first data caller is authorized to obtain the target power grid data. While the first data caller obtains the target power grid data, a first contract authorization is established with the first data caller. The dimensions of the propagation constraints provided in the first contract authorization include at least: the attribute information of the next data caller, the effective duration of data propagation, and the effective number of data propagation. The first contract authorization is populated into the dynamic tag of the target power grid data to obtain the updated dynamic tag; Based on the static tag and the updated dynamic tag corresponding to the target power grid data, monitor the acquisition of the target power grid data by the second data caller across geographical regions and / or business domains, including: When the first data caller receives a second data call request from the second data caller for the target power grid data, it verifies whether the second data caller meets the security rule information in the static tag. If the security rule information is not met, the second data access request is rejected; If the security rule information is satisfied, then verify whether the second data caller meets the constraints in the first contract authorization; If the constraints in the first contract authorization are not met, the second data access request is rejected; If the constraints in the first contract authorization are met, then the second data caller is authorized to obtain the target power grid data from the first data caller; While the second data caller obtains the target power grid data, a second contract authorization is established with the second data caller. The second contract authorization has the same dimension of propagation constraint conditions as the first contract authorization. The second contract authorization is filled into the dynamic tag of the target power grid data in a manner that overrides the first contract authorization, resulting in an updated dynamic tag; Based on the static tag corresponding to the target power grid data and the updated dynamic tag, monitor the target power grid data being obtained by a third data caller across geographical regions and / or business domains.
2. The method according to claim 1, characterized in that, The method further includes, for the authorization of the target contract established between the previous data caller and the next data caller: Add a timestamp to each of the target contract authorizations; Based on the timestamp corresponding to each target contract authorization, control the dynamic tag to overwrite the previous target contract authorization with the most recently added target contract authorization.
3. The method according to claim 1 or 2, wherein during the propagation of the target power grid data across geographical regions and / or across business areas, the method further comprises: Based on the current target contract authorization stored in the dynamic tag of the target power grid data, determine the remaining effective duration and the remaining effective number of data propagation attempts; If the remaining data propagation duration is less than the first preset threshold, then the acquisition operation of the target power grid data corresponding to the next data caller is rejected. or, If the number of valid data propagation attempts is less than the second preset threshold, the acquisition operation of the target power grid data by the next data caller will be rejected.
4. The method according to claim 1 or 2, characterized in that, The method further includes the following steps during the propagation of the target power grid data across geographical regions and / or business areas: When the previous data caller establishes a target contract authorization with the next data caller, obtain the identification information corresponding to the next data caller; The identification information, carrying the corresponding timestamp, is added to the dynamic tag corresponding to the target power grid data.
5. A power grid data extension access control system, characterized in that, The system includes: The determining unit is used to determine the target power grid data to be invoked. The target power grid data is associated with a static tag and a dynamic tag. The static tag is used to provide security rule information for accessing the target power grid data, and the dynamic tag is used to provide propagation rule information corresponding to the target power grid data when propagating it across geographical regions and / or business domains. The verification unit is used to verify whether the first data caller meets the security rule information in the static tag when it receives a first data caller's first data call request for the target power grid data; An authorization unit is configured to, if the conditions are met and the verification is successful, authorize the first data caller to obtain the target power grid data. The establishment unit is used to establish a first contract authorization with the first data caller while the first data caller obtains the target power grid data. The dimensions of the propagation constraints provided in the first contract authorization include at least: the attribute information of the next data caller, the effective duration of data propagation, and the effective number of data propagation. A filling unit is used to fill the first contract authorization into the dynamic tag of the target power grid data to obtain the updated dynamic tag; The monitoring unit is used to monitor, based on the static tag and the updated dynamic tag corresponding to the target power grid data, whether the target power grid data is obtained by the second data caller in a cross-geographical region and / or cross-business domain. The monitoring unit includes: The first verification module is used to verify whether the second data caller meets the security rule information in the static tag when the first data caller receives a second data call request for the target power grid data from the second data caller. The rejection module is used to reject the second data access request if the security rule information is not met. The second verification module is used to verify whether the second data caller meets the constraints in the first contract authorization if the security rule information is satisfied. The rejection module is further configured to reject the second data call request if the constraints in the first contract authorization are not met. An authorization module is used to authorize the second data caller to obtain the target power grid data from the first data caller if the constraints in the first contract authorization are met. A module is established to establish a second contract authorization with the second data caller while the second data caller obtains the target power grid data. The second contract authorization has the same dimension of propagation constraints as the first contract authorization. The filling module is used to fill the dynamic tags of the target power grid data with the second contract authorization in a manner that overrides the first contract authorization, so as to obtain the updated dynamic tags again; The monitoring module is used to monitor the acquisition of the target power grid data by a third data caller in cross-geographical regions and / or cross-business domains, based on the static tag corresponding to the target power grid data and the updated dynamic tag.
6. The system according to claim 5, characterized in that, The system also includes an adding unit for: For each target contract authorization established between the previous data caller and the next data caller, a timestamp is added to each target contract authorization; Based on the timestamp corresponding to each target contract authorization, control the dynamic tag to overwrite the previous target contract authorization with the most recently added target contract authorization.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the power grid data extensional access control method as described in any one of claims 1-4.
8. An electronic device, characterized in that, The device includes at least one processor, and at least one memory and bus connected to the processor; The processor and the memory communicate with each other via the bus. The processor is used to invoke program instructions in the memory to execute the power grid data extension access control method as described in any one of claims 1-4.
Citation Information
Patent Citations
Terminal equipment, server and method for access control
CN113094656A
Access control method and device, electronic equipment and storage medium
CN118869223A