Data transmission method, device and equipment applied to power internet of things, storage medium and program product
By employing lightweight trusted metrics and containerization technology in the power Internet of Things, and dynamically adjusting the adaptive encryption strategy, the real-time communication problem caused by the fixed configuration strategy is solved, achieving a balance between stability and security in power grid communication.
Patent Information
- Application Number
- CN202511151272.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-11-14
AI Technical Summary
In existing power Internet of Things (IoT) communications, the fixed configuration of adaptive encryption strategies can affect the real-time performance of communications when computing resources are limited or network conditions are poor, thereby affecting the stable operation of the power grid.
A lightweight trust measurement layer is used to measure the trustworthiness of containers, establish a binding relationship between containers and processors, determine an adaptive encryption strategy based on real-time power business network traffic, and dynamically update the encryption strategy through a closed-loop control and strategy optimization layer to achieve adaptive encryption processing.
While ensuring communication security, the real-time performance of data transmission has been improved, ensuring the stable and safe operation of the power grid.
Smart Images

Figure CN120956486A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security in the Internet of Things (IoT) for power systems, and more particularly to a data transmission method, apparatus, equipment, storage medium, and program product for use in the Internet of Things for power systems. Background Technology
[0002] With the continuous development of the energy internet and new power systems, the Power Internet of Things (PIoT) has become a key infrastructure for realizing comprehensive power grid perception, efficient information processing, and intelligent business decision-making. In the northbound communication link of the PIoT, which is the channel through which edge devices upload data to the main station platform or cloud platform, a large amount of power data, including power grid topology, equipment status, and user electricity consumption information, is carried. Its security is crucial to the stable operation of the power grid and energy security.
[0003] In the existing technology, gateway units are set up at two power dispatch communication nodes that need to transmit data to each other. A communication tunnel is established according to the power-specific encryption and authentication communication protocol. The identity of the other party is verified by a certificate-based authentication method, and the negotiated session key is used to encrypt and decrypt the power data to be transmitted.
[0004] However, in the above methods, the adaptive encryption strategy is fixed, which may affect the real-time performance of communication due to excessive computational resource overhead of the encryption algorithm when computing resources are limited or network conditions are poor, thereby affecting the stable operation of the power grid. Summary of the Invention
[0005] This application provides data transmission methods, devices, equipment, storage media, and program products for the power Internet of Things, which can improve the real-time performance of data transmission while ensuring communication security, thereby ensuring the stable and safe operation of the power grid.
[0006] In a first aspect, embodiments of this application provide a data transmission method applied to the power Internet of Things, comprising:
[0007] Based on the lightweight trusted measurement layer, in response to the start signal, the trusted root interface in the trusted root adaptation layer is called, and based on the trusted root interface, trusted measurement processing is performed on at least one container in the virtualization container isolation layer to obtain the measurement result.
[0008] If the measurement results indicate that each container is in a trusted state, a correspondence between each container and each target processor is established based on the virtualization container isolation layer to run the key components in each container;
[0009] Based on the northbound communication tunnel layer, real-time power service network traffic is acquired, and an adaptive encryption strategy is determined according to the traffic characteristic data of the real-time power service network traffic; wherein, the adaptive encryption strategy is used to perform encrypted transmission processing of the power data to be transmitted based on each of the key components.
[0010] Based on the closed-loop control and strategy optimization layer, the adaptive encryption strategy is updated according to the current operating status data.
[0011] In one possible implementation, determining the adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic includes:
[0012] Based on the traffic characteristic data of the real-time power service network traffic, determine the traffic characteristic data of the predicted power service network traffic corresponding to the real-time power service network traffic.
[0013] The adaptive encryption strategy is determined based on the traffic characteristic data of the predicted power service network traffic.
[0014] In one possible implementation, the method further includes:
[0015] Based on the traffic characteristic data of the real-time power service network traffic, the key granularity and the whitelist in the adaptive encryption strategy are determined; wherein, the whitelist is used to filter access protocol instructions.
[0016] In one possible implementation, the method further includes:
[0017] In response to the scarcity of computing resources, the power data to be transmitted is encrypted using a low-overhead encryption mode.
[0018] In one possible implementation, the closed-loop control and policy optimization layer updates the adaptive encryption policy based on current operating state data, including:
[0019] Based on a preset security performance trade-off decision model, the traffic characteristic data, network environment information, security threat information, business requirement information, and system resource information in the current operating status data are processed by the model to obtain the optimal adaptive encryption strategy parameters.
[0020] The adaptive encryption strategy is updated based on the optimal adaptive encryption strategy parameters.
[0021] In one possible implementation, the method further includes:
[0022] The operation status data is compressed, and the compressed operation status data is fed back to the preset safety performance trade-off decision model.
[0023] Alternatively, the operating status data can be incrementally updated, and the updated operating status data can be fed back to the preset security performance trade-off decision model.
[0024] Alternatively, in response to a preset event, the operational status data can be fed back to the preset security performance trade-off decision model.
[0025] In one possible implementation, the step of performing a trust measurement process on at least one container in the virtualization container isolation layer based on the trusted root interface to obtain a measurement result includes:
[0026] Trust measurement processing is performed on the firmware and kernel in the trusted root adaptation layer;
[0027] If it is determined that both the firmware and the kernel are in a trusted state, a trust measurement process is performed on the container image corresponding to the at least one container.
[0028] If it is determined that the container images corresponding to the at least one container are all in a trusted state, in response to starting the container, a trust measurement is performed on the key file and communication process of the container to obtain the measurement result.
[0029] In one possible implementation, after the critical components in each of the containers have been run, the method further includes:
[0030] Based on the lightweight trust measurement layer, trust measurement processing is performed on the key files and communication processes of each running container.
[0031] In one possible implementation, the method further includes:
[0032] Based on the trusted root adaptation layer, the trusted status information of each terminal device in the target power Internet of Things is monitored, and the trusted status information is synchronized to each terminal device in the target power Internet of Things.
[0033] Secondly, embodiments of this application provide a data transmission device for use in the power Internet of Things, comprising:
[0034] The measurement module is used to call the trusted root interface in the trusted root adaptation layer in response to the start signal, based on the lightweight trusted measurement layer, and to perform trusted measurement processing on at least one container in the virtualization container isolation layer based on the trusted root interface to obtain the measurement result.
[0035] The running module is used to, if it is determined that the measurement result indicates that each of the containers is in a trusted state, establish a correspondence between each container and each target processor based on the virtualization container isolation layer, so as to run the key components in each container;
[0036] An encryption module is used to acquire real-time power service network traffic based on the northbound communication tunnel layer, and determine an adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic; wherein, the adaptive encryption strategy is used to perform encrypted transmission processing on the power data to be transmitted based on each of the key components.
[0037] The update module is used to update the adaptive encryption strategy based on the current operating status data, using the closed-loop control and strategy optimization layer.
[0038] In one possible implementation, the encryption module is specifically configured to: determine the traffic characteristic data of the predicted power service network traffic corresponding to the real-time power service network traffic based on the traffic characteristic data of the real-time power service network traffic; and determine the adaptive encryption strategy based on the traffic characteristic data of the predicted power service network traffic.
[0039] In one possible implementation, the encryption module is further specifically used to: determine the key granularity and the whitelist in the adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic; wherein the whitelist is used to filter access protocol instructions.
[0040] In one possible implementation, the encryption module is further specifically used to: in response to a shortage of computing resources, perform encrypted transmission processing on the power data to be transmitted based on a low-overhead encryption mode.
[0041] In one possible implementation, the update module is specifically used to: perform model processing on traffic characteristic data, network environment information, security threat information, business requirement information, and system resource information in the current operating status data based on a preset security performance trade-off decision model to obtain optimal adaptive encryption strategy parameters; and update the adaptive encryption strategy according to the optimal adaptive encryption strategy parameters.
[0042] In one possible implementation, the update module is further configured to: compress the running status data and feed the compressed running status data back to the preset security performance trade-off decision model; or, perform incremental update processing on the running status data and feed the updated running status data back to the preset security performance trade-off decision model; or, in response to triggering a preset event, feed the running status data back to the preset security performance trade-off decision model.
[0043] In one possible implementation, the measurement module is specifically configured to: perform trust measurement processing on the firmware and kernel in the trusted root adaptation layer; if it is determined that the firmware and the kernel are both in a trusted state, perform trust measurement processing on the container image corresponding to the at least one container; if it is determined that the container images corresponding to the at least one container are both in a trusted state, in response to starting the container, perform trust measurement on the key file and communication process of the container to obtain the measurement result.
[0044] In one possible implementation, after the running module is used to run the key components in each of the containers, the apparatus is further used to: perform trust measurement processing on the key files and communication processes of the running containers based on the lightweight trust measurement layer.
[0045] In one possible implementation, the device is further configured to: monitor the trusted status information of each terminal device in the target power Internet of Things based on the trusted root adaptation layer, and synchronize the trusted status information to each terminal device in the target power Internet of Things.
[0046] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;
[0047] The memory stores computer-executed instructions;
[0048] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0049] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.
[0050] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0051] The data transmission method, apparatus, device, storage medium, and program product for the power Internet of Things provided in this application embodiment, through a lightweight trusted measurement layer, calls the trusted root interface in the trusted root adaptation layer when data transmission is initiated, and performs trusted measurement processing on each container in the virtualized container isolation layer. When each container is in a trusted state, the virtualized container isolation layer binds each container to each target processor to run the key components of each container. The northbound communication tunnel layer determines an adaptive encryption strategy based on the traffic characteristics data of real-time power business network traffic, and runs each key component to encrypt the power data to be transmitted according to the adaptive encryption strategy. The closed-loop control and strategy optimization layer updates the adaptive encryption strategy according to the current operating status data. Furthermore, by dynamically adjusting the adaptive encryption strategy based on the lightweight trusted measurement, containerization, and processor core binding strategy, and by sensing the business traffic characteristics and operating status data in real time, the communication security strength can be guaranteed while taking into account the real-time requirements of communication. Attached Figure Description
[0052] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0053] Figure 1 A schematic flowchart illustrating a data transmission method applied to the power Internet of Things, provided as an embodiment of this application;
[0054] Figure 2 An overall architecture diagram of an adaptive encryption system for northbound communication tunnels in the power Internet of Things provided in this application embodiment;
[0055] Figure 3 This is a schematic diagram illustrating virtualized container isolation and resource binding provided in an embodiment of this application;
[0056] Figure 4 A flowchart illustrating another data transmission method applied to the power Internet of Things, provided as an embodiment of this application;
[0057] Figure 5 A lightweight trust measurement flowchart is provided for embodiments of this application;
[0058] Figure 6 An adaptive encryption strategy decision-making flowchart is provided for embodiments of this application;
[0059] Figure 7 A flowchart of closed-loop feedback and strategy optimization provided for embodiments of this application;
[0060] Figure 8 A schematic diagram of a data transmission device for the power Internet of Things provided in this application embodiment;
[0061] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0062] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0063] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0064] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, they do not violate public order and good morals, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0065] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0066] It should be noted that this application can be used in the field of power Internet of Things communication security, or in any other field. The application field of this application is not limited.
[0067] By setting up gateway units at two power dispatch communication nodes that need to transmit data to each other, and utilizing built-in key negotiation and encryption / decryption modules, a communication tunnel is established based on a power-specific encrypted authentication communication protocol. This scheme employs certificate-based authentication to verify the other party's identity and uses the negotiated session key to encrypt and decrypt transmitted data.
[0068] Based on the above scenarios, it can be seen that the adaptive encryption strategy is a fixed configuration. This may lead to excessive computational overhead of the encryption algorithm when computing resources are limited or network conditions are poor, which may affect the real-time performance of communication and thus affect the stable operation of the power grid.
[0069] In view of this, the data transmission method for the power Internet of Things provided in this application, by using lightweight trusted measurement, containerization and processor core binding strategies, and by dynamically adjusting the adaptive encryption strategy through real-time perception of business traffic characteristics and operating status data, can ensure the strength of communication security while taking into account the real-time requirements of communication.
[0070] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0071] Figure 1 A flowchart illustrating a data transmission method for the power Internet of Things (IoT) provided in this application is shown below. Figure 1 As shown, the method includes:
[0072] 201. Based on the lightweight trusted measurement layer, in response to the start signal, the trusted root interface in the trusted root adaptation layer is called, and based on the trusted root interface, trusted measurement processing is performed on at least one container in the virtualization container isolation layer to obtain the measurement result.
[0073] For example, the implementing entity of this embodiment may be an adaptive encryption system for northbound communication tunnels in the power Internet of Things, hereinafter referred to as the system. Figure 2 An overall architecture diagram of an adaptive encryption system for northbound communication tunnels in the power Internet of Things (IoT) provided in this application embodiment is shown below. Figure 2As shown, the system's bottom layer is a trusted root adaptation layer deployed on chip hardware, providing a hardware-based trust foundation for the entire system. Above this, a lightweight trusted measurement layer is responsible for verifying the integrity of critical system components during startup and runtime, ensuring the establishment and transmission of the trust chain. The virtualization container isolation layer utilizes container technology to encapsulate core functions such as key management, encryption algorithms, and protocol instruction filters within independent containers, achieving resource isolation and parallel processing. The northbound communication tunnel layer is the core functional layer of the system. It uses layers 4-7 of deep parsing modules to perceive business traffic characteristics in real time and dynamically adjusts adaptive encryption strategies according to preset policies to achieve adaptive encryption. The closed-loop control and policy optimization layer is responsible for collecting operational data from each layer, analyzing and optimizing it through a security performance trade-off decision model, and distributing the optimized strategies to each execution unit, forming a continuously improving closed-loop control system.
[0074] Specifically, the Trusted Root Adaptation Layer defines a unified set of Trusted Root interfaces, such as Application Programming Interfaces (APIs), to abstract and encapsulate trusted computing functions provided by chips from different manufacturers and models. Upper-layer applications only need to call this unified API to use various trusted computing functions without needing to concern themselves with the specific implementation of the underlying hardware. For example, at system startup, a dynamic loading mechanism loads the corresponding driver module based on the hardware platform's identification information. Upper-layer applications (such as the Lightweight Trusted Measurement Layer) call these unified APIs to initialize the Trusted Root, generate keys, or calculate integrity metrics. This interface abstraction not only improves the portability of upper-layer applications but also facilitates the upgrading and replacement of underlying hardware without modifying the upper-layer application code. Furthermore, this module provides rich configuration options, allowing flexible configuration of various parameters of the Trusted Root according to different application scenarios and security requirements.
[0075] Furthermore, based on the lightweight trusted measurement layer, in response to the system's startup signal, the trusted root interface in the trusted root adaptation layer is invoked, and various trusted computing functions are used to perform trusted measurement processing on at least one container in the virtualized container isolation layer to obtain measurement results, thereby determining whether the key components in each container are trusted.
[0076] For example, the system calculates the container's hash value and compares it to a baseline hash value pre-stored in the root of trust. If they match, the container is considered tamper-proof and trustworthy, and the system will continue to create and run it. Conversely, if the hash values do not match, the container may have been abnormally tampered with, the system will refuse to create it and trigger an appropriate alarm mechanism. This hash-based verification method has the advantages of low computational cost and high efficiency, making it ideal for deployment on resource-constrained power IoT terminal devices.
[0077] 202. If the measurement results indicate that each container is in a trusted state, establish a correspondence between each container and each target processor based on the virtualization container isolation layer to run the key components in each container.
[0078] For example, Figure 3 This application provides a schematic diagram of virtualized container isolation and resource binding, as shown in the embodiments. Figure 3 As shown, the virtualization container isolation layer (container layer) packages key management, encryption algorithms, protocol instruction filtering, and other functions into independent, minimal container images. Through container orchestration tools, resource limits (processor (Central Processing Unit, CPU), memory), network configurations, and security policies are defined for each container. If the measurement results indicate that each container is in a trusted state, the virtualization container isolation layer binds the container to a specified CPU core in the host machine's multi-core CPU upon startup, enabling the corresponding CPU core to drive and run the critical components within the container. For example, computationally intensive encryption algorithm containers can be bound to high-performance CPU cores, while input / output (I / O) intensive protocol instruction filter containers can be bound to other cores, thereby optimizing resource allocation and improving overall system efficiency. Simultaneously, strict system permissions for each container are limited, adhering to the principle of least privilege, further enhancing isolation.
[0079] It's worth noting that, to achieve flexible binding strategies, the system offers a wealth of configuration options, dynamically adjusting the CPU core binding relationships of containers based on different application scenarios and performance requirements. For example, it can automatically adjust the number of CPU cores bound to a container based on its load, thereby achieving dynamic resource allocation and load balancing.
[0080] Furthermore, to ensure key security, the key management container employs multiple security mechanisms. First, key generation and storage are completed internally within the container and protected by high-strength encryption algorithms to prevent unauthorized key theft. Second, key distribution utilizes secure communication protocols such as Transport Layer Security (TLS) / Secure Socket Layer (SSL) to ensure the confidentiality and integrity of keys during transmission. Additionally, the container supports periodic key rotation and destruction to reduce the risk of key leakage. For high availability, multiple instances of the key management container can be deployed, with load balancing enabling failover. When the primary key management container fails, a backup container can immediately take over, ensuring continuous key service. The container also provides a rich set of API interfaces, facilitating key access and management by other containers or applications. By encapsulating key management functionality within an independent container, not only is key security improved, but key management policies can also be easily updated and upgraded without affecting other functional modules. Alternatively, a centralized key management pool solution can be adopted. By deploying a highly available hardware security module cluster at the center, a unified key generation, storage, distribution, and rotation service can be provided to all edge nodes. Each edge node requests key services from the center through a secure channel to facilitate unified key management.
[0081] Furthermore, the encryption algorithm container is responsible for implementing the specific functions of various encryption algorithms, such as symmetric encryption, asymmetric encryption, and hash algorithms. This container is designed with high flexibility and scalability, dynamically loading different encryption algorithm libraries according to different security requirements. For example, in scenarios requiring high-strength encryption, the national cryptographic algorithm library can be loaded; in resource-constrained scenarios, a lightweight encryption algorithm library can be loaded. To improve performance, the container employs various optimization techniques, such as hardware acceleration and parallel computing. For example, it can utilize the encryption instruction set provided by a specific chip to accelerate encryption and decryption operations. In addition, the container supports dynamic algorithm switching, allowing switching to different encryption algorithms without interrupting service based on adjustments to upper-layer strategies. By encapsulating encryption algorithms in independent containers, not only can flexible configuration and dynamic upgrades of algorithms be achieved, but also convenient performance testing and security assessment of algorithms can be performed without affecting other functional modules.
[0082] Furthermore, the protocol instruction filter container is responsible for deep parsing and filtering network traffic to prevent the transmission of abnormal instructions and illegal data. This container supports the parsing of various power IoT communication protocols and can perform deep parsing of Protocol Data Units (PDUs) to extract key instructions and parameters. The container also supports filtering the data content of the power data to be transmitted, preventing the leakage of sensitive data. By encapsulating the protocol instruction filtering function in a separate container, not only can flexible filtering strategy configurations be achieved, but protocol expansion and upgrades can also be easily performed without affecting other functional modules.
[0083] The virtualization container isolation layer can also utilize machine learning algorithms to predict the resource requirements of each container and dynamically adjust the CPU core binding relationship of the containers based on the prediction results and real-time system load. This dynamic adjustment algorithm can better adapt to fluctuations in business load, achieve elastic resource allocation and load balancing, and further improve the overall system performance and resource utilization.
[0084] Furthermore, the virtualization container isolation layer utilizes advanced virtualization container technology to encapsulate core functional modules such as key management, encryption algorithm instances, and protocol instruction filters into independent containers. Through CPU core binding technology, it achieves resource isolation and parallel processing. This design not only effectively prevents single points of failure but also fully utilizes the computing power of multi-core processors, improving overall system performance. Each container runs in an independent user space, possessing its own file system, network stack, and process space, achieving strict isolation between them. Even if one container fails or is attacked, it will not affect the normal operation of other containers, thus ensuring the stability and reliability of the entire system.
[0085] Alternatively, lightweight virtual machines can be considered as an alternative to containers. By providing each container with an independent, streamlined virtual machine kernel, lightweight virtual machines achieve stronger process, network, and file system isolation than containers, effectively defending against kernel-level attacks.
[0086] 203. Based on the northbound communication tunnel layer, obtain real-time power service network traffic, and determine an adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic; wherein, the adaptive encryption strategy is used to perform encrypted transmission processing of the power data to be transmitted based on each key component.
[0087] For example, the northbound communication tunnel layer acquires the system's real-time power service network traffic. Through the layer 4-7 deep parsing modules, it performs deep analysis on the real-time power service network traffic, extracting rich traffic characteristic data such as protocol type, application type, data packet size, and transmission rate. Based on this traffic characteristic data, the system can accurately identify and classify the real-time power service network traffic. For instance, it can identify different types of power data to be transmitted, such as video streams, file transfers, and control commands, and match them with an adaptive encryption strategy with a preset correspondence. By executing this adaptive encryption strategy, the power data to be transmitted is encrypted during transmission.
[0088] To achieve efficient deep parsing, this Layer 4-7 deep parsing module employs various optimization techniques, such as zero-copy and parallel processing, significantly improving parsing efficiency. Furthermore, the module supports custom protocol parsing plugins, allowing for flexible selection of different tunnel protocols based on network environment and security requirements, and easily expanding support for new protocols.
[0089] For example, a high-performance 4-7 layer deep parsing module can be integrated to analyze real-time power service network traffic packets entering and exiting the tunnel, extracting traffic feature data. Then, the extracted traffic feature data is input into a traffic feature awareness algorithm, which can be a rule-based engine or a lightweight machine learning model, to identify service types and network conditions. Finally, the encryption strategy is dynamically adjusted based on the algorithm's output. For instance, a lightweight encryption algorithm can be used to reduce computational overhead when transmitting non-sensitive data, while a high-strength encryption algorithm can be switched to ensure data confidentiality when transmitting sensitive data.
[0090] As a supplementary solution, more multi-dimensional trigger conditions can be added to determine the adaptive encryption strategy. For example, time-based trigger conditions can be introduced to employ different encryption strategies during peak and off-peak periods. Geographic location-based trigger conditions can also be introduced to apply different security levels to communication requests from different geographical locations. Furthermore, it can be integrated with external intelligence platforms to automatically increase the system's encryption strength when new intelligence information is received.
[0091] 204. Based on the closed-loop control and strategy optimization layer, the adaptive encryption strategy is updated according to the current operating status data.
[0092] For example, the closed-loop control and policy optimization layer is based on a lightweight message queue system to obtain current running status data, including the running status of each container (such as CPU utilization and processing latency) and policy execution results. Based on the current running status data, the encryption policy is dynamically adjusted to achieve the best balance between security and performance.
[0093] For example, the closed-loop control and policy optimization layer acts as the policy publisher, publishing decision results (such as new encryption policies) to specific topics. Each execution container (such as encryption algorithm containers and protocol instruction filter containers) acts as a subscriber, monitoring topics relevant to itself and executing them immediately upon receiving a new policy. Simultaneously, each container periodically feeds back its operational status (such as CPU utilization and processing latency) and policy execution results to the closed-loop control layer via a message queue. For instance, when network security threats are high, the model tends to select high-strength encryption algorithms and stricter access control policies, forming a complete "perception-decision-execution-feedback" closed loop.
[0094] This embodiment provides a data transmission method for the power Internet of Things (IoT). Through an architecture design that combines multi-container parallel isolation with CPU core binding, the system's modularity and maintainability are improved. More importantly, the strong isolation between containers effectively prevents single-point failures and the lateral spread of attacks. Binding different containers to different CPU cores avoids resource contention between containers and improves the system's parallel processing capabilities. Through closed-loop control and policy optimization, the system can continuously learn and evolve to adapt to the complex and ever-changing power IoT environment, always maintaining optimal security and performance.
[0095] Figure 4 A flowchart illustrating another data transmission method for the power Internet of Things provided in this application embodiment is shown below. Figure 4 As shown, the method includes:
[0096] 301. Based on the lightweight trusted measurement layer, in response to the start signal, the trusted root interface in the trusted root adaptation layer is called.
[0097] For example, this step can be referred to as step 201, which will not be repeated here.
[0098] In one possible implementation, step 301 includes: monitoring the trusted status information of each terminal device in the target power Internet of Things based on the trusted root adaptation layer, and synchronizing the trusted status information to each terminal device in the target power Internet of Things.
[0099] Specifically, in the target power Internet of Things (IoT), there are typically a large number of terminal devices that need to work collaboratively to complete various tasks. To ensure the security of the entire system, it is necessary to ensure that all devices are in a trusted state. The Trusted Root Adaptation Layer, based on the Trusted Root State Synchronization Mechanism, synchronizes the trusted state information of each device periodically or when triggered by specific events to ensure that all devices have the latest trusted state information. For example, when the trusted state of a device changes (such as when abnormal software is detected), it immediately synchronizes this information to other devices so that they can take appropriate protective measures. To achieve efficient state synchronization, this mechanism employs various optimization techniques, such as incremental synchronization and hierarchical synchronization. For example, incremental synchronization can be used to synchronize only the changed state information to reduce network bandwidth consumption; hierarchical synchronization can be used to divide devices into different levels, first synchronizing between devices in the same level, and then synchronizing between different levels to improve synchronization efficiency.
[0100] The Trusted Root Adaptor Layer provides a hardware-level security foundation for the entire system. It interacts with upper layers through abstract interfaces, ensuring the trusted state of the underlying hardware. By pushing trusted computing functionality down to the hardware level, software-level attacks can be effectively prevented, improving system security.
[0101] 302. Based on the trusted root interface, perform trusted measurement processing on at least one container in the virtualized container isolation layer to obtain the measurement result.
[0102] For example, this step can be referred to as step 201, which will not be repeated here.
[0103] In one possible implementation, step 302 includes: performing trust measurement processing on the firmware and kernel in the trusted root adaptation layer; if it is determined that both the firmware and kernel are in a trusted state, performing trust measurement processing on the container image corresponding to at least one container; if it is determined that both the container image corresponding to at least one container are in a trusted state, in response to starting the container, performing trust measurement on the container's key file and communication process to obtain the measurement result.
[0104] Specifically, Figure 5 A lightweight trust measurement flowchart is provided for embodiments of this application, such as Figure 5As shown, during the system startup phase, by modifying the bootloader and operating system kernel, a metric hook is inserted before loading critical components (such as the kernel, container image, and key file). This hook calls the target interface to perform hash calculations on the firmware and kernel of the Trusted Platform Control Module (TPCM) in the Trusted Root Adaptation Layer. The calculation results are compared with a baseline value stored in the secure area. If they match, the firmware and kernel are considered trusted. The lightweight trusted metric layer continues to verify the integrity of container images related to the encrypted tunnel. For example, the system can calculate the hash value of the container image and compare it with a baseline hash value pre-stored in the Trusted Root. If they match, the container image has not been tampered with and is trusted; the system will continue to create and run the container. Conversely, if the hash values do not match, the container image may have been abnormally tampered with; the system will refuse to create the container and trigger the corresponding alarm mechanism. During container creation, the system also measures the key file and communication process to ensure they are trusted at startup. In addition, to further enhance security, the system can also verify the metadata of container images, such as the image creation time and author information, to ensure that the image's source is trustworthy.
[0105] Through this series of rigorous startup measurement processes, the system can effectively prevent malicious software from being injected during system startup, laying a solid foundation for subsequent safe operation and improving system security.
[0106] 303. If the measurement results indicate that each container is in a trusted state, establish a correspondence between each container and each target processor based on the virtualization container isolation layer to run the key components in each container.
[0107] For example, this step can be referred to as step 202, which will not be repeated here.
[0108] In one possible implementation, after step 303, the method further includes: performing trust measurement processing on the key files and communication processes of each running container based on a lightweight trust measurement layer.
[0109] Specifically, in combination Figure 5During container operation, the lightweight trusted measurement layer continuously monitors and verifies the container's key file and communication processes. Specifically, the system periodically or upon triggering specific events (such as file modification or process creation) calculates hash values for the container's key file and communication processes and compares them with a baseline hash value. If any inconsistency is found, the system immediately takes appropriate measures, such as isolating the container, terminating suspicious processes, and reporting alert information, to prevent further escalation of the security incident. This runtime continuous verification mechanism can effectively detect and prevent any unauthorized tampering with critical components, such as the injection of malicious software or modification of configuration files. To achieve the goal of lightweight operation, the system can employ optimization strategies such as incremental verification and event-driven verification to reduce unnecessary computational overhead. For example, the system can only verify changed files or trigger verification operations only when files are modified. In addition, the system can utilize hardware support provided by the chip's root of trust, such as a Trusted Execution Environment (TEE), to accelerate the verification process and further improve system performance and security.
[0110] For example, during system runtime, by deploying a Trusted Software Base (TSB) module in the kernel and setting active measurement points, trust measurements are performed on the key files and communication processes of each running container. This includes intercepting critical system calls (such as file read / write and process creation) within each container and performing dynamic integrity checks on related objects. To achieve lightweight performance, strategies such as sampling measurement and event-triggered measurement can be employed, and hardware acceleration instructions can be used to optimize the hash calculation process, thereby reducing the impact on system performance.
[0111] Furthermore, behavior-based triggering mechanisms can be introduced. For example, integrity measurements of a process can only be triggered when the system detects that the behavior pattern of a process deviates from its normal baseline (such as abnormal system call sequences, network connection patterns, etc.). This behavior-based triggering approach is more intelligent, reduces unnecessary measurement overhead, and focuses measurement resources on higher-risk objects.
[0112] The lightweight trusted measurement layer, combined with hardware support provided by the root of trust, performs step-by-step measurements at startup, from the hardware firmware to the operating system kernel, and then to the upper-layer container image and key files, ensuring the system starts from a trusted baseline. During runtime, the system sets proactive measurement points in the kernel to continuously, event-triggered, or periodically verify critical processes, file systems, and network behavior, enabling real-time detection and prevention of dynamic attacks such as memory injection and code tampering. Furthermore, this measurement method is designed with lightweight considerations for the resource-constrained nature of power IoT terminals. By optimizing measurement strategies and utilizing hardware acceleration, it minimizes the impact on system performance while maintaining high security levels.
[0113] 304. Based on the northbound communication tunnel layer, obtain real-time power service network traffic, and determine the traffic characteristic data of the predicted power service network traffic corresponding to the real-time power service network traffic based on the traffic characteristic data of the real-time power service network traffic.
[0114] For example, Figure 6 An adaptive encryption strategy decision-making flowchart is provided for embodiments of this application, such as... Figure 6 As shown, based on a 4-7 layer deep parsing module, traffic feature information is extracted from real-time power business network traffic. Through machine learning, statistical analysis, and other methods, this algorithm can identify the traffic feature data of real-time power business network traffic, including traffic change trends and abnormal behaviors, and predict future traffic feature data of the power business network.
[0115] For example, by analyzing historical traffic data, peak traffic levels can be predicted for a future period, allowing for proactive adjustments to encryption strategies to ensure system stability and performance. Furthermore, the algorithm can identify network attacks such as Distributed Denial of Service (DDoS) attacks and port scanning, triggering corresponding security measures. By combining traffic feature awareness algorithms with encryption strategies, the system can achieve intelligent security protection, dynamically adjusting encryption strategies based on different network environments and security threats to achieve the optimal balance between security and performance.
[0116] 305. Determine an adaptive encryption strategy based on the traffic characteristic data of the predicted power business network traffic.
[0117] For example, based on traffic characteristic data of predicted power service network traffic, including protocol type, application type, packet size, transmission rate, etc., the system can accurately identify and classify service traffic. For instance, it can identify different types of traffic such as video streams, file transfers, and control commands, and match them with different encryption strategies.
[0118] The adaptive encryption strategy based on traffic characteristics achieves an intelligent trade-off between security and communication efficiency. This dynamic adaptability enables the system to perfectly adapt to the diverse, dynamic, and complex characteristics of the power Internet of Things (IoT) services, providing differentiated security guarantees for different services while maximizing resource utilization.
[0119] In one possible implementation, the method further includes: determining the key granularity and whitelist in the adaptive encryption strategy based on the traffic characteristic data of real-time power service network traffic; wherein the whitelist is used to filter access protocol instructions.
[0120] Specifically, the northbound communication tunnel layer employs a dynamic key granularity adjustment mechanism based on an adaptive encryption strategy, which can dynamically adjust the key granularity according to the characteristics of service traffic. For example, it can determine whether to use an independent key for each data packet, each session, or each connection based on parameters such as packet size, transmission rate, and session duration.
[0121] Furthermore, in the power Internet of Things (IoT), different devices and services have different requirements for protocol commands. For example, smart meters may only need to support read operation commands, while smart switches need to support both read and write operation commands. To achieve fine-grained access control, a whitelist-based protocol command switching mechanism is implemented. This mechanism dynamically switches the whitelist of protocol commands based on information such as device type and user permissions. For example, a whitelist containing only read operation commands can be set for smart meters, while a whitelist containing both read and write operation commands can be set for smart switches. When a device initiates a communication request, the system loads the corresponding whitelist based on its identity information and filters subsequent protocol commands.
[0122] Adaptive encryption strategies can dynamically adjust key granularity based on business traffic characteristics and resource conditions. This ensures the highest security level for critical business operations while providing efficient communication services for general business operations, achieving a better balance between security and performance. Through whitelist protocol command switching, the system can implement fine-grained access control for different devices and users, preventing unauthorized operations and improving system security.
[0123] In one possible implementation, the method further includes: in response to a shortage of computing resources, performing encrypted transmission processing on the power data to be transmitted based on a low-overhead encryption mode.
[0124] Specifically, the triggering conditions for low-overhead encryption mode can be set according to the system's resource status. For example, when the system's CPU utilization, memory usage, and other indicators exceed preset thresholds, the system can automatically switch to low-overhead encryption mode.
[0125] The implementation employs lightweight encryption algorithms and optimized protocols to minimize the consumption of system resources. For example, stream cipher-based encryption algorithms or pre-shared keys can be used to avoid complex key negotiation processes.
[0126] By using low-overhead encryption, the system can minimize the consumption of terminal device resources while ensuring basic security requirements, thereby improving system availability and real-time performance.
[0127] 306. Based on a preset security performance trade-off decision model, the model processes the traffic characteristic data, network environment information, security threat information, business requirement information, and system resource information in the current operating status data to obtain the optimal adaptive encryption strategy parameters.
[0128] For example, combined Figure 6 The system invokes a preset security performance trade-off decision model. The input to this model is the current operating status data, including traffic characteristic data, network environment information (such as bandwidth, latency, packet loss rate, etc.), security threat information (such as attack type, attack strength, etc.), business requirement information (such as data sensitivity, real-time requirements, etc.), and system resource information (such as CPU utilization, memory usage, etc.). The output of this model is a set of optimal adaptive encryption strategy parameters, such as encryption algorithm, key length, key granularity, access control policy, etc.
[0129] For example, combining Figure 6 When network security threats are high, the model tends to choose high-strength encryption algorithms and stricter access control policies; while when network bandwidth is limited, the model tends to choose low-overhead encryption modes. The lightweight policy feedback channel is responsible for feeding back system operating status information, such as traffic characteristics, performance indicators, and security events, to the decision-making model in real time, providing data support for the model's decision-making.
[0130] To achieve efficient decision-making, the model can employ artificial intelligence algorithms such as machine learning and reinforcement learning. By learning from historical data, it can predict the effects of different strategies in different scenarios and select the optimal strategy.
[0131] Through a security performance trade-off decision model, the system can intelligently adjust its strategies to maximize system performance and availability while ensuring security.
[0132] 307. Update the adaptive encryption strategy according to the optimal adaptive encryption strategy parameters.
[0133] For example, based on the determined optimal adaptive encryption strategy parameters, including encryption algorithm, key length, key granularity, access control policy, etc., the adaptive encryption strategy is updated to obtain the updated adaptive encryption strategy. The updated adaptive encryption strategy is then distributed to each container, so that the key components in each container update the tunnel parameters (e.g., key parameters) and run to execute the updated adaptive encryption strategy for data transmission.
[0134] The security-performance trade-off decision model enables continuous monitoring of system operation and adaptive optimization of policies. This model dynamically adjusts encryption strategies based on current network conditions, security threats, and business needs to achieve the optimal balance between security and performance.
[0135] In one possible implementation, the method further includes: compressing the operating status data and feeding the compressed operating status data back to a preset security performance trade-off decision model; or, incrementally updating the operating status data and feeding the updated operating status data back to a preset security performance trade-off decision model; or, responding to the triggering of a preset event, feeding the operating status data back to a preset security performance trade-off decision model.
[0136] Specifically, Figure 7 A flowchart of closed-loop feedback and strategy optimization is provided for embodiments of this application, such as... Figure 7 As shown, continuous monitoring of system operation and adaptive optimization of policies are achieved through a security-performance trade-off decision model and a lightweight policy feedback channel. The security-performance trade-off decision model dynamically adjusts encryption policies based on current network environment, security threats, and business needs to achieve the optimal balance between security and performance. Based on the lightweight policy feedback channel, system operation information, such as traffic characteristics, performance indicators, and security events, is fed back to the security-performance trade-off decision model in real time. To achieve the lightweight goal, this channel employs various optimization techniques, such as data compression, incremental updates, and event-driven mechanisms.
[0137] Feedback data can be compressed to reduce network bandwidth consumption; incremental updates can be used to transmit only changed data, reducing data transmission volume; and an event-driven approach can be adopted to trigger feedback only when important events occur, reducing unnecessary communication overhead. Furthermore, this channel supports multiple communication protocols, allowing for flexible selection based on network environment and device capabilities.
[0138] Through the lightweight strategy feedback channel, the system can achieve real-time monitoring and rapid response of the operating status, providing timely and accurate data support for strategy optimization.
[0139] In this embodiment, based on the above embodiments, lightweight trust measurement technology is used to perform dual integrity checks on the container image, key file, and communication process related to the encrypted tunnel at startup and runtime, ensuring end-to-end trustworthiness of the encrypted link. Virtualization container technology is used to encapsulate core security functions such as key management, encryption algorithm instances, and protocol instruction filters into independent containers, and a CPU core binding strategy is used to achieve resource isolation and parallel processing, effectively preventing single points of failure. Furthermore, by real-time sensing of business traffic characteristics and based on a security-performance trade-off decision model, adaptive encryption strategies, including key granularity and protocol instruction whitelists, are dynamically adjusted. In resource-constrained scenarios, the system can automatically switch to a low-overhead encryption mode, thereby ensuring security strength while also meeting the real-time requirements of the business.
[0140] Figure 8 A schematic diagram of a data transmission device for the power Internet of Things provided in this application embodiment is shown below. Figure 8 As shown, the device includes:
[0141] The measurement module 401 is used to call the trusted root interface in the trusted root adaptation layer in response to the start signal based on the lightweight trusted measurement layer, and to perform trusted measurement processing on at least one container in the virtualization container isolation layer based on the trusted root interface to obtain the measurement result.
[0142] The running module 402 is used to establish a correspondence between each container and each target processor based on the virtualization container isolation layer if the measurement results indicate that each container is in a trusted state, so as to run the key components in each container.
[0143] The encryption module 403 is used to acquire real-time power service network traffic based on the northbound communication tunnel layer, and determine an adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic; wherein, the adaptive encryption strategy is used to perform encrypted transmission processing of the power data to be transmitted based on each key component.
[0144] The update module 404 is used to update the adaptive encryption strategy based on the current operating status data, based on the closed-loop control and strategy optimization layer.
[0145] In one possible implementation, the encryption module 403 is specifically used to: determine the traffic characteristic data of the predicted power service network traffic corresponding to the real-time power service network traffic based on the traffic characteristic data of the real-time power service network traffic; and determine an adaptive encryption strategy based on the traffic characteristic data of the predicted power service network traffic.
[0146] In one possible implementation, the encryption module 403 is further specifically used to: determine the key granularity and the whitelist in the adaptive encryption strategy based on the traffic characteristic data of real-time power service network traffic; wherein the whitelist is used to filter access protocol instructions.
[0147] In one possible implementation, the encryption module 403 is also specifically used to: in response to a shortage of computing resources, perform encrypted transmission processing on the power data to be transmitted based on a low-overhead encryption mode.
[0148] In one possible implementation, the update module 404 is specifically used to: perform model processing on traffic characteristic data, network environment information, security threat information, business requirement information and system resource information in the current operating status data based on a preset security performance trade-off decision model to obtain the optimal adaptive encryption strategy parameters; and update the adaptive encryption strategy according to the optimal adaptive encryption strategy parameters.
[0149] In one possible implementation, the update module 404 is further specifically used to: compress the running status data and feed the compressed running status data back to the preset security performance trade-off decision model; or, perform incremental update processing on the running status data and feed the updated running status data back to the preset security performance trade-off decision model; or, in response to triggering a preset event, feed the running status data back to the preset security performance trade-off decision model.
[0150] In one possible implementation, the measurement module 401 is specifically used for: performing trust measurement processing on the firmware and kernel in the trusted root adaptation layer; if it is determined that the firmware and kernel are both in a trusted state, performing trust measurement processing on the container image corresponding to at least one container; if it is determined that the container image corresponding to at least one container is in a trusted state, in response to starting the container, performing trust measurement on the container's key file and communication process to obtain the measurement result.
[0151] In one possible implementation, after the running module 402 is used to run the key components in each container, the apparatus is further used to: perform trust measurement processing on the key files and communication processes of each running container based on a lightweight trust measurement layer.
[0152] In one possible implementation, the device is also used to: monitor the trusted status information of each terminal device in the target power Internet of Things based on the trusted root adaptation layer, and synchronize the trusted status information to each terminal device in the target power Internet of Things.
[0153] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.
[0154] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, such as... Figure 9 As shown, the electronic device includes: a memory 501 and a processor 502; the memory 501 is a memory used to store instructions executable by the processor 502.
[0155] The processor 502 is configured to perform the method provided in the above embodiments.
[0156] The electronic device also includes a receiver 503 and a transmitter 504. The receiver 503 is used to receive instructions and data sent by other devices, and the transmitter 504 is used to send instructions and data to external devices.
[0157] The specific implementation process of the processor can be found in the above method embodiments, and its implementation principle and technical effect are similar, so it will not be repeated here.
[0158] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The steps of the method disclosed in this invention can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0159] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed on a computer, cause the computer to perform the technical solutions described above.
[0160] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, programmable read-only memory, read-only memory, magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0161] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. The readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in a device.
[0162] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solutions in the above embodiments.
[0163] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0164] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as magnetic disks or optical disks.
[0165] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A data transmission method for the power Internet of Things, characterized in that, include: Based on the lightweight trusted measurement layer, in response to the start signal, the trusted root interface in the trusted root adaptation layer is called, and based on the trusted root interface, trusted measurement processing is performed on at least one container in the virtualization container isolation layer to obtain the measurement result. If the measurement results indicate that each container is in a trusted state, a correspondence between each container and each target processor is established based on the virtualization container isolation layer to run the key components in each container; Based on the northbound communication tunnel layer, real-time power service network traffic is acquired, and an adaptive encryption strategy is determined according to the traffic characteristic data of the real-time power service network traffic; wherein, the adaptive encryption strategy is used to perform encrypted transmission processing of the power data to be transmitted based on each of the key components. Based on the closed-loop control and strategy optimization layer, the adaptive encryption strategy is updated according to the current operating status data.
2. The method according to claim 1, characterized in that, The step of determining an adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic includes: Based on the traffic characteristic data of the real-time power service network traffic, determine the traffic characteristic data of the predicted power service network traffic corresponding to the real-time power service network traffic. The adaptive encryption strategy is determined based on the traffic characteristic data of the predicted power service network traffic.
3. The method according to claim 2, characterized in that, The method further includes: Based on the traffic characteristic data of the real-time power service network traffic, the key granularity and the whitelist in the adaptive encryption strategy are determined; wherein, the whitelist is used to filter access protocol instructions.
4. The method according to claim 2, characterized in that, The method further includes: In response to the scarcity of computing resources, the power data to be transmitted is encrypted using a low-overhead encryption mode.
5. The method according to claim 1, characterized in that, The closed-loop control and strategy optimization layer updates the adaptive encryption strategy based on the current operating status data, including: Based on a preset security performance trade-off decision model, the traffic characteristic data, network environment information, security threat information, business requirement information, and system resource information in the current operating status data are processed by the model to obtain the optimal adaptive encryption strategy parameters. The adaptive encryption strategy is updated based on the optimal adaptive encryption strategy parameters.
6. The method according to claim 5, characterized in that, The method further includes: The operation status data is compressed, and the compressed operation status data is fed back to the preset safety performance trade-off decision model. Alternatively, the operating status data can be incrementally updated, and the updated operating status data can be fed back to the preset security performance trade-off decision model. Alternatively, in response to a preset event, the operational status data can be fed back to the preset security performance trade-off decision model.
7. The method according to claim 1, characterized in that, The process of performing a trust measurement on at least one container in the virtualization container isolation layer based on the trusted root interface to obtain the measurement result includes: Trust measurement processing is performed on the firmware and kernel in the trusted root adaptation layer; If it is determined that both the firmware and the kernel are in a trusted state, a trust measurement process is performed on the container image corresponding to the at least one container. If it is determined that the container images corresponding to the at least one container are all in a trusted state, in response to starting the container, a trust measurement is performed on the key file and communication process of the container to obtain the measurement result.
8. The method according to claim 1, characterized in that, After the critical components in each of the containers have been run, the method further includes: Based on the lightweight trust measurement layer, trust measurement processing is performed on the key files and communication processes of each running container.
9. The method according to any one of claims 1-8, characterized in that, The method further includes: Based on the trusted root adaptation layer, the trusted status information of each terminal device in the target power Internet of Things is monitored, and the trusted status information is synchronized to each terminal device in the target power Internet of Things.
10. A data transmission device for use in the power Internet of Things, characterized in that, include: The measurement module is used to call the trusted root interface in the trusted root adaptation layer in response to the start signal, based on the lightweight trusted measurement layer, and to perform trusted measurement processing on at least one container in the virtualization container isolation layer based on the trusted root interface to obtain the measurement result. The running module is used to, if it is determined that the measurement result indicates that each of the containers is in a trusted state, establish a correspondence between each container and each target processor based on the virtualization container isolation layer, so as to run the key components in each container; An encryption module is used to acquire real-time power service network traffic based on the northbound communication tunnel layer, and determine an adaptive encryption strategy based on the traffic characteristic data of the real-time power service network traffic; wherein, the adaptive encryption strategy is used to perform encrypted transmission processing on the power data to be transmitted based on each of the key components. The update module is used to update the adaptive encryption strategy based on the current operating status data, using the closed-loop control and strategy optimization layer.
11. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-9.
13. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-9.