Electric power data cross-region circulation control method, control platform, control system and equipment
By injecting flow identifiers and security identifiers into the power data flow process and combining them with knowledge graphs, the problem of low efficiency in bypassing detection and tracing in traditional cross-domain power data flow control is solved, achieving efficient data flow recording and security protection.
Patent Information
- Application Number
- CN202511666188.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-14
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-11-14
AI Technical Summary
In the traditional process of cross-domain flow control of power data, attackers can bypass rule detection through methods such as format distortion, resulting in low accuracy and efficiency of security control, as well as low efficiency of data traceability and inaccurate positioning.
By injecting flow identifiers into the data to be transferred at each transfer node within the power management information region and the internet region, and combining the knowledge graph of business identifiers and security identifiers, the transfer records are dynamically updated to achieve full-link transfer records and anomaly detection.
It enables the recording of the entire power data flow and the rapid location of leaked nodes, improving data tracking efficiency and location accuracy, and enhancing system security protection capabilities.
Smart Images

Figure CN121125365A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power information security, in particular to a power data cross-region flow control method, a control platform, a control system and equipment. BACKGROUND
[0002] With the large-scale development of new formats such as unmanned aerial vehicles, vehicle-network interaction, and energy big data services, and the continuous deepening of the power data application system with extensive business interactions, the number of power data flow and processing nodes increases, and the flow path is extended, which significantly increases the risk of sensitive data leakage and the difficulty of data leakage discovery, flow tracking, and responsibility definition.
[0003] The traditional data cross-domain flow control process based on regular expressions, keyword matching, or rule-based sensitive content recognition technology can easily bypass rule detection by means of synonym replacement, character obfuscation (such as Unicode encoding conversion), format transformation (such as segmented display, image embedding), etc., resulting in low accuracy and efficiency of security prevention and control. At the same time, data anomaly tracing is mainly based on single-point tracing, and the flow path mainly relies on expert experience, which has the problems of low efficiency and inaccurate positioning. SUMMARY
[0004] In order to overcome the above technical problems, the present application provides a power data cross-region flow control method and device, and a cross-region flow system and equipment.
[0005] In one aspect, the present application provides a power data cross-region flow control method, comprising: Based on the received business data access request from the external user, determine the target power data associated with the business data access request; wherein the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to represent the business attribute and security attribute of the business data; Based on the business calling relationship between different power business systems, control the data flow of the target power data in the power management information area and the Internet area; wherein in the data flow process, a flow identifier is injected into the data to be flowed at each flow node in the power management information area and the Internet area, each flow identifier contains the association relationship between itself and the business identifier, and the flow identifier is used to represent the flow relationship of the power business data associated with the business identifier in the power communication network; When the target power data flows to the flow exit node of the Internet region, a security identifier sent from the flow exit node is received; based on the security identifier, an association matching is performed in the security identifier knowledge graph, and the flow of the target power data at the flow exit node is controlled based on the association matching result; wherein, the security identifier is the flow identifier corresponding to the last flow node; the security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through interrelated business identifiers and flow identifiers, and the initial security knowledge graph is constructed based on the historical access behavior of the power data.
[0006] Optionally, the flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier.
[0007] Optionally, the service identifier includes a service identifier number, and the process of generating the service identifier includes: The system receives target service features sent from the transfer entry node of the power management information region, generates a corresponding service identifier based on the target service features, and returns the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
[0008] Optionally, the injection process of the service identifier includes: If the target power data has an unstructured data structure, the business identifier is embedded into the attributes of the file containing the target power data. If the target power data has a semi-structured or structured data structure, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
[0009] Optionally, injecting a flow identifier into the data to be transferred includes: The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
[0010] Optionally, the process of generating the flow identifier includes: For the first transfer node, network traffic is monitored at the transfer node, and the service identifier in the network traffic is extracted through information extraction hardware; based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node; wherein, the flow identifier of the first transfer node includes the association relationship between the flow identifier and the service identifier. For all other flow nodes except the first flow node, network traffic is monitored at each flow node, and the flow identifier in the monitored network traffic is extracted by information extraction hardware as the old flow identifier. A new flow identifier is generated based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node. The new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
[0011] Optionally, after the new flow identifier is generated, the following may also be included: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers.
[0012] Optionally, the process of constructing the initial security knowledge graph includes: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
[0013] Optionally, the security identifier is the flow identifier number of the last transit node obtained by extracting the flow identifier of the outgoing network traffic from the transit exit node; the association matching result includes the complete transit path, associated service characteristics, associated access behavior, and access trend; and the association matching is performed in the security identifier knowledge graph based on the security identifier, including: Based on the flow identifier of the last flow node and the association between the flow identifiers of each flow node during the data flow process, the corresponding business identifier and the complete flow path of the business data are associated in the security identifier knowledge graph. Based on the business identifier, the corresponding related business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding related access behaviors and access trends are associated in the security identifier knowledge graph.
[0014] Optionally, controlling the flow of the target power data at the flow exit node based on the association matching result includes: Based on the anomaly analysis model and the complete flow path, anomaly analysis is performed on the related business characteristics, related access behaviors and access trends to identify abnormal behaviors. A corresponding anomaly handling strategy is generated for the abnormal behavior, and the flow of the target power data at the flow exit node is controlled based on the anomaly handling strategy; The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
[0015] Optionally, the information extraction process of the information extraction hardware includes: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
[0016] On the other hand, the present invention also provides a power data cross-regional transfer control platform, comprising: The data association module is used to determine the target power data associated with the received business data access request from the external user; wherein the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; The data transfer control module is used to control the data transfer of the target power data within the power management information region and the Internet region based on the business call relationship between different power business systems. When the target power data is transferred to the transfer exit node of the Internet region, the module receives a security identifier sent from the transfer exit node, performs association matching in the security identifier knowledge graph based on the security identifier, and controls the transfer of the target power data at the transfer exit node based on the association matching result. During the data transfer process, a flow identifier is injected into the data to be transferred at each transfer node within the power management information region and the internet region. Each flow identifier contains the association relationship between itself and the service identifier. The flow identifier is used to characterize the transfer relationship of power business data associated with the service identifier in the power communication network. The security identifier is the flow identifier corresponding to the last transfer node. The security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through the interrelated service identifiers and flow identifiers. The initial security knowledge graph is constructed based on the historical access behavior of power data.
[0017] On the other hand, the present invention also provides a power data cross-regional transfer control system, including the power data cross-regional transfer control platform as described in any of the above claims.
[0018] On the other hand, the present invention also provides an electronic device, comprising: at least one processor and a memory; the memory and the processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the method described in any of the foregoing is implemented.
[0019] On the other hand, the present invention also provides a readable storage medium having an executable program stored thereon, wherein when the executable program is executed, it implements the method described in any one of the above.
[0020] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention provides a method for controlling the cross-regional flow of power data. By injecting a business identifier into the power business data, which represents the business and security attributes of the data, the power data acquires its own identity label, eliminating the need to rely on easily cracked regular expressions and keyword rules. This fundamentally avoids the risk of attackers bypassing detection through format distortion and other means. During the data flow process, a flow identifier is injected into the data to be flowed at each flow node within the power management information region and the Internet region. This dynamic injection of flow identifiers forms a one-to-one correspondence between nodes and identifiers in the entire flow record. In the event of a data leak, the flow identifiers can clearly reconstruct the data flow trajectory, quickly locate the leak node, and significantly improve tracking efficiency and location accuracy.
[0021] This invention constructs an initial security knowledge graph based on historical access behavior of power data, and dynamically updates the initial security knowledge graph based on current access behavior through interrelated business identifiers and flow identifiers. This realizes the dynamic association construction process of the knowledge graph. By having each flow identifier contain its own association with the business identifier, the mutual association between the business identifier and the flow identifier is realized, forming a multi-dimensional association of business data-flow path-access behavior, improving the accuracy and efficiency of anomaly detection based on this dynamic knowledge graph. By extracting security identifiers at the flow exit node and associating them with the dynamic graph based on these security identifiers, it is possible to quickly determine whether the current access behavior is abnormal, thereby improving the system's security protection capabilities. Attached Figure Description
[0022] Figure 1 This is one of the flowcharts illustrating an example of a cross-regional power data transfer control method according to the present invention; Figure 2 This is a schematic diagram illustrating a flow identifier generation process according to an example of the present invention; Figure 3 A schematic diagram illustrating the location of flow identifier injection into a network data packet, as exemplified by the present invention; Figure 4 This is a flowchart illustrating the initial security knowledge graph construction process, as an example of the present invention. Figure 5 This is a schematic diagram of the association structure of a security identification knowledge graph, as an example of the present invention. Figure 6 This is a schematic diagram illustrating an abnormal behavior analysis process as an example of the present invention; Figure 7 This is a schematic diagram illustrating the extraction process of an example of information extraction hardware according to the present invention; Figure 8 This is a flowchart illustrating an example of an identifier-based cross-regional transfer control method according to the present invention. Figure 9A second schematic flowchart of an example of a cross-regional power data transfer control method of the present invention; Figure 10 This is an example of the architecture diagram of a power data inter-regional transfer control system according to the present invention; Figure 11 This is a block diagram of an electronic device according to the present invention. Detailed Implementation
[0023] The following conceptual explanations will facilitate a better understanding of the technical content of this invention: The network security structure of the power secondary system includes the production control area and the management information area. The production control area is the core area of the power monitoring system's security partitioning, with the highest security level. It is mainly used for real-time monitoring, dispatching, and control of the safe and stable operation of the power grid. It can directly realize the monitoring, control, regulation, and protection of primary power equipment (generators, transformers, transmission lines, circuit breakers, etc.). For example, the production control area may include energy management systems, wide-area phasor measurement systems, distribution automation system master station control functions, etc.
[0024] The Management Information Zone refers to the collection of management business systems of a power company outside the Production Control Zone. Business systems within the Management Information Zone may include dispatch and production management systems, administrative telephone network management systems, power company data networks, lightning monitoring systems, statistical reporting systems, management information systems, office automation systems, customer service systems, and so on.
[0025] The Internet Zone is located between the Management Information Zone and the external network, serving as an intermediate transition area between the power grid's internal network and external networks (such as the Internet and mobile office systems), and undertakes data exchange functions. The Internet Zone uses dedicated equipment to achieve unidirectional data transmission between the internal and external networks, ensuring that external network data cannot directly access core systems such as the Production Control Zone.
[0026] Cross-domain data flow: refers to the flow of data between different regions, such as power business data flowing from the management information region to the internet region or from the internet region to the internet, and management information region dedicated lines flowing to external units such as enterprises and banks.
[0027] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0028] Example 1 The present invention provides a method for controlling the cross-regional transfer of power data, the schematic diagram of which is shown below. Figure 1 As shown, the method includes: Step S110: Based on the received business data access request from an external user, determine the target power data associated with the business data access request; wherein, the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; Step S120: Based on the business call relationship between different power business systems, control the data flow of the target power data within the power management information region and the Internet region; wherein, during the data flow process, a flow identifier is injected into the data to be flowed at each flow node within the power management information region and the Internet region, and each flow identifier contains the association relationship between itself and the business identifier, and the flow identifier is used to characterize the flow relationship of the power business data associated with the business identifier in the power communication network; Step S130: When the target power data flows to the flow exit node of the Internet region, a security identifier sent from the flow exit node is received; based on the security identifier, an association match is performed in the security identifier knowledge graph, and the flow of the target power data at the flow exit node is controlled based on the association match result; wherein, the security identifier is the flow identifier corresponding to the last flow node; the security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through mutually related business identifiers and flow identifiers, and the initial security knowledge graph is constructed based on the historical access behavior of the power data.
[0029] In this example implementation, external users refer to external network users, such as external Internet users. Transfer nodes can be set up between different business systems within the power management information zone (management information zone), and also between different business systems within the Internet zone. These transfer nodes enable high-speed data transmission between different business systems while simultaneously achieving data isolation and preventing data mixing between different business systems. The transfer exit node can be a network traffic forwarding device from the Internet zone to the external network. The business identifier can be a power business data security identifier constructed based on standard classification and grading guidelines, according to the characteristics of different professional business data such as power finance, equipment, marketing, and dispatch. The business identifier is mainly used to identify information such as data content, sensitivity, and owner. It can include a business identifier header and a business identifier body. The business identifier header is the metadata part of the business identifier, providing basic information for the management, identification, and verification of the identifier itself, and is the core of ensuring the validity and traceability of the identifier. Its content is fixed and mandatory. The business identifier body is the core payload of the business identifier, used to record the specific security attributes of the identified power data. Due to the diverse business scenarios in the power industry (development, finance, safety supervision, equipment, marketing, infrastructure, materials, human resources, dispatching, trading, integrated data, etc.), different business scenarios have different focuses on data security. Therefore, the business identifier can adopt an open design, containing security attribute items, which are defined independently by specific application projects according to their needs. The flow identifier is a network flow security identifier built based on network traffic size, direction, protocol, and other characteristics. The flow identifier is a standardized information carrier used to accurately record and manage the flow relationship of power data in the network. By describing the data flow path, participating entities, and technical characteristics, it enables visual tracking, permission verification, and security auditing of data transmission across systems and networks. The flow identifier can include two parts: a flow identifier header and a flow identifier body. The flow identifier header, as the metadata carrier of the flow identifier, is used to ensure the uniqueness, validity, and verifiability of the identifier itself, providing a basic anchor point for tracing flow relationships. Its fields are mandatory and fixed. The flow identifier body is the core payload of the flow identifier, specifically recording the key relationship characteristics of data in network flow, focusing on core questions such as "who is transmitting, where is it transmitted to, and how is it transmitted?" Each flow identifier contains the association between itself and the business identifier. Flow identifiers are designed specifically for cross-domain flow scenarios of power data to solve problems such as "untraceable source, uncontrollable path, and unclear permissions" in the data flow process.
[0030] In this example, the execution entity is the control platform. Business identifiers can be generated on the control platform or a business server, while flow identifiers can be generated at corresponding transfer nodes. Business identifiers can be injected through the corresponding business server, and flow identifiers can be injected at the corresponding transfer node. Security identifier extraction can be performed through the transfer exit node. For external access requests, data needs to be obtained from different business systems in the management information region and then returned to the external network user via the internet region. During data flow, business identifiers are generated based on different business data types, and these identifiers are embedded into the data content on the corresponding business server. When data is transmitted to the first transfer node in the network transmission link, the first transfer node quickly extracts the business identifier and generates a corresponding flow identifier based on the business identifier and network traffic characteristics. This flow identifier contains its association with the business identifier, and the corresponding flow identifier is injected into the network traffic. For the second and subsequent flow nodes, the flow identifier of the previous flow node is extracted. A new flow identifier is generated based on the extracted flow identifier and current network traffic attributes and injected into the current flow node. The association between the extracted flow identifier and the new flow identifier is sent to the control platform to update the security identifier knowledge graph, constructing a flow relationship graph between business identifiers and flow identifiers. During data flow, business identifiers and flow identifiers are dynamically generated and injected, achieving dynamic association between them and generating a dynamic association graph. This graph is used to associate business identifiers with each flow identifier, quickly grasping details such as the sensitive data content and level of the flow. Based on access characteristics, spatiotemporal characteristics, and association characteristics, abnormal data access processes are identified in a timely manner. The flow exit node is controlled to perform alarms, circuit breakers, and blocking operations to handle security risks, improving the accuracy of anomaly identification and data leakage location, and enhancing the system's security protection capabilities.
[0031] For example, the business identifier header may include a business identifier number, business identifier generation time, validity period, and digital signature. Business attributes include business category and detailed subcategory to which the data belongs. Security attributes may include data security level, data sensitivity, identifier owner, data access control policy, data source, data encryption status, and circulation scope restrictions. For instance, the identifier header and body of the business identifier are shown in Tables 1 and 2 below: Table 1
[0032] Table 2
[0033] For example, the flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier. For example, the header and body of the service identifier are shown in Tables 3 and 4 below: Table 3
[0034] Table 4
[0035] Flow identifiers are primarily used to identify the flow relationships of data within a network, facilitating rapid risk assessment. This invention designs power data security identifiers, including both business identifiers and flow identifiers. These identifiers serve as standardized information carriers for regulating power data security management and providing a structured description of data security attributes. The aim is to support secure control, flow tracking, and access management throughout the entire lifecycle of power data.
[0036] In some implementations, the service identifier includes a service identifier number, and the process of generating the service identifier includes: The system receives target service features sent from the transfer entry node of the power management information region, generates a corresponding service identifier based on the target service features, and returns the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
[0037] In this example implementation, after determining the business data associated with the business data access request, the business server scans the business data and extracts the corresponding business features, then sends the business features to the control platform. Based on the business features, the control platform generates a corresponding business identifier according to the business identifier definitions in Tables 1 and 2, and returns the business identifier number to the corresponding business server. The business server then injects the business identifier number into the corresponding business data. Business features may include business attributes and security attributes as shown in Tables 1 and 2.
[0038] For example, the injection process of the business identifier includes: If the target power data has an unstructured data structure, the business identifier is embedded into the attributes of the file containing the target power data. If the target power data has a semi-structured or structured data structure, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
[0039] In this example implementation, for unstructured data transmitted via files or images, a business identifier is embedded in the file's attributes and content. To ensure the identifier's lightweight nature and minimize its impact on business operations, the embedded identifier content consists only of the data identifier ID information. Simultaneously, the corresponding identifier header and body content are sent back to the identifier management center. For semi-structured or structured data in formats such as XML or JSOM transmitted via the interface, memory snapshot analysis is used to extract business characteristics. Then, a lightweight dynamic hook injection method is used to inject the business identifier into the extended fields of the network packet. This example uses a non-intrusive hook mechanism, specifically Dynamic Binary Instrumentation (DBI) technology, to capture data generation and transmission events in real time without modifying the business system's source code.
[0040] In some example implementations, the process of generating the flow identifier includes: For the first transfer node, network traffic is monitored at the transfer node, and the service identifier in the network traffic is extracted through information extraction hardware; based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node; wherein, the flow identifier of the first transfer node includes the association relationship between the flow identifier and the service identifier. For all other flow nodes except the first flow node, network traffic is monitored at each flow node, and the flow identifier in the monitored network traffic is extracted by information extraction hardware as the old flow identifier. A new flow identifier is generated based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node. The new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
[0041] In this example implementation, a corresponding flow identifier is generated at each flow node. Each flow node is equipped with information extraction hardware, which can be integrated circuit hardware, such as an FPGA chip, capable of multi-path parallel identifier generation. The flow identifier generation process is as follows: Figure 2As shown, when service traffic flows to the core node (transfer node), it listens to network traffic packets and uses dedicated information extraction hardware to quickly extract the identifier ID (identifier number) from the network traffic. For the first transfer node on the service access transfer link, the extracted identifier ID is the service identifier number; for other transfer nodes, the extracted identifier ID is the flow identifier number. Next, a new flow identifier is generated based on the extracted identifier ID and network traffic attributes (attributes in the identifier definition), and the association between the old identifier ID and the new identifier ID is established. The new flow identifier (including the association between the old and new identifier IDs) is sent to the control center. The transfer node re-injects the flow identifier ID into the network extension field for traffic forwarding. If the data packet does not have an identifier or its identifier is non-compliant, identifier ID extraction may fail. In this case, the transfer node can generate an identifier based on the data content and identifier definition. After the identifier is generated, the transfer node attaches the identifier to the end of the data content without changing the original data content and re-encapsulates it into a targeted data packet sent to the traffic receiving device. After receiving the data packet, the business visitor parses it. Because the identifier does not corrupt the original data content, the original data content can be successfully retrieved. In this example, a flow identifier can be quickly generated based on different business characteristics and identifier definitions.
[0042] For example, after generating the flow identifier, each flow node injects the flow identifier into the data to be flowed, including: The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
[0043] In this example implementation, the flow identifier is injected into the optional field of the network traffic packet in a seamless manner, without affecting the content of the service message. For example... Figure 3 The diagram illustrates the injection of a flow identifier into a network IP packet. As can be seen, a network IP packet consists of several inherent parts. The flow identifier number (flow identifier ID) in the flow identifier header is injected into a reserved optional field (variable length) in the packet. After injection, it is transmitted along with the network traffic. The flow identifier is embedded in the network layer's expandable option field without affecting the use of the original data, thus achieving seamless injection of network packets.
[0044] In the injection of business identifiers and mobile identifiers, the above example adopts a two-layer architecture of lightweight injection using dynamic hooks and seamless injection using network packets. Simultaneously, based on dynamic graph data association technology, it achieves seamless linkage between business identifiers and mobile identifiers, minimizing the intrusiveness of identifier injection on core business systems. Based on the hash mapping and timestamp alignment of the identifier IDs in the dynamic graph, it achieves millisecond-level association between business identifiers and mobile identifiers, forming a dual-identifier linkage engine and solving the "identifier disconnection" problem in traditional injection methods. The identifier IDs in this example can be stored using a DHT (Distributed Hash Table) network. A DHT is a type of distributed computing system used to distribute a set of keys across all nodes in a distributed system; these nodes are similar to storage locations in a hash table. Distributed hash tables are typically used in systems with a large number of nodes, where nodes frequently join or leave.
[0045] In some example implementations, an initial security knowledge graph needs to be constructed before an access request begins. The process of constructing the initial security knowledge graph includes: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
[0046] In this example implementation, business identifiers and flow identifiers can be generated and associated based on relevant record data of historical access behavior. Content extraction based on business identifier IDs, entities, relationships, and attributes is performed on the business characteristics, data characteristics, and access characteristics associated with historical access behavior. Flow identifiers generated at each flow node in the historical access behavior are extracted, and business identifiers and flow identifiers are associated through the data flow relationships in the historical access behavior. Finally, an initial security knowledge graph is formed by integrating existing third-party power security knowledge bases. The initial security knowledge graph construction process is as follows: Figure 4 As shown, firstly, based on business identifiers and flow identifiers, entity, relationship, and attribute information are extracted through identifier ID information to obtain the association between identifiers; secondly, the association knowledge of the extracted identifiers is combined with a third-party knowledge base to perform knowledge fusion, such as entity resolution, coreference resolution, and knowledge merging, to form an initial security knowledge graph.
[0047] In some example implementations, after the new flow identifier is generated, the following is also included: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers.
[0048] In this example implementation, after each flow node (including the first flow node and other flow nodes) generates a new flow identifier, it injects the identifier ID (identifier number) into the network traffic and sends the newly generated flow identifier to the control platform. The control platform updates the real-time security knowledge graph based on the received flow identifier. As real-time service access proceeds, it dynamically updates the initial security knowledge graph using the current service access behavior to form a security identifier knowledge graph; the security identifier knowledge graph is also dynamically updated with access behavior. Figure 4 As shown, a graph database can also be established based on the knowledge graph construction system, containing a dynamic knowledge graph with multiple sub-graphs such as flow paths, interaction behaviors, and access trends, providing a technical foundation for identifier-driven data flow control. For example, a security identifier knowledge graph is as follows: Figure 5 As shown, each Flow Identifier ID (Identifier Header) can be associated with corresponding identifier bodies such as access source, access purpose, and cross-domain flow direction. The cross-domain flow direction can be associated with the corresponding data volume. Flow Identifier IDs can be associated with each other, and Flow Identifier IDs can also be associated with Business Identifier IDs. The Business Identifier ID (Identifier Header) is associated with identifier bodies such as data source, marketing business (business type), and data access scope. Marketing business can be associated with electricity address and data sensitivity level, and data access scope is associated with access policy, ultimately establishing a system like... Figure 5 The knowledge graph.
[0049] This invention uses business identifiers and flow identifiers as the basic carriers and a dynamic knowledge graph as the association engine to construct a three-in-one identifier association system integrating data, identifiers, and behaviors. Compared with traditional static rule matching technology, it breaks through the limitations of linear rules and utilizes the multi-dimensional association capabilities of knowledge graphs to quickly identify data flow processes across businesses and networks.
[0050] In some implementations, when the business data corresponding to the access request flows to the exit node of the Internet region, the exit node extracts the flow identifier of the last transit node from the outgoing network traffic to obtain the flow identifier number, i.e., the security identifier, and sends the security identifier to the control platform so that the control platform can perform reverse identification ID association based on the security identifier. Then, S130 performs association matching in the security identifier knowledge graph based on the security identifier, including: Based on the flow identifier of the last flow node and the association between the flow identifiers of each flow node during the data flow process, the corresponding business identifier and the complete flow path of the business data are associated in the security identifier knowledge graph. Based on the business identifier, the corresponding related business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding related access behaviors and access trends are associated in the security identifier knowledge graph.
[0051] In this example implementation, the flow path is associated in the security identifier knowledge graph using the flow identifier number of the last flow node. Because the security identifier knowledge graph is updated in real-time through the generation and injection of flow identifiers and the association relationship between the flow identifier IDs of adjacent flow nodes during the data flow corresponding to the current access behavior, the security identifier knowledge graph has flow association relationships. The complete flow path can then be traced back using the extracted last-hop identifier ID. This complete flow path is then used to associate business characteristics (business type, data volume, etc.), access behavior, accessed data range, and access trends, such as... Figure 5 In this process, the complete workflow path is Flow ID - Flow ID - Business ID. This path can also be used to associate business type, data volume, data range, access strategy, and more. The final matching results include the complete workflow path, associated business characteristics, associated access behaviors, and access trends.
[0052] In one example implementation, controlling the flow of the target power data at the flow exit node based on the association matching result includes: Based on the anomaly analysis model and the complete flow path, anomaly analysis is performed on the related business characteristics, related access behaviors and access trends to identify abnormal behaviors. A corresponding anomaly handling strategy is generated for the abnormal behavior, and the flow of the target power data at the flow exit node is controlled based on the anomaly handling strategy; The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
[0053] In this example implementation, an anomaly analysis model can be constructed based on historical access behavior of power business data. This anomaly analysis model is essentially the relationship between features and abnormal behaviors. For example... Figure 6As shown, considering the cross-regional correlation characteristics of security identifier knowledge graphs and abnormal behaviors, this example constructs a dynamic mapping relationship between cross-regional multi-dimensional features and abnormal behaviors. Cross-regional multi-dimensional features include business characteristics, access characteristics, spatiotemporal characteristics, and traffic flow trends. Abnormal behaviors can include abnormal access to sensitive data (such as excessive sensitive data access), excessive marketing data access, illegal access to core data, abnormal interface access, etc. The current access behavior can be used to dynamically update the anomaly analysis model. By constructing the correlation between cross-regional data through multi-dimensional features, and combining data access behavior, a fine-grained anomaly analysis model for cross-domain data flow can be constructed. For example, for the abnormal behavior of sensitive data leakage, such as monitoring a marketing payment interface, if it is accessed by a single terminal, and within a unit period (e.g., 15 minutes or 1 hour), the number of accesses exceeds a threshold (e.g., 50 times), and the total data volume exceeds a data volume abnormal threshold (e.g., 100M), and the accessed data content contains sensitive data, then the abnormal behavior rule is met. For abnormal interface access that does not conform to the baseline, such as when a user accesses a power distribution service data interface, the system learns from historical data such as the number of times the user accesses the interface and the content of the interface interaction data. This allows the system to learn the trend of the interface data. If the deviation (the proportion of deviation from the preset baseline) is large the next time the interface data is accessed, an abnormal behavior alarm will be generated. Anomaly handling strategies can include alarms, circuit breakers, and blocking.
[0054] For example, such as Figure 6As shown, the process first extracts the flow identifier ID from the received flow exit node and compares it with the security identifier knowledge graph. By linking the identifier relationships in the graph, the cross-domain business process is analyzed, and "business process nodes" are constructed within the graph. Connection edges are defined between "data nodes → business process nodes → target business domain nodes," allowing for rapid understanding of the sensitive data content, level, and other details of the flow. For example, in the flow of drone flight trajectory data, the data flows from the management information regional business database → intranet drone business application → internet drone application → internet drone business. Next, based on data access behavior, a fine-grained cross-domain data flow anomaly analysis model is used to analyze and output abnormal data behavior. For instance, in the drone flight trajectory data flow process, the flow identifier from the internet region is linked to the business identifier to obtain the drone flight trajectory data acquired by the internet drone business application at a certain time. The amount of data acquired (e.g., 50MB) is also known, and this is compared with an anomaly threshold (determined based on historical access behavior). If the deviation is within the allowable range, the access behavior is considered normal; if it exceeds the anomaly threshold, the anomaly behavior type is output. Finally, based on the abnormal behavior assessment results, an anomaly handling strategy is generated and sent to the flow exit node for risk mitigation such as alarms, circuit breakers, and blocking, to avoid risks such as sensitive data leakage and improve system security. This example uses extracted identification information to correlate with an identification graph, identifies relationships between data, and analyzes abnormal data access behavior based on different dimensions such as business characteristics, access relationships, timelines, and traffic trends to identify data leakage points. Based on different risk levels of abnormal behavior, different levels of security protection are implemented, including alarms, circuit breakers, and blocking.
[0055] In one example implementation, the information extraction process of the information extraction hardware includes: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature.
[0056] In this example implementation, interactive service traffic (network traffic to be extracted) can be obtained through network traffic mirroring. The network traffic to be extracted includes network traffic at each transit node and network traffic at the transit exit node. Irrelevant traffic (such as packets from non-target services) is quickly eliminated using preset frame header features (such as Ethernet type fields and VLAN tags). Figure 7 As shown, the serial bit stream is divided into fixed-length micro-data blocks and distributed to multiple parallel processing channels (such as logic gate 1, logic gate 2, logic gate 3, ...) within the information extraction hardware (such as an FPGA). Each channel independently carries a certain data flow, such as no more than 12.5Gbps of sub-flow (such as data stream 1, data stream 2, data stream 3, ...), avoiding serial processing bottlenecks. A "bit-level feature mask" for the data flow identifier is pre-configured in the FPGA, and specific features of the flow identifier (such as the start bit offset and check bit rules of a specific field) are compiled into hardware-executable logic gates. Parallel comparison of micro-data blocks is performed directly through a mask. Multiple channels simultaneously perform logical operations on the target bits (corresponding to specific features) of their respective data blocks, without needing to parse IP, TCP, or other network protocol packets or headers. Basic metadata of the data packet containing the identifier is automatically extracted through hardware logic and written in batches to host memory via PCIe (Peripheral Component Interconnect Express) interface using DMA (Direct Memory Access), such as writing the UUIDs of data stream 1, data stream 2, and data stream 3. This allows the application layer to directly obtain the identifier information, avoiding the latency of packet-by-packet interaction. This example, designed for high-speed network traffic, utilizes the parallel computing capabilities of dedicated hardware (information extraction hardware) to skip the redundant process of traditional "parsing protocol fields first and then locating content," directly achieving real-time high-speed extraction of data security identifiers and improving identifier recognition speed.
[0057] For example, such as Figure 8As shown, when data flows to the exit node, the security identifier, i.e., the last-hop flow identifier ID, is quickly located and extracted from the high-speed network packets, achieving rapid identifier extraction. Next, correlation analysis is performed: the extracted identifier is dynamically bound to the context to build a relationship network. This not only identifies the "user ID number" but also associates it with its source (which business interface it came from), related data (such as the bound mobile phone number and address), access records (such as who viewed it), etc., forming a complete data flow profile. Combined with data access behavior, risk assessment is performed on the associated data. Finally, precise response is implemented, i.e., targeted measures are automatically taken based on the analysis results, including blocking operations and triggering alarms. This method, with "end-to-end identifier connectivity" as its core, constructs a closed-loop protection system of "rapid extraction - graph correlation analysis - precise protection," achieving full-process automation of sensitive data from identification to control through deep fusion of dynamic graphs.
[0058] With the large-scale development of new business models such as drones, vehicle-to-grid (V2G) interaction, and energy big data services, and the deepening of power data application systems with extensive business interactions, the number of power data transfer and processing nodes has increased, and the transfer path has lengthened. This has led to a significant increase in the number of sensitive data leakage points and risks, and the challenges of data leakage detection, transfer tracking, and the determination of responsibility for leakage have been continuously enhanced. Currently, more than 37,500 valid data leakage incidents have been monitored. Cases of data leakage caused by attackers using various new attack methods have surged by 71% year-on-year. The threat of data leakage attacks from external sources is also constantly intensifying. Traditional data protection systems based on content identification rely on high-precision identification of sensitive information, resulting in low prevention and control efficiency and problems of false alarms and false negatives. Moreover, the power grid business applications and data interaction chains are complex, with numerous and widespread data leakage points, making it difficult to achieve accurate protection for cross-domain power data transfer.
[0059] In this context, traditional data breach detection solutions rely on matching specific keywords and phrases using regular expressions or different static statistical methods. However, keyword-based methods are not accurate enough for data breach detection scenarios and struggle to detect distorted data. For example, in power distribution, "tower coordinates" might be rewritten as "tower location" or split into "tower·coordinates," making detection impossible and prone to false negatives.
[0060] With technological advancements and the rise of artificial intelligence, there's a growing trend towards machine learning, contextual semantic analysis, and other AI technologies. However, content-based methods for detecting sensitive data leaks often overlook the contextual relationships within text and document structure, resulting in less than ideal detection performance for distorted data. While some research focuses on detecting distorted data, most consider only simple scenarios, such as adding or deleting content from the original file. In reality, data distortion is often significant, and failure to effectively detect heavily distorted data poses a high risk of data leakage. For example, a prior art patent titled "A Full-Link Data Security Protection Method" generates a security identifier during data acquisition. During data transmission, the identifier information and its meaning are uploaded to a cloud service center. When data processing and exchange are required, the identifier and secret value are decrypted and then verified against the identifier information in the cloud service center. Data destruction can be performed on demand. Each step specifically includes: constructing data security identifiers during the data acquisition phase; dividing the ciphertext file into blocks and generating ciphertext components during the data transmission and storage phase; calculating virtual indexes and data tags; sending the ciphertext components to the DHT network; uploading the tuple consisting of virtual index data blocks and data tags to the cloud server; re-encrypting based on a re-encryption key generation algorithm during the data processing and data exchange phase; obtaining the identifier and secret value after decryption; acquiring the tuple of the index associated with the ciphertext components; implementing fine-grained access control for cloud storage based on attribute proxy re-encryption; and achieving data self-destruction using the DHT network's automatic update function during the data destruction phase. This method is highly dependent on the key generation center. It is responsible for the registration, key generation and distribution, data acquisition, and transmission of all users (data owners and users), including the advance verification and control of data identifier information, making key management and distribution complex. Furthermore, symmetric keys need to be associated with security attributes and indirectly distributed to authorized users through attribute-based encryption. This process involves re-encryption and the derivation of multiple keys, placing high demands on data retrieval efficiency and performance, and lacking lightweight, high real-time, and fine-grained identifier-based data flow management characteristics. For the existing technology entitled "A Method for Real-Time Dynamic Processing of Security Identification of Structured Data," the core idea of this method includes: calling a sensitive data identification engine through a data connection security component to scan the acquired data content; the sensitive data identification engine extracts natural language from the data content and compares its semantic similarity with the key points provided by the policy management service; for those with a similarity reaching a specified threshold, it returns the security level and related security attributes of the corresponding key point, thus completing the automatic determination of the data's security level; the database connection security component calls a sensitive data processing component, and based on the result of the security level determination, encodes the security level and its related security attributes according to abstract syntax tags to generate a data security identifier; the sensitive data processing component binds the generated data security identifier to the corresponding data item.This method treats the security identifier as part of the data and writes it into the database in plaintext along with the original data, which poses certain security risks. For example, any malicious user who can directly access the database (through database management tools, command line, or by exploiting SQL injection vulnerabilities) can easily modify or remove the security identifier, thereby rendering the security control completely ineffective.
[0061] In the process of data leakage monitoring and cross-domain data flow control, which is mainly based on sensitive content identification technology using regular expressions, keyword matching, or rule bases, the following two main problems are faced: (1) The identification ability of sensitive content identification technology based on regular expressions, keyword matching, or rule bases is limited by the coverage and update frequency of the preset rule base. At the same time, since the expression form of sensitive information is highly dynamic, attackers can easily bypass rule detection through synonym replacement, character obfuscation (such as Unicode encoding conversion), and format deformation (such as segmented display and image embedding). The prevention and control efficiency is low and there are false alarms and false alarms, making it difficult to achieve efficient and accurate prevention and control of data leakage risks. (2) Existing data leakage risk tracing methods are mostly based on single-point tracing. The flow path of data leakage depends on the experience mining of human experts and the correlation analysis of information of various subjects in the link. There are problems such as low analysis efficiency and unclear characterization of the path of each node in the data leakage flow. It is difficult to accurately locate the data leakage node and the propagation path, resulting in coarse granularity and incomplete coverage of cross-domain data control.
[0062] To address the aforementioned problems, this invention considers that security identification technology can embed predefined security attribute information into data and accompany the entire data flow process. Therefore, security identification is adopted as a key foundational technology for solving cross-domain data flow control. Taking into account the current problems of poor accuracy in identifying sensitive data and large granularity of risk control in the cross-domain flow of power data, this invention proposes a security identification-driven method and device for cross-domain power data flow control, such as... Figure 9As shown, based on the characteristics of different professional business data such as power finance, equipment, marketing, and dispatch, and based on existing classification and grading guidelines, a power business data security identifier, namely the business identifier, is constructed. Based on network traffic size, direction, and protocol characteristics, a network flow security identifier, namely the flow identifier, is constructed. According to different business data types, the business identifier is embedded into the data content. When data is transmitted, the business identifier is quickly identified. Based on the business identifier content and network traffic characteristics, a flow identifier is generated and injected into the network packet extension field. Simultaneously, a knowledge graph of the flow relationship between the business identifier and the flow identifier is constructed. Using dedicated hardware (information extraction hardware), the network identifier is quickly extracted without decoding protocol packets. Through the identifier association relationships in the association graph, details such as the sensitive data content and level of the flow are quickly grasped. Based on access characteristics, spatiotemporal characteristics, and association characteristics, a fine-grained flow control model is constructed to promptly handle risks such as alarms, circuit breakers, and blocking during abnormal data access processes.
[0063] This invention addresses the potential security issues, such as data leakage, that may occur during the cross-domain flow of power data across multiple regions, including production control zones, management information zones, and internet zones. It proposes a security-identifier-driven method for controlling the cross-domain flow of power data. This method constructs data service identifiers and flow identifiers based on power characteristics. Service identifiers are embedded at the data source for different data types, both structured and unstructured. Flow identifiers are also embedded during the flow process. A correlation between flow identifiers and service identifiers is established based on graph data. Dedicated hardware is used to extract identifier features from the traffic, enabling rapid tracking of multi-link power data flow and access to associated data. A security-identifier-driven cross-domain power data flow control model is constructed, and corresponding devices and equipment are developed to improve the efficiency and accuracy of controlling the cross-domain flow of sensitive power data.
[0064] The security identifier-driven cross-domain power data flow control method of this invention can improve the ability to accurately detect and trace the source of power sensitive data leakage, prevent and resolve the risks of power data leaving the domain illegally and data leakage. The relevant results can be transformed into data security products, strengthen and supplement existing data security capabilities, and can be widely applied to scenarios such as cross-entity data interaction and middleware applications, to ensure the security of power business data, improve the security protection level of data sharing and interaction in new power systems, and has great potential value.
[0065] Example 2 Based on the same inventive concept, this invention also discloses a power data cross-regional transfer control platform, comprising: The data association module is used to determine the target power data associated with the received business data access request from the external user; wherein the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; The data transfer control module is used to control the data transfer of the target power data within the power management information region and the Internet region based on the business call relationship between different power business systems. When the target power data is transferred to the transfer exit node of the Internet region, the module receives a security identifier sent from the transfer exit node, performs association matching in the security identifier knowledge graph based on the security identifier, and controls the transfer of the target power data at the transfer exit node based on the association matching result. During the data transfer process, a flow identifier is injected into the data to be transferred at each transfer node within the power management information region and the internet region. Each flow identifier contains the association relationship between itself and the service identifier. The flow identifier is used to characterize the transfer relationship of power business data associated with the service identifier in the power communication network. The security identifier is the flow identifier corresponding to the last transfer node. The security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through the interrelated service identifiers and flow identifiers. The initial security knowledge graph is constructed based on the historical access behavior of power data.
[0066] In this example implementation, the power data cross-regional transfer control platform can be deployed in the power management information area or on the cloud side.
[0067] In one possible implementation, the flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier.
[0068] In one possible implementation, the service identifier includes a service identifier number, and the system further includes: The service identifier generation module is used to receive target service features sent from the transfer entry node of the power management information region, generate a corresponding service identifier based on the target service features, and return the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
[0069] In one possible implementation, the flow control module includes an initial map construction submodule, which is used for: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
[0070] In one possible implementation, the flow control module further includes a map update submodule, which is used for: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers; The new flow identifier is generated by each flow node based on the old flow identifier extracted from the previous flow node.
[0071] Example 3 Based on the same inventive concept, the present invention also discloses a power data cross-regional transfer control system, including the power data cross-regional transfer control platform as described in Example 2.
[0072] In one example implementation, the system further includes: multiple network traffic aggregation devices located in the power management information zone and the Internet zone, and network traffic outflow devices located in the Internet zone; each network traffic aggregation device serves as a transfer node, and the network traffic outflow device serves as a transfer exit node.
[0073] In this example implementation, the network traffic aggregation device can be a switch or router between different business systems within the power management information region and the Internet region, and the network traffic outflow device can be a router. Through the joint design of the hardware and software of these devices, the injection of flow identifiers, the rapid extraction of flow identifier IDs, and the handling of anomalies are realized. This enhances the security protection capability of cross-domain flow of power-sensitive data while ensuring the efficiency of data flow control.
[0074] In one example implementation, the system further includes a business server located in the power management information zone, which serves as the entry point node for data transfer; the business server is used for: If the target power data is unstructured data, the business identifier is embedded into the attributes of the file containing the target power data; If the target power data is semi-structured or structured data, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
[0075] In one example implementation, each network traffic aggregation device is used for: The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
[0076] In one example implementation, each network traffic aggregation device is further used for: The network traffic aggregation device corresponding to the first transfer node is also used for: The system monitors network traffic and extracts the service identifier from the network traffic using information extraction hardware. Based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node. The flow identifier of the first transfer node includes the association between the flow identifier and the service identifier. For network traffic aggregation devices corresponding to other flow nodes besides the first flow node, the following functions are also used: to monitor network traffic, extract the flow identifier from the monitored network traffic using information extraction hardware as the old flow identifier; generate a new flow identifier based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node; wherein, the new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
[0077] In one example implementation, each network traffic aggregation device and the network traffic outflow device are equipped with information extraction hardware; the information extraction hardware is used for: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
[0078] This invention constructs power business identifiers and flow identifiers, and studies identifier injection methods based on different data and flow characteristics to achieve rapid injection of security identifiers. It utilizes dedicated hardware to achieve rapid capture and precise protection of security identifiers, thereby realizing lightweight, high real-time, and fine-grained data flow control.
[0079] For example, such as Figure 10 As shown, this is a security identifier-driven cross-domain power data flow control system designed based on the above security identifier model. The system includes: a business server for business identifier injection, a network traffic aggregation device for flow identifier generation and injection, a network traffic outflow device for precise protection of network traffic sensitive data, and a cross-regional flow control platform.
[0080] Taking typical external interactive businesses such as power business drones and power grid integration as examples, the system deploys business identifier injection capabilities on the business server of the management information system, deploys mobile identifier generation and injection capabilities during the drone business flow, deploys sensitive data precision protection capabilities at the boundary traffic exit, and deploys a cross-regional flow control platform in the management information big data area. The process involves several steps: First, the business server quickly scans the business data content and sends its characteristics to the cross-regional flow control platform. The platform generates a business identifier based on these characteristics, and the business server injects this identifier into the business data. Second, the information extraction hardware within the network traffic aggregation device rapidly extracts the identifier information and generates a flow identifier for the current node. This newly generated flow identifier ID is then injected into the network traffic packet, and the generated flow identifier is simultaneously synchronized to the cross-regional flow control platform. Third, the network traffic outflow device quickly extracts and identifies the identifier information, sends the identified identifier ID to the cross-regional flow control platform, receives handling strategies from the platform, and sends abnormal handling control commands to the network traffic outflow device to perform alarm, circuit breaker, and blocking operations on network packets. Finally, the cross-regional flow control platform provides functions such as automatic identifier generation, identifier management, identifier association, cross-domain flow abnormal behavior analysis, and strategy configuration. Ultimately, it offers a complete data leakage evidence chain, enabling static and mobile data labeling and tracking, flexible adjustment of anti-leakage strategies, and precise risk tracing.
[0081] For the deployment of business identifier injection capability: For the data stored in the business database of the business system in the management information region, deploy the business data identifier injection capability and integrate it with the business system. Inject the identifier information ID into the accessed data set. When a user or business accesses the data through database access or other tools or interfaces, the identifier will flow with the data and the identifier information will be synchronized to the cross-regional flow control platform.
[0082] Regarding the deployment of flow identifier generation and injection capabilities: The flow identifier injection capability is deployed at the traffic aggregation point of business calls. When business data flows through the flow identifier injection, a flow data identifier will be generated based on the identifier information, and the flow data identifier ID will be injected into the extended field of the network packet without affecting the original packet. At the same time, the flow identifier information will be synchronized to the identifier cross-domain flow control center to facilitate the depiction of the data flow path.
[0083] For the deployment of precise protection capabilities for sensitive data: These capabilities are deployed at the traffic egress points of major internet regions. They are responsible for extracting the last-hop identifier ID information and reporting it to the cross-regional flow control platform. Based on the last-hop identifier header information, the cross-regional flow control platform correlates the access process of relevant identifiers, performs comprehensive analysis and early warning, and distributes relevant policies to the traffic egress devices to issue warnings or block subsequent data access behaviors. Simultaneously, it monitors the flow of important data without tags, captures, analyzes, and deeply identifies the message content, performs behavioral and content analysis according to rules, and sends the analysis results to the identifier cross-domain flow control center.
[0084] For the deployment of the cross-regional data transfer control platform: The cross-regional data transfer control platform is deployed in the management information area. It is responsible for receiving the identification information of each transfer node and outflow node, making comprehensive judgments, tracing the source of leaked sensitive data, determining the transfer path of the sensitive data, and issuing policies to traffic exit devices to block subsequent related threat access.
[0085] The proposed security identifier-driven cross-domain power data flow control system constructs data service identifiers and flow identifiers based on power characteristics. It embeds service identifiers at the data source end for different data types (structured and unstructured) and embeds flow identifiers during the flow process. Based on graph data, it establishes the association between flow identifiers and service identifiers. Dedicated hardware extracts identifier features from the traffic, rapidly realizing multi-link flow traceability of power data and access to associated data. This system constructs a security identifier-driven cross-domain power data flow control model and forms corresponding devices and equipment, thereby improving the efficiency and accuracy of cross-domain flow control of sensitive power data. Compared to traditional analysis models based on content extraction methods (keyword or regular expression recognition methods) and contextual semantic analysis, it represents a significant technological breakthrough.
[0086] This invention, based on a security identifier-driven method and device for controlling cross-domain power data flow, can be extended to other cross-domain data flow scenarios, improving the energy industry's data risk prevention capabilities and cross-domain data precision protection capabilities, and effectively promoting the realization of energy data value. For example, the technology can be further extended to cross-domain data flow scenarios in various industries and enterprises, providing a "one-stop" security solution for realizing the value of data elements, serving third-party precise policy implementation, enterprise energy efficiency management, and social welfare protection.
[0087] Example 4 like Figure 11 As shown, the present invention also provides an electronic device, which may be a computer device, a microcontroller device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, processor, and transceiver component are connected via a bus; the memory can be used to store executable programs, and an exemplary executable program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, which can be accessed and / or modified when instructions are executed.
[0088] The processor may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and it is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to realize the corresponding method flow or corresponding function, so as to realize the steps of the power data cross-regional flow control method in the above embodiments.
[0089] Example 5 Based on the same inventive concept, this invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory). An electronic device readable storage medium is a memory device within an electronic device used to store programs and data. It is understood that the storage medium here can include both the built-in storage medium of the electronic device and extended storage media supported by the electronic device. The storage medium provides storage space, which stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more executable programs (including program code). It should be noted that the storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. Loading and executing one or more instructions stored in the storage medium by the processor can implement the steps of the power data inter-regional flow control method described in the above embodiments.
[0090] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0091] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0092] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0093] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit its scope of protection. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that after reading the present invention, they can still make various changes, modifications or equivalent substitutions to the specific implementation methods of the application, but these changes, modifications or equivalent substitutions are all within the scope of protection of the claims pending approval.
Claims
1. A method for controlling the cross-regional transfer of power data, characterized in that, include: Based on the received business data access request from an external user, the target power data associated with the business data access request is determined; wherein, the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; Based on the business call relationship between different power business systems, the target power data is controlled to flow within the power management information region and the Internet region; wherein, during the data flow process, a flow identifier is injected into the data to be flowed at each flow node within the power management information region and the Internet region, and each flow identifier contains the association relationship between itself and the business identifier. The flow identifier is used to characterize the flow relationship of the power business data associated with the business identifier in the power communication network. When the target power data flows to the flow exit node of the Internet region, a security identifier sent from the flow exit node is received; based on the security identifier, an association matching is performed in the security identifier knowledge graph, and the flow of the target power data at the flow exit node is controlled based on the association matching result; wherein, the security identifier is the flow identifier corresponding to the last flow node; the security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through interrelated business identifiers and flow identifiers, and the initial security knowledge graph is constructed based on the historical access behavior of the power data.
2. The method according to claim 1, characterized in that, The flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier.
3. The method according to claim 1, characterized in that, The service identifier includes a service identifier number, and the process of generating the service identifier includes: The system receives target service features sent from the transfer entry node of the power management information region, generates a corresponding service identifier based on the target service features, and returns the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
4. The method according to claim 3, characterized in that, The injection process of the business identifier includes: If the target power data has an unstructured data structure, the business identifier is embedded into the attributes of the file containing the target power data. If the target power data has a semi-structured or structured data structure, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
5. The method according to claim 2, characterized in that, The process of injecting a flow identifier into the data to be transferred includes: The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
6. The method according to claim 2, characterized in that, The process of generating the flow identifier includes: For the first transfer node, network traffic is monitored at the transfer node, and the service identifier in the network traffic is extracted through information extraction hardware; based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node; wherein, the flow identifier of the first transfer node includes the association relationship between the flow identifier and the service identifier. For all other flow nodes except the first flow node, network traffic is monitored at each flow node, and the flow identifier in the monitored network traffic is extracted by information extraction hardware as the old flow identifier. A new flow identifier is generated based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node. The new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
7. The method according to claim 6, characterized in that, After the new flow identifier is generated, it also includes: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers.
8. The method according to claim 7, characterized in that, The process of constructing the initial security knowledge graph includes: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
9. The method according to claim 8, characterized in that, The security identifier is the flow identifier number of the last transit node obtained by extracting the flow identifier of the outgoing network traffic from the transit exit node; the association matching result includes the complete transit path, associated business characteristics, associated access behavior, and access trend; Based on the security identifier, association matching is performed in the security identifier knowledge graph, including: Based on the flow identifier of the last flow node and the association between the flow identifiers of each flow node during the data flow process, the corresponding business identifier and the complete flow path of the business data are associated in the security identifier knowledge graph. Based on the business identifier, the corresponding related business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding related access behaviors and access trends are associated in the security identifier knowledge graph.
10. The method according to claim 9, characterized in that, Controlling the flow of the target power data at the flow exit node based on the correlation matching results includes: Based on the anomaly analysis model and the complete flow path, anomaly analysis is performed on the related business characteristics, related access behaviors and access trends to identify abnormal behaviors. A corresponding anomaly handling strategy is generated for the abnormal behavior, and the flow of the target power data at the flow exit node is controlled based on the anomaly handling strategy; The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
11. The method according to claim 6, characterized in that, The information extraction process of the information extraction hardware includes: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
12. A cross-regional power data transfer control platform, characterized in that, include: The data association module is used to determine the target power data associated with the received business data access request from the external user; wherein the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; The data transfer control module is used to control the data transfer of the target power data within the power management information region and the Internet region based on the business call relationship between different power business systems. When the target power data is transferred to the transfer exit node of the Internet region, the module receives a security identifier sent from the transfer exit node, performs association matching in the security identifier knowledge graph based on the security identifier, and controls the transfer of the target power data at the transfer exit node based on the association matching result. During the data transfer process, a flow identifier is injected into the data to be transferred at each transfer node within the power management information region and the internet region. Each flow identifier contains the association relationship between itself and the service identifier. The flow identifier is used to characterize the transfer relationship of power business data associated with the service identifier in the power communication network. The security identifier is the flow identifier corresponding to the last transfer node. The security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through the interrelated service identifiers and flow identifiers. The initial security knowledge graph is constructed based on the historical access behavior of power data.
13. The control platform according to claim 12, characterized in that, The flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier.
14. The control platform according to claim 12, characterized in that, The service identifier includes a service identifier number, and the system further includes: The service identifier generation module is used to receive target service features sent from the transfer entry node of the power management information region, generate a corresponding service identifier based on the target service features, and return the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
15. The control platform according to claim 12, characterized in that, The flow control module includes an initial map construction submodule, which is used for: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
16. The control platform according to claim 15, characterized in that, The circulation control module further includes a map update submodule, which is used for: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers; The new flow identifier is generated by each flow node based on the old flow identifier extracted from the previous flow node.
17. The control platform according to claim 16, characterized in that, The security identifier is the flow identifier number of the last transit node obtained by extracting the flow identifier of the outgoing network traffic from the transit exit node; the association matching result includes the complete transit path, associated service characteristics, associated access behavior, and access trend; the transit control module also includes an association sub-module, which is used for: Based on the flow identifier of the last flow node and the association between the flow identifiers of each flow node during the data flow process, the corresponding business identifier and the complete flow path of the business data are associated in the security identifier knowledge graph. Based on the business identifier, the corresponding related business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding related access behaviors and access trends are associated in the security identifier knowledge graph.
18. The control platform according to claim 17, characterized in that, The flow control module also includes: The anomaly analysis submodule is used to perform anomaly analysis on the associated business characteristics and associated access behaviors based on the anomaly analysis model and the data flow link, and to determine the abnormal behavior. An anomaly control submodule is used to generate corresponding anomaly handling strategies for the abnormal behavior, and to control the flow of the target power data at the flow exit node based on the anomaly handling strategies. The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
19. A power data inter-regional transfer control system, characterized in that, Including the power data cross-regional transfer control platform as described in any one of claims 12-18.
20. The system according to claim 19, characterized in that, Also includes: Multiple network traffic aggregation devices located in the power management information zone and the internet zone, and network traffic outflow devices located in the internet zone; Each network traffic aggregation device acts as a transfer node, and the network traffic outflow device acts as a transfer exit node.
21. The system according to claim 20, characterized in that, It also includes a business server located in the power management information zone, which serves as the entry point node for data transfer; the business server is used for: If the target power data is unstructured data, the business identifier is embedded into the attributes of the file containing the target power data; If the target power data is semi-structured or structured data, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
22. The system according to claim 20, characterized in that, Each network traffic aggregation device is used for: The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
23. The system according to claim 22, characterized in that, The network traffic aggregation device corresponding to the first transfer node is also used for: The system monitors network traffic and extracts the service identifier from the network traffic using information extraction hardware. Based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node. The flow identifier of the first transfer node includes the association between the flow identifier and the service identifier. For network traffic aggregation devices corresponding to other flow nodes besides the first flow node, the following functions are also used: to monitor network traffic, extract the flow identifier from the monitored network traffic using information extraction hardware as the old flow identifier; generate a new flow identifier based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node; wherein, the new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
24. The system according to claim 23, characterized in that, Each network traffic aggregation device and the network traffic outflow device are equipped with information extraction hardware; the information extraction hardware is used for: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
25. An electronic device, characterized in that, include: At least one processor and memory; The memory and processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the method as described in any one of claims 1 to 11 is implemented.
26. A readable storage medium, characterized in that, It contains an executable program, which, when executed, implements the method as described in any one of claims 1 to 11.
Citation Information
Patent Citations
Data circulation method and device, computer equipment and storage medium
CN111738702A
Cross-regional interconnection detection method and device for power monitoring system and computer equipment
CN114244864A
Workflow logic control method and device, electronic equipment and readable storage medium
CN116795458A
Power data transaction risk discovery method, system, equipment and medium
CN119475143A
Visual scene method, system and device based on digital twinning and medium
CN120596690A