Power data cross-region flow control method, control platform, control system and device
By injecting flow identifiers and constructing dynamic knowledge graphs during the power data flow process, the problems of low accuracy in security control and low traceability efficiency in traditional cross-domain power data flow control are solved, achieving efficient and accurate data flow security control.
Patent Information
- Application Number
- CN202511666188.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-14
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2045-11-14
AI Technical Summary
In the traditional process of cross-domain flow control of power data, attackers can bypass rule detection through methods such as format distortion, resulting in low accuracy and efficiency of security control, as well as low efficiency of data traceability and inaccurate positioning.
By injecting flow identifiers into the data to be transferred at each transfer node within the power management information region and the internet region, and dynamically associating them with a knowledge graph of business identifiers and security identifiers, a full-link transfer record is constructed, enabling clear reconstruction and rapid location of the data transfer trajectory.
It achieves efficient and accurate security protection for power data, can quickly locate leakage nodes, improves the tracking efficiency and location accuracy of data flow, and enhances the system's security protection capabilities.
Smart Images

Figure CN121125365B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power information security, in particular to a power data cross-region flow control method, a control platform, a control system and equipment. BACKGROUND
[0002] With the large-scale development of new formats such as unmanned aerial vehicles, vehicle-network interaction, and energy big data services, and the continuous deepening of the power data application system with extensive business interactions, the number of power data flow and processing nodes increases, and the flow path is extended, which significantly increases the risk of sensitive data leakage and the difficulty of data leakage discovery, flow tracking, and responsibility definition.
[0003] The traditional data cross-domain flow control process based on regular expressions, keyword matching, or rule-based sensitive content recognition technology can easily bypass rule detection by means such as synonym replacement, character obfuscation (such as Unicode encoding conversion), and format transformation (such as segmented display and image embedding), resulting in low accuracy and efficiency of security prevention and control. At the same time, data anomaly tracing is mainly based on single-point tracing, and the flow path mainly relies on expert experience, which has the problems of low efficiency and inaccurate positioning. SUMMARY
[0004] To overcome the above technical problems, the present application provides a power data cross-region flow control method and device, and a cross-region flow system and equipment.
[0005] In one aspect, the present application provides a power data cross-region flow control method, comprising:
[0006] Based on the received business data access request from the external user, determine the target power data associated with the business data access request; wherein the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to represent the business attribute and security attribute of the business data;
[0007] Based on the business calling relationship between different power business systems, control the data flow of the target power data in the power management information area and the Internet area; wherein in the data flow process, a flow identifier is injected into the data to be flowed at each flow node in the power management information area and the Internet area, each flow identifier contains the association relationship between itself and the business identifier, and the flow identifier is used to represent the flow relationship of the power business data associated with the business identifier in the power communication network;
[0008] When the target power data stream is transferred to the transfer exit node of the Internet area, a security identifier sent from the transfer exit node is received; association matching is performed in a security identifier knowledge graph based on the security identifier, and the transfer of the target power data at the transfer exit node is controlled based on the association matching result; wherein the security identifier is a flow identifier corresponding to the last transfer node; the security identifier knowledge graph is obtained by dynamically updating an initial security knowledge graph based on the current access behavior through the mutually associated business identifier and flow identifier, and the initial security knowledge graph is constructed based on the historical access behavior of the power data.
[0009] Optionally, the flow identifier includes a flow identifier number, an association identifier, a source IP, a destination IP, a transmission interface, a cross-area transfer direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the business identifier.
[0010] Optionally, the business identifier includes a business identifier number, and the generation process of the business identifier includes:
[0011] A target business feature sent from the transfer entry node of the power management information area is received, a corresponding business identifier is generated based on the target business feature, and a business identifier number of the business identifier is returned to the transfer entry node, so that the transfer entry node injects the received business identifier number into the business data based on the data structure of the business data associated with the business data access request;
[0012] Wherein, the target business feature is obtained by scanning the business data and extracting the business feature of the business data.
[0013] Optionally, the injection process of the business identifier includes:
[0014] If the data structure of the target power data is unstructured data, the business identifier number is embedded in the attribute of the file where the target power data is located.
[0015] If the data structure of the target power data is semi-structured or structured data, the business identifier number is injected into the extension field of the network packet corresponding to the target power data through a dynamic hook injection method.
[0016] Optionally, the injection of the flow identifier into the data to be transferred includes:
[0017] The flow identifier number is injected into the optional field of the network traffic data packet corresponding to the data to be transferred.
[0018] Optionally, the generation process of the flow identifier includes:
[0019] For the first flow transfer node, network traffic is listened to at the flow transfer node, and a service identification number in the network traffic is extracted by information extraction hardware; a corresponding flow identification is generated based on the extracted service identification number and the attribute of the listened network traffic as the flow identification of the first flow transfer node; wherein the flow identification of the first flow transfer node comprises an association relationship between the flow identification number and the service identification number.
[0020] For the flow transfer nodes other than the first flow transfer node, network traffic is listened to at each flow transfer node, and a flow identification number in the listened network traffic is extracted by information extraction hardware as an old flow identification number; a new flow identification is generated based on the old flow identification number and the attribute of the listened network traffic as the flow identification of the current flow transfer node; wherein the new flow identification comprises an association relationship between the new flow identification number and the old flow identification number.
[0021] Optionally, after the new flow identification is generated, the method further comprises:
[0022] Receiving the newly generated flow identification sent by each flow transfer node;
[0023] Based on the newly generated flow identification, dynamically updating the initial security knowledge graph.
[0024] Optionally, the construction process of the initial security knowledge graph comprises:
[0025] Extracting the service identification, entity information, inter-entity relationship and entity attribute of the historical access behavior corresponding to the power data;
[0026] Extracting the flow identification generated by each flow transfer node in the historical access behavior, and associating the service identification and each flow identification through the power data corresponding to the historical access behavior and the data flow transfer relationship;
[0027] Associating the service identification with the entity information, inter-entity relationship and entity attribute, combining the association relationship between the service identification and the flow identification, and forming an initial knowledge graph;
[0028] Performing knowledge fusion on the third-party power security knowledge base and the initial knowledge graph to form the initial security knowledge graph.
[0029] Optionally, the security identification is the flow identification number of the last flow transfer node of the flow transfer export node for flow identification extraction of the network traffic to be flowed out; the association matching result comprises a complete flow transfer path, an associated service feature, an associated access behavior and an access trend; based on the security identification, performing association matching in the security identification knowledge graph, comprising:
[0030] based on the association relationship between the flow identification number of the last flow transfer node and the flow identification numbers of the flow transfer nodes in the data flow, the complete flow transfer path of the corresponding business identification and the business data is associated in the security identification knowledge graph;
[0031] based on the business identification, the associated business features are associated in the security identification knowledge graph; and based on the business identification and the flow identification, the associated access behavior and access trend are associated in the security identification knowledge graph.
[0032] Optionally, based on the association matching result, the flow transfer of the target power data at the flow transfer export node is controlled, including:
[0033] based on the anomaly analysis model and the complete flow transfer path, the associated business features, the associated access behavior and the access trend are analyzed to determine the abnormal behavior;
[0034] for the abnormal behavior, a corresponding abnormal handling strategy is generated, and the flow transfer of the target power data at the flow transfer export node is controlled based on the abnormal handling strategy;
[0035] wherein the anomaly analysis model is an association model of multi-dimensional features and abnormal behaviors based on historical access behaviors of power data, and the multi-dimensional features include business features, access features, space-time features and flow transfer trend.
[0036] Optionally, the information extraction process of the information extraction hardware includes:
[0037] obtain the network traffic to be extracted, remove irrelevant network traffic through a preset frame header feature, and obtain target network traffic;
[0038] cut the target network traffic into a plurality of micro data blocks according to a preset length, and distribute the plurality of micro data blocks to a plurality of parallel processing channels; wherein the micro data blocks correspond to the processing channels one by one; in each processing channel, a specific feature of an identification mask is compiled into a hardware executable logic gate circuit;
[0039] the logic gate circuit is executed in parallel to realize the logic operation of the target bit of each micro data block, the metadata of the data packet where the flow identification number is located in each micro data block is extracted and stored in the memory for calling by the application layer;
[0040] wherein the identification mask is a bit-level feature mask of the flow identification number in the micro data block pre-configured; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow transfer node and the network traffic at the flow transfer export node.
[0041] On the other hand, the present application also provides a power data cross-region flow transfer control platform, comprising:
[0042] a data association module, configured to determine target power data associated with a service data access request from an external user based on the received service data access request; wherein the target power data is obtained by injecting a service identifier into corresponding power service data; and the service identifier is used to represent service attributes and security attributes of service data;
[0043] a flow control module, configured to control data flow of the target power data in a power management information zone and an Internet zone based on service calling relationships between different power service systems; when the target power data flows to a flow export node in the Internet zone, receive a security identifier sent from the flow export node, and perform association matching in a security identifier knowledge graph based on the security identifier, and control flow of the target power data at the flow export node based on the association matching result.
[0044] In the data flow process, a flow identifier is injected into to-be-flowed data at each flow node in the power management information zone and the Internet zone, each flow identifier contains an association relationship between itself and a service identifier, and the flow identifier is used to represent flow relationships of power service data associated with the service identifier in a power communication network; the security identifier is a flow identifier corresponding to a last flow node; the security identifier knowledge graph is obtained by dynamically updating an initial security knowledge graph based on a current access behavior through mutually associated service identifiers and flow identifiers, and the initial security knowledge graph is constructed based on historical access behaviors of power data.
[0045] In another aspect, the present application also provides a power data cross-zone flow control system, comprising the power data cross-zone flow control platform according to any one of the above.
[0046] In another aspect, the present application also provides an electronic device, comprising at least one processor and a memory; the memory and the processor are connected through a bus;
[0047] the memory is used to store one or more programs;
[0048] when the one or more programs are executed by the at least one processor, the method according to any one of the above is implemented.
[0049] In another aspect, the present application also provides a readable storage medium, which has an execution program stored thereon, and the execution program, when executed, implements the method according to any one of the above.
[0050] Compared with the prior art, the present application has the following beneficial effects:
[0051] The application provides a power data cross-region flow control method, by injecting a service identifier into power service data, the service identifier is used to represent the service attribute and the security attribute of the service data, so that the power data has an identity tag, without relying on regular and keyword rules which are easy to be cracked, the risk of bypassing detection by attackers through format deformation and other means is fundamentally avoided; by injecting a flow identifier into the data to be transferred at each transfer node in the power management information region and the Internet region during the data transfer process, dynamic injection of the flow identifier is realized, full-link transfer records corresponding to nodes and identifiers are formed, when data leakage occurs, the data transfer track can be clearly restored through the flow identifier, the leakage node can be quickly located, and the tracking efficiency and positioning accuracy are greatly improved.
[0052] The application constructs an initial security knowledge graph based on the historical access behavior of power data, and dynamically updates the initial security knowledge graph based on the current access behavior through the mutual correlation of the service identifier and the flow identifier, realizes the dynamic correlation construction process of the knowledge graph, realizes the mutual correlation of the service identifier and the flow identifier through the correlation between each flow identifier and the service identifier, forms the multi-dimensional correlation of the business data-flow path-access behavior, and improves the abnormal detection accuracy and efficiency based on the dynamic knowledge graph; by performing security identifier extraction at the transfer export node and dynamic graph correlation based on the security identifier, it can be quickly judged whether the current access behavior is abnormal, and the system security protection capability is improved. BRIEF DESCRIPTION OF DRAWINGS
[0053] Figure 1 One of the flow schematic diagrams of the power data cross-region flow control method of an example of the application;
[0054] Figure 2 The flow identifier generation process schematic diagram of an example of the application;
[0055] Figure 3 The position schematic diagram of the flow identifier injection network data packet of an example of the application;
[0056] Figure 4 The flow schematic diagram of the initial security knowledge graph construction process of an example of the application;
[0057] Figure 5 The association structure schematic diagram of the security identifier knowledge graph of an example of the application;
[0058] Figure 6 The abnormal behavior analysis process schematic diagram of an example of the application;
[0059] Figure 7 The extraction process schematic diagram of the information extraction hardware of an example of the application;
[0060] Figure 8 A flowchart of an example of the cross-zone flow control method based on identification extraction of the present application;
[0061] Figure 9 A flowchart of an example of the cross-zone flow control method of electric power data of the present application;
[0062] Figure 10 An architecture diagram of an example of the cross-zone flow control system of electric power data of the present application;
[0063] Figure 11 An example of the structure block diagram of the electronic device of the present application. DETAILED DESCRIPTION
[0064] The technical content of the present application can be better understood through the following concepts:
[0065] The network security structure of the electric power secondary system includes a production control zone and a management information zone. The production control zone is the core area of the security partition of the electric power monitoring system, has the highest security level, and is mainly used for real-time monitoring, dispatching and control of the safe and stable operation of the power grid. It can directly realize monitoring, control, regulation and protection of the electric power primary equipment (generators, transformers, transmission lines, circuit breakers, etc.). For example, the production control zone can include an energy management system, a wide-area phasor measurement system, a distribution automation system main station control function, etc.
[0066] The management information zone refers to the collection of electric power enterprise management business systems outside the production control zone. The business systems in the management information zone can include a dispatching production management system, an administrative telephone network management system, an electric power enterprise data network, a lightning monitoring system, a statistical report system, a management information system, an office automation system, a customer service system, etc.
[0067] The Internet zone is located between the management information zone and the external network, and is an intermediate transition area between the electric power internal network and the external network (such as the Internet, a mobile office system, etc.), and undertakes data interaction functions. The Internet zone realizes one-way transmission of internal and external network data through special equipment, and ensures that external network data cannot directly access core systems such as the production control zone.
[0068] Data cross-domain flow refers to the flow of data between different zones, such as the flow of electric power business data through the management information zone to the Internet zone or from the Internet zone to the Internet, the flow of the management information zone dedicated line to external units such as enterprises and banks, etc.
[0069] The specific embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0070] Example 1
[0071] The application provides a power data cross-region flow control method, a schematic diagram of which is shown in the figure Figure 1 The method comprises the following steps:
[0072] In step S110, target power data associated with the service data access request is determined based on the received service data access request from an external user; wherein the target power data is obtained by injecting a service identifier into corresponding power service data; the service identifier is used to represent the service attribute and security attribute of the service data;
[0073] In step S120, the target power data is controlled to flow in the power management information region and the Internet region based on the service calling relationship between different power service systems; wherein during the data flow process, a flow identifier is injected into the data to be flowed at each flow node in the power management information region and the Internet region, each flow identifier contains the association relationship between itself and the service identifier, and the flow identifier is used to represent the flow relationship of the power service data associated with the service identifier in the power communication network;
[0074] In step S130, when the target power data flows to the flow export node of the Internet region, a security identifier sent from the flow export node is received; the security identifier is associated and matched in the security identifier knowledge graph based on the security identifier, and the flow of the target power data at the flow export node is controlled based on the association matching result; wherein the security identifier is the flow identifier corresponding to the last flow node; the security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through the mutually associated service identifier and flow identifier, and the initial security knowledge graph is constructed based on the historical access behavior of the power data.
[0075] In the example embodiment, the external user refers to an external network user, such as an external Internet user. Flow transfer nodes can be set between different business systems in the power management information domain (management information domain), and flow transfer nodes can also be set between different business systems in the Internet domain. High-speed data transmission between different business systems is realized through the flow transfer nodes, and data isolation can also be realized to prevent data mixing of different business systems. The flow transfer export node can be a network traffic forwarding device from the Internet domain to the external network. The business identifier can be a power business data security identifier constructed based on a standard classification and grading guide according to different professional business data characteristics of power finance, equipment, marketing, dispatching, etc. The business identifier is mainly used to identify data content, sensitivity, owner and other information; the business identifier can include a business identifier header and a business identifier body. The business identifier header is the meta-information part of the business identifier, which provides basic information for the management, identification and verification of the identifier itself, and is the core of ensuring the effectiveness and traceability of the identifier. Its content is fixed and mandatory. The business identifier body is the core load of the business identifier, which is used to record the specific security attributes of the identified power data. Due to the diversity of power industry business scenarios (development, finance, safety supervision, equipment, marketing, infrastructure, materials, human resources, dispatching, trading, integrated data, etc.), the focus of data security differs in different business scenarios. Therefore, the business identifier body can be designed in an open manner. The business identifier body contains a security attribute item, which is defined by the specific application project according to the needs. The flow identifier is a network flow security identifier constructed based on the size, direction, protocol and other characteristics of network traffic. The flow identifier is a standardized information carrier for accurately recording and controlling the flow relationship of power data in the network. Through the description of the flow path, participating subjects and technical characteristics of the data, the visualization tracking, permission verification and security audit of the data transmission process across systems and networks are realized. The flow identifier can include a flow identifier header and a flow identifier body. The flow identifier header is an information carrier of the flow identifier, which is used to ensure the uniqueness, effectiveness and verifiability of the identifier itself, and provides a basic anchor point for the traceability of the flow relationship. Its fields are mandatory and fixed. The flow identifier body is the core load of the flow identifier, which specifically records the key relationship characteristics of data in network flow, focusing on the core issues such as "who is transmitting, where is transmitting, and how is transmitting". Each flow identifier contains an association relationship between itself and the business identifier. The flow identifier is designed specifically for the cross-domain flow scenario of power data, and is used to solve the problems of "source traceability, path controllability and permission clarity" in the data flow process.
[0076] The execution subject of the present example is a control platform. The business identifier can be generated at the control platform or the business server, the flow identifier can be generated at the corresponding flow transfer node, the business identifier can be injected by the corresponding business server, the flow identifier can be injected at the corresponding flow transfer node, and the extraction of the security identifier can be performed by the flow transfer exit node. For an access request from the outside, data needs to be obtained by different business systems in the management information area and then returned to the external network user through the Internet area. During the data flow transfer process, according to different types of business data, a business identifier is generated and embedded into the data content at the corresponding business server; when the data is transmitted to the first flow transfer node of the network transmission link, the first flow transfer node quickly extracts the business identifier, and according to the business identifier, the corresponding flow identifier is generated in combination with the network flow characteristics, the flow identifier contains the association relationship between itself and the business identifier, and the corresponding flow identifier is injected into the network flow. For the second flow transfer node and the flow transfer nodes thereafter, the flow identifier of the previous hop flow transfer node is extracted, and a new flow identifier is generated based on the extracted flow identifier and the current network flow attribute and injected into the current flow transfer node, and the association relationship between the extracted flow identifier and the new flow identifier is sent to the control platform for updating the security identifier knowledge graph, and a flow transfer relationship graph of the business identifier and the flow identifier is constructed. During the data flow transfer process, the dynamic generation and dynamic injection of the business identifier and the flow identifier are performed, the dynamic association of the business identifier and the flow identifier is realized, and then a dynamic association graph is generated, the association between the business identifier and each flow identifier is performed through the graph, the details of the transferred sensitive data content, level, etc. are quickly mastered, and based on the access characteristics, the space-time characteristics, the association characteristics and the timely identification of the data abnormal access process, the flow transfer exit node performs alarm, fusing, blocking and other operations for security risk disposal, improves the abnormal identification accuracy and the positioning accuracy of data leakage, and improves the system security protection capability.
[0077] Exemplarily, the business identifier header can include a business identifier number, a business identifier generation time, a validity period, a digital signature, the business attribute includes a business category and a data belonging detailed subcategory, and the security attribute can include a data security level, a data sensitivity, an identifier owner, a data access control policy, a data source, a data encryption state, a flow transfer range limit, etc. For example, the identifier header and the identifier body of the business identifier are shown in Table 1 and Table 2 as follows:
[0078] Table 1
[0079]
[0080] Table 2
[0081]
[0082] Exemplarily, the flow identifier comprises a flow identifier number, an association identifier, a source IP, a destination IP, a transmission interface, a cross-zone flow transfer direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier. For example, the identification header and identification body of the service identifier are shown in Table 3 and Table 4:
[0083] Table 3
[0084]
[0085] Table 4
[0086]
[0087] The flow identifier is mainly used to identify the flow relationship of data in the network, facilitating personnel to make rapid risk research and judgment. The present application designs two kinds of identifiers, i.e., service identifier and flow identifier, through power data security identifier, to standardize power data security management and realize the standardized information carrier of data security attribute structured description, aiming to support the security management, flow transfer tracking and permission governance of the whole life cycle of power data.
[0088] In some embodiments, the service identifier comprises a service identifier number, and the generation process of the service identifier comprises:
[0089] receiving a target service feature sent by a flow transfer entry node from a power management information zone, generating a corresponding service identifier based on the target service feature, and returning a service identifier number of the service identifier to the flow transfer entry node, so that the flow transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request;
[0090] The target service feature is obtained by scanning the service data and extracting the service feature of the service data.
[0091] In the example embodiment, after determining the service data associated with the service data access request, the service server extracts the corresponding service feature by scanning the service data and sends the service feature to the control platform. The control platform generates a corresponding service identifier based on the service feature according to the service identifier definition in Table 1 and Table 2 and returns a service identifier number to the corresponding service server. The service server injects the service identifier number into the corresponding service data. The service feature can include the service attribute and the security attribute in Table 1 and Table 2.
[0092] Exemplarily, the injection process of the service identifier comprises:
[0093] If the data structure of the target power data is unstructured data, the service identifier number is embedded in the attribute of the file where the target power data is located.
[0094] If the data structure of the target power data is semi-structured and structured data, the business identification number is injected into the extension field of the network message corresponding to the target power data through a dynamic hook injection mode.
[0095] In the example embodiment, for unstructured data such as files or pictures, a business identification is embedded in the attributes and content of the file; to ensure the lightness of the identification and the minimum impact on the business, only the data identification ID information is embedded in the identification content, and the corresponding identification header and identification body content of the identification are sent back to the identification management center. For semi-structured data or structured data in XML or JSOM format transmitted through an interface, the business characteristics are extracted by memory snapshot analysis, and the business identification number is injected into the extension field of the network message through a dynamic hook light injection mode. The example uses a non-intrusive hook mechanism, that is, through dynamic binary instrumentation (DBI) technology, the data generation and transmission events are captured in real time without modifying the source code of the business system.
[0096] In some example embodiments, the generation process of the flow identification includes:
[0097] For the first flow node, the network traffic is listened to at the flow node, and the business identification number in the network traffic is extracted by the information extraction hardware; the corresponding flow identification is generated based on the extracted business identification number and the attributes of the listened network traffic as the flow identification of the first flow node; wherein the flow identification of the first flow node includes the association relationship between the flow identification number and the business identification number.
[0098] For flow nodes other than the first flow node, the network traffic is listened to at each flow node, and the flow identification number in the listened network traffic is extracted by the information extraction hardware as an old flow identification number; a new flow identification is generated based on the old flow identification number and the attributes of the listened network traffic as the flow identification of the current flow node; wherein the new flow identification includes the association relationship between the new flow identification number and the old flow identification number.
[0099] In the example embodiment, the corresponding flow identification is generated at each flow node, and each flow node is installed with information extraction hardware, which can be an integrated circuit hardware such as an FPGA chip loaded with a multi-channel parallel identification ID. The flow identification generation process is as follows Figure 2As shown, when service traffic flows to the core node (transfer node), it listens to network traffic packets and uses dedicated information extraction hardware to quickly extract the identifier ID (identifier number) from the network traffic. For the first transfer node on the service access transfer link, the extracted identifier ID is the service identifier number; for other transfer nodes, the extracted identifier ID is the flow identifier number. Next, a new flow identifier is generated based on the extracted identifier ID and network traffic attributes (attributes in the identifier definition), and the association between the old identifier ID and the new identifier ID is established. The new flow identifier (including the association between the old and new identifier IDs) is sent to the control center. The transfer node re-injects the flow identifier ID into the network extension field for traffic forwarding. If the data packet does not have an identifier or its identifier is non-compliant, identifier ID extraction may fail. In this case, the transfer node can generate an identifier based on the data content and identifier definition. After the identifier is generated, the transfer node attaches the identifier to the end of the data content without changing the original data content and re-encapsulates it into a targeted data packet sent to the traffic receiving device. After receiving the data packet, the business visitor parses it. Because the identifier does not corrupt the original data content, the original data content can be successfully retrieved. In this example, a flow identifier can be quickly generated based on different business characteristics and identifier definitions.
[0100] For example, after generating the flow identifier, each flow node injects the flow identifier into the data to be flowed, including:
[0101] The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
[0102] In this example implementation, the flow identifier is injected into the optional field of the network traffic packet in a seamless manner, without affecting the content of the service message. For example... Figure 3 The diagram illustrates the injection of a flow identifier into a network IP packet. As can be seen, a network IP packet consists of several inherent parts. The flow identifier number (flow identifier ID) in the flow identifier header is injected into a reserved optional field (variable length) in the packet. After injection, it is transmitted along with the network traffic. The flow identifier is embedded in the network layer's expandable option field without affecting the use of the original data, thus achieving seamless injection into network packets.
[0103] In the business identification and flow identification injection process, the above example adopts a double-layer architecture of dynamic hook lightweight injection + network message non-sensing injection, and realizes seamless linkage of business identification and flow identification based on dynamic graph data association technology, so as to reduce the invasiveness of identification injection to the core business system to the minimum. Based on the hash mapping of the identification ID of the dynamic graph and the timestamp alignment, the millisecond-level association of the business identification and the flow identification is realized, the double-identification linkage engine is formed, and the "identification disconnection" problem in the traditional injection mode is solved. The identification ID of the example can be stored in the DHT (Distributed Hash Table) network. DHT is a kind of distributed computing system, which is used to disperse a set of keys to all nodes in the distributed system. The node here is similar to the storage location in the hash table. Distributed hash table is usually used for systems with a large number of nodes, and the nodes of the system often join or leave.
[0104] In some example embodiments, an initial security knowledge graph needs to be constructed before the access request starts, and the construction process of the initial security knowledge graph includes:
[0105] Extracting the business identification, entity information, entity relationship and entity attribute of the historical access behavior corresponding power data;
[0106] Extracting the flow identification generated by each flow node in the historical access behavior, and associating the business identification and each flow identification through the historical access behavior corresponding power data and data flow relationship;
[0107] Associating the business identification with the entity information, the entity relationship and the entity attribute, combining the association relationship between the business identification and the flow identification, and forming an initial knowledge graph;
[0108] Fusing the third-party power security knowledge base with the initial knowledge graph to form the initial security knowledge graph.
[0109] In the example embodiment, the generation and association of business identification and flow identification can be performed according to the relevant record data of historical access behavior. Through the content extraction of entities and their relationships and attributes based on business identification ID of the historical access behavior associated business features, data features and access features; extracting the flow identification generated by each flow node in the historical access behavior, and associating the business identification and each flow identification through the data flow relationship in the historical access behavior; finally, by fusing the existing third-party power security knowledge base, an initial security knowledge graph is formed. The initial security knowledge graph construction process is as follows: Figure 4As shown, first, based on the business identification and the flow identification, the identification ID information is used to extract entities, relationships, attributes, etc., to obtain the association relationship between the identifications; second, the associated knowledge of the extracted identification is combined with the third-party knowledge base to perform knowledge fusion, such as entity resolution, coreference resolution, and knowledge merging, to form an initial security knowledge graph.
[0110] In some example embodiments, after the new flow identification is generated, the following is further included:
[0111] Receiving the newly generated flow identification sent by each flow transfer node;
[0112] Based on the newly generated flow identification, the initial security knowledge graph is dynamically updated.
[0113] In the example embodiment, after each flow transfer node (including the first flow transfer node and other flow transfer nodes) generates a new flow identification, the identification ID (identification number) is injected into the network traffic and the newly generated flow identification is sent to the control platform, and the control platform updates the persistent security knowledge graph according to the received flow identification. As the real-time business access proceeds, the initial security knowledge graph is dynamically updated using the current business access behavior to form a security identification knowledge graph; the security identification knowledge graph is also dynamically updated as the access behavior proceeds. As shown, Figure 4 As shown, a graph database can also be established according to the knowledge graph construction system classification, containing a dynamic knowledge graph of multiple sub-graphs such as flow transfer path, interaction behavior, and access trend, providing a technical foundation for identification-driven data flow control. As shown, Figure 5 As shown, each flow identification ID (identification header) can be associated with corresponding identification bodies such as access source, access destination, and cross-domain flow transfer direction, the cross-domain flow transfer direction can be associated with corresponding data volume, the flow identification IDs can be associated, and the flow identification IDs and the business identification IDs can also be associated. The business identification ID (identification header) is associated with identification bodies such as data source, marketing business (business type), and data access range, the marketing business can be associated with electricity address and data sensitivity level, the data access range is associated with access strategy, and finally a knowledge graph like Figure 5 is established.
[0114] The present application takes business identification and flow identification as the basic carrier and dynamic knowledge graph as the association engine to construct a data-identification-behavior trinity identification association system. Compared with traditional static rule matching technology, the linear rule limitation is broken, the multi-dimensional association capability of the knowledge graph is used to quickly identify the data flow transfer process across businesses and networks.
[0115] In some embodiments, when the access request corresponding business data flow is transferred to the transfer export node of the Internet large area, the transfer export node extracts the last flow identifier of the flow identifier of the outgoing network traffic to obtain the last flow identifier, i.e. the security identifier, and sends the security identifier to the control platform, so that the control platform reverses the identification ID association from the security identifier, and the security identifier is matched in the security identifier knowledge graph based on the security identifier, including:
[0116] Based on the association relationship between the flow identifier number of the last transfer node and the flow identifier number of each transfer node in the data transfer process, the corresponding business identifier and the complete transfer path of the business data are associated in the security identifier knowledge graph;
[0117] Based on the business identifier, the corresponding associated business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding associated access behavior and access trend are associated in the security identifier knowledge graph.
[0118] In the example embodiment, the flow identifier of the last transfer node is associated in the security identifier knowledge graph to associate the transfer path. Since the real-time generation of the flow identifier and the ID injection in the data transfer process corresponding to the current access behavior and the update of the security identifier knowledge graph through the flow identifier ID association relationship of adjacent transfer nodes, the security identifier knowledge graph has a transfer association relationship. The last hop identifier ID can be reversely tracked to obtain the complete transfer path. Through the complete transfer path, the association of business features (business type, data volume, etc.), access behavior, data range and access trend, etc. is performed, such as Figure 5 In the example embodiment, the flow identifier ID-flow identifier ID-business identifier ID is associated through the complete transfer path. Through the path, the business type, data volume, data range, access strategy, etc. can also be associated. The final association matching result includes the complete transfer path, the associated business features, the associated access behavior and the access trend.
[0119] In an example embodiment, the transfer of the target power data at the transfer export node is controlled based on the association matching result, including:
[0120] Based on the abnormal analysis model and the complete transfer path, the associated business features, the associated access behavior and the access trend are analyzed to determine the abnormal behavior;
[0121] An abnormal handling strategy corresponding to the abnormal behavior is generated, and the transfer of the target power data at the transfer export node is controlled based on the abnormal handling strategy;
[0122] The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
[0123] In this example implementation, an anomaly analysis model can be constructed based on historical access behavior of power business data. This anomaly analysis model is essentially the relationship between features and abnormal behaviors. For example... Figure 6 As shown, considering the cross-regional correlation characteristics of security identifier knowledge graphs and abnormal behaviors, this example constructs a dynamic mapping relationship between cross-regional multi-dimensional features and abnormal behaviors. Cross-regional multi-dimensional features include business characteristics, access characteristics, spatiotemporal characteristics, and traffic flow trends. Abnormal behaviors can include abnormal access to sensitive data (such as excessive sensitive data access), excessive marketing data access, illegal access to core data, abnormal interface access, etc. The current access behavior can be used to dynamically update the anomaly analysis model. By constructing the correlation between cross-regional data through multi-dimensional features, and combining data access behavior, a fine-grained anomaly analysis model for cross-domain data flow can be constructed. For example, for the abnormal behavior of sensitive data leakage, such as monitoring a marketing payment interface, if it is accessed by a single terminal, and within a unit period (e.g., 15 minutes or 1 hour), the number of accesses exceeds a threshold (e.g., 50 times), and the total data volume exceeds a data volume abnormal threshold (e.g., 100M), and the accessed data content contains sensitive data, then the abnormal behavior rule is met. For abnormal interface access that does not conform to the baseline, such as when a user accesses a power distribution service data interface, the system learns from historical data such as the number of times the user accesses the interface and the content of the interface interaction data. This allows the system to learn the trend of the interface data. If the deviation (the proportion of deviation from the preset baseline) is large the next time the interface data is accessed, an abnormal behavior alarm will be generated. Anomaly handling strategies can include alarms, circuit breakers, and blocking.
[0124] For example, such as Figure 6As shown, first, the flow ID extracted by the receiving flow export node is compared with the security identification knowledge graph, the cross-domain business process is sorted out through the identification association relationship of the graph, the "business process node" is constructed in the graph, the association edge of "data node→business process node→target business domain node" is defined, and the details of the sensitive data content and level of the flow are quickly mastered. For example, for the unmanned aerial vehicle flight trajectory data flow process, from the management information district business library→internal network unmanned aerial vehicle business application→Internet unmanned aerial vehicle application→Internet unmanned aerial vehicle business. Then, based on the data access behavior, the data cross-domain fine-grained flow anomaly analysis model is used to analyze and output the data abnormal behavior. For example, for the unmanned aerial vehicle flight trajectory data flow process, first, the Internet district flow identification is associated with the business identification, the unmanned aerial vehicle business operation trajectory data obtained by the Internet unmanned aerial vehicle business application at a certain time can be obtained, and the data amount (such as 50M) of the operation trajectory data obtained this time is known. Compared with the abnormal threshold (determined based on the historical access behavior), if the deviation is within the allowed range, the access behavior is normal, and if the abnormal threshold is exceeded, the abnormal behavior type is output. Finally, according to the abnormal behavior judgment result, an abnormal handling strategy is generated, and the abnormal handling strategy is sent to the flow export node for alarm, fusing, blocking and other risk handling to avoid sensitive data leakage and other risks and improve system security. The example is based on the extracted identification information, associates the identification graph, finds out the association relationship between data, analyzes the abnormal behavior of data access based on different dimensions such as business characteristics, access relationship, time clues and traffic trend, finds out the data leakage point, and performs alarm, fusing and blocking of different levels of security protection based on different risk levels of abnormal behavior.
[0125] In an example implementation, the information extraction process of the information extraction hardware includes:
[0126] Obtaining network traffic to be extracted, removing irrelevant network traffic through a preset frame header feature, and obtaining target network traffic;
[0127] Cutting the target network traffic into a plurality of micro data blocks according to a preset length, and distributing the plurality of micro data blocks to a plurality of parallel processing channels; wherein the micro data blocks correspond to the processing channels one by one; in each processing channel, a specific feature of an identification mask is compiled into a hardware executable logic gate circuit;
[0128] Parallelly executing the logic gate circuit to realize logical operation of target bit positions of each micro data block, extracting metadata of a data packet in which a flow identification number is located in each micro data block, and storing the metadata in a memory for calling by an application layer;
[0129] Wherein, the identification mask is a bit-level feature mask of the flow identification number in the micro data block; the target bit position corresponds to the specific feature.
[0130] In the present example embodiment, the interactive service traffic (to-be-extracted network traffic) can be obtained through network traffic mirroring, and the to-be-extracted network traffic includes network traffic at each flow transfer node and network traffic at the flow transfer exit node. Unrelated traffic (such as data packets of non-target services) can be quickly removed through preset frame header features (such as an Ethernet type field and a VLAN tag). As shown in Figure 7 The serial bit stream is cut into fixed-length micro data blocks and distributed to multiple parallel processing channels (such as logic gate circuit 1, logic gate circuit 2, logic gate circuit 3,...) inside the information extraction hardware (such as FPGA), and each channel independently carries a certain data flow, such as each channel carrying no more than 12.5 Gbps sub-flow (such as data stream 1, data stream 2, data stream 3,...), to avoid serial processing bottlenecks. A "bit-level feature mask" of data flow identification is preconfigured in the FPGA, and specific features (such as the starting bit offset of a specific field and the check bit rule) of the flow identification are compiled into hardware executable logic gate circuits. The micro data blocks are directly compared through the mask, and multiple channels simultaneously perform logical operations on the target bit positions (corresponding to specific features) of the respective data blocks, without the need to parse IP, TCP, and other network protocol messages or protocol headers. The basic metadata of the data packets of the identification are automatically extracted through hardware logic, and are written in batches to the host memory through a PCIe (Peripheral Component Interconnect Express) interface in a DMA (Direct Memory Access) manner, such as writing the UUIDs of data stream 1, data stream 2, and data stream 3. In this way, the application layer can directly obtain the identification information, avoiding the delay of packet-by-packet interaction. The present example utilizes the parallel computing capability of the designed special hardware (information extraction hardware) to directly realize real-time and high-speed extraction of data security identification, skipping the traditional redundant process of "first parsing protocol fields and then locating content", and improving the identification speed.
[0131] For example, as shown in Figure 8As shown, when the data flow is transferred to the flow transfer exit node, the security identifier, i.e. the last hop flow identifier ID, is quickly located and extracted from the high-speed network message, realizing fast extraction of the identifier; then, correlation analysis is carried out: the extracted identifier is dynamically bound with the context to construct a relationship network. Not only the "user identity card number" is identified, but also its source (which business interface is transmitted), associated data (such as bound mobile phone number, address), access record (such as who has viewed) and the like are associated, forming a complete data flow portrait. In combination with the data access behavior, the associated data is risk judged. Finally, accurate response is carried out, i.e. according to the analysis result, targeted measures including blocking operation, triggering alarm and the like are automatically taken. The method takes "identifier full-link penetration" as the core, constructs a closed-loop protection system of "fast extraction-graph correlation analysis-accurate protection", and realizes full-process automation of sensitive data from identification to control through deep integration of dynamic graph.
[0132] With the large-scale development of new formats such as unmanned aerial vehicles, vehicle-network interaction and energy big data services, and the continuous deepening of power data application system with extensive business interaction, the number of power data transfer and processing nodes increases, the transfer path is extended, which leads to a substantial increase in sensitive data leakage links and risks, and the challenges of data leakage discovery, transfer tracking and leakage subject responsibility definition continue to rise. At present, more than 37,500 effective data leakage events have been monitored, and the number of cases of data leakage caused by attackers using various new attack methods has increased by 71% year-on-year. The threat of data leakage attacks from the outside is also increasing. The traditional data protection system based on content recognition relies on high-precision identification of sensitive information, and has low prevention and control efficiency and false positives and false negatives. Moreover, the power grid business application and data interaction chain are complex, and the data leakage points are multiple and widespread, making it difficult to achieve accurate protection of power data cross-domain transfer.
[0133] Under this background, the traditional data leakage perception scheme: match specific keywords and phrases through regular expressions, or use different static statistical methods. However, the keyword-based method is not accurate enough for data leakage detection scenarios, and it is difficult to detect data that has been transformed. For example, the "pole tower coordinates" in power distribution may be rewritten as "pole tower position" or split into "pole·tower·seat·coordinates", which cannot be detected and is prone to false negatives.
[0134] With the development of technology, the rise of artificial intelligence technology, starting to turn to machine learning, up and down semantic association into artificial intelligence technology. But the content-based sensitive data leakage perception method considers less about the context association of the text and the document structure, and the detection effect of the transformed data is not ideal. Some research has been focusing on how to detect transformed data. However, most of them only consider the relatively simple case, such as adding or deleting some content from the original file. In actual situations, the degree of data transformation is often relatively large, and if the data with large transformation cannot be well detected, there is a high risk of data leakage. For example, the existing technology with the patent name of a kind of full link data security protection method generates a security identifier in the data collection stage, uploads the identifier information and the meaning represented by the identifier to the cloud service center in the data transmission stage, decrypts the identifier and the secret value when the data needs to be processed and exchanged, and then checks and controls with the cloud service center identifier information. The data destruction stage can be processed as needed. The specific content of each step includes: constructing a data security identifier in the data collection stage, dividing the ciphertext file into blocks and generating ciphertext components in the data transmission and storage stage, calculating the virtual index and data label, sending the ciphertext components to the DHT network, uploading the tuple composed of the virtual index data block and the data label to the cloud server, re-encrypting based on the re-encryption key generation algorithm in the data processing and data exchange stage, obtaining the tuple of the associated index of the ciphertext component after decryption, realizing fine-grained access control of cloud storage based on attribute proxy re-encryption, and realizing data self-destruction using the automatic update function of the DHT network in the data destruction stage. This method is highly dependent on the key generation center. It is responsible for the registration, key generation and distribution, data collection, transmission and other stages of all users (data owners and users), and the advance, check control of data identifier information. The key management and distribution are complex. At the same time, the symmetric key needs to be associated with the security attribute and indirectly distributed to the authorized user through attribute-based encryption. This process involves re-encryption and derivation of multiple keys, which requires high data retrieval efficiency, performance, and lacks lightweight, high real-time, fine-grained identification-based data flow control features. For the existing technology with the patent name of a method for real-time dynamic processing of structured data security identification, the core idea of the method includes: calling the sensitive data recognition engine through the data connection security component to scan the obtained data content, the sensitive data recognition engine extracts the natural semantic of the data content, and compares the semantic similarity with the security points provided by the policy management service, and returns the security level and related security attributes of the corresponding security point for the data with a specified threshold similarity, and completes the automatic judgment of the data security level; the database connection security component calls the sensitive data processing component to encode the security level and related security attributes according to the result of the security level judgment, and generates data security identification according to the abstract syntax mark; the sensitive data processing component binds the generated data security identification with the corresponding data item.The method writes the security identifier as part of the data in the database in plaintext form together with the original data, and there is a certain security risk, for example, any malicious user who can directly access the database (through database management tools, command lines, or using SQL injection vulnerabilities) can easily modify or strip the security identifier, thus completely invalidating the security control.
[0135] However, the traditional sensitive content recognition technology based on regular expressions, keyword matching or rule library also faces the following two main problems in the process of data leakage monitoring and data cross-domain flow control: (1) The recognition ability of the regular expression, keyword matching or rule library sensitive content recognition technology is limited by the coverage and update frequency of the preset rule library. At the same time, due to the highly dynamic characteristics of the expression form of sensitive information, attackers can easily bypass rule detection through synonym replacement, character confusion (such as Unicode encoding conversion), format transformation (such as segmented display, picture embedding) and other means, and the prevention and control efficiency is low and there are false positives and false negatives. It is difficult to achieve efficient and accurate data leakage risk prevention and control. (2) Existing data leakage risk tracing methods are mainly single-point tracing, and the flow path of data leakage depends on manual expert experience mining and correlation analysis of information on each link, which has the problems of low analysis efficiency, unclear description of data leakage flow path of each node, etc. It is difficult to accurately locate the data leakage node and transmission path, resulting in coarse granularity of data cross-domain management and control and incomplete coverage.
[0136] In view of the above problems, the present application considers that the security identifier technology can embed pre-defined security attribute information in the data, and accompany the whole process of data flow, so the security identifier is used as the key basic technology to solve the data cross-domain flow control. Considering the problems of poor accuracy of sensitive data recognition and large risk control granularity in the process of power data cross-domain flow, a security identifier driven power data cross-domain flow control method and device are proposed, such as Figure 9As shown, according to the different professional business data characteristics of power finance, equipment, marketing, dispatching and the like, based on the existing classification and grading guide, the power business data security identifier, that is, the business identifier, is constructed, and based on the network flow size, direction, protocol and the like, the network flow security identifier, that is, the flow identifier, is constructed. According to different types of business data, the business identifier is embedded into the data content, when the data is transmitted, the business identifier is quickly identified, the flow identifier is generated according to the content of the business identifier, combined with the network flow characteristics, and is injected into the network message extension field, and a flow transfer relationship knowledge graph of the business identifier and the flow identifier is constructed. The special hardware (information extraction hardware) is used to quickly extract the network identifier, without needing to parse the protocol message, the details of the sensitive data content and the level and the like in the flow transfer are quickly mastered through the identifier association relationship of the graph, and a fine-grained flow control model is constructed based on access characteristics, space-time characteristics, association characteristics and the like, and the data abnormal access process is timely alarmed, fused, blocked and the like.
[0137] The present application considers that the security problems such as data leakage may occur in the process of power data flow transfer in multiple regions such as production control region, management information region and Internet region, and proposes a security identifier driven power data cross-domain flow control method, constructs the data business identifier and flow identifier of power characteristics, embeds the business identifier in the data source end for different data types of structured and unstructured data, embeds the flow identifier in the flow process, establishes the association relationship of the flow identifier and the business identifier based on graph data, extracts the identifier characteristics in the flow by using special hardware, quickly realizes the multi-link flow tracing of power data, associates the access behaviors of data, constructs the security identifier driven power data cross-domain flow control model and forms the corresponding device and equipment, so as to improve the efficiency and accuracy of power sensitive data cross-domain flow control.
[0138] The security identifier driven power data cross-domain flow control method can improve the accurate perception and full-link tracing and tracing capabilities of power sensitive data leakage, prevent and resolve the risks of power data illegal out-of-domain and data leakage behaviors, the related achievements can be converted into data security products, strengthen and supplement the existing data security capabilities, can be widely applied to data cross-subject interaction, middle platform application and the like, guarantee the security of power business data, improve the security protection level of data sharing and interaction in the new power system, and has great potential value.
[0139] Embodiment 2
[0140] Based on the same inventive concept, the present application also discloses a power data cross-region flow transfer control platform, comprising:
[0141] a data association module configured to determine target power data associated with the service data access request based on the received service data access request from the external user, wherein the target power data is obtained by injecting a service identifier into corresponding power service data, and the service identifier is used to represent service attributes and security attributes of the service data;
[0142] a flow control module configured to control data flow of the target power data in the power management information zone and the Internet zone based on service calling relationships between different power service systems, receive a security identifier sent from a flow export node in the Internet zone when the target power data flows to the flow export node, and perform association matching in a security identifier knowledge graph based on the security identifier, and control flow of the target power data at the flow export node based on the association matching result;
[0143] In the data flow process, a flow identifier is injected into data to be flowed at each flow node in the power management information zone and the Internet zone, each flow identifier contains an association relationship between itself and a service identifier, the flow identifier is used to represent flow relationships of power service data associated with the service identifier in the power communication network, the security identifier is a flow identifier corresponding to the last flow node, the security identifier knowledge graph is obtained by dynamically updating an initial security knowledge graph based on a current access behavior through the mutually associated service identifier and flow identifier, and the initial security knowledge graph is constructed based on historical access behaviors of power data.
[0144] In the example embodiment, the power data cross-zone flow control platform can be arranged in the power management information zone or in the cloud side.
[0145] In a possible implementation, the flow identifier includes a flow identifier number, an association identifier, a source IP, a destination IP, a transmission interface, a cross-zone flow direction identifier, and a data volume identifier, and the association identifier is used to establish an association between the flow identifier and the service identifier.
[0146] In a possible implementation, the service identifier includes a service identifier number, and the system further includes:
[0147] a service identifier generation module configured to receive a target service feature sent from a flow import node in the power management information zone, generate a corresponding service identifier based on the target service feature, and return a service identifier number of the service identifier to the flow import node, so that the flow import node injects the received service identifier number into service data associated with the service data access request based on a data structure of the service data.
[0148] The target service feature is obtained by scanning the service data and extracting service features of the service data.
[0149] In a possible implementation, the flow control module comprises an initial graph construction submodule, which is configured to:
[0150] extract the business identifier, entity information, inter-entity relationship and entity attribute of the power data corresponding to the historical access behavior;
[0151] extract the flow identifier generated by each flow transfer node in the historical access behavior, and associate the business identifier with each flow identifier through the power data corresponding to the historical access behavior and the data flow transfer relationship;
[0152] associate the business identifier with the entity information, inter-entity relationship and entity attribute, and form an initial knowledge graph in combination with the association relationship between the business identifier and the flow identifier;
[0153] fuse the third-party power safety knowledge base with the initial knowledge graph to form the initial safety knowledge graph.
[0154] In a possible implementation, the flow control module further comprises a graph updating submodule, which is configured to:
[0155] receive the newly generated flow identifier sent by each flow transfer node;
[0156] dynamically update the initial safety knowledge graph based on the newly generated flow identifier;
[0157] The new flow identifier is generated by each flow transfer node based on the old flow identifier of the previous flow transfer node.
[0158] Embodiment 3
[0159] Based on the same inventive concept, the application further discloses a power data cross-region flow control system, comprising the power data cross-region flow control platform according to the embodiment 2.
[0160] In an example implementation, further comprising: a plurality of network traffic aggregation devices located in the power management information region and the Internet region, and a network traffic outflow device located in the Internet region; each network traffic aggregation device serves as a flow transfer node, and the network traffic outflow device serves as a flow transfer export node.
[0161] In the example embodiment, the network traffic aggregation device can be a switch or router between different service systems in the power management information zone and the Internet zone, and the network traffic outflow device can be a router. Through joint design of hardware and software of the devices, flow identity injection, fast flow identity extraction and abnormality handling are implemented, so as to improve the security protection capability of power-sensitive data cross-domain flow and ensure data flow control efficiency.
[0162] In an example embodiment, the method further comprises a service server located in the power management information zone, and the service server is used as a flow transfer entry node; the service server is configured to:
[0163] If the target power data is unstructured data, the service identity number is embedded in a property of a file in which the target power data is located.
[0164] If the target power data is semi-structured or structured data, the service identity number is injected into an extension field of a network packet corresponding to the target power data through a dynamic hook injection manner.
[0165] In an example embodiment, each network traffic aggregation device is configured to:
[0166] The flow identity number is injected into an optional field of a network traffic data packet corresponding to the data to be transferred.
[0167] In an example embodiment, each network traffic aggregation device is further configured to:
[0168] The network traffic aggregation device corresponding to the first flow transfer node is further configured to:
[0169] The network traffic aggregation device corresponding to the first flow transfer node is further configured to:
[0170] For the network traffic aggregation device corresponding to the flow transfer node other than the first flow transfer node, the network traffic aggregation device is further configured to: listen to network traffic, extract a flow identity number in the listened network traffic through information extraction hardware as an old flow identity number; and generate a new flow identity based on the old flow identity number and a property of the listened network traffic as a flow identity of a current flow transfer node; wherein the new flow identity comprises an association relationship between the new flow identity number and the old flow identity number.
[0171] In an example embodiment, each network traffic aggregation device and the network traffic outflow device are installed with information extraction hardware; the information extraction hardware is configured to:
[0172] The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic;
[0173] The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits;
[0174] The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call;
[0175] Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
[0176] This invention constructs power business identifiers and flow identifiers, and studies identifier injection methods based on different data and flow characteristics to achieve rapid injection of security identifiers. It utilizes dedicated hardware to achieve rapid capture and precise protection of security identifiers, thereby realizing lightweight, high real-time, and fine-grained data flow control.
[0177] For example, such as Figure 10 As shown, this is a security identifier-driven cross-domain power data flow control system designed based on the above security identifier model. The system includes: a business server for business identifier injection, a network traffic aggregation device for flow identifier generation and injection, a network traffic outflow device for precise protection of network traffic sensitive data, and a cross-regional flow control platform.
[0178] Take the typical external interaction services such as power business unmanned aerial vehicle, can, etc. As an example, deploy the service identification injection capability on the business server of the management information system, deploy the flow identification generation and injection capability in the process of unmanned aerial vehicle service flow, deploy the sensitive data accurate protection capability at the boundary traffic export, and deploy the cross-region flow control platform in the management information area. Among them, the business server first scans the business data content quickly, and sends the business data characteristics to the cross-region flow control platform. The cross-region flow control platform generates the service identification according to the business characteristics, and the business server is responsible for injecting the service identification ID into the business data. The information extraction hardware in the network traffic aggregation device quickly extracts the identification information, and according to the identification information, quickly generates the flow identification of the node, and is responsible for injecting the newly generated flow identification ID into the network traffic packet. At the same time, the generated flow identification is synchronized to the cross-region flow control platform. The network traffic export device can quickly extract and identify the identification information, and send the identified identification ID information to the cross-region flow control platform. The cross-region flow control platform receives the disposal strategy sent by the cross-region flow control platform, and sends the abnormal disposal control instruction to the network traffic export device according to the disposal strategy to perform alarm, fuse and block operations on the network message. The cross-region flow control platform has the functions of automatic generation of identification, identification management, identification association, cross-domain flow abnormal behavior analysis, policy configuration, etc. Finally, it provides a complete data leakage evidence chain, realizes the functions of static data and flow data labeling and tracking, flexible adjustment of anti-leakage strategy and accurate traceability of risk.
[0179] For the deployment of service identification injection capability: for the data stored in the business database of the management information area, deploy the business data identification injection capability and integrate with the business system, inject the identification information ID into the accessed data set, when a user or business accesses the data through database access tools or interfaces, the identification will flow with the data, at the same time, the identification information is synchronized to the cross-region flow control platform.
[0180] For the deployment of flow identification generation and injection capability: the flow identification injection capability is deployed at the traffic aggregation point of business call. When the business data flows through the flow identification injection, the flow data identification will be generated according to the identification information, and the flow data identification ID will be injected into the extension field of the network message, which does not affect the original message. At the same time, the flow identification information is synchronized to the identification cross-region flow control center, which is convenient for the description of data flow path.
[0181] Deployment of sensitive data accurate protection capability: the sensitive data accurate protection capability is deployed at the traffic export of the Internet large area, responsible for extracting the identification ID information of the last hop, and reporting to the cross-area flow control platform. The cross-area flow control platform associates the access process of the relevant identification based on the identification header information of the last hop, and conducts comprehensive research and judgment and early warning, and issues relevant policies to the traffic export device to prewarn or block the subsequent data access behavior. At the same time, the flow of important data without label is monitored, the message content is captured, analyzed, deeply identified, and the behavior and content are analyzed according to the rules, and the analysis result is uploaded to the identification cross-domain flow control center.
[0182] Deployment of cross-area flow control platform: the cross-area flow control platform is deployed in the management information large area, responsible for receiving the identification information of each flow node and flow-out node, conducting comprehensive research and judgment, tracing the sensitive data after leakage, determining the flow path of the sensitive data, and issuing policies to the traffic export device to block the subsequent related threat access.
[0183] The power data cross-domain flow control system based on the security identification driving provided by the application constructs the data business identification and flow identification of the power characteristics, embeds the business identification in the data source end for the structured and non-structured different data types, embeds the flow identification in the flow process, establishes the association relationship between the flow identification and the business identification based on the graph data, extracts the identification features in the traffic by using the special hardware, realizes the power data multi-link flow tracing, associates the data access behavior, constructs the security identification driven power data cross-domain flow control model, and forms the corresponding device and equipment, so that the efficiency and accuracy of the power sensitive data cross-domain flow control are improved. Compared with the traditional content extraction method (keyword or regular identification method) and the context semantic analysis analysis model, there is a significant technical breakthrough.
[0184] The power data cross-domain flow control method and device based on the security identification driving provided by the application can be extended to other data cross-domain flow scenes, improve the energy industry data risk prevention ability and cross-domain data accurate protection ability, and effectively promote the value of energy data. For example, the technology can be further popularized to the data cross-domain flow scene of various industries and enterprises, provide a "one-stop" security solution for the value of data elements, serve the third-party accurate strategy, enterprise energy efficiency management and social livelihood security.
[0185] Embodiment 4
[0186] As Figure 11As shown, the present application also provides an electronic device, which can be a computer device, a single-chip microcomputer device, a smart mobile device, etc. The electronic device in the embodiment can include a processor, a memory, a transceiver component, etc. The memory, the processor and the transceiver component are connected through a bus; the memory can be used to store an execution program, and the exemplary execution program can include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, which can be called and / or modified when the instructions are executed.
[0187] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, and are suitable for implementing one or more instructions, and are specifically suitable for loading and executing one or more instructions in the storage medium to implement a corresponding method flow or a corresponding function, so as to implement the steps of the power data cross-region flow control method in the above embodiment.
[0188] Embodiment 5
[0189] Based on the same inventive concept, the present application also provides a readable storage medium, specifically an electronic device readable storage medium (Memory). The electronic device readable storage medium is a memory device in the electronic device, and is used to store programs and data. It can be understood that the storage medium herein can include a built-in storage medium in the electronic device, and of course can also include an expansion storage medium supported by the electronic device. The storage medium provides a storage space, and the storage space stores an operating system of the terminal. Moreover, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and the instructions can be one or more execution programs (including program codes). It should be noted that the storage medium herein can be a high-speed RAM memory, or a non-volatile memory, such as at least one disk memory. The processor loads and executes one or more instructions stored in the storage medium, and the steps of the power data cross-region flow control method in the above embodiment can be implemented.
[0190] Those skilled in the art will appreciate that embodiments of the application can be devised for a method, a system, or a computer program product. Accordingly, the present application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.
[0191] The present application is described in reference to the flowchart and / or block diagrams of the method, apparatus (system) and computer program product according to embodiments of the application. It will be understood that each block of the flowchart and / or block diagrams, and combinations of blocks in the flowchart and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing device or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0192] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0193] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0194] Finally, it should be noted that the above-mentioned embodiments are merely used to illustrate the technical solutions of the present application, but not to limit the scope of protection of the present application. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that: after reading the present application, those skilled in the art can make various changes, modifications or equivalent replacements to the specific embodiments of the application, but these changes, modifications or equivalent replacements are all within the scope of protection of the claims of the application.
Claims
1. A method for controlling the cross-regional transfer of power data, characterized in that, include: Based on the received business data access request from an external user, the target power data associated with the business data access request is determined; wherein, the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; Based on the business call relationship between different power business systems, the target power data is controlled to flow within the power management information region and the Internet region; wherein, during the data flow process, a flow identifier is injected into the data to be flowed at each flow node within the power management information region and the Internet region, and each flow identifier contains the association relationship between itself and the business identifier. The flow identifier is used to characterize the flow relationship of the power business data associated with the business identifier in the power communication network. When the target power data flows to the flow exit node of the Internet region, a security identifier sent from the flow exit node is received; based on the security identifier, an association matching is performed in the security identifier knowledge graph, and the flow of the target power data at the flow exit node is controlled based on the association matching result; wherein, the security identifier is the flow identifier corresponding to the last flow node; the security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through interrelated business identifiers and flow identifiers, and the initial security knowledge graph is constructed based on the historical access behavior of the power data.
2. The method according to claim 1, characterized in that, The flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier.
3. The method according to claim 1, characterized in that, The service identifier includes a service identifier number, and the process of generating the service identifier includes: The system receives target service features sent from the transfer entry node of the power management information region, generates a corresponding service identifier based on the target service features, and returns the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
4. The method according to claim 3, characterized in that, The injection process of the business identifier includes: If the target power data has an unstructured data structure, the business identifier is embedded into the attributes of the file containing the target power data. If the target power data has a semi-structured or structured data structure, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
5. The method according to claim 2, characterized in that, The process of injecting a flow identifier into the data to be transferred includes: The flow identifier is injected into an optional field of the network traffic data packet corresponding to the data to be transferred.
6. The method according to claim 2, characterized in that, The process of generating the flow identifier includes: For the first transfer node, network traffic is monitored at the transfer node, and the service identifier in the network traffic is extracted through information extraction hardware; based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node; wherein, the flow identifier of the first transfer node includes the association relationship between the flow identifier and the service identifier. For all other flow nodes except the first flow node, network traffic is monitored at each flow node, and the flow identifier in the monitored network traffic is extracted by information extraction hardware as the old flow identifier. A new flow identifier is generated based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node. The new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
7. The method according to claim 6, characterized in that, After the new flow identifier is generated, it also includes: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers.
8. The method according to claim 7, characterized in that, The process of constructing the initial security knowledge graph includes: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
9. The method according to claim 8, characterized in that, The security identifier is the flow identifier number of the last transit node obtained by extracting the flow identifier of the outgoing network traffic from the transit exit node; the association matching result includes the complete transit path, associated business characteristics, associated access behavior, and access trend; Based on the security identifier, association matching is performed in the security identifier knowledge graph, including: Based on the flow identifier of the last flow node and the association between the flow identifiers of each flow node during the data flow process, the corresponding business identifier and the complete flow path of the business data are associated in the security identifier knowledge graph. Based on the business identifier, the corresponding related business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding related access behaviors and access trends are associated in the security identifier knowledge graph.
10. The method according to claim 9, characterized in that, Controlling the flow of the target power data at the flow exit node based on the correlation matching results includes: Based on the anomaly analysis model and the complete flow path, anomaly analysis is performed on the related business characteristics, related access behaviors and access trends to identify abnormal behaviors. A corresponding anomaly handling strategy is generated for the abnormal behavior, and the flow of the target power data at the flow exit node is controlled based on the anomaly handling strategy; The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
11. The method according to claim 6, characterized in that, The information extraction process of the information extraction hardware includes: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
12. A cross-regional power data transfer control platform, characterized in that, include: The data association module is used to determine the target power data associated with the received business data access request from the external user; wherein the target power data is obtained by injecting a business identifier into the corresponding power business data; the business identifier is used to characterize the business attributes and security attributes of the business data; The data transfer control module is used to control the data transfer of the target power data within the power management information region and the Internet region based on the business call relationship between different power business systems. When the target power data is transferred to the transfer exit node of the Internet region, the module receives a security identifier sent from the transfer exit node, performs association matching in the security identifier knowledge graph based on the security identifier, and controls the transfer of the target power data at the transfer exit node based on the association matching result. During the data transfer process, a flow identifier is injected into the data to be transferred at each transfer node within the power management information region and the internet region. Each flow identifier contains the association relationship between itself and the service identifier. The flow identifier is used to characterize the transfer relationship of power business data associated with the service identifier in the power communication network. The security identifier is the flow identifier corresponding to the last transfer node. The security identifier knowledge graph is obtained by dynamically updating the initial security knowledge graph based on the current access behavior through the interrelated service identifiers and flow identifiers. The initial security knowledge graph is constructed based on the historical access behavior of power data.
13. The control platform according to claim 12, characterized in that, The flow identifier includes a flow identifier number, an association identifier, a source IP address, a destination IP address, a transmission interface, an inter-regional flow direction identifier, and a data volume identifier; the association identifier is used to establish an association between the flow identifier and the service identifier.
14. The control platform according to claim 12, characterized in that, The service identifier includes a service identifier number, and the system further includes: The service identifier generation module is used to receive target service features sent from the transfer entry node of the power management information region, generate a corresponding service identifier based on the target service features, and return the service identifier number of the service identifier to the transfer entry node, so that the transfer entry node injects the received service identifier number into the service data based on the data structure of the service data associated with the service data access request; The target business feature is obtained by scanning the business data and extracting the business features from the business data.
15. The control platform according to claim 12, characterized in that, The flow control module includes an initial map construction submodule, which is used for: Extract the service identifier, entity information, inter-entity relationship, and entity attribute of the power data corresponding to the historical access behavior; Extract the flow identifiers generated by each flow node in the historical access behavior, and associate the service identifiers with each flow identifier through the power data and data flow relationship corresponding to the historical access behavior; By associating business identifiers with entity information, relationships between entities, and entity attributes, and combining the association between business identifiers and flow identifiers, an initial knowledge graph is formed. The initial safety knowledge graph is formed by integrating the knowledge from a third-party power safety knowledge base with the initial knowledge graph.
16. The control platform according to claim 15, characterized in that, The circulation control module further includes a map update submodule, which is used for: Receive the newly generated flow identifier sent by each flow node; The initial security knowledge graph is dynamically updated based on the newly generated flow identifiers; The newly generated flow identifier is generated by each flow node based on the old flow identifier extracted from the previous flow node.
17. The control platform according to claim 16, characterized in that, The security identifier is the flow identifier number of the last transit node obtained by extracting the flow identifier of the outgoing network traffic from the transit exit node; the association matching result includes the complete transit path, associated service characteristics, associated access behavior, and access trend; the transit control module also includes an association sub-module, which is used for: Based on the flow identifier of the last flow node and the association between the flow identifiers of each flow node during the data flow process, the corresponding business identifier and the complete flow path of the business data are associated in the security identifier knowledge graph. Based on the business identifier, the corresponding related business features are associated in the security identifier knowledge graph; based on the business identifier and each flow identifier, the corresponding related access behaviors and access trends are associated in the security identifier knowledge graph.
18. The control platform according to claim 17, characterized in that, The flow control module also includes: The anomaly analysis submodule is used to perform anomaly analysis on the associated business characteristics and associated access behaviors based on the anomaly analysis model and the complete flow path, and to determine the abnormal behavior. An anomaly control submodule is used to generate corresponding anomaly handling strategies for the anomaly behavior, and to control the flow of the target power data at the flow exit node based on the anomaly handling strategies. The anomaly analysis model is a correlation model between multi-dimensional features and abnormal behavior built based on historical access behavior of power data. The multi-dimensional features include business features, access features, spatiotemporal features, and traffic flow trends.
19. A power data inter-regional transfer control system, characterized in that, Including the power data cross-regional transfer control platform as described in any one of claims 12-18.
20. The system according to claim 19, characterized in that, Also includes: Multiple network traffic aggregation devices located in the power management information zone and the internet zone, and network traffic outflow devices located in the internet zone; Each network traffic aggregation device acts as a transfer node, and the network traffic outflow device acts as a transfer exit node.
21. The system according to claim 20, characterized in that, It also includes a business server located in the power management information zone, which serves as the entry point node for data transfer; the business server is used for: If the target power data is unstructured data, the business identifier number of the business identifier is embedded into the attributes of the file where the target power data is located; If the target power data is semi-structured or structured data, the service identifier is injected into the extended field of the network packet corresponding to the target power data through dynamic hook injection.
22. The system according to claim 20, characterized in that, Each network traffic aggregation device is used for: The flow identifier number generated by itself is injected into the optional field of the network traffic data packet corresponding to the data to be transferred.
23. The system according to claim 22, characterized in that, The network traffic aggregation device corresponding to the first transfer node is also used for: The system monitors network traffic and extracts the service identifier from the network traffic using information extraction hardware. Based on the extracted service identifier and the attributes of the monitored network traffic, a corresponding flow identifier is generated as the flow identifier of the first transfer node. The flow identifier of the first transfer node includes the association between the flow identifier and the service identifier. For network traffic aggregation devices corresponding to other flow nodes besides the first flow node, the following functions are also used: to monitor network traffic, extract the flow identifier from the monitored network traffic using information extraction hardware as the old flow identifier; generate a new flow identifier based on the old flow identifier and the attributes of the monitored network traffic as the flow identifier of the current flow node; wherein, the new flow identifier includes the association relationship between the new flow identifier and the old flow identifier.
24. The system according to claim 23, characterized in that, Each network traffic aggregation device and the network traffic outflow device are equipped with information extraction hardware; the information extraction hardware is used for: The network traffic to be extracted is obtained, and irrelevant network traffic is removed by using preset frame header features to obtain the target network traffic; The target network traffic is divided into multiple micro data blocks according to a preset length, and the multiple micro data blocks are allocated to multiple parallel processing channels; wherein, there is a one-to-one correspondence between the micro data blocks and the processing channels; in each processing channel, the specific features of the identifier mask are compiled into hardware-executable logic gate circuits; The logic gate circuits are executed in parallel to perform logical operations on the target bits of each micro data block, extract the metadata of the data packet containing the flow identifier in each micro data block and store it in memory for the application layer to call; Wherein, the identifier mask is a bit-level feature mask of the flow identifier in the pre-configured micro data block; the target bit corresponds to the specific feature; the network traffic to be extracted includes the network traffic at each flow node and the network traffic at the flow exit node.
25. An electronic device, characterized in that, include: At least one processor and memory; The memory and processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the method as described in any one of claims 1 to 11 is implemented.
26. A readable storage medium, characterized in that, It contains an executable program, which, when executed, implements the method as described in any one of claims 1 to 11.
Citation Information
Patent Citations
Data circulation method and device, computer equipment and storage medium
CN111738702A
Cross-regional interconnection detection method and device for power monitoring system and computer equipment
CN114244864A