A method for secure transmission and access of hydropower station data
By adding dynamic security level labels to hydropower station data and monitoring the transmission path quality in real time, combined with multi-protocol label switching technology and user access analysis, the problems of discontinuity and internal threats in hydropower station data transmission and access were solved, achieving stability and security of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUIZHOU WUJIANG HYDROPOWER DEV
- Filing Date
- 2026-02-03
- Publication Date
- 2026-04-24
AI Technical Summary
Existing technologies for data transmission and access in hydropower stations suffer from static security strategies, fixed transmission paths, and a lack of dynamic perception and user behavior analysis, resulting in discontinuous and unstable critical data transmission and difficulty in protecting against internal threats.
Dynamic security level labels are used to add high, medium and low security levels to hydropower station data, and transmission paths are selected according to the level. Path quality is monitored in real time, path switching is carried out using multi-protocol label switching, and access control policies are updated in real time by analyzing user access behavior.
Ensure that highly critical data is transmitted in encrypted and redundant channels, enabling intelligent optimization and seamless switching of transmission paths, proactively identifying internal threats, improving the continuity and stability of data transmission, and reducing the risk of leakage.
Smart Images

Figure CN121619178B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of secure transmission and access technology for hydropower station data, and relates to a method for secure transmission and access of hydropower station data. Background Technology
[0002] With the rapid development of smart hydropower, hydropower stations need to reliably transmit massive amounts of data in real time, both within the station and with the dispatch center. This data includes critical commands that directly control unit operation, monitoring data reflecting equipment status, and historical logs and environmental information used for analysis. Due to significant differences in real-time requirements and security levels, the security of data transmission and access is directly related to the physical security of power production and the stable operation of the power grid.
[0003] However, although existing technologies have laid a certain foundation for secure data transmission and access in hydropower stations, the following shortcomings still exist: First, in actual operating environments, different types of data, such as control commands and status monitoring, have significantly different requirements in terms of security criticality and real-time performance. Existing technologies typically employ static security strategies and fixed transmission paths. This extensive management approach is difficult to meet the confidentiality requirements of highly critical data in hydropower station industrial control systems, leading to the transmission of critical control commands through channels with insufficient security protection, thereby introducing potential risks.
[0004] Secondly, the network environment of hydropower stations is complex, and the quality of transmission paths fluctuates dynamically due to various factors such as equipment load and link congestion. Existing technical solutions mostly rely on fixed routing or simple load balancing strategies, lacking the ability to perceive end-to-end transmission path quality indicators, and are unable to quickly select optimal paths and seamlessly switch between them, thus making it difficult to guarantee the continuity and stability of data transmission.
[0005] Finally, in actual operation, legitimate user accounts may be stolen, and their behavior may also be abnormal. These may be precursors to internal threats or potential attacks. Existing technology lacks continuous analysis of user access behavior, which makes the system lack proactive protection capabilities when facing internal threats or lateral movement attacks. Summary of the Invention
[0006] In view of this, in order to solve the problems mentioned in the background art, the present invention provides a method for secure transmission and access of hydropower station data.
[0007] The objective of this invention can be achieved through the following technical solution: a method for secure transmission and access of hydropower station data, comprising: S1, adding dynamic security level labels of high, medium, and low to the hydropower station data based on the criticality of the hydropower station data and the control level of the generating equipment.
[0008] S2. Based on the dynamic security level label, pre-select the corresponding transmission path for the hydropower station data.
[0009] S3. During the data transmission process of the hydropower station, the quality indicators of the transmission path are collected in real time. When any abnormality of the quality indicator of the transmission path is detected, a path quality degradation event is generated.
[0010] S4. Based on path quality degradation events, prioritize and filter backup transmission paths, and switch the data stream from the pre-selected transmission path to the backup transmission path based on multi-protocol label switching.
[0011] S5. After switching to the backup transmission path, continuously monitor the transmission quality of the backup transmission path. If it still does not meet the standard within the observation period, restart the transmission path optimization until the maximum number of retries is reached.
[0012] S6. When hydropower station data arrives at the access terminal, grant access permissions to users based on user permission characteristics, analyze user access operation behavior in real time, and update access control policies.
[0013] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention dynamically adds high, medium and low security level tags by parsing the business type and equipment control level of hydropower station data, and pre-selects the corresponding transmission path for hydropower station data according to the security level tags, which solves the problem of the static security strategy and fixed transmission path adopted by the prior art, ensures that highly critical data is transmitted in encrypted and redundant channels, and reduces the risk of instruction leakage or tampering caused by insufficient path security protection.
[0014] (2) This invention collects quality indicators in real time. When any quality indicator of the transmission path is detected to be abnormal, a path quality degradation event is generated. The backup path is prioritized and screened, and data stream switching is performed using multi-protocol label switching technology. This solves the problem of lack of dynamic perception of fixed routes, realizes intelligent optimization and seamless switching of transmission paths, and effectively ensures the continuity and stability of key data transmission in hydropower stations.
[0015] (3) By establishing a baseline for user access frequency and monitoring their access behavior to high-security data in real time, this invention dynamically implements access permission downgrades or additional authentication requirements, which solves the problem of static control in existing access control mechanisms and lacks continuous analysis and risk assessment of user behavior. It can proactively identify and respond to potential internal threats or account theft. Attached Figure Description
[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a diagram illustrating the implementation steps of the method of the present invention.
[0018] Figure 2 A flowchart for adding dynamic security level labels to hydropower station data in this invention.
[0019] Figure 3 This is a flowchart illustrating the selection of a backup path after the transmission path quality deteriorates according to the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Please see Figure 1 As shown, the present invention provides a method for secure transmission and access of hydropower station data, including: S1, adding dynamic security level labels of high, medium and low to the hydropower station data based on the criticality of the hydropower station data and the control level of the generating equipment.
[0022] Given the significant differences in the business attributes of data generated during the operation of hydropower stations, the potential security risks and system impacts caused by the leakage, loss, or abnormal transmission of data of different business types vary. Furthermore, the requirements for transmission stability and access control differ for data generated by equipment at different control levels. If the criticality of the data and the control level of the generating equipment are not defined, it may lead to the adoption of transmission and access strategies with insufficient adaptability for hydropower station data, resulting in security risks, as well as wasting network resources or squeezing out the bandwidth for critical data transmission.
[0023] Therefore, the criticality of hydropower station data and the control level of the generating equipment include: parsing the header or load content of hydropower station data and identifying the business type to which the data belongs.
[0024] Specifically, the system first receives raw data packets through the data acquisition interface, uses CRC check to verify the integrity of the frame structure to filter out invalid data, then identifies the frame start character, synchronization word or fixed link layer header according to the standard protocol to complete frame synchronization, and divides the packet header and load boundary; then it extracts the protocol identifier, function control code and data priority field from the packet header, parses it according to the protocol characteristics, and preliminarily classifies the service type based on the priority field. If the identifier is clear, the result is output; if the field is missing or contradictory, it enters the load parsing stage.
[0025] If the business type involves control commands or security protection, the level of criticality is determined to be high; if the business type involves operational status monitoring, the level of criticality is determined to be medium; and if the business type involves historical logs or environmental information, the level of criticality is determined to be low.
[0026] Among them, control commands and safety protection data directly affect the core link of hydropower station production control and directly determine the operating status of primary power equipment. If such business data is tampered with, lost or delayed, it may directly cause major safety accidents such as equipment malfunction, unplanned unit shutdown or even system collapse. Therefore, the degree of criticality is high.
[0027] Operational status monitoring data, such as unit speed, bus voltage, and bearing temperature, are the basis for real-time decision-making in production scheduling and equipment health management. Although they do not directly control equipment, data anomalies can lead to decision-making biases, delayed early warnings, and affect operational stability. They correspond to a medium level of safety protection, hence their criticality is medium.
[0028] Historical logs and environmental information data are only used for post-event traceability and auditing, and do not participate in real-time production control. Data anomalies only affect the integrity of traceability and do not directly interfere with production. Therefore, they correspond to a low level of security protection and are classified as low in criticality.
[0029] Obtain the device identifier that generated the data, and determine whether the control level of the device is direct control level, regulation level, or monitoring level.
[0030] Specifically, firstly, by parsing the device ID field preset in the data packet header of the hydropower station, the device identifier that generated the data is extracted, and it is compared with the unique device code in the pre-established equipment ledger of the hydropower station to eliminate invalid or incorrect identifiers; then, based on the equipment type and core function corresponding to the device identifier, and in accordance with the preset correspondence rules between equipment function and control level, the equipment that directly performs production control operations such as unit start-up and shutdown, circuit breaker opening and closing is determined to be direct control level, the equipment that needs to dynamically adjust operating parameters such as guide vane opening and bus voltage is determined to be regulation level, and the equipment that only collects environmental data and equipment operation logs and has no control and regulation functions is determined to be monitoring level.
[0031] Considering the various types of data generated during the operation of hydropower stations, which vary in criticality and equipment control levels, if a unified security level identification mechanism is not established based on the criticality and equipment control level, it is easy for high-security-requirement data to be tampered with or lost due to insufficient protection measures, or for low-security-requirement data to occupy excessive protection resources, resulting in resource waste. This makes it difficult to meet the security requirements of the power monitoring system for zoning and hierarchical protection and key protection.
[0032] See Figure 2As shown, in order to match the data security protection strategy with the actual data security needs, the following dynamic security level label is added to the hydropower station data: the criticality of the hydropower station data and the control level of the generating equipment are identified, and dynamic security level labels are added to the hydropower station data through predefined security level mapping rules.
[0033] The security level mapping rule is as follows: if the criticality is high, or the control level of the generating device is direct control level, then add a security level label of high.
[0034] If the criticality level is medium, or the control level of the generating equipment is adjustable, then add a safety level label of medium.
[0035] In other cases, add a "low" security level label.
[0036] It should be noted that data of a high criticality level is directly linked to the core production chain, and its security anomalies can directly lead to major accidents such as equipment malfunctions and system shutdowns. Data generated by directly control-level equipment determines the equipment's operating status because the equipment directly executes production control operations. Both types of data have high risk transmission and strong security requirements, and are therefore classified as high security level, ensuring that such high-risk data receives the highest level of protection.
[0037] The critical level is medium. Data support enables real-time scheduling and anomaly early warning. Although it does not directly control equipment, data anomalies can lead to scheduling judgment deviations and delayed early warnings, affecting operational stability. The adjustment level requires dynamic adjustment of operating parameters. Data anomalies in the adjustment level can lead to inaccurate parameter adjustment. Both have medium risk impact and require timely protection. Therefore, they are judged as medium safety level and matched with appropriate protection strength.
[0038] In other cases, the data is only used for post-event traceability or non-real-time analysis, does not participate in the production control closed loop, the equipment has no control or adjustment functions, and the data anomalies only affect the traceability integrity and have no direct production interference. Therefore, it is judged as a low security level with low risk impact and weak security requirements, so the protection resources can be reasonably allocated.
[0039] S2. Based on the dynamic security level label, pre-select the corresponding transmission path for the hydropower station data.
[0040] Furthermore, scan all available transmission paths in the current network to identify whether each transmission path supports encryption and redundancy features.
[0041] Specifically, based on the hydropower station equipment ledger and network topology, the port status and routing information of switches and routers are first read through SNMP, and then industrial control probe frames are sent to exclude invalid paths and obtain a list of available paths.
[0042] For each available path, identify encryption features: first send an encryption negotiation frame to adapt to the link; if there is an encryption suite response, it is determined that encryption is supported. For each available path, identify redundancy features: first check whether the topology is a ring and whether the node has a FRER identifier; then send a test packet with a unique identifier; if it is detected that the data packet is transmitted through different sub-paths and duplicate frames are deleted, or the node returns a redundant configuration, it is determined that redundancy is supported.
[0043] Based on the dynamic security level label of the hydropower station data to be transmitted, a set of transmission paths that meet the conditions is pre-selected: if the security level label is high, a transmission path with encryption and redundancy features is selected; if the security level label is medium, a transmission path with encryption features is selected; if the security level label is low, a low-load transmission path is selected first based on network security.
[0044] It should be added that data with a high dynamic security level label needs encryption features to resist the risk of data tampering or leakage, and redundancy features to avoid equipment malfunction caused by transmission interruption, which meets the high protection requirements for core data; data with a medium label only needs encryption features to meet security requirements, and does not need redundancy features to avoid resource waste; data with a low label prioritizes low-load paths to avoid occupying high-security path resources, thus achieving efficient allocation of network resources.
[0045] From the selected set of transmission paths, obtain the current real-time bandwidth utilization and number of active sessions for each path.
[0046] Prioritize the transmission path with the lowest real-time bandwidth utilization. If the real-time bandwidth utilization is the same, select the transmission path with the fewest active sessions.
[0047] By prioritizing the selection of the path with the lowest real-time bandwidth occupancy, more remaining transmission resources are available, which can effectively avoid transmission delays and packet loss caused by bandwidth congestion, ensuring the real-time transmission requirements of high-security data and meeting the timeliness requirements of hydropower station production control for data transmission.
[0048] When bandwidth utilization is the same, the path with the fewest active sessions has fewer data transmission contention conflicts, which can further reduce transmission jitter and response latency, reduce the interference of multiple concurrent sessions on the quality of single data transmission, and ensure data transmission stability. This selection method not only adapts to the transmission quality requirements of data with different security levels, but also achieves efficient use of network resources, avoiding resource waste or damage to the quality of critical data transmission.
[0049] S3. During the data transmission process of the hydropower station, the quality indicators of the transmission path are collected in real time. When any abnormality of the quality indicator of the transmission path is detected, a path quality degradation event is generated.
[0050] During the data transmission process at hydropower stations, the pre-selected transmission path may experience a decline in transmission quality due to factors such as dynamic fluctuations in network load, temporary failures of node equipment, and link interference. Abnormal transmission quality indicators can directly affect the real-time performance and integrity of critical data transmission, which may lead to deviations in production scheduling judgments, delayed equipment control responses, or even safety accidents.
[0051] Based on this, the steps to generate path quality degradation events are as follows: deploy probes at the source node, destination node, and key intermediate nodes of the pre-selected transmission path, and periodically collect quality indicators such as end-to-end latency, jitter value, and packet loss rate of the path.
[0052] The collected quality indicators are compared with the corresponding path health benchmark, and the anomaly judgment logic is executed: if the current end-to-end latency exceeds the latency benchmark value and shows a continuous increasing trend for three consecutive collection cycles, it is judged as an anomaly.
[0053] The latency baseline value is determined by a method of statistical analysis of historical health data and calibration according to industry standards. Specifically, an initial latency baseline value is first obtained according to industry standards. Then, during the normal operation of the transmission path, historical data for no less than 30 cycles is collected, the average value is calculated and compared with the initial latency baseline value, and the larger value is taken as the final latency baseline value.
[0054] End-to-end latency exceeding the latency benchmark is the initial signal of path quality degradation. However, a single instance of exceeding the benchmark may be caused by occasional factors such as instantaneous network load fluctuations or temporary signal interference. Directly identifying an anomaly could easily trigger false path switching, resulting in transmission interruption or resource waste. The continuous increase trend over three consecutive acquisition cycles indicates that the latency degradation is not accidental, but rather a persistent problem with the path, such as continuous bandwidth saturation, reduced processing capacity of intermediate nodes, and latent fault precursors. This leads to delayed response of control commands and loss of timeliness of real-time monitoring data, ultimately affecting the accuracy of hydropower station production control decisions.
[0055] If the current jitter value exceeds the jitter baseline value, and the change amplitude in adjacent acquisition cycles exceeds the stable change range, it is judged as abnormal.
[0056] The jitter baseline value is selected during a healthy operating period when there are no equipment failures in the transmission path and the network load is within the normal range. Sufficient jitter sample data is collected and the arithmetic mean is calculated as its baseline value.
[0057] If the jitter value exceeding the benchmark is used as the sole criterion, it is easy to misjudge due to occasional factors such as instantaneous electromagnetic interference and temporary light load fluctuations of nodes, triggering unnecessary path switching, resulting in transmission interruption and resource waste. However, if the change amplitude between adjacent acquisition cycles exceeds the stable change range, the persistence of jitter degradation can be accurately identified. When the change amplitude exceeds the standard, it indicates that the jitter fluctuation is not occasional, but rather that there are persistent problems such as increased link interference, insufficient buffer resources of intermediate nodes, and drift of transmission protocol parameters in the path, which lead to further deterioration of jitter over time.
[0058] If the current packet loss rate exceeds the baseline value, and the increase in the loss rate exceeds the normal fluctuation range within a single collection period, it is judged as abnormal.
[0059] The jitter baseline value mentioned above is first referenced to the jitter limit of typical hydropower station operations in the industry standard as the initial baseline value; then, when the transmission path is running normally, 10 valid jitter samples are collected according to the preset monitoring cycle and the average value is calculated. If the average value is less than or equal to the initial baseline value, the initial baseline value is used as the final jitter baseline value. If the average value is greater than the initial baseline value, the measured average value is used as the final jitter baseline value.
[0060] Packet loss rate determines the integrity of data transmission, but a single instance of exceeding the baseline may be caused by non-continuous factors such as instantaneous network congestion or occasional signal interference. If only this is used to determine anomalies, it is easy to trigger false alarms, resulting in unnecessary path switching and resource waste. However, if the increase exceeds the normal fluctuation range within a single collection period, it can distinguish between occasional packet loss and trend packet loss. When the increase exceeds the standard, it indicates that there are persistent problems such as increased link attenuation, node buffer overflow, and hardware failure precursors.
[0061] When any quality indicator is determined to be abnormal, the node that first detects the abnormality generates a path quality degradation event message and sends it to the network control center.
[0062] S4. Based on path quality degradation events, prioritize and filter backup transmission paths, and switch the data stream from the pre-selected transmission path to the backup transmission path based on multi-protocol label switching.
[0063] refer to Figure 3 As shown, to ensure that the selected backup paths have both high historical reliability and excellent real-time transmission performance, and to meet the continuous and reliable data transmission requirements of hydropower station production, the priority ranking and screening steps for backup transmission paths are as follows: Based on the path quality degradation event, the abnormal transmission path identifier is parsed, and the abnormal transmission path is excluded from all available transmission paths to obtain a set of candidate backup transmission paths.
[0064] In addition, if the set of candidate backup transmission paths is empty, an emergency transmission path is activated, which is a pre-configured low-priority path, and the administrator is immediately notified to perform network maintenance.
[0065] The number of quality degradation events recorded for each path in the candidate backup transmission path set within a preset period is counted. If a path has never recorded any quality degradation events within the preset period, its historical reliability level is determined to be excellent.
[0066] The preset cycle can be determined according to the sensitivity level of the hydropower station's services to transmission reliability. For example, the preset cycle for control services is set to 24 hours, which can cover the typical equipment inspection cycle of the hydropower station and capture the path degradation trend caused by factors such as equipment aging and sudden changes in environmental temperature and humidity. The preset cycle for monitoring services is set to 7 days, which can effectively filter short-term network fluctuation interference and focus on long-term link stability assessment.
[0067] For the remaining paths, sort them in ascending order according to the number of recorded quality degradation events to form a sorted list.
[0068] The sorted list is divided into a front section and a back section according to a preset ratio. Paths ranked in the front section are classified as having a good historical reliability level, while paths ranked in the back section are classified as having a medium historical reliability level. This avoids inefficient selection due to the lack of a clear gradient in path reliability and provides a basis for prioritizing subsequent backup paths.
[0069] The preset ratio is determined based on the number of candidate backup transmission paths and the service reliability requirements. For example, if there are 5 to 10 candidate paths, the preset ratio is set to 50%, that is, the top 50% of the paths are the front end and the bottom 50% are the back end; if there are more than 10 candidate paths, the preset ratio is set to 40%, that is, the front end accounts for 40% and the back end accounts for 60%, and more reliable paths are selected first; if core services such as control commands are carried, the front end ratio can be increased to 60%.
[0070] Prioritize the backup transmission path with the best historical reliability level. If there are multiple backup transmission paths with the best historical reliability level, select the backup transmission path with the lowest current latency. If the latency is still the same, select the backup transmission path with the lowest jitter. Prioritize the backup path with the best historical reliability level to ensure long-term transmission stability. Then, prioritize the backup path with the lowest current latency and jitter to ensure the real-time performance and timing consistency of data transmission.
[0071] The steps for switching a data stream from a pre-selected transmission path to a backup transmission path based on multi-protocol label switching are as follows: After determining the backup transmission path, the network control center issues flow labels to the label switching routers along the path.
[0072] After receiving a path switching command, the ingress label switching router updates the ingress label of the data stream from the label of the corresponding abnormal path to the label of the backup label switching path; this achieves millisecond-level path convergence, effectively reducing data loss and transmission interruption during the switching process, while ensuring the quality of service of the data stream and ensuring the continuity of critical data transmission.
[0073] S5. After switching to the backup transmission path, continuously monitor the transmission quality of the backup transmission path. If it still fails to meet the standards within the observation period, restart the transmission path optimization until the maximum number of retries is reached. Promptly investigate any remaining transmission problems on the backup path to avoid long-term interruptions in critical data transmission of the hydropower station due to a single backup path failure, and maximize the continuous reliability of data transmission.
[0074] The maximum number of retries is preset based on the business criticality: 3 retries for high-security data, 2 retries for medium-security data, and 1 retry for low-security data. Once the maximum number of retries is reached, the system switches to the default transmission path and triggers an alarm to notify the network administrator.
[0075] Specifically, after the data stream is successfully switched to the backup transmission path, an observation period for the backup transmission path is initiated.
[0076] During the observation period, quality indicators of the backup transmission path are collected at a higher frequency than regular monitoring; early minor quality degradation that may occur when the path just begins to carry data streams is captured, potential hidden dangers are investigated in a timely manner, and data transmission interruptions caused by sudden path problems are avoided, ensuring the continuous reliability of critical data transmission in hydropower stations.
[0077] If the quality indicators of all acquisition cycles do not trigger the anomaly judgment logic, the backup transmission path is deemed to meet the standard. If the anomaly judgment logic is triggered again in any acquisition cycle during the observation period, the backup transmission path is deemed to fail to meet the standard.
[0078] If the path quality is deemed unsatisfactory, a new path quality degradation event is generated, and the process returns to prioritize and filter alternative transmission paths.
[0079] S6. When hydropower station data arrives at the access terminal, grant access permissions to users based on user permission characteristics, analyze user access operation behavior in real time, and update access control policies.
[0080] Given the varying levels of sensitivity in hydropower station data, and the different operational needs and permission boundaries of users with different roles, the lack of an access control mechanism based on user permission characteristics could easily lead to security risks such as sensitive data leakage and unauthorized operations interfering with production processes. To ensure the security and controllability of data access, the following steps are taken to grant access permissions to users based on their permission characteristics: When a user initiates a data access request, the user identifier and the identifier of the data object to be accessed are parsed from the data access request.
[0081] Retrieve the set of operation permissions granted to the user for the data object identifier based on the user identifier.
[0082] If the set of operation permissions contains operation permissions that match the current access request, then allow the user to access; otherwise, deny the access request.
[0083] The steps for analyzing user access behavior and updating access control policies in real time are as follows: Based on historical access operation data, calculate the average access frequency of users to hydropower station data in the past preset historical period and record it as the access frequency baseline.
[0084] Previously, the preset historical period was determined based on the data sensitivity level of the hydropower station associated with the baseline of the access frequency to be calculated and the user role type. Specifically, if the baseline to be calculated corresponds to the user's access frequency to the unit control parameters and the user role is operation and maintenance personnel, then the previously preset historical period was set to 7 days.
[0085] During the process of users accessing hydropower station data in real time, the frequency of users accessing hydropower station data within the current monitoring window is counted.
[0086] If a user's current access frequency to data with a high dynamic security level exceeds the access frequency baseline, and the access frequency shows a continuous upward trend in multiple consecutive monitoring windows, it is judged as abnormal access behavior; this not only avoids the interference of misjudgment due to occasional factors, but also accurately captures the risk of abnormal access to data with a high dynamic security level.
[0087] It should be noted that the continuously increasing access frequency across multiple monitoring windows indicates that the deviation from normal access patterns is not accidental, but rather represents a potential risk of unauthorized access attempts, malicious bulk acquisition of highly sensitive data, and other non-compliant access behaviors. If this trend is not stopped in time, it could lead to security incidents such as leakage of highly sensitive data and tampering with production control information. The multiple monitoring windows mentioned here can be three consecutive monitoring windows, each lasting 5 minutes.
[0088] When an abnormal access behavior is identified, the user's subsequent access requests will be subject to downgraded access permissions or additional authentication requirements.
[0089] Access permission downgrade refers to reducing a user's current access permissions from a high level to a low level, while additional authentication requirements mean that users must go through additional authentication steps before they can continue to access the site.
[0090] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.
[0091] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0092] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0093] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0094] Finally, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for secure transmission and access of data in hydropower stations, characterized in that: include: S1. Based on the criticality of hydropower station data and the control level of the generating equipment, dynamic security level labels are added to the hydropower station data as high, medium, and low. S2. Based on the dynamic security level label, pre-select the corresponding transmission path for the hydropower station data; S3. During the data transmission process of the hydropower station, the quality indicators of the transmission path are collected in real time. When any quality indicator of the transmission path is detected to be abnormal, a path quality degradation event is generated. The steps for generating a path quality degradation event when any quality indicator of the transmission path is detected to be abnormal are as follows: Probes are deployed at the source node, destination node, and key intermediate nodes of the pre-selected transmission path to periodically collect quality indicators such as end-to-end latency, jitter, and packet loss rate. The collected quality indicators are compared with the corresponding path health benchmark, and the anomaly judgment logic is executed: if the current end-to-end latency exceeds the latency benchmark value and shows a continuous increasing trend for three consecutive collection cycles, it is judged as an anomaly. If the current jitter value exceeds the jitter baseline value, and the change amplitude in adjacent acquisition cycles exceeds the stable change range, it is judged as abnormal; If the current packet loss rate exceeds the baseline value, and the increase in the loss rate exceeds the normal fluctuation range within a single collection period, it is judged as abnormal. When any quality indicator is determined to be abnormal, the node that first detects the abnormality generates a path quality degradation event message and sends it to the network control center. S4. Based on path quality degradation events, prioritize and filter backup transmission paths, and switch the data stream from the pre-selected transmission path to the backup transmission path based on multi-protocol label switching. S5. After switching to the backup transmission path, continuously monitor the transmission quality of the backup transmission path. If it still does not meet the standard within the observation period, restart the transmission path optimization until the maximum number of retries is reached. S6. When hydropower station data arrives at the access terminal, grant access permissions to users based on user permission characteristics, analyze user access operation behavior in real time, and update access control policies.
2. The method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The criticality of the hydropower station data and the control level of the generating equipment include: Analyze the header or load content of hydropower station data to identify the business type to which the data belongs; If the business type involves control commands or security protection, the level of criticality is determined to be high; if the business type involves operational status monitoring, the level of criticality is determined to be medium; if the business type involves historical logs or environmental information, the level of criticality is determined to be low. Obtain the device identifier that generated the data, and determine whether the control level of the device is direct control level, regulation level, or monitoring level.
3. The method for secure transmission and access of hydropower station data according to claim 2, characterized in that: The details of adding dynamic security level tags to hydropower station data are as follows: Identify the criticality of hydropower station data and the control level of the generating equipment, and add dynamic security level labels to the hydropower station data through predefined security level mapping rules; The security level mapping rule is as follows: if the criticality is high, or the control level of the generating device is direct control level, then add a security level label of high. If the criticality level is medium, or the control level of the generating equipment is adjustable, then add a safety level label of medium. In other cases, add a "low" security level label.
4. The method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The steps for pre-selecting the corresponding transmission path for hydropower station data are as follows: Scan all available transmission paths in the current network and identify whether each transmission path supports encryption and redundancy features; Based on the dynamic security level label of the hydropower station data to be transmitted, a set of transmission paths that meet the conditions is pre-selected: if the security level label is high, a transmission path with encryption and redundancy is selected; if the security level label is medium, a transmission path with encryption is selected; if the security level label is low, a low-load transmission path is selected first based on network security. From the selected set of transmission paths, obtain the current real-time bandwidth utilization and number of active sessions for each path; Prioritize the transmission path with the lowest real-time bandwidth utilization. If the real-time bandwidth utilization is the same, select the transmission path with the fewest active sessions.
5. The method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The steps for prioritizing and filtering backup transmission paths are as follows: Based on the path quality degradation event, the abnormal transmission path identifier is parsed, and the abnormal transmission path is excluded from all available transmission paths to obtain a set of candidate backup transmission paths. The number of quality degradation events recorded for each path in the candidate backup transmission path set within a preset period is counted. If a path has never recorded any quality degradation events within the preset period, its historical reliability level is determined to be excellent. For the remaining paths, sort them in ascending order according to the number of recorded quality degradation events to form a sorted list; The sorted list is divided into a front section and a back section according to a preset ratio. Paths ranked in the front section are judged to have a good historical reliability level, and paths ranked in the back section are judged to have a medium historical reliability level. Prioritize the backup transmission path with the best historical reliability level. If there are multiple backup transmission paths with the best historical reliability level, select the backup transmission path with the lowest current latency. If the latency is still the same, select the backup transmission path with the lowest jitter.
6. The method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The steps for switching the data stream from the pre-selected transmission path to the backup transmission path based on multi-protocol label switching are as follows: After determining the alternative transmission path, the network control center sends flow labels to the label switching routers along that path. After receiving a path switching instruction, the ingress label switching router updates the ingress label of the data stream from the label of the corresponding abnormal path to the label of the backup label switching path.
7. The method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The implementation of S5 includes: After the data stream is successfully switched to the backup transmission path, an observation period for the backup transmission path is initiated. During the observation period, quality indicators of the backup transmission path were collected at a frequency higher than that of routine monitoring. If the quality indicators of all acquisition cycles do not trigger the anomaly judgment logic, the backup transmission path is deemed to meet the standard. If the anomaly judgment logic is triggered again in any acquisition cycle during the observation period, the backup transmission path is deemed to fail to meet the standard. If the path quality is deemed unsatisfactory, a new path quality degradation event is generated, and the process returns to prioritize and filter alternative transmission paths.
8. The method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The steps for granting access permissions to users based on user permission characteristics are as follows: When a user initiates a data access request, the user identifier and the identifier of the data object to be accessed are parsed from the data access request. Based on the user identifier, obtain the set of operation permissions that the user has been granted to access data object identifiers; If the set of operation permissions contains operation permissions that match the current access request, then allow the user to access; otherwise, deny the access request.
9. A method for secure transmission and access of hydropower station data according to claim 1, characterized in that: The steps for real-time analysis of user access behavior and updating access control policies are as follows: Based on historical access operation data, the average access frequency of users to hydropower station data in the past preset historical period is calculated and recorded as the access frequency baseline. During the real-time access to hydropower station data by users, the frequency of user access to hydropower station data within the current monitoring window is counted. If a user's current access frequency to data with a high dynamic security level exceeds the access frequency baseline, and the access frequency shows a continuous upward trend in multiple consecutive monitoring windows, it is judged as abnormal access behavior. When an abnormal access behavior is identified, the user's subsequent access requests will be subject to downgraded access permissions or additional authentication requirements.
Citation Information
Patent Citations
Safety early warning system based on big data
CN120614199A
Tax system-oriented multi-interface data interaction method and system
CN121029867A
Beidou electric power data intelligent acquisition and dynamic communication scheduling method and system
CN121217660A