Virtual power plant digital resource protection method and system based on privacy computing
By acquiring historical network attack records and data access records of virtual power plants, the privacy protection needs are dynamically assessed, and differential privacy protection operations are adopted to solve the problems of low efficiency and poor adaptability of virtual power plant resource protection, thus achieving more efficient privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING ZHONGWEI SHENGDING TECH CO LTD
- Filing Date
- 2026-02-27
- Publication Date
- 2026-04-24
AI Technical Summary
Existing digital resource protection solutions for virtual power plants suffer from low resource protection efficiency and poor adaptability, making it difficult to meet privacy and security needs in complex scenarios.
By acquiring historical network attack records and historical access records of various types of data from virtual power plants, risk value assessment analysis is conducted to dynamically determine the privacy protection requirements for each type of data, and adaptive adjustments are made based on differential privacy protection operations.
It achieves precise differentiation and dynamic protection of different types of data, improves the adaptability of privacy protection, ensures the security of high-demand data while taking into account the availability of low-demand data, and improves the overall privacy computing protection efficiency of virtual power plants.
Smart Images

Figure CN121923932A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, specifically to a method and system for protecting digital resources in virtual power plants based on privacy computing. Background Technology
[0002] Virtual Power Plants (VPPs), as a crucial component of smart grids, enable flexible scheduling and optimized grid operation by aggregating distributed energy resources (such as energy storage systems, photovoltaic power generation, and electric vehicles). The multi-party collaboration within VPPs involves the exchange and sharing of a large amount of sensitive data, including critical information such as user electricity consumption habits, energy storage status, and equipment topology. The security and privacy protection of this data directly impact the stable operation of the power system and the privacy rights of users. To prevent data leakage, the industry widely employs differential privacy computing technology to protect shared information.
[0003] However, existing virtual power plant privacy protection solutions typically employ preset, fixed privacy budget parameters. This static protection strategy ignores the varying importance of different types of data in practical applications, as well as the dynamic differences in storage risk faced by enterprise digital resource storage platforms at different times. Therefore, existing technologies suffer from low efficiency and poor adaptability in protecting virtual power plant digital resources, making it difficult to meet the privacy and security needs of complex scenarios. Summary of the Invention
[0004] To address the problems of low efficiency and poor adaptability in existing resource protection technologies, the present invention aims to provide a method and system for protecting digital resources in virtual power plants based on privacy computing. The specific technical solution adopted is as follows: This application provides a method for protecting digital resources of a virtual power plant based on privacy computing, including: Obtain historical network attack records and historical access records of various types of data from the virtual power plant; For each type of data, a risk value assessment analysis is performed based on the historical network attack records of the virtual power plant and the historical access records of the data of that type to determine the privacy protection requirement level corresponding to that type of data; the privacy protection requirement level is used to characterize the priority level of privacy protection for the corresponding type of data; Differential privacy protection operations are performed based on the privacy protection requirements of different types of data.
[0005] The present invention has the following beneficial effects: In view of the technical problems of low efficiency and poor adaptability in existing resource protection technologies, this application provides a method and system for protecting virtual power plant digital resources based on privacy computing. By acquiring historical network attack records and historical access records of various data types from the virtual power plant, it provides real and comprehensive basic data for privacy protection requirement assessment. Then, for each type of data, a risk value assessment analysis is performed based on the historical network attack records and historical access records of that type of data to determine the corresponding privacy protection requirement. This transforms static data classification into dynamic privacy protection requirement, accurately quantifying the sensitivity of data in specific environments and achieving precise differentiation of protection priorities for different data. Finally, differential privacy protection operations are performed based on the privacy protection requirement of each type of data, ensuring that the protection strategy matches the actual data needs and security risks. Compared to traditional methods that preset a fixed privacy budget, this application effectively improves the adaptability of privacy protection, ensuring the privacy security of high-demand data while also considering the usability of low-demand data, thus improving the overall protection efficiency of privacy computing for virtual power plant digital resources. Attached Figure Description
[0006] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0007] Figure 1 This is a flowchart illustrating a method for protecting digital resources in a virtual power plant based on privacy computing, provided as an embodiment of the present invention. Figure 2 This is a system architecture diagram of a privacy-based virtual power plant digital resource protection system provided in one embodiment of the present invention. Detailed Implementation
[0008] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of the privacy-based computing-based virtual power plant digital resource protection method and system proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0009] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0010] In all division and logarithmic operations covered in this application, a smoothing mechanism is employed to prevent computer program crashes or invalid values from being generated due to a zero denominator or a zero input. Specifically, a positive correction factor is superimposed on the denominator term of the division operation or the argument term of the logarithmic function. For example, the value is This ensures the robustness and feasibility of the algorithm under extreme conditions.
[0011] The normalization function mentioned in this application Unless otherwise specified, all values are normalized using maximum and minimum values. The maximum and minimum values are preset empirical extreme values derived from a large amount of historical experimental data. If the calculated result exceeds the [0,1] interval, it is restricted to the [0,1] range by a truncation function (i.e., if the result is less than 0, it is taken as 0, and if it is greater than 1, it is taken as 1) to eliminate the influence of outliers on the evaluation index.
[0012] In view of the technical problems of low efficiency and poor adaptability in existing resource protection technologies, this application provides a method and system for protecting virtual power plant digital resources based on privacy computing. By acquiring historical network attack records and historical access records of various data types from the virtual power plant, it provides real and comprehensive basic data for privacy protection requirement assessment. Then, for each type of data, a risk value assessment analysis is performed based on the historical network attack records and historical access records of that type of data to determine the corresponding privacy protection requirement. This transforms static data classification into dynamic privacy protection requirement, accurately quantifying the sensitivity of data in specific environments and achieving precise differentiation of protection priorities for different data. Finally, differential privacy protection operations are performed based on the privacy protection requirement of each type of data, ensuring that the protection strategy matches the actual data needs and security risks. Compared to traditional methods that preset a fixed privacy budget, this application effectively improves the adaptability of privacy protection, ensuring the privacy security of high-demand data while also considering the usability of low-demand data, thus improving the overall protection efficiency of privacy computing for virtual power plant digital resources.
[0013] The specific solution of the privacy-based computing-based digital resource protection method and system for virtual power plants provided by the present invention will be described in detail below with reference to the accompanying drawings.
[0014] Please see Figure 1 The diagram illustrates a flowchart of a method for protecting digital resources in a virtual power plant based on privacy computing, according to an embodiment of the present invention. The method includes the following steps: Step 101: Obtain historical network attack records and historical access records of various types of data for the virtual power plant.
[0015] Among them, historical network attack records refer to network attack-related information intercepted or monitored by the virtual power plant data storage platform during its past operation. Historical network attack records include the network attack period and attack intensity evaluation value for each network attack event, such as the time of occurrence, end time, attack type, attack intensity evaluation value, and attack impact range.
[0016] The various types of data in a virtual power plant refer to all kinds of sensitive data that need to be protected for privacy during the multi-party collaboration process of the virtual power plant. For example, the types of data can be user electricity consumption data, energy storage device operating status data, power grid infrastructure topology data, dispatch instruction data, etc. Historical access records refer to relevant information about the access of each type of data in the past, including the access time, access subject, and access permissions (authorized / unauthorized) for each access.
[0017] In some embodiments, this application can read historical access records, historical network attack records, and other data of various types through data storage devices deployed in a virtual power plant. After acquiring the data, the data can also be cleaned and preprocessed, such as removing invalid data (e.g., access records with incorrect format or duplicate attack logs) and completing missing data (e.g., completing some missing access frequency data through time series interpolation) to ensure the accuracy of subsequent analysis.
[0018] Step 102: For each type of data, conduct a risk value assessment analysis based on the historical network attack records of the virtual power plant and the historical access records of the data type to determine the privacy protection requirements corresponding to the data type.
[0019] The privacy protection requirement level is used to characterize the priority level of privacy protection for the corresponding data type. A higher privacy protection requirement level indicates a higher level of privacy protection needed for the corresponding data type, and a smaller privacy budget parameter should be used. This application can achieve adaptive adjustment of the privacy budget by comprehensively assessing the importance and real-time risks of various data types. The importance of each data type can be reflected by historical access records, and the security risks faced by the data can be reflected by historical network attack records. The higher the importance and the greater the security risks, the higher the privacy protection priority. In this way, this application can achieve adaptive adjustment of the privacy budget.
[0020] In this embodiment, risk value assessment analysis can adopt conventional assessment methods such as comprehensive scoring method and analytic hierarchy process. By quantifying key indicators in historical access records (such as access frequency, authorized access ratio, etc.) and key indicators in historical network attack records (such as attack frequency, attack intensity, etc.), an assessment model is constructed and the privacy protection requirements of each type of data are calculated.
[0021] The above steps, by differentiating the privacy protection needs of different types of data, can avoid overprotecting low-importance, low-risk data (leading to a significant decrease in data availability), while ensuring that high-importance, high-risk data is given priority protection (to prevent privacy leaks).
[0022] Step 103: Perform differential privacy protection operations based on the privacy protection requirements of each type of data.
[0023] Differential privacy protection refers to the technical means of protecting individual privacy while ensuring data availability by adding noise (such as Laplace noise or Gaussian noise) to the original data so that changes to the information of a single individual in the dataset will not have a significant impact on the data publication results.
[0024] In one possible implementation, this application can adaptively adjust the privacy budget parameters of each type of data based on the privacy protection requirements of each type of data to obtain the adjusted privacy budget parameters of each type of data. Then, for each type of data, differential privacy protection operations are performed based on the adjusted privacy budget parameters of the type data.
[0025] For example, the adjusted privacy budget parameter satisfies the following formula: ; in, For the first Privacy budget parameters after data adjustment for different types of data The privacy budget parameter rating can be set according to industry standards or actual scenarios, for example, it can be 10. For the first The degree of privacy protection required for different types of data.
[0026] In some embodiments, differential privacy protection operations include the following steps: First, determining the sensitivity of the data, where sensitivity refers to the maximum impact of a change to a single record in the dataset on the query results, which can be determined based on the data range. Then, based on the adjusted privacy budget parameters... The system generates noise that follows a Laplace distribution based on sensitivity. Finally, the generated noise is added to the original data to obtain the perturbed data, thus completing the differential privacy protection operation.
[0027] After the operation is completed, this application can also verify the availability of the perturbed data. For example, it can calculate the error rate (such as mean absolute error or mean square error) between the perturbed data and the original data. If the error rate exceeds a preset threshold (such as 10%), the privacy budget rating can be adjusted appropriately to ensure that the data availability meets business needs.
[0028] Based on the above technical solution, this application provides real and comprehensive basic data for privacy protection requirement assessment by obtaining historical network attack records of virtual power plants and historical access records of various data types. Then, for each type of data, a risk value assessment analysis is performed based on the historical network attack records of the virtual power plant and the historical access records of that type of data to determine the corresponding privacy protection requirement. This transforms static data classification into dynamic privacy protection requirement, accurately quantifying the sensitivity of data in specific environments and achieving precise differentiation of different data protection priorities. Finally, differential privacy protection operations are performed based on the privacy protection requirement of each type of data, ensuring that the protection strategy matches the actual data needs and security risks. Compared to the traditional method of pre-setting a fixed privacy budget, this application effectively improves the adaptability of privacy protection, ensuring the privacy security of high-demand data while also considering the usability of low-demand data, thus improving the overall protection efficiency of privacy computing for virtual power plant digital resources.
[0029] As a possible embodiment of this application, step 102 above can be implemented through the following steps: Step 201: For each type of data, perform a resource protection importance analysis based on the historical access records of the data type to determine the level of importance of resource protection for that type of data.
[0030] Among them, the resource protection priority is used to characterize the data protection priority of the corresponding data type. It can reflect the importance of the data itself. The higher the importance, the higher the resource protection priority of this type of data, that is, the more priority should be given to allocating higher protection resources.
[0031] The importance of data can be reflected by the historical access performance of the corresponding data type. For example, data types that are accessed frequently usually correspond to core business scenarios and are therefore more important. At the same time, the proportion of unauthorized access can also reflect the potential risk of data type attacks. The higher the proportion of unauthorized access, the more attention that type of data is paid to by malicious attackers, and its protection priority should be increased accordingly.
[0032] In some embodiments, this application may construct a resource protection importance assessment model using indicators such as historical access frequency of statistical data, the importance of access subjects (such as the access ratio of core business systems), and the authorized access ratio.
[0033] Step 202: For each type of data, conduct a storage status risk assessment based on the historical access records of the data type and in conjunction with historical network attack records, and determine the information attention coefficient of the data type.
[0034] Among them, the information attention coefficient is used to characterize the degree of attention that the corresponding type of data receives in a cyberattack environment. It can reflect the vulnerability of data in security risk scenarios. The higher the information attention coefficient, the easier it is for this type of data to become a target in a cyberattack, and therefore stronger privacy protection is required.
[0035] The level of attention a data receives is not only related to its own access characteristics (such as changes in access frequency during an attack), but also to the overall security risk of the storage platform (such as the intensity and frequency of recent cyberattacks). For example, if the access frequency of a certain type of data increases significantly during historical cyberattacks, and the storage platform has recently suffered a large-scale attack, then the information attention coefficient of that type of data is high.
[0036] In some embodiments, this application may first assess the overall risk level of the storage platform based on historical network attack records, and then combine the access performance of this type of data during the attack (such as the growth rate of access frequency and the change in the proportion of unauthorized access) to quantify the information attention coefficient.
[0037] Step 203: For each type of data, determine the privacy protection requirement corresponding to the type of data based on the resource protection importance and information attention coefficient of the data type.
[0038] The demand for privacy protection is a comprehensive assessment of the importance of the data itself and the security risks. The higher the importance attached to resource protection and the higher the information attention coefficient, the higher the demand for privacy protection.
[0039] For example, the privacy protection requirement satisfies the following formula: ; in, For the first The degree of privacy protection required for each type of data For the first The importance attached to the protection of various types of data resources For the first Information attention coefficient for each type of data. This is a normalization function (e.g., maximum / minimum normalization) used to map the calculation results to the range of 0 to 1.
[0040] Based on the above technical solution, this application can conduct resource protection importance analysis for each type of data according to the historical access records of the data type to determine the resource protection importance of the data type. Based on the historical access records of the data type and combined with historical network attack records, a storage status risk assessment is conducted to determine the information attention coefficient of the data type. The resource protection importance focuses on the importance of the data itself, while the information attention coefficient focuses on the vulnerability of the data in security risk scenarios. In this way, the privacy protection requirement degree corresponding to the data type can be determined by combining the resource protection importance and the information attention coefficient of the data type. This makes the privacy protection requirement degree reflect both the business value of the data and the security risk of the data, providing a more reliable basis for the precise adjustment of subsequent privacy budget parameters, and further improving the pertinence and effectiveness of privacy protection.
[0041] As a possible embodiment of this application, step 201 above can be implemented through the following steps: Step 301: For each type of data, determine the presentation level of important information based on the historical access records of the data type.
[0042] The importance information presentation level is used to indicate the degree of importance of the corresponding data type. This application can reflect the business coreness of each type of data through historical access characteristics (such as access popularity and correlation with other types of data). The higher the importance information presentation level, the more critical the role of this type of data in the virtual power plant business process.
[0043] It should be noted that the importance of each type of data is not only reflected in its own access frequency (such as data accessed frequently is usually more important), but also in its collaborative access relationship with other types of data (such as data accessed in collaboration with multiple core data has a stronger business relevance and is more important). Therefore, this application can be comprehensively evaluated by combining access frequency and data correlation strength.
[0044] Step 302: For each type of data, adjust the presentation of important information based on the proportion of unauthorized access in the historical access records of the data type to obtain the resource protection importance of the data type.
[0045] For example, the level of importance attached to resource protection satisfies the following formula: ; in, For the first The importance attached to the protection of various types of data resources For the first The percentage of unauthorized access in the historical access records of this type of data can be determined by the [missing information - likely a data type name]. The ratio of the number of unauthorized accesses to the total number of accesses in the historical access records of this type of data is calculated. For the first The presentation of important information in each type of data The sensitivity adjustment parameter can be determined based on experimental data statistics; for example, it can be 2. The above formula uses an exponential function to strengthen the impact of the proportion of unauthorized access on protection priority, ensuring that even data with moderate business importance but high security risks receive sufficient protection attention.
[0046] It should be noted that the presentation of important information only reflects the business importance of each type of data, while the proportion of unauthorized access reflects the potential risk of malicious attacks on each type of data. Even if the business importance of a certain type of data is average, if the proportion of unauthorized access is high, it means that it is very likely to have become a target of malicious attackers and its protection priority needs to be increased. Conversely, if the business importance of a certain type of data is high, but the proportion of unauthorized access is extremely low, it means that it currently faces a relatively small attack risk and its protection priority can be adjusted appropriately (but it still needs to be kept at a high level).
[0047] Based on the above technical solution, this application can determine the presentation degree of important information for each type of data according to its historical access records. This presentation degree reflects the core nature of the corresponding data type from a business perspective, ensuring that protection resources prioritize key business data. Subsequently, the presentation degree of important information is adjusted based on the proportion of unauthorized access in the historical access records of the data type, resulting in the resource protection priority for that data type. Adjusting for the proportion of unauthorized access allows the security risk factors of the data type to be integrated into the assessment process, avoiding the problem of focusing solely on business importance while ignoring potential attack risks. This technical solution considers both the business value and security risks of the data, making the resource protection priority more aligned with actual protection needs and providing stronger support for the accurate calculation of subsequent privacy protection requirements.
[0048] As a possible embodiment of this application, step 301 above can be implemented through the following steps: Step 401: For each type of data, determine the resource popularity index of the data type based on the historical access records of the data type.
[0049] Among them, the resource popularity index is used to characterize the growth trend of the historical access frequency of the corresponding data type. It can reflect the changes in the access popularity of the data. The higher the resource popularity index, the faster the access frequency of the data type increases and the higher the business attention.
[0050] In one possible implementation, this application can determine the access frequency slope factor and the total number of historical accesses for each type of data based on the historical access records of the data, and determine the resource popularity index of the data based on the access frequency slope factor and the total number of historical accesses.
[0051] Among them, a positive access frequency slope factor indicates that the access frequency is on the rise, and the larger the value of the access frequency slope factor, the faster the growth rate; a negative access frequency slope factor indicates that the access frequency is on the fall, and the larger the absolute value of the access frequency slope factor, the faster the fall rate.
[0052] In some embodiments, this application can divide the historical access time into multiple consecutive time periods (such as by hour), count the number of accesses of this type of data in each time period, and then use a linear regression algorithm to fit the data to obtain a fitted line. The slope of the fitted line is the access frequency slope factor.
[0053] The total number of historical visits represents the cumulative number of visits to this type of data within the entire historical access period recorded in the historical access records. It reflects the long-term business focus on this type of data; a higher total number of historical visits indicates that the data has been accessed frequently over a long period and has higher business value. This application can obtain the total number of historical visits by iterating through the historical access records of this type of data and counting the number of all authorized and unauthorized accesses.
[0054] For example, the resource popularity index satisfies the following formula: ; in, For the first Resource popularity indicators for various types of data For the first Total number of historical accesses for each type of data For the first Access frequency slope factor for this type of data This is a normalization function (e.g., maximum / minimum normalization) used to map the calculation results to the range of 0 to 1.
[0055] The resource popularity metric is positively influenced by both cumulative visits and growth trends. The larger the value, the higher the long-term attention given to the data. The larger the value, the faster the data growth trend. The larger the value, the higher the access popularity. This resource popularity index provides a quantitative basis for calculating the presentation degree of important information, ensuring that the presentation degree of important information can accurately reflect the access popularity characteristics of the data.
[0056] Step 402: For each type of data, determine the data association strength of the type of data based on the historical access records of the type of data and other types of data.
[0057] Among them, data association strength is used to characterize the degree of collaborative access of corresponding data types with other data types. It can reflect the relevance of this type of data in the business process. The higher the data association strength, the stronger the collaborative effect of this type of data with other data types and the higher the irreplaceability of the business.
[0058] In one possible implementation, this application can obtain the access time periods of type data and other types of data from the historical access records of type data and other types of data for each type of data.
[0059] The access period refers to the time period during which the data of a certain type is accessed. For example, if a certain type of data is accessed at 9:36 on May 10, 2024, then the period from 8:00 on May 10, 2024 to 9:00 on May 10, 2024 is an access period for that type of data. By obtaining the access period, we can analyze whether different types of data are accessed within the same time period, and thus determine the correlation between different types of data.
[0060] Then, for each type of data, a correlation analysis is performed based on the access time periods of the type data and other types of data to determine the associated type data.
[0061] Virtual power plant operations (such as grid dispatching and equipment monitoring) typically require simultaneous access to multiple related data types. Therefore, the intersection of the access periods for two types of data can directly reflect the business correlation between the two types of data. The greater the intersection and the larger the proportion, the stronger the correlation.
[0062] In some embodiments, this application may determine the association factor between type data and other types of data based on the access time of type data and other types of data, and determine the associated type data of type data based on the association factor.
[0063] For example, the association factor satisfies the following formula: ; in, For the first Type of data and the first Association factors for different types of data For the first Type of data and the first The number of time periods in the intersection of the access time periods of the two types of data. For the first Type of data and the first The number of time periods in the union of access time periods for each type of data.
[0064] This application can use other types of data with correlation factors greater than a preset correlation threshold as the correlation type data for that type of data. The preset correlation threshold can be determined based on statistical data analysis, for example, it can be 0.85. In this way, this application can obtain the correlation type data for each type of data.
[0065] Ultimately, this application can determine the data association strength of each type of data based on the associated data of each type of data.
[0066] In particular, the more related data types a certain type of data has, the wider the scope of collaboration of that type of data in the business process, the stronger the irreplaceability of the business, and the higher the data association strength.
[0067] For example, the strength of data association satisfies the following formula: ; in, For the first The strength of data association between different types of data For the first The number of related data types of this type. The maximum quantity among all related data types. It is a safety parameter used to correct fractions where the denominator is 0, and its dimensions are the same as... The same applies; the specific value can be determined based on... The value of the value determines the outcome, such as . The larger it is, the more likely it is to be the first The stronger the business relevance of a data type, the higher its irreplaceability.
[0068] Step 403: For each type of data, determine the presentation degree of important information of the data type based on the resource popularity index and data correlation strength of the data type.
[0069] It should be noted that the resource popularity index reflects the access popularity and business attention of the data, while the data association strength reflects the business relevance and irreplaceability of the data. This application can combine the above two factors to evaluate the presentation of important information. The higher the resource popularity index and the higher the data association strength, the higher the business importance of the data and the higher the presentation of important information.
[0070] For example, the presentation of important information satisfies the following formula: ; in, For the first The presentation of important information in each type of data For the first Resource popularity indicators for various types of data For the first The strength of data association between different types of data This is a normalization function (e.g., maximum / minimum normalization) used to map the calculation results to the range of 0 to 1.
[0071] Based on the above technical solution, this application determines the resource popularity index of each type of data according to its historical access records to focus on changes in data access popularity and ensure that data with increased recent business attention is captured. Then, for each type of data, the data correlation strength is determined based on the historical access records of that type of data and other types of data to analyze the business relevance of the data and ensure the identification of core data indispensable to the business process. Finally, for each type of data, the importance information presentation degree is determined based on the resource popularity index and data correlation strength, so that the importance information presentation degree can comprehensively and objectively reflect the business importance of the data. This technical solution further improves the accuracy of resource protection importance assessment and provides a more reliable foundation for the accurate calculation of subsequent privacy protection needs.
[0072] As a possible embodiment of this application, step 202 above can be implemented through the following steps: Step 501: Determine the storage state risk level of the virtual power plant based on historical network attack records.
[0073] The storage state risk level is used to characterize the severity of cyberattacks on virtual power plants. A higher storage state risk level indicates a greater risk of cyberattacks against the storage platform and a higher likelihood of data privacy breaches.
[0074] Since cyberattacks on virtual power plants are usually continuous and related, recent cyberattacks can more accurately reflect the current storage security status. Therefore, this application can obtain the storage status risk level by analyzing the relevant characteristics of the most recent cyberattack event (such as attack intensity and time interval from the present).
[0075] It should be noted that the technical solution provided in this application is applicable to routine operation and maintenance scenarios that are not currently under cyberattack. If a cyberattack is in progress, the current assessment process should be immediately interrupted, and the privacy protection level of all types of data should be forcibly increased to the preset highest emergency level (i.e., using the minimum privacy budget parameter), or access to all types of data should be directly prohibited to ensure the strongest data protection during the attack. Normal monitoring mode should be restarted after the cyberattack ends and the system stabilizes.
[0076] In one possible implementation, this application can obtain the network attack period and attack intensity evaluation value of the most recent network attack event from historical network attack records, and determine the storage state risk level based on the network attack period and attack intensity evaluation value.
[0077] For example, the storage state risk level satisfies the following formula: ; in, The storage state risk level of the virtual power plant. This application defines the time interval between the most recent cyberattack event in historical cyberattack records and the current time. It can extract the end time of the most recent cyberattack event from the historical records, calculate the time interval between that end time and the current time, and thus obtain... . This is the attack intensity rating of the most recent cyberattack event in the historical cyberattack records. This is a normalization function (e.g., maximum / minimum normalization) used to map the calculation results to the range of 0 to 1.
[0078] The attack strength evaluation value can be automatically calculated by the security monitoring system of the virtual power plant. For example, it can be scored based on factors such as the attack type of the network attack event (such as DDoS attack, SQL injection attack), attack frequency, attack impact scope (such as whether it leads to partial data leakage or system paralysis). The relevant scoring rules can refer to industry standards or internal enterprise specifications.
[0079] The shorter the time interval between the most recent cyberattack and the current time, the more recent the attack occurred, the higher the attack intensity rating, the more severe the security damage to the storage platform, and the higher the security risk of the storage platform.
[0080] Step 502: For each type of data, determine the information attention coefficient of the data type based on the historical access records of the data type and the storage status risk level of the virtual power plant.
[0081] It should be noted that the higher the storage status risk level, the greater the overall security risk of the storage platform and the more serious the attack threat to the data. At the same time, if the access frequency of a certain type of data is significantly higher than usual during historical network attacks, it indicates that this type of data is a key target of malicious attackers and receives a higher degree of attention. Therefore, this application can combine the storage status risk level and the access performance of data during the attack to comprehensively evaluate the information attention coefficient.
[0082] For example, the information attention coefficient satisfies the following formula: ; in, For the first Information attention coefficient for each type of data The storage state risk level of the virtual power plant. For the first The number of times this type of data was accessed during the most recent cyberattack. This represents the maximum number of accesses for all types of data during the most recent cyberattack. This reflects the access frequency of this type of data during the most recent cyberattack. The larger the value, the more attention this type of data received during the most recent cyberattack.
[0083] Based on the above technical solution, this application can determine the storage state risk level of the virtual power plant according to the historical network attack records, so as to quantify the overall security environment of the virtual power plant. Then, for each type of data, the information attention coefficient of the data type is determined according to the historical access records of the data type and the storage state risk level of the virtual power plant. This allows the information attention coefficient to comprehensively reflect the security risk of each type of data in the attack environment. The higher the storage state risk level and the higher the access popularity of the data type during the attack, the more likely the data type is to become an attack target and requires stronger privacy protection. The above technical solution provides reliable support for the accurate calculation of privacy protection needs and further improves the pertinence of privacy protection strategies.
[0084] Please see Figure 2 The diagram illustrates a system architecture of a privacy-based computing-based virtual power plant digital resource protection system 20 according to an embodiment of the present invention. The privacy-based computing-based virtual power plant digital resource protection system 20 includes: Data acquisition unit 21 is used to acquire historical network attack records of the virtual power plant and historical access records of various types of data; Risk assessment unit 22 is used to conduct risk value assessment analysis for each type of data based on the historical network attack records of the virtual power plant and the historical access records of the data type, and to determine the privacy protection requirement level corresponding to the data type; the privacy protection requirement level is used to characterize the priority level of privacy protection for the corresponding data type. Privacy control unit 23 is used to perform differential privacy protection operations based on the privacy protection requirements of various types of data.
[0085] It should be noted that the various embodiments of this application can be referenced or learned from each other. For example, the same or similar steps, method embodiments, system embodiments and device embodiments can be referenced from each other without limitation.
[0086] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0087] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
Claims
1. A method for protecting digital resources in a virtual power plant based on privacy computing, characterized in that, include: Obtain historical network attack records and historical access records of various types of data from the virtual power plant; For each type of data, a risk value assessment analysis is performed based on the historical network attack records of the virtual power plant and the historical access records of the data of that type to determine the privacy protection requirement level corresponding to that type of data; the privacy protection requirement level is used to characterize the priority level of privacy protection for the corresponding type of data; Differential privacy protection operations are performed based on the privacy protection requirements of different types of data.
2. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 1, characterized in that, For each type of data, a risk value assessment analysis is performed based on the historical network attack records of the virtual power plant and the historical access records of that type of data to determine the privacy protection requirements corresponding to that type of data, including: For each type of data, a resource protection importance analysis is performed based on the historical access records of that type of data to determine the resource protection importance of that type of data; the resource protection importance is used to characterize the data protection priority of the corresponding type of data; For each type of data, a storage status risk assessment is conducted based on the historical access records of that type of data and in conjunction with the historical network attack records to determine the information attention coefficient of that type of data; the information attention coefficient is used to characterize the degree of attention received by the corresponding type of data in a network attack environment; For each type of data, the privacy protection requirement is determined based on the resource protection importance and information attention coefficient of that type of data.
3. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 2, characterized in that, For each type of data, a resource protection importance analysis is performed based on the historical access records of that type of data to determine the resource protection importance of that type of data, including: For each type of data, the presentation degree of important information of that type of data is determined based on the historical access records of that type of data; the presentation degree of important information is used to determine the data importance of the corresponding type of data; For each type of data, the presentation of important information is adjusted based on the proportion of unauthorized access in the historical access records of that type of data, thus obtaining the resource protection importance of that type of data.
4. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 3, characterized in that, For each type of data, the presentation level of important information of that type of data is determined based on the historical access records of that type of data, including: For each type of data, a resource popularity index is determined based on the historical access records of that type of data; the resource popularity index is used to characterize the growth trend of the historical access frequency of the corresponding type of data. For each type of data, the data association strength of that type of data is determined based on the historical access records of that type of data and other types of data; the data association strength is used to characterize the degree of collaborative access between the corresponding type of data and other types of data; For each type of data, the presentation degree of important information of that type of data is determined based on the resource popularity index and data correlation strength of that type of data.
5. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 4, characterized in that, For each type of data, a resource popularity index is determined based on the historical access records of that type of data, including: For each type of data, the access frequency slope factor and the total number of historical accesses for that type of data are determined based on the historical access records of that type of data. The resource popularity index of the data type is determined based on the access frequency slope factor and the total number of historical accesses.
6. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 4, characterized in that, For each type of data, the data association strength of that type of data is determined based on historical access records of that type of data and other types of data, including: For each type of data, the access time periods of the data type and other data types are obtained from the historical access records of the data type and other data types. For each type of data, a correlation analysis is performed based on the access time periods of the data of that type and other types of data to determine the associated data types of the data of that type. The strength of the data association for each data type is determined based on the associated data types of each data type.
7. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 2, characterized in that, For each type of data, a storage status risk assessment is performed based on the historical access records of that data type and in conjunction with the historical network attack records to determine the information attention coefficient of that data type, including: The storage state risk level of the virtual power plant is determined based on the historical network attack records; the storage state risk level is used to characterize the severity of the network attack on the virtual power plant. For each type of data, an information attention coefficient is determined based on the historical access records of the data type and the storage status risk level of the virtual power plant.
8. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 7, characterized in that, The storage state risk level of the virtual power plant is determined based on the historical network attack records, including: Obtain the network attack period and attack intensity rating of the most recent network attack event from the historical network attack records; The storage state risk level is determined based on the network attack period and the attack intensity evaluation value.
9. The method for protecting digital resources of a virtual power plant based on privacy computing according to claim 1, characterized in that, Differential privacy protection operations are performed based on the privacy protection requirements of different types of data, including: Based on the privacy protection needs of different types of data, the privacy budget parameters of each type of data are adaptively adjusted to obtain the adjusted privacy budget parameters of each type of data. For each type of data, differential privacy protection operations are performed based on the privacy budget parameters adjusted according to the data type.
10. A virtual power plant digital resource protection system based on privacy computing, characterized in that, include: The data acquisition unit is used to acquire historical network attack records and historical access records of various types of data from the virtual power plant. The risk assessment unit is used to perform risk value assessment analysis on each type of data based on the historical network attack records of the virtual power plant and the historical access records of the data of that type, and to determine the privacy protection requirement level corresponding to the data of that type; the privacy protection requirement level is used to characterize the priority level of privacy protection for the corresponding data type. The privacy control unit is used to perform differential privacy protection operations based on the privacy protection requirements of various types of data.
Citation Information
Patent Citations
Enterprise knowledge brain data storage method based on privacy calculation
CN117454410A
Power system data privacy protection and access control method
CN117951722A
Multi-application environment encryption communication method and system for user privacy protection
CN119382995A
Differential privacy-based power plant network security asset management method and related device
CN119854008A
Security protection method, system and device for data sharing and exchange and medium
CN120162811A