Distribution network data stream security policy and bandwidth allocation joint determination method and device
By constructing a joint determination model for security strategy and bandwidth allocation in the distribution network, and utilizing multi-agent reinforcement learning and random forest models, the security strategy and bandwidth allocation are dynamically adjusted. This solves the problem of security strategy adaptability caused by changes in the distribution network environment, achieves efficient security protection and resource allocation under different risk conditions, and improves the overall security and reliability of the distribution network.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
- Filing Date
- 2024-10-31
- Publication Date
- 2026-05-01
AI Technical Summary
In existing technologies, the security protection strategies of power distribution networks cannot adapt to the dynamically changing network environment, resulting in excessive resource consumption and affecting service quality when the network risk level is low, while the protection strategies fail when the risk level is high.
A joint determination method for distribution network data flow security strategy and bandwidth allocation is adopted. Through multi-agent reinforcement learning and random forest model, the security strategy and bandwidth resource allocation are dynamically adjusted to construct a security strategy and bandwidth allocation determination model. With the goal of maximizing the utility function, the actions of the security agent and the communication agent are optimized by combining the Stackelberg game framework to achieve adaptive security protection.
In the dynamic and changing distribution network environment, it enables rapid adaptation of security strategies and efficient allocation of bandwidth resources, ensuring the security and quality of service under different risk conditions, and improving the overall security and reliability of the distribution network system.
Smart Images

Figure CN121967227A_ABST
Abstract
Description
Method and apparatus for jointly determining data flow security strategy and bandwidth allocation in power distribution network Technical Field
[0001] This invention relates to the fields of mobile communication security technology and industrial internet technology, and in particular to a method and apparatus for jointly determining data flow security strategy and bandwidth allocation in a distribution network. Background Technology
[0002] With the increasing openness of distribution network equipment and the trends of diversified terminal equipment, multiple stakeholders, and data integration, the risk surface of distribution network data is constantly expanding, and data security risks are increasing dramatically. To address the increasingly serious distribution network data security issues, existing technologies support the introduction of distribution network data stream security protection measures to ensure its security during transmission, storage, and access.
[0003] However, the selection of these security measures relies on manual configuration by technical engineers, and once the configuration is effective, it is rarely changed, meaning a static security strategy is always adopted. This static security strategy is difficult to adapt to the dynamically changing distribution network environment, resulting in situations where security measures consume a lot of resources and degrade service quality when the network risk level is low, and the security strategy fails when the network risk level is high.
[0004] Therefore, how to adaptively adjust security protection strategies and bandwidth resource allocation for dynamically changing distribution network environments and heterogeneous distribution network data flows is an urgent problem to be solved. Summary of the Invention
[0005] This invention provides a method and apparatus for jointly determining distribution network data flow security strategy and bandwidth allocation, which addresses the shortcomings of existing static security protection strategies that are difficult to adapt to dynamically changing distribution network environments. These shortcomings include the consumption of excessive resources and loss of service quality by security protection measures when the network risk level is low, and the failure of security protection strategies when the network risk level is high. This invention enables adaptive adjustment of security protection strategies for dynamically changing distribution network environments and heterogeneous distribution network data flows.
[0006] This invention provides a method for jointly determining the security strategy and bandwidth allocation of distribution network data streams, comprising the following steps: obtaining a security strategy and bandwidth allocation determination model, wherein the security strategy and bandwidth allocation determination model is constructed with the objective of maximizing the utility function of each service's security strategy and bandwidth allocation, and with the predicted risk level of each service after orchestrating the target security strategy and the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources as constraints; the utility function of each service's security strategy is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service; and solving the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0007] According to a method for jointly determining a distribution network data flow security policy and bandwidth allocation provided by the present invention, the steps for determining the total security gain and total cost of the security policy and bandwidth allocation include: determining a first security gain of a distribution data encryption storage method, a second security gain of a distribution data encryption transmission method, and a third security gain of a distribution data access control method; determining the total security gain based on the first security gain, the second security gain, and the third security gain; the first security gain being determined based on the effectiveness of the distribution data encryption storage method and a first length of the encryption key; the second security gain being determined based on the effectiveness of the distribution data encryption transmission method and a second length of the encryption key; determining a first cost of the distribution data encryption storage method and a second cost of the distribution data encryption transmission method; and determining the total cost based on the first cost, the second cost, and the third cost of the distribution data access control method.
[0008] According to the present invention, a method for jointly determining the security strategy and bandwidth allocation of distribution network data streams, the determination of the first cost of the encrypted storage means of distribution data and the second cost of the encrypted transmission means of distribution data includes: determining the first cost based on the first encryption delay and the first decryption delay of the encrypted storage means of distribution data; and determining the second cost based on the second encryption delay, the transmission delay and the second decryption delay of the encrypted transmission means of distribution data.
[0009] According to the present invention, a method for jointly determining the security strategy and bandwidth allocation of distribution network data streams is provided. The first encryption delay and the second encryption delay are both determined based on the encryption algorithm complexity, key length, and CPU rotation speed of each device in each service. The first decryption delay and the second decryption delay are both determined based on the decryption algorithm complexity, key length, and CPU rotation speed of each device in each service. The transmission delay is determined based on the service data traffic size of each service, the length of the encryption header of the selected encryption algorithm, the transmission bandwidth allocated to each service, and the channel signal-to-noise ratio.
[0010] According to a method for jointly determining distribution network data flow security strategy and bandwidth allocation provided by the present invention, the step of determining the predicted risk level includes: acquiring distribution network environment data; inputting the distribution network environment data into a risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
[0011] According to the present invention, a method for jointly determining the security policy and bandwidth allocation of distribution network data flow is provided. The step of solving the security policy and bandwidth allocation determination model to obtain the target security policy and bandwidth resource allocation scheme includes: solving the security policy and bandwidth allocation determination model based on multi-agent reinforcement learning to obtain the target security policy and bandwidth resource allocation scheme.
[0012] This invention also provides a device for jointly determining the security strategy and bandwidth allocation of distribution network data streams, comprising the following units: an acquisition unit, used to acquire a security strategy and bandwidth allocation determination model, wherein the security strategy and bandwidth allocation model is constructed with the objective of maximizing the utility function of each service's security strategy, and with constraints including the predicted risk level of each service after orchestrating the target security strategy, and the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources; the utility function of each service's security strategy is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service; and a target security strategy determination unit, used to solve the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0013] According to the present invention, a device for jointly determining a distribution network data flow security strategy and bandwidth allocation further includes a total security gain and a total cost determination unit. The total security gain and total cost determination unit is specifically used for: a gain determination unit, used to determine a first security gain of a distribution data encryption storage method, a second security gain of a distribution data encryption transmission method, and a third security gain of a distribution data access control method; a total security gain determination unit, used to determine the total security gain based on the first security gain, the second security gain, and the third security gain; the first security gain is determined based on the effectiveness of the distribution data encryption storage method and a first length of the encryption key; the second security gain is determined based on the effectiveness of the distribution data encryption transmission method and a second length of the encryption key; a cost determination unit, used to determine a first cost of the distribution data encryption storage method and a second cost of the distribution data encryption transmission method; and a total cost determination unit, used to determine the total cost based on the first cost, the second cost, and the third cost of the distribution data access control method.
[0014] According to the present invention, a joint determination device for distribution network data flow security strategy and bandwidth allocation is provided, wherein the cost determination unit is specifically used for: a first cost determination unit, used for determining the first cost based on the first encryption delay and the first decryption delay of the distribution data encryption storage method; and a second cost determination unit, used for determining the second cost based on the second encryption delay, the transmission delay and the second decryption delay of the distribution data encryption transmission method.
[0015] According to the present invention, a joint determination device for security strategy and bandwidth allocation of distribution network data flow is provided. The first encryption delay and the second encryption delay are both determined based on the encryption algorithm complexity, key length, and CPU speed of each device in each service; the first decryption delay and the second decryption delay are both determined based on the decryption algorithm complexity, key length, and CPU speed of each device in each service; the transmission delay is determined based on the service data traffic size of each service, the length of the encryption header of the selected encryption algorithm, the transmission bandwidth allocated to each service, and the channel signal-to-noise ratio.
[0016] According to the present invention, a device for jointly determining the security strategy and bandwidth allocation of distribution network data flow further includes a risk level prediction unit. The risk level prediction unit is specifically used for: acquiring distribution network environment data; inputting the distribution network environment data into a risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
[0017] According to the present invention, a device for jointly determining the security strategy and bandwidth allocation of a distribution network data stream is provided. The target security strategy determination unit is specifically used to: solve the security strategy and bandwidth allocation determination model based on multi-agent reinforcement learning to obtain the target security strategy and bandwidth resource allocation scheme.
[0018] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for jointly determining the data flow security strategy and bandwidth allocation as described above.
[0019] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for jointly determining the data flow security strategy and bandwidth allocation of the distribution network as described above.
[0020] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the method for jointly determining the data flow security strategy and bandwidth allocation as described above.
[0021] The present invention provides a method and apparatus for jointly determining data flow security strategies and bandwidth allocation in distribution networks. The method and apparatus acquire a security strategy and bandwidth allocation determination model. This model aims to maximize the utility function of each service's security strategy and bandwidth allocation, and is constructed under constraints including the predicted risk level after orchestrating the target security strategy for each service, the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources, and then solves the security strategy and bandwidth allocation model to obtain the target security strategy and bandwidth resource allocation scheme. This process enables the model to quickly adapt to the dynamically changing environment of the distribution network, ensuring the security and service quality of each service under different risk conditions. Furthermore, it allows the entire distribution network system to efficiently and accurately adjust security strategies and rationally allocate bandwidth resources when facing complex and highly dynamic environments. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0023] Figure 1 is a flowchart illustrating the method for jointly determining the data flow security strategy and bandwidth allocation in the distribution network provided by the present invention.
[0024] Figure 2 is a schematic diagram of the structure of the device for jointly determining the data flow security strategy and bandwidth allocation of the distribution network provided by the present invention.
[0025] Figure 3 is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0027] The terms "first," "second," etc., used in this invention are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and that the objects distinguished by "first," "second," etc., are generally of the same class.
[0028] This invention provides a method for jointly determining the security strategy and bandwidth allocation of distribution network data flow. Figure 1 is a flowchart of the method for jointly determining the security strategy and bandwidth allocation of distribution network data flow provided by this invention. As shown in Figure 1, the method includes steps 110 and 120.
[0029] Step 110: Obtain the security policy and bandwidth allocation determination model. The security policy and bandwidth allocation determination model is constructed with the objective of maximizing the utility function of each service's security policy, and with the predicted risk level of each service after orchestrating the target security policy, and the overall service quality of each service after orchestrating the target security policy and allocating bandwidth resources as constraints. The utility function of each service's security policy and bandwidth allocation is determined based on the total security gain and total cost of the security policy and bandwidth allocation corresponding to the risk level of each power distribution service.
[0030] Specifically, a security policy and bandwidth allocation determination model can be obtained. This model is used to determine the target security policy and bandwidth allocation. It can be understood that the security policy and bandwidth allocation determination model can sense and adaptively adjust the security protection policy and bandwidth allocation of the distribution network data stream based on the risk level of the distribution network environment. This model is a method for dynamically adjusting the target policy, enabling the formulation of an effective security protection policy and the most suitable bandwidth allocation scheme for the distribution network data stream without affecting the quality of distribution network services.
[0031] Here, the formula for the security policy and bandwidth allocation determination model is as follows:
[0032] Wherein, Security represents the set of security policies for each service orchestration; Bandwidth represents the set of bandwidth sizes allocated to each service, both of which are represented in matrix form; Constraint C1 means that after orchestrating the target security policy for each service, the predicted risk level output by the random forest must be 0 (i.e., low risk level); Constraint C2 means that after orchestrating the target security policy and allocating bandwidth resources for each service, the overall service quality of the service (determined by the total latency) cannot be lower than the minimum service quality standard required by the service.
[0033] In other words, it is necessary to adjust the security strategies for various services within the distribution network environment and allocate bandwidth resources to each service to ensure the safe and stable operation of all services within the distribution network. Therefore, this mathematical problem can be expressed as maximizing the long-term utility function while satisfying the security and Quality of Service (QoS) requirements of all services within the distribution network.
[0034] Here, the utility function of each service security policy and bandwidth allocation is determined based on the total security gain and total cost of the security policy and bandwidth allocation corresponding to the risk level of each power distribution service.
[0035] Considering that different business types have different requirements for security and service quality, the embodiments of this invention define... Characterization business The weighting factor between security and quality of service requirements. Based on this, the utility function used to orchestrate security policies and bandwidth allocation for various services in time slot t can be expressed as: ,in, Indicates the total security gain. This represents the total cost.
[0036] It should be noted that the security protection strategy based on the security policy and bandwidth allocation determination model will achieve the best balance between security protection strength and distribution network service quality according to the real-time risk level and business traffic density of the distribution network. This will ensure that the distribution network data flow can receive the most appropriate security protection when facing different risk levels, thereby improving the overall security and reliability of the distribution network.
[0037] Step 120: Solve the security policy and bandwidth allocation determination model to obtain the target security policy and bandwidth resource allocation scheme.
[0038] Specifically, due to the enormous solution space of the above problem, and the difficulty in directly quantifying the specific expressions of security strategies and risk levels using the random forest-based risk level prediction model, direct solution is extremely difficult. Therefore, this embodiment of the invention transforms the above mathematical model into an optimization problem where a security agent and a communication agent search for optimal actions within a Stackelberg game framework. Both agents search for actions within a space conforming to a Markov Decision Process (MDP). Specifically, the security agent acts as the leader within the Stackelberg game framework, and it achieves this by using a triplet consisting of a State leader, an Action leader, and a Reward leader (i.e., ...). The Markov decision process described above searches for the optimal action, prioritizing the current actions for all business processes. orchestrating security policies .
[0039] For the mathematical problem constructed, this embodiment of the invention defines the Stateleader of the state space of the secure intelligent agent as follows: .in, This represents the set of risk levels for each business segment, and the risk level for each business segment. The values are discrete values in {0, 1, 2, 3}, representing low risk, low-to-medium risk, medium-to-high risk, and high risk levels. This invention defines the Actionleader of the security intelligent agent's action space as... .in, A set of security measures representing each business orchestration Discrete action space with increasing or decreasing intensity. In this embodiment of the invention, the reward leader of the security agent is defined as... This indicates the security gain that the leader brings to the system after performing an action.
[0040] The communicating agent will act as a follower in the Stackelberg game framework, observing the leader's actions in each time slot t. Then, execute all services for which security measures are currently configured. Allocate bandwidth resources The action.
[0041] Specifically, the communicating agent consists of a triplet consisting of Statefollower (state space), Actionfollower (action space), and Rewardfollower (reward). This describes the search for optimal bandwidth resource allocation actions in a Markov decision process. For the constructed mathematical optimization problem, this embodiment of the invention defines the state space of the communication agent, Statefollower, as... ,in This represents the set of service quality levels for each service after the leader has configured the security policy and the followers have configured the bandwidth allocation policy. Each service's service quality level... The values are discrete integers in the range [0, 9], representing the current service quality level of each service. A higher value indicates a better service quality. In this embodiment of the invention, the action space of the communication agent is defined as... ,in, This represents the continuous action space for allocating bandwidth resources to each service i. In this embodiment of the invention, the reward follower of the communication agent is defined as... This represents the total communication cost introduced after the leader and followers have performed their actions.
[0042] Therefore, by solving the security policy and bandwidth allocation determination model, the target security policy and bandwidth resource allocation scheme are obtained.
[0043] The method provided in this invention obtains a security policy and bandwidth allocation determination model. This model aims to maximize the utility function of each service's security policy and bandwidth allocation, and is constructed under constraints including the predicted risk level after orchestrating the target security policy for each service, the overall service quality after orchestrating the target security policy and allocating bandwidth resources, and the solution to obtain the target security policy and bandwidth resource allocation scheme. This process enables the model to quickly adapt to the dynamically changing environment of the distribution network, ensuring the security and service quality of each service under different risk conditions. Furthermore, it allows the entire distribution network system to efficiently and accurately adjust security policies and rationally allocate bandwidth resources when facing complex and highly dynamic environments.
[0044] Based on the above embodiments, the steps for determining the total security gain and total cost of the security policy and bandwidth allocation include: step 210, determining a first security gain for the power distribution data encryption storage method, a second security gain for the power distribution data encryption transmission method, and a third security gain for the power distribution data access control method; step 220, determining the total security gain based on the first security gain, the second security gain, and the third security gain; the first security gain is determined based on the effectiveness of the power distribution data encryption storage method and a first length of the encryption key; the second security gain is determined based on the effectiveness of the power distribution data encryption transmission method and a second length of the encryption key.
[0045] Step 230: Determine the first cost of the power distribution data encryption storage method and the second cost of the power distribution data encryption transmission method.
[0046] Step 240: Determine the total cost based on the first cost, the second cost, and the third cost of the power distribution data access control means.
[0047] Specifically, the distribution network environment is described and formally represented as follows: At the current moment, simultaneous initiation within the distribution network... The first business, expected to be the [number]th The data traffic size of each business is , No. The risk sensitivity of each business is: Distribution network environmental risks Given by the anomaly detection system deployed within the distribution network, denoted as the frequency of anomalies occurring per unit time, then the th... Risk index of individual power distribution business It can be defined as (Values range from 0 to 1, with higher values indicating higher risk). To address the safety risks inherent in the power distribution network, a series of safety measures are permitted for each power distribution service. This includes methods for encrypting and storing power distribution data. Encryption methods for power distribution data stream transmission Power distribution data access control methods Among them, the methods for encrypting and storing power distribution data In this process, each service can choose the most suitable encryption storage strategy from multiple encryption algorithms and key lengths; in the encrypted transmission of power distribution data streams... In this context, each service can choose the most suitable encryption transmission strategy from multiple encryption algorithms and key lengths; in power distribution data access control methods In this system, each service can choose the most suitable access control strategy from a variety of access control algorithms with varying strengths. As described above, under different risk indices, a series of optimal security measures are selected for services within the distribution network. This is the process model for orchestrating security policies.
[0048] Security policy and bandwidth allocation orchestration utility function design: To ensure that the security policy orchestrated for power distribution services achieves long-term maximum utility, this embodiment of the invention first divides the system time into numerous time slots from a time dimension. ,Right now For each service's chosen security strategy in time slot t, each security measure will provide a certain security boost to the current service.
[0049] Specifically, embodiments of the present invention define a means for encrypting and storing power distribution data. First security gain ,in, This indicates the validity of the selected encryption storage algorithm. Indicates the first length of the selected encryption key; means of encrypting power distribution data transmission. Second security gain ,in, This indicates the effectiveness of the selected encryption transmission algorithm. Indicates the second length of the selected encryption key; power distribution data access control means Safety gain This represents the strength of access control. Combining the above definition, this refers to a series of security measures taken for service i in time slot t. The total security gain brought to business i can be expressed as: ,in The risk index for business i.
[0050] That is, the total security gain is determined based on the first security gain, the second security gain, and the third security gain.
[0051] Then, the first cost of the power distribution data encryption storage method and the second cost of the power distribution data encryption transmission method can be determined. Based on the first cost, the second cost, and the third cost of the power distribution data access control method, the total cost can be determined, as follows: A series of security measures taken for service i in time slot t. The total cost to business i This can be expressed as:
[0052] in, Indicates data encryption storage methods The first cost of introduction Indicates the means of encrypted data transmission The second cost introduced, Indicates power distribution data access control methods The third cost is the means of power distribution data access control. The cost of the introduction is expressed as the proportion of normal business operations that cannot be accessed smoothly due to the increased access control measures.
[0053] Based on the above embodiments, step 230 includes: step 231, determining the first cost based on the first encryption delay and the first decryption delay of the power distribution data encryption storage method; step 232, determining the second cost based on the second encryption delay, the transmission delay and the second decryption delay of the power distribution data encryption transmission method.
[0054] Specifically, since the adoption of various security measures inevitably introduces additional costs, resulting in performance loss of power distribution services, the embodiments of the present invention further calculate the costs after introducing security measures.
[0055] Specifically, regarding the methods for encrypting and storing power distribution data The first cost introduced includes the first encryption delay. First decryption delay The encryption latency primarily depends on the complexity of the encryption algorithm chosen by the i-th device. Key length And the speed of the device's CPU (Central Processing Unit). , represented as The decryption delay is calculated using the same method as the encryption delay, and is expressed as follows: Then data encryption storage methods Total cost introduced For power distribution data transmission and storage methods The second cost introduced includes a second encryption delay. Transmission delay Second decryption delay Similar to encrypted storage methods, encryption latency and decryption latency can be calculated using the following formulas. , ,in , These represent the CPU rotation speeds of the encryption and decryption devices, respectively; the transmission latency mainly depends on the data traffic size of the i-th service. The length of the encryption header of the selected encryption algorithm The transmission bandwidth allocated to the i-th service Channel signal-to-noise ratio , represented as Then data encryption transmission methods Total cost introduced .
[0056] Based on the above embodiments, the step of determining the predicted risk level includes: step 410, acquiring distribution network environment data; step 420, inputting the distribution network environment data into the risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
[0057] Specifically, the risk level prediction model can be a dynamic risk assessment model for distribution networks based on random forests.
[0058] Considering the dynamic and complex nature of the distribution network environment, it is difficult to directly establish a mathematical expression relating the predicted risk level to factors such as the current distribution network environment risk index, business sensitivity, business type, and security strategies adopted by the business. Therefore, this embodiment of the invention uses a random forest model to directly learn the risk levels of various businesses under different environments from expert-annotated data. The main steps include: Step 1: Obtain sample distribution network environment data. Here, sample distribution network environment data refers to domain expert-annotated data. Distribution network security experts, based on the distribution network environment, alarm status of the distribution network anomaly detection system, characteristics of distribution business, and the use of security measures, label the current distribution business as being at a first-label risk level, a second-label risk level, a third-label risk level, or a fourth-label risk level. The first-label risk level is higher than the second-label risk level, the second-label risk level is higher than the third-label risk level, and the third-label risk level is higher than the fourth-label risk level. Specifically, the first-label risk level is high risk, the second-label risk level is medium-high risk, the third-label risk level is medium-low risk, and the fourth-label risk level is low risk.
[0059] Step 2: Constructing the Power Distribution Environment-Risk Level Dataset. The large amount of expert-annotated data is cleaned and integrated to construct a dataset for subsequent training of the random forest model. The dataset covers power distribution environment characteristics including the current environmental risk index, business sensitivity, business type, and adopted security strategies. The label column can have four values, representing high risk, medium-high risk, medium-low risk, and low risk levels, respectively.
[0060] Step 3: Train the risk level prediction model, specifically a random forest model, to dynamically assess the predicted risk level of the current business. The random forest model is trained using a constructed distribution environment-risk level dataset to obtain model parameters that effectively characterize the relationship between distribution network environment data and risk levels. Deploying this model in the distribution network allows for real-time output of the predicted risk level for each distribution business based on the perceived distribution network environment data.
[0061] The specific process of training the risk level prediction model is as follows: First, an initial risk level prediction model can be obtained, along with sample distribution network environment data and the labeled risk level of the sample distribution network environment data.
[0062] Then, the sample distribution network environment data can be input into the initial risk level prediction model to obtain the predicted risk level output by the initial risk level model.
[0063] After obtaining the predicted risk level, the predicted risk level can be compared with the labeled risk level. The loss function value is calculated based on the difference between the two. Then, the parameters of the initial risk level prediction model are iterated based on the loss function value, and the initial risk level prediction model after parameter iteration is used as the risk level prediction model.
[0064] It is understandable that the greater the difference between the predicted risk level and the labeled risk level, the larger the loss function value; the smaller the difference between the predicted risk level and the labeled risk level, the smaller the loss function value.
[0065] Based on the above embodiments, step 120 includes: solving the security policy and bandwidth allocation determination model based on multi-agent reinforcement learning to obtain the target security policy and bandwidth resource allocation scheme.
[0066] Specifically, the security policy and bandwidth allocation determination model can be solved based on multi-agent reinforcement learning (MARL) to obtain the target security policy and bandwidth resource allocation scheme.
[0067] In the aforementioned constructed security agent and communication agent, their action spaces are discrete and continuous, respectively. To ensure efficient policy updates for each agent, this embodiment of the invention introduces the DQN (Deep Q-learning) algorithm to solve the Markov decision problem for the security agent and the DDPG (Deep Deterministic Policy Gradient) algorithm to solve the Markov decision problem for the communication agent.
[0068] Specifically, embodiments of the present invention perform joint training of multiple agents through the following steps, aiming to obtain a global reward. Maximizing the optimal strategy for a secure intelligent agent and .
[0069] Step 1: Initialization. Initialize the distribution network environment and obtain the global initial state. Initialize the Q-network of the security agent, which is used to output discrete actions for orchestrating security policies; initialize the policy network (Actor network) and Q-value estimation network (Critic network) of the communication agent, which is used to output continuous actions for allocating bandwidth resources.
[0070] Step Two: The leader (security agent) takes action. At each time step t, the leader first... - Greedy strategy in the current state Next action That is, with 1- The probability of choosing the action with the highest current Q value is given. The probability of randomly selecting an action.
[0071] Step 3: The follower (communication agent) takes action. At each time step t, the follower observes the leader's actions. and through its policy network Choose in the current state Actions with leaders The best move Subsequently, the followers' Critic network inputs the leader's actions. and the actions of followers To estimate the joint Q value in the current state. .
[0072] Step 4: Obtain the global reward and the next state. The system environment will be based on the combined actions of the leader and followers. Generate global rewards and the next state .
[0073] Step 5: Experience Storage. Both the leader and followers store their experiences in an experience replay pool for batch learning in subsequent training. Each experience contains the current state. The joint actions of leaders and followers Global Rewards and the next state ,Right now .
[0074] Step 6: Every fixed time step, both agents sample experience from the experience pool to update the Q-value and policy network in batches. Specifically, for Q-value updates, the leader samples a series of stored experiences... The Q-value is updated according to the DQN algorithm, that is... Followers learn from a series of stored experiences The Q value is updated according to the DDPG algorithm, that is... For policy network updates, the leader's policy network is updated by selecting discrete actions that maximize the Q-value, i.e. The follower's policy network is updated using policy gradient descent to maximize the expected Q-value in the current state, i.e.: Both the leader and followers continuously sample experiences and update the Q-value and policy network until both policies converge.
[0075] Security agent and communication agent execute strategies: After the above training process is completed, the two agents can execute actions according to their respective trained strategies. That is, the security agent determines the optimal security orchestration scheme for all current services based on the observed environmental state; the communication agent executes the optimal bandwidth allocation strategy for all current services based on the observed leader's actions and the current state.
[0076] The method provided in this invention applies a multi-agent reinforcement learning scheme to solve the above-mentioned MDP model, so as to obtain the optimal strategy for deciding on the orchestration scheme of security policies for each business. Utilizing the optimal strategy obtained from the final fit. This allows for quick calculation of which security strategy and bandwidth resource allocation is most appropriate for each service in a dynamically changing power distribution network environment.
[0077] Based on any of the above embodiments, a method for jointly determining the security strategy and bandwidth allocation of distribution network data flow includes the following steps: First, obtain a security strategy and bandwidth allocation determination model. Here, the security strategy and bandwidth allocation determination model aims to maximize the utility function of each service's security strategy and bandwidth allocation, and is constructed under the constraints of the predicted risk level after orchestrating the target security strategy for each service, the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources, wherein the utility function of each service's security strategy and bandwidth allocation is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service; Second, solve the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0078] Here, the steps for determining the total security gain and total cost of the security policy and bandwidth allocation include: S1, determining the first security gain of the power distribution data encryption storage method, the second security gain of the power distribution data encryption transmission method, and the third security gain of the power distribution data access control method; S2, determining the total security gain based on the first security gain, the second security gain, and the third security gain, wherein the first security gain is determined based on the effectiveness of the power distribution data encryption storage method and the first length of the encryption key, and the second security gain is determined based on the effectiveness of the power distribution data encryption transmission method and the second length of the encryption key; S3, determining the first cost based on the first encryption delay and the first decryption delay of the power distribution data encryption storage method; S4, determining the second cost based on the second encryption delay, the transmission delay, and the second decryption delay of the power distribution data encryption transmission method; S5, determining the total cost based on the first cost, the second cost, and the third cost of the power distribution data access control method.
[0079] The first and second encryption delays are both determined based on the encryption algorithm complexity, key length, and CPU speed of each device in each service. The first and second decryption delays are also determined based on the decryption algorithm complexity, key length, and CPU speed of each device in each service. The transmission delay is determined based on the service data traffic volume of each service, the length of the encryption header of the selected encryption algorithm, the transmission bandwidth allocated to each service, and the channel signal-to-noise ratio.
[0080] Here, the steps for determining the predicted risk level include: acquiring distribution network environment data; inputting the distribution network environment data into the risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained by training based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
[0081] In summary, the above process can be simplified as follows: First, a dynamic risk prediction model for the distribution network is constructed based on random forest to analyze the risk levels of various services within the distribution network under different security strategies in real time. Second, the utility functions of various services adopting different security strategies in the distribution network environment are constructed, and a mathematical model is established to maximize the utility functions by orchestrating the security strategies of each service while meeting the service quality and security performance requirements of each service. Third, the established mathematical model is transformed into an optimization problem of searching for the best action based on Markov Decision Process (MDP) within a Stackelberg game framework using multiple agents, to better describe the dynamically changing distribution network environment and simplify the solution process. Finally, a multi-agent reinforcement learning scheme is applied to solve the MDP model to obtain the optimal strategy for deciding the orchestration scheme of security strategies for each service. Optimal strategy for execution bandwidth allocation Using the optimal strategy that was finally fitted... , This allows for quick calculation of which security strategy and bandwidth resource allocation is most suitable for each service in a dynamically changing power distribution network environment.
[0082] The methods provided in this invention include: 1) A dynamic risk prediction model for distribution networks based on random forests comprehensively considers multiple factors such as data importance and service availability. By weighing and integrating different factors, it more comprehensively reflects the actual risk situation. This helps system administrators or decision-makers to more accurately understand and respond to risks of different levels. Unlike the traditional static equal division method, the random forest method can dynamically adjust the risk assessment results based on real-time monitored data flow information, user activities, and environmental conditions. 2) The utility function design and mathematical model construction for orchestrating security strategies and bandwidth allocation abstracts the dynamic and complex distribution network environment into a mathematical model, comprehensively modeling the effect gain of security strategies and the resulting service quality loss, providing a specific problem model for orchestrating security strategies for various services within the distribution network. 3) An optimal strategy solution based on multi-agent reinforcement learning avoids the difficulty of describing state transition probabilities in complex environments using mathematical models, and after solving for the optimal strategy, it can quickly search for the best security measures to be deployed for each service and the bandwidth allocated to each service.
[0083] Understandably, through the methods described above, the system can quickly adapt to the dynamically changing environment of the distribution network, ensuring the security and quality of service of various businesses under different risk conditions. In particular, the combination of a dynamic risk prediction model based on random forests and multi-agent reinforcement learning enables the entire distribution network system to efficiently and accurately adjust security strategies and bandwidth allocation when facing complex and highly dynamic environments.
[0084] The security protection strategy and bandwidth allocation formulated based on the embodiments of the present invention will achieve the best balance between security protection strength and distribution network service quality according to the real-time risk level and business traffic density of the distribution network, ensuring that the distribution network data flow can receive the most appropriate security protection when facing different risk levels, thereby improving the overall security and reliability of the distribution network.
[0085] The following describes the distribution network data flow security strategy and bandwidth allocation joint determination device provided by the present invention. The distribution network data flow security strategy and bandwidth allocation joint determination device described below and the distribution network data flow security strategy and bandwidth allocation joint determination method described above can be referred to in correspondence with each other.
[0086] Based on any of the above embodiments, the present invention provides a device for jointly determining the security strategy and bandwidth allocation of distribution network data streams. Figure 2 is a schematic diagram of the structure of the device for jointly determining the security strategy and bandwidth allocation of distribution network data streams provided by the present invention. As shown in Figure 2, the device includes: an acquisition unit 201, used to acquire a security strategy and bandwidth allocation determination model. The security strategy and bandwidth allocation determination model is constructed with the objective of maximizing the utility function of each service's security strategy and bandwidth allocation, and with the predicted risk level of each service after orchestrating the target security strategy and the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources as constraints. The utility function of each service's security strategy and bandwidth allocation is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service. A target security strategy determination unit 202 is used to solve the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0087] The apparatus provided in this invention acquires a security policy and bandwidth allocation determination model. This model aims to maximize the utility function of each service's security policy and bandwidth allocation, and is constructed under constraints including the predicted risk level after orchestrating the target security policy for each service, the overall service quality after orchestrating the target security policy and allocating bandwidth resources, and the target security policy and bandwidth resource allocation scheme. Solving the security policy and bandwidth allocation determination model yields the target security policy and bandwidth resource allocation scheme. This process enables the model to quickly adapt to the dynamically changing environment of the distribution network, ensuring the security and service quality of each service under different risk conditions. Furthermore, it allows the entire distribution network system to efficiently and accurately adjust security policies and rationally allocate bandwidth resources when facing complex and highly dynamic environments.
[0088] Based on any of the above embodiments, the system further includes a total security gain and total cost determination unit, which is specifically configured to: a gain determination unit, configured to determine a first security gain of the power distribution data encryption storage method, a second security gain of the power distribution data encryption transmission method, and a third security gain of the power distribution data access control method; a total security gain determination unit, configured to determine the total security gain based on the first security gain, the second security gain, and the third security gain; the first security gain is determined based on the effectiveness of the power distribution data encryption storage method and a first length of the encryption key; the second security gain is determined based on the effectiveness of the power distribution data encryption transmission method and a second length of the encryption key; a cost determination unit, configured to determine a first cost of the power distribution data encryption storage method and a second cost of the power distribution data encryption transmission method; and a total cost determination unit, configured to determine the total cost based on the first cost, the second cost, and the third cost of the power distribution data access control method.
[0089] Based on any of the above embodiments, the cost determination unit is specifically used for: a first cost determination unit, used for determining the first cost based on the first encryption delay and the first decryption delay of the power distribution data encryption storage method; and a second cost determination unit, used for determining the second cost based on the second encryption delay, the transmission delay, and the second decryption delay of the power distribution data encryption transmission method.
[0090] Based on any of the above embodiments, the first encryption delay and the second encryption delay are both determined based on the encryption algorithm complexity, key length, and CPU rotation speed of each device in each service; the first decryption delay and the second decryption delay are both determined based on the decryption algorithm complexity, key length, and CPU rotation speed of each device in each service; the transmission delay is determined based on the service data traffic size of each service, the length of the encryption header of the selected encryption algorithm, the transmission bandwidth allocated to each service, and the channel signal-to-noise ratio.
[0091] Based on any of the above embodiments, a risk level prediction determination unit is further included. This risk level prediction determination unit is specifically used for: acquiring distribution network environment data; inputting the distribution network environment data into a risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
[0092] Based on any of the above embodiments, the target security policy determination unit 202 is specifically used to: solve the security policy and bandwidth allocation determination model based on multi-agent reinforcement learning, and obtain the target security policy and bandwidth resource allocation scheme.
[0093] Figure 3 is a schematic diagram of the electronic device provided by the present invention. As shown in Figure 3, the electronic device may include: a processor 310, a communication interface 320, a memory 330, and a communication bus 340. The processor 310, communication interface 320, and memory 330 communicate with each other via the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute a method for jointly determining the security strategy and bandwidth allocation of the distribution network data flow. This method includes: obtaining a security strategy and bandwidth allocation determination model, wherein the security strategy and bandwidth allocation determination model aims to maximize the utility function of each service's security strategy, and is constructed under constraints of the predicted risk level after each service has orchestrated the target security strategy, and the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources; the utility function of each service's security strategy and bandwidth allocation is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service; and solving the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0094] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0095] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the method for jointly determining the security strategy and bandwidth allocation of the distribution network data flow provided by the above methods. The method includes: obtaining a security strategy and bandwidth allocation determination model, wherein the security strategy and bandwidth allocation determination model is constructed with the objective of maximizing the utility function of the security strategy and bandwidth allocation of each service, and with the predicted risk level after the target security strategy is arranged for each service, and the overall service quality of each service after the target security strategy and bandwidth resources are arranged for each service as constraints; the utility function of the security strategy and bandwidth allocation of each service is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service; and solving the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0096] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements a method for jointly determining the security strategy and bandwidth allocation of distribution network data streams provided by the above methods. This method includes: obtaining a security strategy and bandwidth allocation determination model, wherein the security strategy and bandwidth allocation determination model is constructed with the objective of maximizing the utility function of each service's security strategy, and constrained by the predicted risk level of each service after orchestrating the target security strategy and allocating bandwidth resources, and the overall service quality of each service after orchestrating the target security strategy and allocating bandwidth resources; the utility function of each service's security strategy and bandwidth allocation is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each distribution service; and solving the security strategy and bandwidth allocation determination model to obtain the target security strategy and bandwidth resource allocation scheme.
[0097] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0098] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0099] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for jointly determining data flow security strategy and bandwidth allocation in a distribution network, characterized in that, include: A security strategy and bandwidth allocation determination model is obtained. This model aims to maximize the utility function of each service's security strategy and bandwidth allocation, and is constructed under the constraints of the predicted risk level after orchestrating the target security strategy for each service and the overall service quality after orchestrating the target security strategy and allocating bandwidth resources for each service. The utility function of each service's security strategy and bandwidth allocation is determined based on the total security gain and total cost of the security strategy and bandwidth allocation corresponding to the risk level of each power distribution service. The security strategy and bandwidth allocation determination model is solved to obtain the target security strategy and bandwidth resource allocation scheme.
2. The method for jointly determining the data flow security strategy and bandwidth allocation in a distribution network according to claim 1, characterized in that, The steps for determining the total security gain and total cost of the security policy and bandwidth allocation include: determining a first security gain for the power distribution data encryption storage method, a second security gain for the power distribution data encryption transmission method, and a third security gain for the power distribution data access control method; determining the total security gain based on the first security gain, the second security gain, and the third security gain; the first security gain being determined based on the effectiveness of the power distribution data encryption storage method and a first length of the encryption key; the second security gain being determined based on the effectiveness of the power distribution data encryption transmission method and a second length of the encryption key; determining a first cost for the power distribution data encryption storage method and a second cost for the power distribution data encryption transmission method; and determining the total cost based on the first cost, the second cost, and the third cost of the power distribution data access control method.
3. The method for jointly determining the data flow security strategy and bandwidth allocation in a distribution network according to claim 2, characterized in that, The determination of the first cost of power distribution data encryption storage method and bandwidth allocation, and the second cost of power distribution data encryption transmission method and bandwidth allocation, includes: determining the first cost based on the first encryption delay and the first decryption delay of the power distribution data encryption storage method; and determining the second cost based on the second encryption delay, transmission delay and the second decryption delay of the power distribution data encryption transmission method.
4. The method for jointly determining the data flow security strategy and bandwidth allocation in a distribution network according to claim 3, characterized in that, The first encryption delay and the second encryption delay are both determined based on the encryption algorithm complexity, key length, and CPU speed of each device in each service; the first decryption delay and the second decryption delay are both determined based on the decryption algorithm complexity, key length, and CPU speed of each device in each service; the transmission delay is determined based on the service data traffic size of each service, the length of the encryption header of the selected encryption algorithm, the transmission bandwidth allocated to each service, and the channel signal-to-noise ratio.
5. The method for jointly determining the data flow security strategy and bandwidth allocation in a distribution network according to any one of claims 1 to 4, characterized in that, The steps for determining the predicted risk level include: acquiring distribution network environment data; inputting the distribution network environment data into a risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
6. The method for jointly determining the data flow security strategy and bandwidth allocation in a distribution network according to any one of claims 1 to 4, characterized in that, Solving the security policy and bandwidth allocation determination model to obtain the target security policy and bandwidth resource allocation scheme includes: solving the security policy and bandwidth allocation determination model based on multi-agent reinforcement learning to obtain the target security policy and bandwidth resource allocation scheme.
7. A device for jointly determining data flow security strategy and bandwidth allocation in a distribution network, characterized in that, include: The acquisition unit is used to acquire a security policy and bandwidth allocation determination model. This model aims to maximize the utility function of each service's security policy and bandwidth allocation, and is constructed under constraints including the predicted risk level of each service after orchestrating the target security policy, and the overall service quality of each service after orchestrating the target security policy and allocating bandwidth resources. The utility function of each service's security policy and bandwidth allocation is determined based on the total security gain and total cost of the security policy and bandwidth allocation corresponding to the risk level of each power distribution service. A target security policy determination unit is used to solve the security policy and bandwidth allocation determination model to obtain the target security policy and bandwidth resource allocation scheme.
8. The device for jointly determining distribution network data flow security strategy and bandwidth allocation according to claim 7, characterized in that, It also includes a total security gain and total cost determination unit, which is specifically used for: a gain determination unit, used to determine a first security gain of the power distribution data encryption storage means, a second security gain of the power distribution data encryption transmission means, and a third security gain of the power distribution data access control means; and a total security gain determination unit, used to determine the total security gain based on the first security gain, the second security gain, and the third security gain. The first security gain is determined based on the effectiveness of the power distribution data encryption storage method and the first length of the encryption key; The second security gain is determined based on the effectiveness of the power distribution data encryption transmission method and the second length of the encryption key; The cost determination unit is used to determine the first cost of the power distribution data encryption storage method and the second cost of the power distribution data encryption transmission method. The total cost determination unit is used to determine the total cost based on the first cost, the second cost, and the third cost of the power distribution data access control means.
9. The device for jointly determining distribution network data flow security strategy and bandwidth allocation according to claim 8, characterized in that, The cost determination unit is specifically used for: a first cost determination unit, used to determine the first cost based on the first encryption delay and the first decryption delay of the power distribution data encryption storage method; and a second cost determination unit, used to determine the second cost based on the second encryption delay, the transmission delay and the second decryption delay of the power distribution data encryption transmission method.
10. The device for jointly determining distribution network data flow security strategy and bandwidth allocation according to claim 9, characterized in that, The first encryption delay and the second encryption delay are both determined based on the encryption algorithm complexity, key length, and CPU speed of each device in each service; the first decryption delay and the second decryption delay are both determined based on the decryption algorithm complexity, key length, and CPU speed of each device in each service; the transmission delay is determined based on the service data traffic size of each service, the length of the encryption header of the selected encryption algorithm, the transmission bandwidth allocated to each service, and the channel signal-to-noise ratio.
11. The device for jointly determining the security strategy and bandwidth allocation of distribution network data streams according to any one of claims 7 to 10, characterized in that, It also includes a risk level prediction determination unit, which is specifically used for: acquiring distribution network environment data; inputting the distribution network environment data into a risk level prediction model to obtain the predicted risk level of each distribution service output by the risk level prediction model; the predicted risk level is obtained based on sample distribution network environment data and the labeled risk level of the sample distribution network environment data; the labeled risk level includes a first labeled risk level, a second labeled risk level, a third labeled risk level, and a fourth labeled risk level, wherein the first labeled risk level is greater than the second labeled risk level, the second labeled risk level is greater than the third labeled risk level, and the third labeled risk level is greater than the fourth labeled risk level.
12. The device for jointly determining the security strategy and bandwidth allocation of distribution network data streams according to any one of claims 7 to 10, characterized in that, The target security policy determination unit is specifically used to: solve the security policy and bandwidth allocation determination model based on multi-agent reinforcement learning, and obtain the target security policy and bandwidth resource allocation scheme.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method for jointly determining the data flow security strategy and bandwidth allocation as described in any one of claims 1 to 6.
14. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method for jointly determining the data flow security strategy and bandwidth allocation as described in any one of claims 1 to 6.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method for jointly determining the data flow security strategy and bandwidth allocation as described in any one of claims 1 to 6.