Power data access control method, device and system and medium
By generating multi-dimensional feature vectors and performing model detection on power data access requests, and dynamically determining access strategies in conjunction with business data, the system addresses the security and intelligence deficiencies of traditional power data access control, achieving efficient access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- STATE GRID BUSINESS BIG DATA CO LTD
- Filing Date
- 2026-01-06
- Publication Date
- 2026-05-05
AI Technical Summary
Traditional power data access control methods rely on static access control policies based on roles or permission lists, which are difficult to adapt to changes in the source, behavior, or environment of access requests, resulting in insufficient identification of security risks or false blocking.
By verifying power data access requests, multi-dimensional feature vectors are generated. Anomaly detection and prediction are performed using pre-trained anomaly detection and classification models. Combined with business dimension data, the target access strategy is determined, and access is granted, access is denied, or secondary verification is performed.
It has achieved intelligent and secure enhancement of power data access control, can accurately identify high-risk access behaviors, avoid misjudgments, and improve the system's flexibility and security.
Smart Images

Figure CN121980609A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power data control technology, and in particular to a method, device, system and medium for access control of power data. Background Technology
[0002] In the course of their operations, including production scheduling, equipment maintenance, customer service, and market transactions, power companies have gradually accumulated a large amount of power data involving grid operation status, user electricity consumption behavior, and business management information. This power data is typically accessed by different types of users through various business systems, data interfaces, or open services.
[0003] Traditional power data access control typically relies on static access control policies based on roles or permission lists, primarily determining access permission through user authentication and authorization matching. However, such methods often only focus on the static identity information of the accessing entity. When the source of the access request, access behavior, or operating environment changes, fixed access control rules struggle to reflect potential security risks in a timely and accurate manner, easily leading to insufficient identification of high-risk access requests or false blocking of legitimate access requests.
[0004] Therefore, how to intelligently analyze and securely control power data access requests to improve the security and intelligence level of the power data access process is an urgent problem to be solved in this field. Summary of the Invention
[0005] This invention provides a method, apparatus, system, and medium for access control of power data, which can solve at least one of the above-mentioned technical problems.
[0006] In a first aspect, embodiments of the present invention provide a method for access control of power data, comprising: In response to a user's power data access request, the request data carried in the power data access request is verified to obtain a verification result; If the verification result is successful, the context information collection interface is automatically triggered to collect the user's multi-dimensional power data to generate the user's multi-dimensional feature vector. Anomaly detection is performed on the multi-dimensional feature vector using a pre-trained anomaly detection model to obtain an anomaly score. Anomaly prediction is performed on the multi-dimensional feature vector using a pre-trained classification model to obtain a risk probability value. Based on the requested data, the business dimension data in the multi-dimensional power data, the anomaly score, and the risk probability value, a target access policy is determined to execute a target action according to the target access policy. The target action includes granting access, denying access, and secondary verification.
[0007] Secondly, embodiments of the present invention provide an access control device for power data, comprising: The request data verification module is used to respond to the user's power data access request and verify the request data carried in the power data access request to obtain the verification result. The context information acquisition module is used to automatically trigger the context information acquisition interface to collect the user's multi-dimensional power data if the verification result is successful, so as to generate the user's multi-dimensional feature vector. An anomaly detection module is used to perform anomaly detection on the multi-dimensional feature vector using a pre-trained anomaly detection model to obtain an anomaly score. The anomaly prediction module is used to predict anomalies in the multi-dimensional feature vector using a pre-trained classification model to obtain a risk probability value. The access control module is used to determine a target access policy based on the request data, the business dimension data in the multi-dimensional power data, the anomaly score, and the risk probability value, so as to execute a target action according to the target access policy, wherein the target action includes granting access, denying access, and secondary verification.
[0008] Thirdly, embodiments of the present invention also provide an access control system for power data, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method described in any one of the embodiments of the present invention.
[0009] Fourthly, embodiments of the present invention also provide a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to perform the method described in any one of the embodiments of the present invention.
[0010] This invention responds to user requests for power data access and verifies the request data carried in the request, obtaining a verification result. If the verification passes, a context information acquisition interface is automatically triggered to collect multi-dimensional power data, generating a multi-dimensional feature vector for the user. This not only ensures the legitimacy of the request source but also provides a rich data foundation for subsequent analysis. Subsequently, a pre-trained anomaly detection model and classification model are used to detect and predict anomalies in the multi-dimensional feature vector, obtaining an anomaly score and risk probability value, respectively. Finally, based on the request data, business dimension data in the dimensional power data, the anomaly score, and the risk probability value, a target access strategy is determined, and various response actions, including granting access, denying access, and secondary verification, are executed according to the target access strategy. Thus, this invention not only improves the security of power data access control but also achieves intelligent access strategy decision-making, effectively preventing unauthorized access.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0012] The accompanying drawings are provided for a better understanding of this solution and do not constitute a limitation of the invention. Wherein: Figure 1 This is a flowchart of an embodiment of a power data access control method according to the present invention; Figure 2 This is a structural block diagram of a power data access control device according to an embodiment of the present invention; Figure 3 This is a schematic block diagram of an electronic device used to implement the methods of the embodiments of the present invention. Detailed Implementation
[0013] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of the present invention, including various details to aid understanding. These details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0014] Figure 1 This is a flowchart of an embodiment of the power data access control method of the present invention.
[0015] like Figure 1 As shown, the access control method for this power data may include: S110, responding to the user's power data access request, and verifying the request data carried in the power data access request to obtain the verification result; S120, if the verification result is successful, the context information collection interface is automatically triggered to collect the user's multi-dimensional power data to generate the user's multi-dimensional feature vector. S130 uses a pre-trained anomaly detection model to detect anomalies in multi-dimensional feature vectors and obtains anomaly scores. S140 uses a pre-trained classification model to predict anomalies in multi-dimensional feature vectors and obtains risk probability values. S150, based on the request data, business dimension data in multi-dimensional power data, anomaly score and risk probability value, determine the target access policy, and execute the target action according to the target access policy, wherein the target action includes granting access, denying access and secondary verification.
[0016] For example, power data access requests can originate from user terminals, business systems, or external systems. This includes, but is not limited to, requests from web pages, mobile devices, Supervisory Control and Data Acquisition (SCADA) systems, or data interface calls. The system handles access requests from different sources uniformly to avoid data structure differences between heterogeneous systems affecting subsequent analysis.
[0017] For example, the system receives access requests through an interface gateway and supports multiple communication protocols to adapt to the multi-system operating environment of the power industry. These communication protocols include HyperText Transfer Protocol Secure (HTTPS), Message Queuing Telemetry Transport (MQTT), gRPC (gRPC Remote Procedure Call), and standard power industry protocols. The interface gateway performs unified authentication access, encrypted channel establishment, and preliminary security checks on access requests.
[0018] For example, the system can verify the cryptographic handshake process of the Transport Layer Security (TLS) protocol and verify the digital signature to ensure that the request has not been tampered with during transmission.
[0019] For example, in step S110, after responding to the user's power data access request, before verifying the request data carried in the power data access request, the access request can be verified based on the timestamp and one-time random number in the request data to check whether it is within a preset valid time window, so as to prevent replay attacks.
[0020] For example, for multiple access requests, access frequency control can be implemented, and access requests from third-party systems can be isolated and verified. Specifically, the token bucket algorithm is used to rate-limit access requests to prevent malicious high-frequency access; for requests from third-party systems, the request format and access permissions are first checked in a security sandbox, and only after the verification is passed can the request proceed to the subsequent processing flow.
[0021] For example, request data refers to a set of structured information carried by a user, device, or external system when initiating a power data access request, which is used to characterize the access behavior and access intent.
[0022] For example, the requested data includes at least one or more of the following information: access subject information: user identifier, system identifier, device identifier, account type, role information; access target information: target power data identifier, data type, business system to which the data belongs; operation behavior information: access type (query, download, write, subscription, etc.); security verification information: timestamp, one-time random number (Nonce), digital signature, certificate information.
[0023] For example, if a power dispatching system initiates a query request for historical load data through an interface, the request data may include system identifier, target data number, query operation type, request timestamp, and signature information.
[0024] For example, multi-dimensional power data refers to a data set collected from multiple dimensions, including the user's or access subject's historical behavior, business attributes, and operating environment in the power system, which is used to construct a description of the user's behavioral characteristics.
[0025] For example, a target access policy refers to a policy rule generated by the system based on a comprehensive judgment of request data, multi-dimensional power data, and model output results, used to constrain or guide power data access behavior. Examples include: Allow access: directly allowing the access request to execute; Suspend access request: blocking the access request; Trigger secondary verification mechanism: triggering additional identity verification or security verification before executing the access.
[0026] According to the above implementation method, starting with a power data access request, the request data is first verified to ensure that only compliant requests proceed to the next processing stage. If the verification passes, multi-dimensional power data related to the user is automatically collected and uniformly represented as a multi-dimensional feature vector to characterize the user's business behavior and operational context. Subsequently, pre-trained anomaly detection and classification models are used to analyze the feature vector from both unsupervised and supervised dimensions. This yields an anomaly score reflecting the degree of behavioral deviation and risk probability values corresponding to different risk levels. Based on this, the request data, business dimension data, anomaly score, and risk probability values are comprehensively considered to dynamically determine the target access strategy matching the risk level. Accordingly, actions such as granting access, denying access, or performing secondary verification are executed, achieving intelligent security control of the power data access process. By organically combining request verification, context awareness, multi-model risk analysis, and strategy execution, potentially high-risk access behaviors can be accurately identified and graded without affecting the efficiency of normal business access. This avoids misjudgment problems caused by single rules or single models, thereby significantly improving the security, flexibility, and intelligence level of power data access control.
[0027] In one implementation, in response to a user's power data access request, and by verifying the request data carried in the power data access request to obtain a verification result, the process includes: parsing the power data access request to obtain request data; formatting and encapsulating the request data to obtain a standardized request object; performing integrity verification on the standardized request object to obtain an integrity verification result; performing validity verification on the signature field in the standardized request object to obtain a validity verification result; performing legality verification on the request timestamp in the standardized request object to obtain a legality verification result; and if the integrity verification result, validity verification result, and legality verification result are all passed, then the user's identity is verified to obtain a verification result.
[0028] For example, the access layer first listens for power data access requests from different terminals or systems and identifies the communication protocol used in the request. For instance, it identifies the request as an HTTPS, MQTT, or distribution management interface standard (International Electrotechnical Commission 61968, IEC 61968) interface request. Then, based on the protocol type, the request message is deserialized to parse the raw binary stream or message string into structured data. Next, key information such as the access subject identifier, target data resource identifier, request operation type, request timestamp, device or terminal identifier, and signature field are extracted from the parsed structured data to form a request data set.
[0029] For example, when an industrial user requests to query its historical electricity consumption curve through an HTTPS interface, the system parses the user identifier (ID) as "U12345", the resource ID as "MeterData_202401", the operation type as "READ", the timestamp as "2024-01-15 10:03:21", the device type as "WebConsole", and the corresponding digital signature string from the Hypertext Transfer Protocol (HTTP) request header and request body.
[0030] For example, after receiving the request data, the data undergoes field mapping and type standardization to uniformly map fields from different sources and protocols to standard field names and correct field data types. For instance, string timestamps are converted to a unified time format, and resource identifiers are standardized to an internal unified encoding. Subsequently, the processed fields are encapsulated into standardized request objects for unified processing by subsequent verification and risk analysis modules.
[0031] For example, the data obtained from the above parsing is encapsulated into a standardized request object Request={UserID: "U12345", ResourceID: "R-00089", Action: "READ", Timestamp: 1705284201, DeviceInfo: "WEB", Signature: "0xAF23..."}, where the timestamp is uniformly converted to Unix time format and the resource identifier is mapped to the system's internal encoding.
[0032] For example, the system checks whether all required fields in the standardized request object are present and verifies the logical consistency between fields. This includes checking for empty user IDs and resource IDs, or mismatches between operation types and resource types. Field validation rules can also be used to check the validity of field lengths, value ranges, and formats. If all required fields are present and all validation rules are met, the integrity check is considered successful; otherwise, it is considered a failure.
[0033] For example, if the UserID, ResourceID, Action (operation type), and Timestamp fields are all present in the request object, and the Action is "READ" which matches the resource type "electricity meter data", and the field formats all conform to the specifications, then the integrity check result is passed.
[0034] For example, a signature field is extracted from a standardized request object, and the public key, certificate, or shared key of the corresponding user or device is obtained. Subsequently, the digest value is recalculated based on the request content excluding the signature field, and the signature field is verified using the corresponding encryption algorithm or signature verification algorithm. If the signature verification results match, the signature is deemed valid; otherwise, the signature is deemed invalid.
[0035] For example, for a request using a digital signature derived from the Chinese Commercial Elliptic Curve Public Key Cryptography Algorithm (SM2), the signature field is verified using the public key bound to user U12345. If the verification result matches the digest calculated from the request content, the signature validity verification is confirmed to be successful.
[0036] For example, the current server time is obtained, and the time difference between the current time and the request timestamp is calculated. This time difference is then compared with a preset time window threshold to determine if the request carries a replay risk or a timeout risk. If the time difference is within the preset valid time window, the timestamp is deemed valid; otherwise, it is deemed invalid.
[0037] For example, if the current system time is 2024-01-15 10:03:40 and the requested timestamp is 2024-01-15 10:03:21, the time difference is 19 seconds, which is less than the preset 60-second valid window. Therefore, the timestamp validity check passes.
[0038] For example, when the integrity verification result, signature validity verification result, and timestamp validity verification result all pass, the system automatically triggers the identity verification process. The system further verifies the user's identity in the requested object by accessing the local identity authentication module or an external authentication service. Identity verification methods may include token-based verification, digital certificate verification, or access token validity verification. If identity verification is successful, a verification result indicating success is output; otherwise, a verification result indicating failure is output.
[0039] For example, the system queries UserID "U12345" and finds that its current access token status is valid and has not been revoked. Therefore, it determines that the user's identity verification is successful and outputs the verification result as successful.
[0040] According to the above implementation method, by parsing, standardizing and encapsulating, and performing multi-level verification on power data access requests, an access verification chain is constructed, progressively advancing from "request standardization - data authenticity verification - timeliness verification - identity trust confirmation." This allows the system to comprehensively determine the legality and trustworthiness of a request before it enters business processing. This effectively avoids security risks caused by inconsistent request formats, missing fields, forged signatures, or request replay. Furthermore, by triggering identity verification only after multiple basic verifications have passed, unnecessary authentication overhead is reduced, thereby improving overall processing efficiency and system stability while ensuring the security of power data access.
[0041] In one implementation, if the verification result is successful, the context information collection interface is automatically triggered to collect the user's multi-dimensional power data to generate the user's multi-dimensional feature vector. This includes: collecting user data in the dimensions of user identity information, device and terminal, time and space, network, business, and power grid operation status through the context information collection interface to obtain the user's multi-dimensional power data; encoding the multi-dimensional power data to obtain numerical feature vectors corresponding to each dimension; and concatenating the numerical feature vectors to obtain the user's multi-dimensional feature vector.
[0042] For example, after a power data access request passes basic verification, a preset context information collection interface is invoked to synchronously or asynchronously retrieve context data related to the current user and current access behavior from multiple data sources. The context information collection interface can interface with user management systems, terminal management systems, network devices, business systems, and power grid operation monitoring systems. The collected data is then uniformly encapsulated to form multi-dimensional power data for the user.
[0043] In this example, at the user identity information level, information such as user identifier, user role type, user's affiliated unit, and historical authorization level are collected. At the device and terminal level, information such as terminal type, device fingerprint, operating system version, and whether it is a registered device are collected. For example, it determines whether the current access comes from a registered dispatch terminal. At the time and space level, information such as access time point, time period category (working hours or non-working hours), and access geographical area or power grid zone is collected. At the network level, information such as access Internet Protocol (IP) address, network type, link stability, and historical abnormal connection count are collected. At the business level, normal business data, load business data, and alarm business data are collected (for example, a value of 1 for normal, a value of 2 for load, and a value of 3 for alarm). At the power grid operation status level, data such as the current operating mode are collected, such as whether the current operation is in peak summer demand or emergency response mode.
[0044] For example, for data types of different dimensions, an encoding method matching their data characteristics is adopted to convert the original unstructured or semi-structured data into numerical feature vectors that can be used for model processing. For example, for discrete categorical data, one-hot encoding, label encoding, or embedded vector encoding can be used; for continuous numerical data, normalization or standardization processing can be performed; for Boolean or state data, it can be mapped to a preset numerical range.
[0045] For example, the numerical feature vectors generated from each dimension are concatenated to form a multi-dimensional feature vector of uniform length, which serves as the input for subsequent anomaly detection and classification models. For instance, the vectors can be concatenated in the following order: "User identity information dimension feature vector - Device and terminal dimension feature vector - Time and space dimension feature vector - Network dimension feature vector - Business dimension feature vector - Power grid operation status dimension feature vector," thereby generating a comprehensive feature vector containing user behavior, access environment, business background, and power grid status information, used to comprehensively characterize the current power data access scenario.
[0046] According to the above implementation method, by introducing a context information acquisition interface and constructing multi-dimensional power data from multiple dimensions such as user, device, time, network, service, and power grid operation status, different types of data are uniformly encoded and fused into a multi-dimensional feature vector. This enables a comprehensive, detailed, and structured characterization of power data access behavior, effectively avoiding misjudgments caused by relying solely on a single identity or rule. This provides high-quality input features for subsequent anomaly detection and risk classification models, improving the accuracy and robustness of risk identification, while enhancing the system's adaptability to complex access scenarios and abnormal behaviors, thereby achieving more intelligent, reliable, and secure power data access control.
[0047] In one implementation, anomaly detection is performed on a multi-dimensional feature vector using a pre-trained anomaly detection model to obtain an anomaly score. This includes: compressing the multi-dimensional feature vector using an encoder network in the anomaly detection model to obtain a latent representation; reconstructing the latent representation using a decoder network in the anomaly detection model to obtain a reconstructed feature vector; calculating a reconstruction error based on the difference between the reconstructed feature vector and the multi-dimensional feature vector, wherein the reconstruction error includes mean squared error or weighted reconstruction error; and determining the anomaly score based on the reconstruction error.
[0048] For example, the multi-dimensional feature vectors constructed above are input into the encoder network in the anomaly detection model. The encoder network consists of multiple fully connected layers or convolutional layers, which are connected by non-linear activation functions. Layer by layer, the dimensionality of the feature vectors is reduced, and the core semantic features of the feature vectors are extracted. Finally, a low-dimensional latent representation vector is output.
[0049] For example, assuming that the multi-dimensional feature vector contains a total of 128 features such as user identity, device status, access time, and business sensitivity level, the encoder network can successively map it to 64-dimensional, 32-dimensional, and finally compress it into a 16-dimensional latent representation. This latent representation is used to characterize the implicit features of the current access behavior in the normal behavior space.
[0050] For example, the latent representation is input into the decoder network in the anomaly detection model. The structure of the decoder network is set symmetrically with that of the encoder network. Through layer-by-layer upsampling or fully connected mapping, the latent representation is restored to a reconstructed feature vector with the same dimensions as the original multi-dimensional feature vector.
[0051] For example, for the aforementioned 16-dimensional latent representation, the decoder network can generate a set of 128-dimensional reconstructed feature vectors through layer-by-layer mapping from 16 to 32, from 32 to 64, and from 64 to 128 dimensions, which can be used to approximate the reconstruction result of the "normal access behavior" learned by the model.
[0052] For example, the reconstructed feature vector is compared dimension by dimension with the original multi-dimensional feature vector, and the reconstruction error is calculated according to a preset error calculation method. The error calculation method may include mean squared error or a weighted reconstruction error incorporating business weights.
[0053] In this example, the mean squared error method can be used, averaging the squared differences of each feature dimension. Alternatively, higher weights (e.g., 0.6) can be assigned to key features such as business sensitivity level and power grid operating status to calculate the weighted reconfiguration error, thereby allowing abnormal deviations in key dimensions to have a greater impact on the overall error.
[0054] For example, the calculated reconstruction error can be directly used as the anomaly score, and its magnitude directly reflects the degree of deviation of the vector from the "normal" data pattern learned by the model during the training phase.
[0055] For example, in addition to the anomaly detection model given in the previous example that performs anomaly detection on multi-dimensional feature vectors to obtain an anomaly score, Isolation Forestz can also be used to perform anomaly detection on multi-dimensional feature vectors to obtain an anomaly score.
[0056] According to the above implementation method, by introducing an anomaly detection model based on an encoder-decoder structure, low-dimensional latent representation learning and feature reconstruction are performed on multi-dimensional feature vectors, and the reconstruction error is used to quantitatively evaluate the degree of anomaly. In this way, normal patterns of power data access behavior can be automatically learned without explicitly labeling anomaly samples, and abnormal behaviors deviating from normal patterns can be accurately identified. This improves the sensitivity and generalization ability of anomaly detection, reduces misjudgment problems caused by rule dependence and manual threshold configuration, and provides a stable, continuous, and interpretable anomaly measurement basis for subsequent risk assessment and access control.
[0057] In one implementation, anomaly prediction is performed on multi-dimensional feature vectors using a pre-trained classification model to obtain risk probability values. This includes: loading the classification model, where the number of risk categories output by the classification model is three; using the multi-dimensional feature vectors as input to the classification model, and performing forward propagation on the multi-dimensional feature vectors through various gradient boosting decision trees integrated by the classification model; based on the values of the multi-dimensional feature vectors, traversing from the root node to the leaf node in the gradient boosting decision tree along a preset branching rule; determining the predicted value of the gradient boosting decision tree based on the scores corresponding to each risk category in the leaf node, where the predicted value includes the predicted score of each risk category; summing the predicted scores of each risk category according to the requirement of aggregating for the same risk category based on the predicted values of each gradient boosting decision tree, to obtain a comprehensive predicted score for each risk category; mapping the comprehensive predicted score of each risk category to a probability distribution using a preset activation function to obtain the predicted probability value for each risk category; and determining the risk probability value based on the predicted probability value for each risk category.
[0058] For example, a pre-trained classification model is loaded from a model storage module or a model management service. The classification model is an ensemble model based on gradient boosting decision trees, and its output layer is configured to output three risk categories, representing low-risk, medium-risk, and high-risk states, respectively.
[0059] In this example, a multi-class classification model trained using Extreme Gradient Boosting (XGBoost) or Light Gradient Boosting Machine (LightGBM) can be loaded. The parameter `num_class` (which limits the number of classes the classification model outputs, representing the number of risk classes the model needs to distinguish and predict simultaneously) is set to 3 to ensure that the model can simultaneously output predictions for three risk classes (high risk, medium risk, and low risk) during the prediction phase.
[0060] For example, in addition to the classification model given in the above example, deep neural networks can also be used to predict anomalies in multi-dimensional feature vectors to obtain risk probability values.
[0061] For example, the constructed multi-dimensional feature vector is input into the classification model, and multiple gradient boosting decision trees integrated within the model sequentially perform forward propagation operations on the feature vector. Each decision tree independently completes feature discrimination and path selection once.
[0062] For example, for any gradient boosting decision tree, based on the specific values of each feature in the current multi-dimensional feature vector, the tree compares layer by layer from the root node according to the pre-defined splitting rules of each internal node in the decision tree, and traverses downwards along the branch paths that meet the conditions until it reaches the leaf node.
[0063] For example, when the root node of a decision tree is pre-defined as having a splitting rule of "whether the access time falls within a high-risk period", the tree selects to enter the corresponding left or right child node from the root node based on the time feature value in the multi-dimensional feature vector. Subsequently, at the next level of internal nodes, the tree continues to make judgments based on the pre-defined splitting rule of "whether the access device is a trusted device". This process is repeated until the leaf nodes are reached.
[0064] For example, the predicted value stored in the leaf node reached during traversal is read. The predicted value is represented in vector form and corresponds to the predicted score of three risk categories: low risk, medium risk, and high risk.
[0065] For example, for all gradient boosting decision trees integrated in the classification model, the predicted scores output by each decision tree are aligned according to risk category. Then, the predicted scores for the same risk category are summed to obtain the comprehensive predicted scores corresponding to the three risk categories: low risk, medium risk, and high risk.
[0066] For example, if the model contains 100 decision trees, the low-risk scores output by each of the 100 decision trees will be summed to obtain a low-risk composite score; the same operation will be performed on the medium-risk and high-risk scores to form a three-dimensional composite prediction score vector.
[0067] For example, the comprehensive prediction score of each risk category is input into a preset activation function for processing. The activation function is used to map the comprehensive prediction score into a probability distribution form, so that the sum of the prediction probability values of each risk category is 1.
[0068] For example, the Softmax function can be used to process the comprehensive prediction score vector. If the comprehensive prediction scores are 1.2, 2.0, 3.5, 1.2, 2.0, 3.5, 1.2, 2.0, 3.5, then the corresponding low-risk, medium-risk, and high-risk prediction probability values are obtained after Softmax mapping.
[0069] For example, the predicted probability values of each risk category are used as risk probability values to characterize the probability of the sample occurring at different risk levels, and can be used as input parameters for subsequent risk assessment or access strategy decision-making.
[0070] According to the above implementation method, by introducing a gradient boosting decision tree classification model with three output risk categories, multi-dimensional feature vectors are inferred tree-by-tree in each decision tree, and the predicted scores of different risk categories are aggregated and probability-mapped. In this way, while maintaining the model's computational efficiency and interpretability, a refined probabilistic assessment of the risk level of access behavior or business objects can be achieved. This not only avoids the coarse decision-making problem caused by single threshold judgments but also reflects the relative confidence level between different risk levels in probabilistic form, thus providing a more discriminative and stable decision-making basis for subsequent access strategy selection and risk management.
[0071] In one implementation, a target access policy is determined based on request data, business dimension data from multi-dimensional power data, anomaly score, and risk probability value. A target action is then executed according to the target access policy. This target action includes granting access, denying access, and secondary verification. The process includes: determining a context sensitivity factor based on business dimension data from multi-dimensional power data; weighting and summing the context sensitivity factor, anomaly score, and risk probability value to obtain a comprehensive risk score; if the requested internet protocol address in the request data is not in a preset whitelist and the comprehensive risk score is greater than a preset first threshold, a secondary verification mechanism is triggered to determine the target access policy, and the user's request is then verified according to the target access policy; if the access object in the request data is the power dispatch master database and the comprehensive risk score is greater than a preset second threshold, the access request is suspended to determine the target access policy, and the user's power data access request is denied according to the target access policy; if the comprehensive risk score is less than a preset third threshold, granting access is determined to determine the target access policy, and the user's power data access request is granted according to the target access policy.
[0072] For example, the aforementioned example shows that the business dimension data includes normal business data, load business data, and alarm business data (e.g., a value of 1 for normal, a value of 2 for load, and a value of 3 for alarm). Based on this, the business dimension data corresponding to this access request is used as the context sensitivity factor. For example, if the business dimension data corresponding to this access request is an alarm, then the context sensitivity factor is set to 3.
[0073] For example, firstly, corresponding weight parameters are set for the context sensitivity factor, anomaly score, and risk probability value (where the risk probability value includes high-risk, medium-risk, and low-risk probability values) to reflect the importance of different risk sources in the comprehensive assessment. Then, these are linearly weighted and summed to generate a comprehensive risk score with uniform dimensions. If necessary, the comprehensive risk score can be normalized for subsequent comparison with individual score thresholds.
[0074] In this example, the calculation process of the comprehensive risk score can be expressed by the following formula: In the formula, For comprehensive risk scoring; These are the weight parameters corresponding to the anomaly score; Anomaly score; The high-risk probability value is the highest probability value among the risk probability values. The corresponding weight parameters; For risk probability values, the medium risk probability value is... The corresponding weight parameters; The lowest risk probability value. The corresponding weight parameters; These are the weight parameters corresponding to the context sensitivity factor; This is a context-sensitive factor.
[0075] It should be noted that the weight parameters in the aforementioned examples can be set according to actual needs, and this application does not impose specific limitations on each weight parameter.
[0076] For example, after the comprehensive risk score is generated, the access Internet Protocol address in the request data is further verified and matched against a preset trusted access whitelist. When an access address is detected to be outside the whitelist and the comprehensive risk score is greater than a preset first score threshold, the current access behavior is judged to have a potential security risk, and a secondary verification mechanism is triggered as the target access policy. Subsequently, in accordance with the target access policy, verification processes such as SMS verification code, human verification, or digital certificate secondary authentication are initiated to the user.
[0077] For example, if a user accesses the power data system from an external office network IP address that is not on the whitelist and has a comprehensive risk score of 0.65, which is higher than the first score threshold of 0.6, the system will automatically require the user to complete SMS verification before continuing access.
[0078] For example, in another implementation path, the system identifies the access object in the request data and determines whether the access object belongs to a critical core resource such as the power dispatch master database. When the access object is the power dispatch master database and the comprehensive risk score is greater than a preset second score threshold, the system identifies the access request as a high-risk access and uses suspending the access request as the target access policy. The access request is rejected according to this target access policy, and a corresponding security audit log is generated.
[0079] For example, if an account requests access to the real-time dispatch instruction table in the power dispatch master database and its comprehensive risk score is 0.85, which is higher than the second score threshold of 0.8, the system will directly reject the request to avoid potential dispatch security risks.
[0080] In this example, the security audit log refers to the structured record data generated and stored by the system during the power data access control process, which includes the system's judgment result on the access request, the target access policy executed, and related risk assessment information. It is used for post-event traceability, security auditing, and compliance analysis of power data access behavior.
[0081] For example, security audit logs may include, but are not limited to, the following specific contents: access subject identification information, used to identify the user account, role type, or authentication credential number that initiates the access request; access request characteristic information, used to record the access object, access operation type, request timestamp, and Internet protocol address requested in the request data; risk assessment related information, used to record context sensitivity factor, anomaly score, risk probability value, and the comprehensive risk score calculated from it; policy determination information, used to record the scoring threshold matched by the system, the triggered rule conditions, and the final determined target access policy type; execution result information, used to indicate the processing result of the access request being granted, denied, or entering secondary verification; and audit auxiliary information, used to record the log generation time, log number, and log integrity verification identifier.
[0082] Furthermore, for example, when an account requests access to the real-time dispatch instruction table in the power dispatch master database, and the system determines that the accessed object is a critical core resource and the comprehensive risk score is 0.85, which is higher than the preset second score threshold of 0.8, the security audit log can record the account identifier, the accessed object as "real-time dispatch instruction table", the access operation as "read", the Internet Protocol address of the request source, the comprehensive risk score as 0.85, the triggering rule as "core resource access and risk score exceeding the threshold", the target access policy as "suspend access request", and the final processing result as "access denied". This provides complete and traceable data for subsequent security audits, responsibility identification, and risk analysis.
[0083] For example, when the system determines that the overall risk score is less than a preset third scoring threshold, it indicates that the current access behavior is in a low-risk state across multiple dimensions, including abnormal characteristics, risk prediction, and business sensitivity. In this case, the system will grant access as the target access policy and grant the user the corresponding power data access permissions according to the normal business process.
[0084] For example, if an internal operations and maintenance personnel access historical electricity consumption statistics via an intranet IP during working hours, and both the anomaly score and risk probability value are low, with a comprehensive risk score of 0.2, which is lower than the third scoring threshold of 0.3, the system will directly allow access without introducing additional security verification steps.
[0085] It should be noted that the thresholds given in the above examples can be set according to actual needs, and the embodiments of the present invention do not limit them.
[0086] According to the above implementation method, by introducing a context-sensitive factor related to business semantics and fusing it with the anomaly score obtained from anomaly detection and the risk probability value output by the classification model, a comprehensive risk score that can comprehensively reflect the security risk level of access behavior is formed. Combined with key security constraints such as access source and access object, the system dynamically selects access strategies such as granting access, denying access, or triggering secondary verification. This achieves refined, differentiated, and adaptive security control of power data access requests, avoiding excessive interception that affects business efficiency in low-risk scenarios, while significantly improving the overall security protection capability of the system in high-risk or critical resource access scenarios.
[0087] In one implementation, after determining a target access strategy based on request data, business dimension data from multi-dimensional power data, anomaly score, and risk probability value, and executing a target action according to the target access strategy, the method further includes: generating an access audit log for the current request based on the request data, multi-dimensional power data, anomaly score, risk probability value, and target access strategy, and storing it in a consortium blockchain or national cryptographic blockchain node; loading a log summary of the previous request from a trusted evidence storage node or local cache; and calculating a log summary of the current request based on a preset hash algorithm.
[0088] For example, after determining the target access strategy, the system automatically aggregates request data, multi-dimensional power data, anomaly scores, risk probability values, and the finally determined target access strategy related to this access request. This information is then formatted and encapsulated to generate an access audit log for the user's request. Subsequently, the access audit log is serialized and submitted to a consortium blockchain or a national cryptographic blockchain node. The blockchain node stores the log data or its summary on the blockchain and returns the corresponding evidence identification.
[0089] For example, in a certain access request, the log content may include user identifier, access resource identifier, access time, access source IP, anomaly score, risk probability value, and the target access policy is "secondary verification". The system encapsulates the log into structured data and submits it to the consortium blockchain node to complete the notarization.
[0090] For example, before generating the current log digest, the system retrieves the user's historical access records from trusted evidence storage nodes or local cache, and locates the log digest corresponding to the user's previous request based on the user identifier and time sequence. If this is the user's first access, a preset initial digest value is loaded as the previous log digest. After loading, the log digest of the previous request is used as one of the input parameters for subsequent hash calculations.
[0091] For example, when the system is processing user A's current access request, it retrieves the log digest value corresponding to user A's previous access request from the blockchain node. This is used to form a chain of associations with the current log. If user A is accessing the site for the first time, the system-initialized digest value is used as... .
[0092] For example, a preset hash algorithm is invoked to concatenate or combine the access audit log content corresponding to the current request with the loaded log summary of the previous request. The combined data is used as input to the hash algorithm to calculate the log summary of the user's current request. The log summary also serves as the basis for integrity verification of the current access behavior and is used for chained evidence storage of subsequent requests.
[0093] In this example, the default hash algorithm is either the Chinese Commercial Cryptographic Hash Algorithm (SM3) or the Secure Hash Algorithm 256-bit (SHA-256).
[0094] For example, the system uses the national cryptographic SM3 hash algorithm to combine "the content of this access audit log + the summary of the previous log" into the hash value. "Using this as input data, a new log summary is calculated." The summary is then written into the blockchain node, thus achieving continuous linking and tamper-proof evidence storage of the access log within the blockchain.
[0095] According to the above implementation method, by generating a complete access audit log for each access request during the power data access control process, and storing the log summary in a chain structure in the consortium blockchain or national cryptographic blockchain node, the access behaviors form a reliable and tamper-proof evidence link that is sequentially related and cannot be tampered with in the time dimension. This not only enables refined auditing of single access behaviors, but also enables traceability and integrity verification of continuous user access behaviors, effectively improving the credibility, anti-tampering capability, and audit evidence reliability of power data access logs, and meeting the high-level requirements of the power industry for security compliance, accountability, and post-event auditing.
[0096] Figure 2 This is a structural block diagram of a power data access control device according to an embodiment of the present invention.
[0097] like Figure 2 As shown, the access control device for the power data may include: The request data verification module 510 is used to respond to the user's power data access request and verify the request data carried in the power data access request to obtain the verification result. The context information acquisition module 520 is used to automatically trigger the context information acquisition interface to collect the user's multi-dimensional power data if the verification result is a successful verification, so as to generate the user's multi-dimensional feature vector. Anomaly detection module 530 is used to perform anomaly detection on the multi-dimensional feature vector using a pre-trained anomaly detection model to obtain an anomaly score. The anomaly prediction module 540 is used to predict anomalies in the multi-dimensional feature vector using a pre-trained classification model to obtain a risk probability value. Access control module 550 is used to determine a target access policy based on the request data, the business dimension data in the multi-dimensional power data, the anomaly score and the risk probability value, so as to execute a target action according to the target access policy, wherein the target action includes granting access, denying access and secondary verification.
[0098] In one implementation, the request data verification module includes: The parsing unit is used to parse the power data access request to obtain the request data; The formatting and encapsulation unit is used to format and encapsulate the request data to obtain a standardized request object; The integrity verification unit is used to perform integrity verification on the standardized request object and obtain the integrity verification result. The validity verification unit is used to perform validity verification on the signature field in the standardized request object and obtain the validity verification result. A validity verification unit is used to verify the validity of the request timestamp in the standardized request object and obtain a validity verification result. An identity verification unit is used to verify the user's identity if the integrity verification result, the validity verification result, and the legality verification result are all passed, and to obtain the verification result.
[0099] In one embodiment, the context information acquisition module includes: The data acquisition unit is used to acquire data of the user in terms of user identity information, device and terminal, time and space, network, business, and power grid operation status through the context information acquisition interface, so as to obtain the user's multi-dimensional power data. The encoding unit is used to encode the multi-dimensional power data to obtain numerical feature vectors corresponding to each dimension of the data; The splicing unit is used to splice the numerical feature vectors to obtain the user's multi-dimensional feature vector.
[0100] In one embodiment, the anomaly detection module includes: The compression unit is used to compress the multi-dimensional feature vector through the encoder network in the anomaly detection model to obtain a latent representation; The reconstruction unit is used to reconstruct the latent representation through the decoder network in the anomaly detection model to obtain a reconstructed feature vector; The reconstruction error calculation unit is used to calculate the reconstruction error based on the difference between the reconstructed feature vector and the multi-dimensional feature vector, wherein the reconstruction error includes mean square error or weighted reconstruction error. An anomaly score determination unit is used to determine the anomaly score based on the reconstruction error.
[0101] In one implementation, the anomaly prediction module includes: A model loading unit is used to load the classification model, wherein the number of risk categories output by the classification model is 3; A forward propagation unit is used to take the multi-dimensional feature vector as input to the classification model, and to perform forward propagation on the multi-dimensional feature vector through the gradient boosting decision trees integrated by the classification model. The node traversal unit is used to traverse from the root node to the leaf node in the gradient boosting decision tree according to the value of the multi-dimensional feature vector. The prediction value determination unit is used to determine the prediction value of the gradient boosting decision tree based on the scores corresponding to each risk category in the leaf node, wherein the prediction value includes the prediction score of each risk category; The summation unit is used to sum the prediction scores of each risk category based on the prediction values of each gradient-enhanced decision tree, according to the requirement of aggregating the same risk category, to obtain the comprehensive prediction score of each risk category. The probability distribution mapping unit is used to perform probability distribution mapping on the comprehensive prediction scores of each risk category through a preset activation function to obtain the predicted probability value of each risk category. The risk probability value determination unit is used to determine the risk probability value based on the probability prediction value of each of the risk categories.
[0102] In one embodiment, the access control module includes: The context sensitivity factor determination unit is used to determine the context sensitivity factor based on the business dimension data in the multi-dimensional power data. The weighted summation unit is used to perform a weighted summation of the context sensitivity factor, the anomaly score, and the risk probability value to obtain a comprehensive risk score. The secondary verification unit is used to trigger a secondary verification mechanism to determine the target access policy if the requested Internet Protocol address in the request data is not in the preset whitelist and the comprehensive risk score is greater than the preset first score threshold, so as to perform secondary verification on the user's request according to the target access policy. The access denial unit is configured to determine the suspension of access request as the target access policy if the access object in the requested data is the power dispatch master database and the comprehensive risk score is greater than a preset second score threshold, so as to deny the user's power data access request according to the target access policy. The consent access unit is used to determine consent access as the target access policy if the comprehensive risk score is less than a preset third score threshold, so as to consent to the user's power data access request according to the target access policy.
[0103] In one embodiment, after the access control module, the device further includes: The log generation module is used to generate an access audit log for the user's current request based on the request data, the multi-dimensional power data, the anomaly score, the risk probability value, and the target access strategy, and store it in the consortium blockchain or the national cryptographic blockchain node. The log summary loading module is used to load the user's log summary about the previous request from a trusted evidence storage node or local cache; The log summary generation module is used to calculate the log summary of the user's access audit log for the current request and the log summary of the previous request based on a preset hash algorithm, so as to obtain the log summary of the user's current request.
[0104] The specific functions and examples of each module and submodule of the system in this embodiment of the invention can be found in the relevant descriptions of the corresponding steps in the above method embodiments, and will not be repeated here.
[0105] The acquisition, storage, and application of user personal information involved in the technical solution of this invention all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0106] This invention also provides an access control system for power data, comprising: At least one processor; and a memory communicatively connected to said at least one processor; The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the method described in any one of the embodiments of the present invention.
[0107] The beneficial effects of the power data access control system of this invention are equivalent to the beneficial effects of the power data access control method described above, and will not be repeated here.
[0108] This invention also provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to perform the method described in any one of the embodiments of this invention.
[0109] The beneficial effects of the storage medium of the present invention are equivalent to the beneficial effects of the above-described power data access control method, and will not be repeated here.
[0110] Figure 3 A schematic block diagram of an example electronic device 800 that can be used to implement embodiments of the present invention is shown. Electronic device 800 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic device 800 may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0111] like Figure 3 As shown, the electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. The RAM 803 may also store various programs and data required for the operation of the electronic device 800. The computing unit 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0112] Multiple components in electronic device 800 are connected to I / O interface 805, including: input unit 806, such as keyboard, mouse, etc.; output unit 807, such as various types of displays, speakers, etc.; storage unit 808, such as disk, optical disk, etc.; and communication unit 809, such as network card, modem, wireless transceiver, etc. Communication unit 809 allows electronic device 800 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0113] The computing unit 801 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as the power data access control method. For example, in some embodiments, the power data access control method can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by the computing unit 801, one or more steps of the power data access control method described above can be performed. Alternatively, in other embodiments, the computing unit 801 can be configured to perform the power data access control method by any other suitable means (e.g., by means of firmware).
[0114] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0115] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0116] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0117] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0118] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0119] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0120] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this invention can be achieved, and this is not limited herein.
[0121] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for access control of power data, characterized in that, include: In response to a user's power data access request, the request data carried in the power data access request is verified to obtain a verification result; If the verification result is successful, the context information collection interface is automatically triggered to collect the user's multi-dimensional power data to generate the user's multi-dimensional feature vector. Anomaly detection is performed on the multi-dimensional feature vector using a pre-trained anomaly detection model to obtain an anomaly score. Anomaly prediction is performed on the multi-dimensional feature vector using a pre-trained classification model to obtain a risk probability value. Based on the requested data, the business dimension data in the multi-dimensional power data, the anomaly score, and the risk probability value, a target access policy is determined to execute a target action according to the target access policy. The target action includes granting access, denying access, and secondary verification.
2. The method according to claim 1, characterized in that, The process of responding to a user's power data access request and verifying the request data carried in the power data access request to obtain a verification result includes: The power data access request is parsed to obtain the request data; The request data is formatted and encapsulated to obtain a standardized request object; Perform integrity verification on the standardized request object to obtain the integrity verification result; The signature field in the standardized request object is validated to obtain the validation result. The validity of the request timestamp in the standardized request object is verified to obtain the validity verification result; If the integrity check result, the validity check result, and the legality check result are all passed, then the user's identity is verified to obtain the verification result.
3. The method according to claim 1, characterized in that, If the verification result is successful, the context information collection interface is automatically triggered to collect the user's multi-dimensional power data to generate the user's multi-dimensional feature vector, including: The context information collection interface is used to collect data on the user in terms of user identity information, device and terminal, time and space, network, business, and power grid operation status, so as to obtain the user's multi-dimensional power data. The multi-dimensional power data is encoded to obtain numerical feature vectors corresponding to each dimension of the data; The numerical feature vectors are concatenated to obtain the user's multi-dimensional feature vector.
4. The method according to claim 1, characterized in that, The pre-trained anomaly detection model performs anomaly detection on the multi-dimensional feature vector to obtain an anomaly score, including: The multi-dimensional feature vector is compressed using the encoder network in the anomaly detection model to obtain a latent representation; The latent representation is reconstructed using the decoder network in the anomaly detection model to obtain a reconstructed feature vector; Based on the difference between the reconstructed feature vector and the multi-dimensional feature vector, the reconstruction error is calculated, wherein the reconstruction error includes mean square error or weighted reconstruction error; The anomaly score is determined based on the reconstruction error.
5. The method according to claim 1, characterized in that, The step of using a pre-trained classification model to predict anomalies in the multi-dimensional feature vectors and obtain risk probability values includes: Load the classification model, wherein the number of risk categories output by the classification model is 3; The multi-dimensional feature vector is used as input to the classification model, and the multi-dimensional feature vector is forward-propagated through the gradient boosting decision trees integrated by the classification model. Based on the values of the multi-dimensional feature vectors, the gradient boosting decision tree is traversed from the root node to the leaf node according to the preset branching rules. Based on the scores corresponding to each risk category in the leaf nodes, the predicted value of the gradient boosting decision tree is determined, wherein the predicted value includes the predicted score of each risk category; Based on the predicted values of each gradient boosting decision tree, the predicted scores of each risk category are summed according to the requirement of aggregating the same risk category to obtain the comprehensive predicted score of each risk category. By mapping the probability distribution of the comprehensive prediction scores of each risk category using a preset activation function, the predicted probability value of each risk category is obtained. The risk probability value is determined based on the probability prediction value of each of the risk categories.
6. The method according to claim 1, characterized in that, The system determines a target access policy based on the request data, the business dimension data in the multi-dimensional power data, the anomaly score, and the risk probability value, and executes a target action according to the target access policy. The target action includes granting access, denying access, and secondary verification, including: Based on the business dimension data in the multi-dimensional power data, a context sensitivity factor is determined; The context sensitivity factor, the anomaly score, and the risk probability value are weighted and summed to obtain a comprehensive risk score. If the requested Internet Protocol address in the request data is not in the preset whitelist, and the comprehensive risk score is greater than the preset first score threshold, then a secondary verification mechanism will be triggered to determine the target access policy, so as to perform secondary verification on the user's request according to the target access policy. If the access object in the requested data is the power dispatch master database, and the comprehensive risk score is greater than the preset second score threshold, then the suspension access request will be determined as the target access policy, so as to reject the user's power data access request according to the target access policy. If the comprehensive risk score is less than the preset third score threshold, then the access consent is determined as the target access policy, so as to consent to the user's power data access request according to the target access policy.
7. The method according to claim 1, characterized in that, After determining the target access strategy based on the request data, the business dimension data in the multi-dimensional power data, the anomaly score, and the risk probability value, and then executing the target action according to the target access strategy, the method further includes: Based on the request data, the multi-dimensional power data, the anomaly score, the risk probability value, and the target access strategy, an access audit log for the user regarding this request is generated and stored in the consortium blockchain or national cryptographic blockchain node; Load the user's log summary of the previous request from a trusted evidence storage node or local cache; Based on a preset hash algorithm, the user's access audit log for this request and the log summary for the previous request are calculated to obtain the user's log summary for this request.
8. A power data access control device, characterized in that, include: The request data verification module is used to respond to the user's power data access request and verify the request data carried in the power data access request to obtain the verification result. The context information acquisition module is used to automatically trigger the context information acquisition interface to collect the user's multi-dimensional power data if the verification result is successful, so as to generate the user's multi-dimensional feature vector. An anomaly detection module is used to perform anomaly detection on the multi-dimensional feature vector using a pre-trained anomaly detection model to obtain an anomaly score. The anomaly prediction module is used to predict anomalies in the multi-dimensional feature vector using a pre-trained classification model to obtain a risk probability value. The access control module is used to determine a target access policy based on the request data, the business dimension data in the multi-dimensional power data, the anomaly score, and the risk probability value, so as to execute a target action according to the target access policy, wherein the target action includes granting access, denying access, and secondary verification.
9. A power data access control system, characterized in that, include: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-7.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-7.