Distribution network data asset protection considering multiple topology and multi-dimensional knowledge graph☆

Junfeng Yanga,b ,Li Liua , Nawaraj Kumar Mahatoa , Luhan Lia , Jiaxuan Yanga ,Gangjun Gonga,*, Jun Lua , Chao Yangc

a Beijing Engineering Research Center of Energy Electric Power Information Security, North China Electric Power University, Beijing 102206, China

b Heze University, Heze, Shandong 274015, China

c State Grid Liaoning Electric Power Co., Ltd, Shenyang, Liaoning 110004, China

Abstract

The proliferation of diverse entities within distribution network has led to an increase in the scale and complexity of data asset interactions, exacerbating security risks, such as unauthorized access, data tampering, and forgery. In response to these challenges, this study introduces a novel framework that enhances the protection of data assets. It incorporates a multi-dimensional knowledge graph(MDKG) to refine access control and overcome current limitations by integrating a comprehensive set of data asset attributes, roles, policies, and permissions. This approach fosters the development of a nuanced and adaptable access-control mechanism. Furthermore, the framework integrates multiple topology(MTP)for holistic security risk detection,leveraging attention mechanisms, and cross-fusion to adapt to the dynamic data security landscape. Empirical evaluations affirm the effectiveness of MDKG-based access control, whereas comparative experiments demonstrate the superiority of the MTP-based security risk model over existing models. The framework was proven to be effective in countering security risks. This study provides innovative perspectives on data asset protection and establishes a solid foundation for the advancement of smart grid technology.

Keywords: Distribution network; Data asset protection; Security access control; Multi-dimen sional knowledge graph; Multiple topology; Security risk detection

0 Introduction

Ongoing modernization and technological advancements in the power sector have led to unprecedented expansion in the interaction and circul ation of data assets within the power grid. This growth, while beneficial, has also escalated security risks such as unauthorized access[1,2], data forgery[3,4], and data tampering[5], with complexities increasing daily. The blurring of security boundaries in distribution network necessitates more stringent requirements for data asset protection, highlighting the urgent need for in-depth research on data security access control and risk detection.

0.1 Research status

In the field of data asset protection in distribution network, data security access control and risk detection are two key research directions. In recent years, some progress has been made in both areas,but many challenges remain,especially in dealing with the complexity and dynami cs of new distribution network.

In the domain of data security access control, significant progress has been made in refining role-based access control models. Bhatt et al. [6] introduced an Attribute-Based Access Control model for fine-grained control,while Fragkos et al. [7] proposed a dynamic Role-Based Access Control (RBAC) model for smart grids, aiming to enhance RBAC policies within system security constraints.Zhang et al.[8] presented the TBDMACM model,enhancing system security throug h trust evaluation. Su et al. [9] optimized data security management with the MT-MHAC model for big data environments, and Zhang et al. [10] improved performance and scalability with a dynamic role access control model. Cai et al. [11] introduced the MR-RBAC model, offering fine-grained authorization, extensibility, and security. Xu et al. [12] further enhanced security with a role and attribute-based zerotrust access control model, utilizing dynamic trust assessment and a resource decision tree. Despite these advancements, chall enges remain in terms of the flexibility of access control, large-scale deployment, and cross-domain management.

In the domain of data security risk detection,Muthubalaji et al. [13] enhanced smart-grid security using a high-precision AEFS-KEN framework. Liu et al. [14]addressed big data security deficiencies in the power system by proposing data security methods and an intelligent management and control platform. Ortiz Huama´n et al.[15] developed a critical data security model for the financial sector, focusing on gap security identification and risk analysis.Zhang et al.[16] strengthened network asset monitoring, Dutta et al. [17] protected cloud data transactions with cryptographic algorithms,and Liu et al.[18] explored data security analysis using tag recogni tion techniques.Zhang et al. [19] employed blockchain in VANET for secure data sharing, and Liang et al. [20] proposed a multi-level intrusion detection model for detecting attack data in cloud and edge terminal layers. Santos et al. [21]tackled unauthorized access in public clouds using fragmentation techniques and NoSQL databases. However,these studies are insufficient to address data security issues in distribution network, which involve massive, sensitive,correlated, and multi-source heterogeneous data and lack adaptability to evolving data security.

0.2 Research questions

Although significant progress has been made in data security access control and risk detection, the existing methods and technologies are still insufficient in the face of the complexity and diversity of data assets, the dynamics of the network environment,and the need for real-time adaptive security measures, and the following questions need to be addressed:

1) How to develop a dynamic and flexible access control model to adapt to the complexity and dynamics of the distribution network?

2) How to design a comprehensive security risk detection model to effectively identify and mitigate emerging threats?

3) How to build a refined access control and security risk detection architecture to ensure the effectiveness and adaptability of data asset protection in a dynamic environment?

0.3 Theoretical basis

Based on the theoretical frameworks of multidimensional knowledge graph (MDKG) and multiple topology (MTP), this study aims to provide a comprehensive solution for the protection of data assets in distribution network. The MDKG implements a fine-grained access control mechanism by structuring the representation of data assets and their relationships. The MTP uses a variety of network topologies to comprehensivel y detect security risks.By integrating MDKG and MTP,this study proposes an architecture that combines dynamic, flexible,and secure access control with advanced risk detection across multiple network topologies to address the complexity and dynamics in the distribution network.

0.4 Main contributions

This study overcomes the shortcomings of existing access control and security risk detection methods in terms of flexibility and dynamics by introducing a comprehensive framework of MDKG and MTP, and prov ides a new perspective for the protection of data assets in distribution network. The main contributions of this study are as follows.

1) A method based on the value of data assets for grading is proposed, highlighting the necessity, significance, and security requirements of data asset protection in distribution network.

2) A dynamic, flexible, and secure authorization model based on MDKG is proposed, which enhances flexibility and dynamic access control mechani sms for distribution network data asset protection by integrating multi-dimensional information.

3) A risk detection model that considers multiple network topology representations is constructed to comprehensively identify and evaluat e the security risks of data assets, thereby improving protection capabilities.

4) An architecture that combines dynamic, flexible, and secure access control with advanced risk detection across multiple network topologies is designed to provide comprehensive protection against security risk challenges.

5) Demonstration practices show that the access authorization model considering MPKG is feasible and effective, and comparative experiments show that the security risk detection model considering MTP outperforms the mainstream models.

0.5 Organization of the paper

The remainder of this paper is organized as follows.Section 1 introduces the necessity and security requirements for the protection of distribution network data assets.Section 2 elaborates on the secure access authorization model considering the Multi-dimensional Permission Knowledge Graph (MPKG), the security risk monitoring model considering MTP, and the distribution network data asset protection architecture. The demonstration practice and experimental results are presented in Section 3. Finally, Section 4 concludes the pa per.

1 Protection analysis of distribution network data assets

1.1 Overview of distribution network data assets

The concept of a ‘‘data asset” finds its earliest documented refer ence in the work of RICHARD E. PETERS[22] in 1974. Peters included a broader range of assets within his definition, encompassing holdings of government and corporate bonds alongside real assets [22].Despite decades of evolving understanding and growing awareness of data assets, a universally accepted definition of data assets remains elusive. Various institutions and scholars have proposed diverse interpretations, highlighting the multifaceted nature of this concept and the ongoing need for a comprehensive and unified framework.

Tony Fisher [23] argues that companies should treat data as a corporate asset. The U.S. Army’s information technology implementation instructions define a data asset as any entity comprising the data itself and the associated service provided by an application to access that da ta.These data assets,originating from human input,systems,or applications, can encompass various formats such as files, databases, documents, or web pages generated by these systems.Zhu et al.[24] and Ye et al.[25] define a data asset as a dataset residing in cyberspace that possesses well-defined ownership characteristics (including exploration rights, usage rights, and clear ownership), demonstrable value, measurable attributes, and readability.According to Wang et al. [26], data assets are data resources that an organization legally possesses and controls. These resources offer the rights and capabilities for development and application with the expectation of generating economic benefits for the enterprise. ‘‘The White Paper on Data Asset Management Practice (Version 2.0)” released by the Institute of Cloud Computing and Big Data of the China Academy of Information and Communications Technology defines data assets as ‘‘data resources owned or controlled by enterprises that can bring future economic benefits to the enterprise and are recorded in physical or electronic form,such as documents and electronic data”[27].

Within the electric power sector, Ji et al. [28] identified power data assets as encompassing a broad spectrum of data. This includes real-time and historical data generated across various stages of the electricity grid, such as dispatching, transmission, substations, distribution, and consumption. Additionally, power data assets incorporate environmental data (meteorology and geographic information)and external factors such as government economic and policy data. Xia et al. [29] defined data assets within the power supply industry as data resources that are controlled or owned by power supply enterprises or organizations. These data assets have the potential to generate economic benefits and typically encompass business,management,and archival data.Chen et al.[30] posit a framework for identifying power data assets, suggesting that data resources qualify as such only if they meet four key criteria: controllability, processability, revenue potential,and quantifiability. Hu et al. [31] et al. define data assets in the power system as encompassing all data resources generated, acquired, and managed throughout operations.These assets hold significant value in informing decisionmaking processes, driving innovation, and propelling enterprise growth. Feng et al. [32] defined power data assets as electronic records reflecting the historical power supply and consumption activities of power companies.These assets are demonst rably owned, controlled, or used by the organizations with the expectation of generating economic benefits [32].

It can be seen that the concept of ‘‘data asset” has undergone a significant evolution, expanding from its initial association with financial bonds to encompass a broader range of data resources. These resources now include records of business activities, legal ownership,and potential economic benefits. While definitions may vary across different fields, there is consensus that data assets represent an indispensable and valuable production factor for enterprises,acting as strategic resources that can generate significant value.

Further, we refer to the distribution network data assets as various data resources generated throughout the operations of the new distribution network. These assets play a crucial role in supporting intelligent management and operation of the network, ultimately contributing to improved security, stability, reliability, and efficiency.Examples of such data assets include, but are not limited to, user data, business data, ‘‘three-remote data” (encompassing remote control, t ele-signaling,and telemetry data),energy data, and associated metadata. Fig. 1 provides a visual representation of the typical data flow status within the new distribution network, considering the production control area, management information area, and internet area.

d6c970442f3a68541e2b7ae343761194.jpg

Fig. 1. Typical data flow status in the new distribution network.

1.2 Characteristics of distribution network data assets

The widespread integration of diverse entities [33]including distributed photovoltaics, energy storage systems, electric vehicles, smart meters, microgrids, and virtual power plants, has introduced several distinctive charact eristics to new distribution network data assets.These characteristics include the following.

1) Large data volume: The widespread integration of various prosumers and expanding complex distribution network, has necessitated the deployme nt of a vast network of monitoring devices, sensors, and smart terminals [34]. This extensive infrastructure continuously generates various data, stored as historical record data, event logs, ‘‘three-remote” data and equipment operation and inspection data. Consequently, the volume of data associated with new distribution network has grown exponentially,reaching the scale of big data [35,36] and increasing the data security risks.

2) Multi-source heterogeneity: The new distribution network encompass a diverse range of data assets originating from multiple sources, including heterogeneous sensing devices [34,37] and recently integrated new energy facilities [33]. This inherent heterogeneity manifests in the format, structure,and semantics of the data, posing challenges for data integration,analysis, security,governance, and compliance [38], requiring more complex and comprehensive strategies to ensure consistent management and effective use of data.

3) Strong correlation: The various components within a new distribution network exhibit a high degree of interdependence. The data generated by monitoring devices, sensors, and smart terminals are inherently intertwined [39]. These data points are also influenced by external factors such as weather variations,seasonal changes, and fluctuations in load demand.This poses challenges for effectively managing and analyzing highly interdependent data to prevent the spread of risks.

4) Privacy sensitivity: The new distribution network data assets encompass a wide range of information,including user data, electricity consumption habits,and energy consumption patterns [40]. These data may also include sensitive information such as trade secrets, operational strategies, and the location of critical facilities [41].

1.3 Security requirements of distribution network data asset

The dynamic evolution of the new distribution network,coupled with the unique characteristics of circulating data,presents substantial challenges to traditional security paradigms. Traditional compartmentalization among security domains, management domains, and business systems is likely to diminish as information interaction across these domains becomes increasingly necessary [36]. Consequently, the robustness and closed-loop nature of current security systems will be compromised, a s illustrated in

Fig. 2. To address these challenges and ensure the security of data assets originating from diverse sources, more robust protection technologies and fine-grained, dynamic,and adaptable access-control mechanisms are required.Furthermore, the huge volume, strong correlations, and inherent heterogeneity of data make it difficult to detect potential security risks. To overcome this hurdle, a more effective security risk-detection model is necessary.

67fdeba2bb0675d1c40b71b2b22d913e.jpg

Fig. 2. Data asset circulation security in the new distribution network.

1.3.1 Full lifecycle data assets security

The objective of ensuring the full lifecycle security of distribution network data assets [42] is to safeguard data from threats or damage during the process of collection,transmission, storage, processing, sharing, and destruction. Data collection serves as the foundation for data asset security and is the first line of defense. It is essential to guarantee the authenticity, dependability, and security of data during this phase. To achieve this, it is necessary to define the roles and obligations of all parties involved in data collection through contracts or agreements, including scope, frequency, type, purpose, and retention period.This ensures the legitimacy and accuracy of the data. In addition, it is crucial to ensure the security and reliability of the data asset process by adhering to legal compliance and technical protection measures. This can be achieved through techniques such as identity authentication, permission control, data desensitization [36,43], firewall restrictions, illegal character filtering, device password encryption, risk detection and assessment, and verification of data authenticity. Finally, when utilizing data assets, it is necessary to select an appropriate encryption method[44] to guarantee the confidentiality, integrit y, and availability [45] of data a ssets.

1)Data confid entiality

Because data assets involve sensitive data such as distribution network operations and faults, these sensitive data need to be encrypted or privately processed [46], and access control methods [47] and secure transmission channels [48,49] need to be dynamically constructed to ensure the security of data during transmission. Simultaneously,it is necessary to build a sensitive information identification model [50] and a data asset map [51] to improve the identification accuracy of weakly structured data and support real-time dynamic desensitization of the entire life cycle of data assets to reduce the risk of data asset leakage.

2)Data integrit y

To ensure data integrity, it is essential to implement comprehensive monitoring technologies [52] that can promptly detect anomalies, take effective countermeasures,and safeguard data against potential threats. In addition,employing encryption algorithms a nd digital signatures[53] is crucial for preventing unauthorized third-party tampering. Advanced data verification methods [54] are also necessary to verify the integrity of the data. However,massive access by various entities introduces overhead owing to data encryption and third-party verification[55]. Therefore, a lightweight cryptographic mechanism [56] is required to mitigate these overheads while maintaini ng the data integrity.

3) Data availab ility

To ensure that the collected data are accessible and usable when needed, it is imperati ve to employ technical strategies, such as backup restoration [57], disaster recovery[58], and failover[59]. Backup restoration involves regular restoration of backed-up data assets, ensuring their timely availability in the event of data loss or damage.Disaster recovery entails swift switching to standby devices to maintain the continuous availability of data assets when the data center server fails. Failover mechanisms automatically redirect data traffic to a standby node in the case of a failure in the style="font-size: 1em; text-align: justify; text-indent: 2em; line-height: 1.8em; margin: 0.5em 0em;">1.3.2 Endpoint-Edge-Cloud side data assets security

The construction of a new distribution network necessitates the integration and application of emerging technologies, such as ubiquitous IoT, intelligent terminals, 5G, and blockchain. Consequently, the traditional distribution network, service model, and data interaction methods are insufficient to meet the current needs. It is imperative to ensure the security of data assets by addressing multiple aspects including the distribution master station, network security infrastructure, communication protocols, and terminal devices.

1)Endpoint securi ty

Most of the terminals in the distribution network are deployed in an open physical environment and are unattended, and their security cannot be guaranteed; there are a large number of security risks,and the security of terminal data is even more difficult to ensure[60]. Therefore,an intelligent and granular permission control mechanism is needed to effectively restrict access to terminal devices and respond to potential security threats and vulnerabilities promptly through comprehensive network topology analysis to improve the securi ty and reliability of the system and to effectively defend against evolving security threats and attacks.Breaking through chip-level data security technology[60] is also a good choice, but it is currently more difficult.

2)Edge securi ty

With the widespread access of diverse entities, the edge side of a new distribution network faces the pressure of massive heterogeneous intelligent terminal integ ration and control [36]. It is necessary to improve the security of access facilities and service access in terms of authentication and authorization mechanisms[61], communication channel security[48], and password management. In addition, it is necessary to promptly detect and respond to possible security threats through real-time monitoring and topology-based edge analysis [62,63].

3) Cloud securi ty

With the rapid increase in third-party business service providers, power grid enterprises, power generation companies, energy-saving service providers, power users, and other participants [36], the data interaction between source, grid, load, and storage has also become frequent,the exposure of distribution network data assets on the Internet has gradually expanded, and the risk of springboard threats has increased [64]. Therefore, it is necessary to pay more attention to the security design of Internet facilities and data center architecture, break through traditional passive defense, turn to proactive defense, and build a detection model that can actively discover whether there is a potential risk in data assets and a prevention and control mechanism that can actively resist large-scale cyberattacks.

1.3.3 Value based data assets security grading

By reasonably grading the security of data assets based on their value, enterprises can effectively protect the critical data [65,66]. For high-value data assets, enterprises need to implement stricter encryption, access control,and risk monitoring measures to protect these data from unauthorized access, data breaches, malicious attacks,and so on to reduce financial losses. Therefore, fully considering the security factors that affect the value of data assets is one of the key measures for ensuring the security of data assets and achieving long-term sustainable development.

1) The value of data assets

The value of a data asset is reflected in its positive impact on the strategic, economic, and operational aspects of an enterprise or organization [67,68]. First, data assets can improve the decision-making ability and efficiency of enterprises, and through in-depth analysis of the value of data assets and their accounting[69], enterprises can make more informed strategic decisions, thereby achieving longterm growth in asset value and improving enterprise competitiveness. Second, through accurate data asset identification, quantitative value analysis [70], and revenue forecasting [71], enterprises can more effectively optimize the data asset management process, reduce costs, and promptly respond to market changes and risk challenges.In addition, data assets can also promote innovation and increa se revenue, and through different methodological models [72,73], the potential value of power data can be unlocked and new business opportunities can be discovered, enterprises can expand their markets,achieve profits,and provide new digital products or services to society[74].It can be seen that data are not only one of the most valuable assets of enterprises, but also an important driving force to promote their development and value creation.Therefore, to protect data assets more economically and effectively, it is necessary to conduct a reasonable evaluation of their value of data assets [26].

2) Grading based on the value of data assets

To address the potential mismatch between asset value and protective measures, such as insufficient security of high-value data assets and excessive security of low-value data assets, a grading method based on the value of data assets has been proposed.

In alignment with the guiding principles of the Information Security Management System Standard (ISO 27001),we defi ne the formula for calculating the value of the data assets as follows:

78fce1639b88ffbb6ca78021fee7f3eb.jpg

where, Vis the value of the data asset in a certain business scenario, Roundxis the rounding function that retains x decimal places, ωi is the weight of the ithsecurity factor required for data asset grading, and θiis the level assignment of the i thsecurity factor required for data asset grading. In general, there are three security factors for data assets: confidentiality,integrity,and availability,their corresponding security levels are generally classified as very high, high, medium, and low, and the corresponding values of these levels can be found in Tables 7, 8, and 9 in the appendix. Fig. 3 shows the grading process centered on the value of data assets. After calculating the value of the data assets, they are graded according to Table 1.

For example, the China Guangdong Power Grid Corporation considers the nature of the power grid operator and the overall distribution of data assets and determines that the confidentiality level of data asset security of a business department is high 3aaf90748aa20eeb5c74c7cc79f660e6.png, the integrity level is medium 2665280befe937dccd36e3d5cad5a719.png, and the availability level is mediuma74cb35b503c4650b239ddc68f7d6664.png, and the weights of confidentiality, integrity, and availability are 20c53343c093701909adf151161fb184.png26ec46d8a84b7445811bd85643f0b6a8.png, and 73f3c3c834cd6cd11e188c2cf4d2874b.png,respectively.

06d7f39a30e077f66f0c0fd3bf3ba2d0.jpg

According to Eq.(2), the value of the data asset 529f825d801a69edae64d705e7e0a93e.pngcan be calculated, and the security grade of the data asset is ’Internal’ according to Table 1.

01551aee642eedada0a88d8cb33e5005.jpg

Fig. 3. Data assets grading process.

Table 1 Value and grade of data assets [68].

bdf57b9764b9eafd6a724f5eae3b70e9.jpg

Note: The values in Table 1 are typically determined by policymakers,data governance teams, or security experts within an organization based on a range of security factors based on data asset criticality assessment and classification and grading needs.

It is worth noting that this section proposes a security classification method based on the value of data assets,which reasonably evaluates the value of data assets and carries out hierarchical protection by comprehensively considering the security factors such as confidentiality,integrity, and availability of data assets. This method can effectively solve the problem of insufficient protection of high-value da ta assets and over-protection of low-value data assets, provide a scientific and reasonable basis for the security management of data assets in the distribution network,and ensure the security of data assets and the effi-cient use of enterprise resources.

1.4 Protection requirements of distribution network data assets

The data assets of the distribution network sometimes have communication security vulnerabilities owing to the granularity of security access control [75], and sometimes abnormal data [76] cannot be discovered in time because of insufficient monitoring which lays security risks for the processing, use, and sharing of data assets. Therefore,it is necessary to build a more fine-grained access authorization method and access data assets dynamically and flexibly, to reduce the possibility of malicious access to data. Simul taneously, more effective risk detection methods are required to promptly detect potential security threats to improve the security and reliability of data assets.

1)All-round access control of data assets

Access control technology needs to restrict the data,interfaces,and authorization extensions[54] of user access from multiple dimensions, such as attributes, time, and scope of action, through the classification and grading of data a ssets and the authorization of users, according to the principle of data access minimization [77]. However,current access control methods [78,79] find it difficult to satisfy these constraints and support the requirements of vertical security authentication and horizontal dynamic access control. Therefore, it is necessary to comprehensively consider multi-dimensional information such as user identity, role, behavior, and data assets, dynamically adjust permission control, and realize refined management of data asset access. In this way, different levels and types of data asset security access control can be completed,and it can also be made more flexible to adapt to changing business needs and respond to security threats.

2)Comprehensive risk detection of data assets

In the new distribution network, with continuous access to photovoltaics, energy storage, charging piles, and other facilities, the topology of the distribution network has become more complex and diverse, involving different levels of equipment and systems, and the monitoring and auditing methods based on block-chain technology [80-84] and the risk monitoring mechanism [85] around the attributes of data assets can no longer meet the needs of vertical and horizontal risk detection. For these different topologies, more flexible monitoring technologies are required to monitor and audit the security risks of each topology to identify potential security threats and risks[86]. Under multiple topologies of the distribution network, all-round risk detection requires accurate monitoring of different topo logy nodes and network connection points to ensure effective management [87-89] and protection of data assets.

2 MDKG and MTP enable data asset protection

2.1 Data assets access control model considering MDKG

Traditional role-based access authorization methods have limitations in the face of large-scale data assets and complex environments, while attribute-based access authorization methods present higher flexibility, but also ha ve certain challenges in implementation and management[47,75]. Given this situation, we propose a data asset security access authorization model that considers MDKG to solve these problems. Owing to the complexity of the process of solving these problems, the background of access control and the proposed security access authorization model, formal representation, authorization method, and model implementation are provided in 2.1.1 to 2.1.5.

2.1.1 Background of access control

The role-based access control (RBAC) approach [75]assigns permission to access data assets through roles and authorizes roles to users. This approach simplifies operations in terms of user management and access rights assignment, improves ease of management, and improves the security of accessing data assets. However, with the development of the computer environment, particularly the proliferation of data volumes and changes in data structures in distribution network, this RBAC approach faces some challenges. Owing to the fixed roles in RBAC,cross-domain authorization is not sufficiently flexible, and it is difficult for RBAC to implement access control of metadata and meet compliance requirement s. In thousands of data asset access scenarios, the role-permission explosion problem has become prominent, data asset access control and authorization have become more complex, and data asset security has become more difficult to guarantee. Therefore, there are certain limitations to the management and security of access rights for large-scale data assets, and other access management methods must be considered to meet the challenges in real-world scenarios.

The Attribute-Based Access Control (ABAC) method[47] implements access control using user attribute information and data asset attribute information. Compared with the RBAC method, ABAC is more flexible and can overcome the shortcomings of RBAC in a new environment. In ABAC, users need to carry their attribute values when accessing the underlying data assets and make judgments based on predefined access policies to determine whether the user has the right to access the data assets.This method makes full use of attribute information as a parameter for access control, and improves a ccess flexibility. However, the access policy analysis of ABAC is relatively complex and there is currently no mature implementation plan. Attribute information about users and data must be analyzed and defined in detail, which can be more difficult to implement and manage.Although ABAC has theoretical advantages, further research and development are required for practical applications.

In conclusion, traditional role-based access control(RBAC) approaches are practical in terms of access control, but they are flawed in the context of large-scale data assets. However, attribute-based access control (ABAC)methods are not yet mature and lack implementable models. To overcome these problems, Refs. [90-92] began to combine the advantages of roles and attributes to explore methods for dynamic matching of roles and permissions,and roles and attributes, but these methods are still tricky in terms of attribute management, dynamic real-time evaluation, and updating access policies.Therefore,it is necessary to build a new approach around users, roles,permissions, attributes, and data assets to ensure secure access control of data assets.

2.1.2 Security access control model

MDKG can describe the knowledge graph of distribution network data assets from different perspectives [93],mainly including attribute knowledge graph, role knowledge graph, policy knowledge graph, identity authentication knowledge graph, context knowledge graph,dynamic access knowledge graph, audit knowledge graph,and so on. For example, the MPKG proposed in this study organically integrates the roles and permissions of operating different types of data assets with data attributes, grading attributes, and operation attributes, as well as the number, time, and scope of permissions, to represent the complex relationship between data assets, permissions,and roles,making the permission assignment more flexible and convenient.In addition,to improve the security of the model, the dynamic assignment of users to roles is constrained by trust and sessions to ensure the security of data asset access. The proposed security access control model that considers the MPKG is shown in Fig. 4.

Fig. 4. encompasses three main sets. The first is the MDKG set that revolves around data assets, including data asset set, data attribute set, grading attribute set,operation attribute set, user attribute set, and environment attribute set. The second is the user-role-permission-opera tion-data asset assignment rules designe d to improve the flexibility and convenience of authorization, which mainly include user/device sets,role sets,and permission sets.The last is the support set designed to improve the security access control of data assets, mainly including data asset classification set, data asset value set, operation set, user trust set, and user session set. Table 2 describes each collection in detail.

2.1.3 Formal representation of MPKG

To clearly express the spatiotemporal relationship of the MPKG and the efficient reasoning of permission knowledge update, we adopt the method of adding dimension attributes to the permissions and completing the access control of roles through the control of dimension attributes,which not only reduces the difficulty of development and implementation, but also enhances the security and flexibility of access rights management [94].

3398e4da6392b08c207216bd339c80f5.jpg

For example,Fig. 5 shows the MPKG schema that considers multi-dimensional attributes, such as data, grade,operation, time, and quantity.

f1458ad709c3eeaceeb1ecaf79b57343.jpg

Fig. 4. Security access control model considering MDKG: MPKG.

Table. 2 Collection definition and description.

c5da68526996910884fb7aff54c8ccba.jpg

2.1.4 Authorize method based on MPKG

In the RBAC method, user permissions can only be updated by modifying or adding the roles assigned to the user, whereas updating the permissions of roles requires modifying the original role permission relationships,which is more difficult to authorize [95]. To solve this problem,the proposed method no longer authorizes the data assets themselves, but dynamically and flexibly assigns permissions to access the data assets through permission sets,role sets, user sets, trust sets, session sets, etc., based on the classification and grading [96,97] of data assets, with the MPK G as the center.

1) User-role assi gnment

First, define the user-role assignment U R: UR ⊆U R,and then calculate the user trust level according to the function ComT199f6bd5bfe5d9a33617b06009be8865.png[98], when the trust level reaches the specified value, the user-to-role assignment can be completed through the function (3).

3a5d845848e9f32ce8ef10bc9f409d88.jpg

where,e0b34a1b9269d252d79bd8b7a215c9d1.jpgindicates that the user-to-role is a many-to-many mapping.

2) Role-permission assi gnment

Define role-permission assignment5b34cd1ac2b8cc4798d776f021b56402.jpgto dynamically build role-to-permission relationships. Ife4e4182ee8f0ff4a68251f57e969f35a.jpg,the permission assignment function of the rol e r can be expressed as:

d7ab000a1380402fc0fe319980e64138.jpg

where, the mapping between roles and permi ssions is also many-to-many.

3) Mapping of permissions to data assets

The mapping of permissions to data assets is done by operation set O and data asset set DA,and the data asset operation6571cfc3418b125c3e14d303382d8f4b.jpgOis defined, then the function that operates on any data asset DA can be expressed as:

8795dbd35b86ea3cce9144c2e616d70b.jpg

4) User session functi ons

Define user session US :US⊆U S,and then the mapping function for a single user to the session set is:

d0a97e9482885c878f7bdaaf9aa70488.jpg

5) Role session functi ons

Define role session R S :RS ⊆S R,and then the mapping function for a session to the role set is:

cfa5fed2130a6cfb8de033a03dd45020.jpg

where, the role corresponding to the session should meet R⊆UR.

6) User-Role-Permission-Data Asset assignment rules

First, assign roles to users who meet the trust level in the session, and then make full use of the M PKGcharacteristics to dynamically assign the minimum permissions to operate data assets to the roles. For example, (8) is a rule that assigns a role r in a session to the user u who meets the trust level, and assigns pi operation da to r.

eaa1a1dc0326041b4f5acd47c9b3525e.jpg

Fig. 5. MPKG schema.

9cd01cbfbeb37053c505dd7caf27ee44.jpg

In other words, the rules on whether a user has access to data assets can be implemented in t he is authorized 24325b5c2de56335523d56cd30fc8c78.pngfunction.

2.1.5 Model implementation details

The MDKG-based access control model was implemented using Python 3.11 and the PyTorch framework.The model integrates multi-dimensional attributes such as user roles, data asset attributes, and environmental factors. The key steps in the implementation include:

1) Knowledge graph construction: The MDKG was constructed using Neo4j, a graph database platform, to store and manage the relationships between data assets, roles, and permissions. This knowledge graph encompasses a total of 1896 metadata entries and 7641 relationships representing various components within the distribution network,such as distributed photovoltaics, energy storage systems, charging piles, switchgear, sensor devices,and others.

2) Permission assignment method: A dynamic permission assignment method was developed to adjust permissions based on user roles and trust levels. The algorithm uses a scoring system to evaluate user trust and assign appropriate permissions dynamically.This method ensures that permissions are adjusted in real-time based on multi-dimensional attributes such as time,control,data rating,and data quantity,enhancing the flexibility and adaptability of the access control system.

3) Model deployment and validation: The MDKG model was deployed in a simulated environment to validate its effectiveness in managing access permissions. The validation process involved testing the model’s ability to dynamically adjust permissions based on user roles and trust levels, ensuring that access control decisions are made accurately and effi-ciently. The results demonstrate that the MDKG model effectively enhances data security and mitigates the risk of data leakage and misuse.

It is worth noting that the MDKG-based access control model proposed in this study realizes dynamic and flexible access control to distribution network data assets by integrating multi-dimensional information,which significantly improves the security and adaptability of the system.

2.2 Data assets security risk detection model considering MTP

With the continuous access of diverse entities, the topology of the distribution network has become complex and volatile, and the possibility of facing secu rity threats and risks has increased,which has a serious impact on the security of data assets [28,29]. The topology of a distribution network is closely related to the risk detection and protection of its data assets[99]. Therefore, we analyze the MTP of the new distribution network in detail in Section 2.2.1,focus on studying the security risk detect ion model considering MTP in Section 2.2.2, and describe the implementation details of the model in Section 2.2.3.

2.2.1 MTP analysis

Fig. 6 shows the new distribution network system with multiple topology fusion, in which the physical topology[100,101] determines the connection mode and distance between devices. There may be strong or weak interconnections between devices in the distribution network,which directly affects the propagation path and scop e of potential security risks and makes a preliminary assessment of the vulnerability and complexity of the network.The data topology[102,103] determines the path and speed of data transmission, and by analyzing the data topology,it is possible to identify the nodes and links that may be vulnerable in the data transmission process, and then evaluate the degree of risk of data assets. Information topology [104,105] specifies the flow of information and rules, and by analyzing the information topology, it is possible to check for potential security risks such as information leakage, tampering, or unauthorized access. By analyzing the security topology[106,107], potential vulnerabilities, faults, or attacks in the system can be identified,ensuring the security and confidentiality of information and helping to prevent and respond to security threats promptly.

As can be seen in Fig. 6, there is a close coupling between the various topologies; therefore, it is important to understand the relationship between them to better ensure the security of the distribution network data assets.Physical topology directly affects the transmission speed and latency of data, and improper physical connections may lead to bottlenecks or security risks in the data topology. The transmission of data in the network may be limited by information topology rules, such as improper configuration of access control policies, which may lead to the disclosure of sensitive information, the flow rules of information limiting the transmission path of data and affecting the security and integrity of data. The information topology ensures the secure transmission and storage of information through access control, encryption technology, and other means. Through security topology analysis,risks such as attacks and vulnerabilities in the system can be identified, and then the information topology rules and physical connections can be strengthened to improve the security of the system. It can be seen that closed-loop security analysis and risk detection of distribution network data assets can be realized through physical,data, information, and security topology analysis to achieve the purpose of empowering data asset security.

2.2.2 Security risk detection model considering MTP

Various topologies of the distribution network play an important role in data asset protection, and security risks and abnormal behaviors can be detected by monitoring topological changes[99]. In fact, the topology in the distribution network is consistent with the heterogeneous graph[108,109], an MTP-based security risk detection (MTPSRD) model considering the attention mechanism and cross-fusion technology is proposed based on the heterogeneous graph theory, as shown in Fig. 7.

1) Aggregation of node neighbors within a topology

d66fc9364c6d919ccfa555485ea753e4.jpg
874424d54a11cbfce8cd302f64f92e5f.jpg

Fig. 6. MTP of the new distribution network.

91dbc61f0c0734489229d9b576749a53.jpg

Fig. 7. The MTP-SRD model.

0b38af902b151685e202a12340ffbf51.jpg
13b98f02615e8a0d9ee991211e49c2d4.jpg
682fb9f9621c10a9695d4c222695381a.jpg
4215fb0832edaaeea14378bbcd2102ba.jpg
fdd762a22476e947f8f570a36e504591.jpg

So, for each topology TP,according to its weight coefficient 4beea819acf8b4b54ccd2b22f193e4b6.png,the output vectors of all neighbor aggregation functions are obtained:

e88ff48b2b512238c164bb1912914d95.jpg

Due to the scale-free nature of the data in the heterogeneous graph here, the variance may be very large [109],and to stabilize the training process, we use a multi-head attention mechanism [111] to solve this problem. Specifically, the attention network module in the topology independent of the head is repeated, and then the learne d embedding vectors are averaged as Eq. (13).

be1ca4a12988d989f1f955888b88a690.jpg

Fig. 8 shows the aggregation process of node neighbors within a topology.

2) Aggregation of the node neighbors among topologies

In general, each node in the multi-heterogeneous topology diagram of a distribution network contains semantic information in many dimensions, and the neighboring nodes connected by most nodes are not the same from different perspectives [108,109]. Therefore, the neighbor aggregation representation at a particular perspective(e.g., any TPi )can only reflect information about neighboring nodes in terms of the semantics of that perspective. To obtain more comprehensive and more perspective information about neighbor nodes of a node, it is necessary to integrate multiple semantics of neighbor information represented from as many perspectives as possible. To semantically fuse the neighbor information of each node in the multi-topological heterogeneous graph of the distribution network,we used the attention mechanism to learn the weights of each topology.

If Mtopologies are given, the aggregation vector7baafeb0d1f102bcdb11dbeb3180fd13.jpgof the central nod ev neighbor of the Mgroup can be obtained through multi-attention aggregation learning in the intra-topology, and the vector group7fde50c5e3c2ab6fd67fb200532cbb19.jpgis used as the input of node fusion among topologies, then the learning weights of all topologies can be expressed as in Eq. (14).

4015ba9dc4965c523689f245c22e8238.jpg

where, int erf3dcf57f311d66ee015dcab668f3c787.pngrepresents the inter-topological attention network, which can obtain a variety of semantic information contained in a variety of heterogeneous topology maps. Then, we use the inter-topological attention mechanism to obtain the importance e TPiof each topo logy,which is calculated as in Eq. (15).

67e0e5f116760cda04f3993d56172fda.jpg

Fig. 8. The aggregation process of node neighbors within a topology.

a901376b1578522e74bcdd2c53e740b4.jpg

where, q is the attention vector among topologies, and b5cd79dada2970d5e448f97fd2fca614.pngis the concatenating operation. After obtaining the importance of each topology, we normalize it with the soft maxfunction to obtain the weight βTPi for each topology as expressed in Eq. (16).

67c525a2a5968d38ca27752a7e508196.jpg

βTPican be seen as the contribution of a specific topology to the risk detection task, and the higher its value, the more important the TPitopology. In other words, different topologies have different importance for risk detection tasks in different scenarios. In this way, we can fuse the learned weights as coefficients with the embedding of their corresponding topologies to obtain the last neighbor information vector 96e7890eb4f9fa076ebb97974ac28f17.pngof the central node v.The 9384bb2a9eb068d0db5c045e1ff7bc2f.pngcan be expressed as in Eq. (17).

b68e827681d041ffd09d01d27a33c5eb.jpg

Fig. 9 shows the aggregation process of the central node v neighbors in MTP. The fusion entity 7143f38ab78b9ec53bdb3bf2872891ef.pngof neighbor information learned through the inter-topological attention network integrates all semantic neighbor information of the central node v.

3) Cross-fusion of nodes and their neighbor aggregation

18ef0646c5df8cb0915b457adbe84613.jpg

Fig. 9. The aggregation process of node neighbors among topologies.

The above method has completed the aggregation of central node neighbors in the intra-topology and intertopology, and the feature vector hv of the central node v and its neighbor aggregation vector a0be853075e142ef55494299214e518a.pngcan be regarded as the features of two aspects. Curr ently,most researchers fuse hv and ed810aab40ae656d4424ff9b3f94e91d.pngby averaging or concatenating [108-110]to update the feature vector of the central node v. However, these simple ways of doing things may not implicitly capture information in a heterogeneous graph. Therefore,for the distribut ion network data asset risk detection task based on a heterogeneous graph neural network,we design a feature crossover model based on encoder-decoder [112]to complete the fusion of vectors h v and 87254532b02a4002777fe0728a421aee.png,to learn the fusion feature of the central node and its neighb ors aggregation feature completely and effectively.

First, the vector hv of the central node v and its neighbor aggregation vector 35ccbd9d3c092325623146f9711f3c3f.pngare converted by the same encoding-decoder. In this way, we can get the new vectors0d4c649577cb474cea1378dfc6849e34.png and 7391fd66f4a1c872e62d4e420eac4882.png:

ca9bbae4bf3684bf56edad8b8774ea46.jpg

The cross-fusion process between the central node and its neighbor aggregation features is shown in Fig. 10.

4) Model training and risk detection

d0e25eb83d4c2a4ac2ca1951dbe31dc3.jpg

Fig. 10. The cross-fusion process between a node and its neighbor aggregation.

For the distribution network data asset risk detection problem, suppose the node v represents a target data asset entity whose risk needs to be proven, for example, it can be a cable or transformer in the distribution network. The node has a label127b573983620879f6062f898330933b.jpgwhere 0 indicates normal,and 1 indicates risk; a relationship is a connection, neighbor, or attribute between nodes, like current and voltage information for multiple connection points under a cable or the same transformer. The risk detection problem based on the topology graph of a distribution network is a binary classification problem with semi-supervised learning on a graph neural network. In other words, we first built and trained the security risk detection model considering the MTP model using labeled data asset information and their large number of relationships,and then inferred the risk of unlabeled nodes from the trained model.

Our approach is to send 0fd47854a6c767beac11668632407e0e.pngto the MLP [114] classifier for risk detection, and output the detection result whendbe7c635332b82ae73ff26b183a17fe9.pngreaches the expected value, otherwise we will judge whether to continue training the model parameters by the total loss Γ.The losses defined in this study are expressed in Eqs. (23)-(26).

a4b14af47930c08f55956b5588c9532e.jpg

where, M is the number of labeled nodes (edges), ff9cb125f361c5ac6baa6ef9accf50fb.pngis the supervision loss of the labeled part of the heterogeneous graph involved, 0244aee770d3ffb5d1ed80836792f84b.pngis the regularization loss (structure loss) caused by retaining the structural information of the graph, 06270ac153a10603787904c5136e9dfa.pngis the regularization loss (coding loss)caused by the fusion of the node and its neighbors using the encoder-decoder, an d λ1 and λ2are hyperparameters. Because the learned parameters can be passed and shared, it is possible to train them effectively in a semisupervised learning manner with limited data. Simultaneously, the proposed model can also perform inductive learning on a large-scale heterogeneous graph, which means that it can extract knowledge and make inferences from different sources and types of data.

2.2.3 Model implementation details

The MTP-based security risk detection model was implemented using MATLAB/Simulink for simulation and Python 3.11 with the PyTorch framework for machine learning. The key steps in the implementation include:

1) Topology simulation: A distribution network topology with diverse entities (e.g., photovoltaics, energy storage systems) was simulated in MATLAB/Simulink. The simulation generated 345,600 samples,including 207,360 normal and 138,240 abnormal samples.

2) Graph neural network design: A heterogeneous graph neural network (GNN) was designed to process the multi-topology data. The GNN architecture includes multiple layers of graph convolutional networks and attention mechanisms to capture the relationships between nodes.

3) Model training and evaluation: The model was trained using a semi-supervised learning approach.The training dataset was divided into training, validation, and testing sets. The model’s performance was evaluated using accuracy, precision, recall, and F1-score.

It is worth noting that the security risk detection model based on MTP proposed in this study can comprehensively identify the security risks of distribut ion network data assets through multi-topology analysis and attention mechanism, which is better than the existing models.

2.3 Distribution network data asset protection architecture

A holistic data asset protection architecture for distribution network was meticulously designe d, as shown in Fig. 1 1. This architecture anchors on three pivotal dimensions: value-based data asset grading, stringent security access control, and proactive security risk detection. It integrates a security access authorization mechanism that considers MDKG and risk detection technology considering MTP and enhances data asset protection.

7e38eed8d9b91822231bf11216111911.jpg

Fig. 11. Distribution network data asset protection architecture.

For open data, which is of low value, low-level access control technology based on an attribute knowledge graph or role knowledge graph is adopted, and user access rights to data assets are determined based on user attributes or roles. Internal data is of medium value, employing medium-level access control techniques based on a policy knowledge graph or authentication knowledge graph,and controlling access to data assets based on policies or user identities. Sensitive data are of high value, and advanced access control technology based on a dynamic access knowledge graph or context knowledge graph is used to dynami cally adjust access rights according to data asset attributes or access environment to ensure data confidentiality and integrity. Highly sensitive data are highly valuable, and the most advanced access control technology based on a dynamic access policy knowledge graph or audit knowledge graph is used to adjust permissions according to dynamic access policies. Detailed audit and monitoring of access behaviors are carried out to ensure data security and compliance.

Furthermore, the data asset protection architecture comprehensively takes into account the multiple topology of the distribution network, including but not limited to physical, data, information, and security topology. By harnessing the capabilities of heterogeneous graph neural networks, the architecture conducts a 360-degree risk detection process. This proactive approach ensures that potential vulnerabilities and anomalies are identified and mitigat ed across all the layers of the network.The integration of MTPs allows for a holistic understanding of the network’s security posture, enabling the architecture to preemptively address emerging threats and safeguard the all-around security of the distribution network’s data assets.

3 Experiments of the MPKG a nd MTP-SRD models

To verify the feasibility and effectiveness of the proposed models, an MPKG is constructed for administrator operation metadata, and experiments of the MTP-SRD model were performed, including convergence, ablation,and contrast.

3.1 Practices of the MPKG model

3.1.1 MPKG of distribution network data assets metadata

Our proposed data asset access control system utilizes an MPKG to manage the access permissions. This MPKG encompasses a total of 1896 metadata and 7641 relationships representing various components within the distribution network, such as distributed photovoltaics, energy storage systems,charging piles,switchgear,sensor devices,and others. Fig. 12 illustrates a portion of the MPKG managed by the administrator role. The graph depicts how the administrator role can be dynamically assigned fine-grained access control permissions (view,add,update,delete)based on multi-dimensional attributes such as time,control, data rating, or data quantity.

The knowledge graph depicted in Fig. 12 documents the access rights, control rules, and associated data governance policies of the data asset metadata. This documentation enhances data security, mitigates the risk of data leakage and misuse, and safeguards power enterprises’data assets. In practical demonstrations, it has been conclusively shown that the dynamic authorization mechanism of the MPKG can effectively respond to real-time changes in users and environments. By dynamically adjusting permissions, it ensures the security and compliance of data access, thereby safeguarding data assets. This approach enables the precise control of data assets by meticulously analyzing user attributes, roles, and operational behaviors. It can be seen that the construction of MDKG can improve the flexibility, large-scale deployment, and cross-d omain shortcomings of security access control. Simultaneously, combined with the MTP-SRD model, it provides comprehensive and active protection for distribution network data assets, showing significant advantages in flexibility, adaptability, and technical compatibility.

3.1.2 Challenges and solutions for MPKG practice

1) Attribute management challenges an d feasible solutions

In the practice of the MPKG model, attribute management faces several challenges. In a dynamic environment where data characteristics and usage patterns change frequently, accurately defining and maintaining data asset attributes can be complex. As the number of attributes and data assets grows, it becomes increasingly difficult to efficiently manage them without degrading performance.In addition, data drift and business changes between different systems make it challenging to ensure that attribute definitions and their values are consistent and accurate.

f8fcdc20be34c73a3355783d0d17faff.jpg

Fig. 12. MPKG for an administrato r to manipulate metadata.

To address these challenges, several feasible solutions can be implemented. Automatic attribute discovery mechanisms can be used to reduce the complexity of manual definition and maintenance in terms of data usage patterns, metadata dynamic identification, and definition of data asset attributes. To accommodate the growing volume of attributes and data assets without compromising performance, attribute management systems can be designed in a modular man ner to be easily updated and expanded. Attribute management can be maintained robust and reliable over time by regularly reviewing and updating attribute definitions and their values for consistency and accuracy, or by detecting and correcting inconsistencies through automated tools.

2) Real-time dynamic evaluation challenges and feasible solutions

In terms of real-time dynamic evaluation of MPKG models, there are some challenges to ensure the effectiveness of the models. Real-time evaluation comes with significant computational overhead, which can degrade model performance. Being able to process real-time data without introducing delays during evaluation comes with significant techn ical pressure and performance bottlenecks. In addition, models need to adapt to changing conditions and data patterns in real time,which can be extremely difficult to maintain their validity and relevance.

To address these challenges, several feasible solutions can be implemented. By optimizing algorithms and data structures to minimize computational overhead, the model is ensured to maintain high performance even under realtime constraints. Edge computing is deployed to process data near the source to reduce latency and improve the model’s ability to process real-time data. An adaptive machine learning approach that dynamically adapts to new data patterns and conditions is used to maintain the adaptability and effectiveness of the model in real-time scenarios.

3.2 Experiments of MTP-SRD model

To verify the effectiveness of the MTP-SRD model for the distribut ion network data asset, a topology as shown in Fig. 13 is proposed, in which node information changes over time due to the uncertainty of photovoltaics, mobile devices, and energy storage devices so that MTP can be derived. To achieve this scenario, we integrated the topology shown in Fig. 13 at bus 18 in the IEEE-33 distribution network in MATLAB/Simulink and simulated it. A total of 345,600 samples with 26 topologies were generated, of which 207,360 were normal and 138,240 were abnormal.

For the tampering risk detection experiment of the distribution network topology, we divided the 345,600 samples into three parts: training set (70%), validation set(15%), and testing set (15%). The experimental environment was NVIDIA RTX 4060 GPU, and the model was trained and tested using Python 3.11 and the PyTorch framework.

3.2.1 Convergence validation

Fig. 14 shows the change of the loss function during the training of the MTP-SRD model. In the initial phase, both training and validation losses are significantly reduced,indicating that the model is learning samples efficiently.As training increases, the rate at which the loss decreases slow down and stabilize, indicating that the model has converged. Importantly, the validation loss is still close to the training loss at this point,with no substantial differences, indicating that the model has a good generalization ability for invisible data and does not overfit the training samples.

To further validate the model’s convergence, we also conducted a statistical analysis using a paired samples ttest[115]. We compared the validation loss values between the early (iterations 1-10) and late stages(iterations 81-90)of training (see Tables 3 and 4). The results showed a tstatistic of 4.876934 with 9 degrees of freedom and a pvalue of 0.000875 (p < 0.05), indicating a significant difference between the validation losses in these two stages.This statistical evidence confirms that the model’s validation loss decreases significantly over time, reinforcing the conclusion that the model converges effectively.

In summary, the MTP-SRD model demonstrates strong learning and generalization capabilities. The significant reduction in validation loss in the early stages, followed by stabilization in the later stages, confirms its robust convergence. The t-test results further support the model’s stability and absence of overfitting. These findings indicate that the MTP-SRD model is well-suited for security risk detection of distribution network data assets.

71a83985931b741c0021b3dcd4400f40.jpg

Fig. 13. A new distribution network topology.

a533b6efe2d83a8a90f78672fc07e207.jpg

Fig. 14. Model training and validation loss.

3.2.2 Ablation experiments

To analyze the effects of attention and cross-fusion on model, ablation experiments were performed on the attention mechanism and cross-fusion of the central node and its neighbor aggregation features.The experimental results are shown in Fig. 15(a), (b), a nd Table 5.

As observed in Fig. 15(a), (b), the effect of the attention mechanism on the accuracy of data tampering risk detection is greater than that of cross-fusion. To reduce the influen ce of random factors and improve confidence during the experiment,at least 10 sets were performed in eachexperiment to obtain the average. According to the accuracy experiment of the MTP-SRD model, 1500 samples of data were randomly selected from the 3975 samples of data in the test set for each experiment, and the accuracy rate was approximately 94.35%. As shown in Table 5,the accuracy of risk detection using the attention mechanism was approximately 11.54% higher than that of nonuse, and the accuracy of risk detection using cross-fusion was approximately 5.65% higher than that of non-use.

Table 3 The loss for iterations 1-10.

78c9fb93d9af4b2d7ba5210981ecf821.jpg

Table 4 The loss for iterations 81-90.

81813c18963d4a01c73769df8f04fa33.jpg

It is worth noting that we also performed an analysis of variance (ANOVA test [116]) according to Table 5.Through the ANOVA test, we found that there were significant differences in performance indicators between different variants of the MTP-SRD model (F-statistic was 22.464123, corresponding to a p-value of 0.000317, and a significance level of p < 0.05). This indicates that the attention mechani sm and cross-fusion have a significant impact on the performance of the model, and the MTP-SRD model performs significantly better than other variants when using the attention mechanism and cross-fusion.

3.2.3 Contrast experiments

To evaluate the efficiency of our model in identifying security risks, minimizing false positives and false negatives, and balancing detection sensitivity and accuracy,we conducted comparative experiments using various classifiers, including Support Vector Machines (SVM),Adaboost, K-Nearest Neighbors (KNN), Decision Trees(DT), Transformer-based Classifier (Trans-C), and Graph Neural Network (GNN). These classifiers were applied to classify inter-topology aggregation features, and the results are detailed in Table 6.

e61dcfd07e67cd265bd29a5ba497a602.jpg

Fig. 15. Ablation experiments: (a) attention mechanisms, (b) cross-fusion of nodes and their aggregation feature.

Table 5 The results of ablation experiments.

e3d3c22ef5f1789193b560045e4d3eb1.jpg

As shown i n Table 6, the proposed MTP-SRD model demonstrated superior performance, outperforming other traditional and advanced methods in terms of accuracy,precision, recall, and F1-score. Specifically, compared with SVM, Adaboost, KNN, and DT, the MTP-SRD model has significant improvements in various indicators, which indicates that it is more adaptable and robust in dealing with complex data patterns. At the same time, despite the significant progress in performance of methods based on Tran s-C and GNN in recent years, the MTP-SRD model still surpasses them with an accuracy of 96.65%and an F1-score of 92.73%. This advantage is mainly due to the unique design of the MTP-SRD model combined with multi-topology, attention mechanism, and cross-fusion of nodes, which enables it to more effectively capture complex relationships and patterns in data. Therefore, the MTP-SRD model not only performs well in performance, but also provides a more reliable solution for security risk detection in complex systems such as smart grids, showing broad application prospects.

3.3 Discussion

Demonstration practices have illustrated the efficacy of the MPKG model in managing secure authorization access to data assets in complex network settings.This success canbe attributed to the model’s ability to integrate multidimensional information effectively, enabling dynamic authorization mechanisms, offering granular management capabilities, and supporting the customization of flexible policies. Furthermore, the model considers context-aware factors, dynamically assigns user roles, and le verages advanced analytical techniques that contribute to its overall performance.

Table 6 The results of comparative experiments.

3ef3a6bbf34941fa672fd124291838a9.jpg

Additionally, the experimental outcomes indicate that the MTP-SRD model outperforms the current mainstream models in detecting anomalies within data assets. This superior performance is attributed to the comprehensive consideration of multiple topologies of the model, which enhances its ability to identify and assess the security of data assets. It is wort h noting that the MTP-SRD model is adept at addressing the security risk detection of complex, multisource, and heterogeneous data assets, demonstrating a degree of adaptability in the security of evolving data.

Nevertheless, our study has certain limitations.Although the MPKG model shows certain adaptability in the demonstration, it needs to be further validated in practical application. Furthermore, despite the promising performance of the MTP-SRD model in simulated environments, its effectiveness in real-world scenarios characterized by complexity and uncertainty requires further validation. Future research could focus on exploring the application of these models across diverse scenarios and refining the underlying algorithms to enhance their adaptability and efficiency in real-world contexts.

4 Conc lusion

This study introduces an innovative framework designed to bolster the protection of data assets within distribution network. The framew ork incorporates a data asset access control model and a security risk detection model underpinned by the MDKG and MTP methodologies, respectively. The experimental findings demonstrate that the MPKG model addresses the deficiencies of the existing access control systems. It facilitates the advancement of detailed and adaptable access control mechanisms through the integration of multi-dimensional information,encompassing data asset valuation, attributes, roles, policies, and permissions. Furthermore, the MTP-SRD model enhances risk detection capabilities by accounting for diverse network topologies, thus bolstering the model’s adaptability to the evolving security landscape of data assets. Collectively, this study proposes a comprehensive framework, combining MDKG and MTP, to provide an innovative solution for the protection of distribution network data assets,and lays a solid foundation for the development of smart grid technology.

CRediT authorship contribution statement

Junfeng Yang: Conceptualization, Methodology, Validation, Writing - original draft, Resources, Formal analysis. Li Liu: Investigation, Resources. Nawaraj Kumar Mahato: Validation, Methodology, Writing - review &editing, Resources. Luhan Li: Data curation, Resources.Jiaxuan Yang: Writing - review & editing, Investigation.Gangjun Gong: Funding acquisition, Project administration,Supervision.Jun Lu:Validation,Data curation.Chao Yang: Methodology, Supervision.Declaration of competing interest

The authors declare the following financial interests/personal relationships which may be considered as potential competing interests: Chao Yang is currently employed by State Grid Liaoning Electric Power Co., Ltd.

Acknowledgments

This work is supported by the National Key R&D Program of China (2022YFB3105100).

Appendix

A. Confidentiality Assignment Criteria: Data asset confidentiality can be classified into four distinct levels. These levels correspond to the relative value of the asset in terms of confidentiality and the severity of consequences if confidentiality is compromised. The assignment criteria for these levels are detailed in Table 7.

Table 7 Confidentiality assignment criteria.

ba43b7e034421bcc25d8b73c51efa87f.jpg

B. Integrity Assignment Criteria: The data asset integrity attributes can be categorized into four distinct levels,reflecting their relative importance and the severity of consequences associated with data integrity compromise.Table 8 details the assignment criteria for these levels.

Table 8 Integrity assignment criteria.

7a989d75b305126ff156e5caf288c6f2.jpg

C. Availability Assignment Criteria: The data asset availability attributes are categorized into four distinct levels. This classification reflects the relative importance of an asset’s availability and the severity of consequences resulting from its unavailability. The criteria for assigning these levels are detailed in Table 9.

Table 9 Availability assignment criteria.

0bfc68e63ec13871f7ebecb6f3a23db6.jpg

References

[1]M. Wen, S. Chen, R. Lu, et al., Security and efficiency enhanced revocable access control for fog-based smart grid system, IEEE Access 7 (2019) 137968-137981.

[2]F. Shen, L. Gong, Y. Feng, et al.,Physical layer identification for wireless local access in the smart grid, in: ‘2023 IEEE 7th Information Technology and Mechatron ics Engineering Conference (ITOEC)’ 2023 IEEE 7th Information Technology and Mechatronics Engineering Conference (ITOEC), 2023, pp.2007-2011.

[3]F.F. Dang, S. Li, L.J. Yan, et al.,Security authentication scheme for power internet of things, in: ‘2022 14th International Conference on Communication Software and Networks(ICCSN)’ 2022 14th International Conference on Communication Software and Networks (ICCSN), 2022, pp.94-97.

[4]F. Zhang, Y. Dubasi, W. Bao, et al.,Detection and localization of data forgery attacks in automatic generation control, IEEE Access 11 (2023) 95999-96013.

[5]M.N. Aman, K. Javed, B. Sikdar, et al.,Detecting data tampering attacks in synchrophasor networks using time hopping, in: ‘2016 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe)’ 2016 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe), 2016, pp. 1-6.

[6]S. Bhatt, T.K. Pham, M. Gupta, et al., Attribute-based access control for AWS internet of things and secure industries of the future, IEEE Access 9 (2021) 107200-107223.

[7]G. Fragkos, J. Johnson, E.E. Tsiropoulou, Dynamic role-based access control policy for smart grid applications an offline deep reinforcement learning approach, IEEE Trans.Hum.-Mach.Syst.52 (4) (2022) 761-773.

[8]P. Zhang, L. Zhou, Trust-based dynamic multi-level access control model, Comput. Modernizat. 7 (2019) 116-121+126.

[9] Q. Su, X. Chen, Y. Luo, Access control model for multi-source heterogeneous data in big data environment , Chinese J. Network Informat. Security 5 (1) (2019) 78-86.

[10]X. Zhang, Z. Xu, J. Lu, et al., A dynamic role-based access control model based on change of attributes, Informat. Technol.11 (2016) 69-74.

[11]T. Cai, Q. Nie, K. Ouyang, et al., Role-extended-based RBAC model, Appl. Res. Comput. 33 (3) (2016) 882-885.

[12]S. Xu, Y. Tian, Y. Deng, et al., Research on zero trust access control model based on role and attribute, J. Informat. Security Res. 10 (3) (2024) 241-247.

[13]S. Muthubalaji, N.K. Muniyaraj, S.P.V.S. Rao, et al., An intelligent big data security framework based on AEFS-KENN algorithms for the detection of cyber-attacks from smart grid systems, Big Data Min. Anal. 7 (2) (2024) 399-418.

[14]D. Liu, R. Wang, H. Zhang, et al., Research on data security protection method based on big data technology, in: ‘2020 12th International Conference on Communicat ion Software and Networks (ICCSN)’ 2020 12th Internationa l Conference on Communication Software and Networks (ICCSN), 2020, pp.79-83.

[15]C.H.O. Huama´n, N.F. Fuster, A.C. Luyo, et al., Critical data security model gap security identification and risk analysis in financial sector, in: ‘2022 17th Iberian Conference on Information Systems and Technologies (CISTI)’ 2022 17th Iberian Conference on Information Systems and Technologies(CISTI), 2022, pp.1-6.

[16]X. Zhang, X. Qiu, J. Liu, et al., A novel network asset security protection system, in: ‘2022 Internationa l Conference on Artificial Intelligence in Everything (AIE). 2022 International Conference on Artificial Intelligence in Everything (AIE), 2022, pp. 442-445.

[17]A. Dutta, R. Bose, S.K. Chakraborty, et al., Data security mechanism for green cloud, in: ‘2021 Innovations in Energy Management and Renewable Resources (52042)’ 2021 Innovations in Energy Management and Renewable Resources(52042), 2021, pp. 1-4.

[18]D. Liu, D. Kong, X. Liu, et al.,Research on data security analysis and label recognition technology based on big data business scenario, in: ‘2020 IEEE 10th International Conference on Electronics Information and Emergency Communication(ICEIEC)’ 2020 IEEE 10th Internationa l Conference on Electronics Information and Emergency Communication(ICEIEC), 2020, pp. 344-347.

[19]X. Zhang, X. Chen, Data security sharing and storage based on a consortium blockchain in a vehicular ad-hoc network, IEEE Access 7 (2019) 58241-58254.

[20]P. Liang, L. Yang, Z. Xiong, et al.,Multi-level intrusion detection based on transformer and wavelet transform for IoT data security,IEEE Internet Things J. 11 (15) (2024) 25613-25624.

[21]N. Santos, B. Ghita, G.L. Masala, Medical systems data security and biometric authentication in public cloud servers,IEEE Trans.Emerg. Top. Comput. 12 (2) (2024) 572-582.

[22]R.E. Peterson, A Cross Section study of the demand for Money the United States, 1960-62, J. Financ. 29 (1) (1974) 73-88.

[23]The data asset how smart companies govern their data for business success|Guide books|ACM Digital Library.https://dl.acm.org/doi/book/10.5555/1717983, accessed May 2024.

[24]Y. Zhu, Y. Ye, Defining data assets based on the attributes of data, Big Data Res. 4 (6) (2018) 65-76.

[25]Y. Ye, G. Liu, Y. Zhu, Survey of concepts related to data assets,Comput. Sci. 46 (11) (2019) 20-24.

[26]S. Wang, Y. Liu, On the recognition and measurement of data assets, Finan. Account. Monthly 44 (8) (2023) 85-92.

[27]China Academy of Information and Communications Technology-Research Capability-Authoritative Release- White Paper. http://www.caict.ac.cn/kxyj/qwfb/bps/201906/t20190604_200629.htm, accessed May 2024.

[28]Z. Ji, C. Deng, J. Wu, et al., Design and application of data asset management system for smart grid, Comput. Appl. Soft. 36 (4)(2019) 118-123.

[29]R. Xia, Y. An, Construction of data asset management model for power supply enterprises from the perspective of data center,Informat. Sci. 39 (10) (2021) 70-75.

[30]J. Chen, H. Chen, W. Chi, Research on the value accounting mechanism of data assets a case study of state grid Fujian electric power data assets, Finan. Account. 20 (2022) 49-53.

[31]Z. Hu, X. Wan, W. Shu, Coordination of global data asset management in digital power grid corporation, in: ‘2024 International Conference on Electrical Drives, Power Electronics& Engineering (EDPEE)’ 2024 International Conference on Electrical Drives, Power Electronics & Engineering (EDPEE),2024, pp. 104-108.

[32]C. Feng, C. Cui, F. Di, et al., The theory and method of power grid data asset modeling based on dispatching cloud, in: ‘2022 IEEE 5th Advanced Information Managemen t, Communicates,Electronic and Automation Control Conferen ce (IMCEC)’ 2022 IEEE 5th Advanced Information Managemen t, Communicates,Electronic and Automation Control Conference (IMCEC), 2022,pp. 705-708.

[33]Z. Liu, The fourth meeting of the 4th staff congress of the state grid corporation of China and the 2024 work conference, State Grid News 2024 (2024) 001.

[34]N. Liu, X. Yu, J. Wang, et al., Optimal operation of power distribution and consumption system based on ubiquitous internet of things: a cyber-physical-social system perspective, Automat.Electr. Power Syst. 44 (1) (2020) 1-12.

[35]H. Sun, J. Zhang, P. Wang, et al., Edge computation technology based on distribution internet of things, Power Syst. Technol. 43(12) (2019) 4314-4321.

[36]S. Guo, Y. Liu, S. Shao, et al., Ubiquitous security boundary protection technology for cross-domain data circulation in new power system, Automat. Electr. Power Syst.48(6)(2024)96-111.

[37]K. Yan, Y. Lu, Z. Yu, et al., Review and prospect of research on security of user-side heterogeneous power IoT devices in distribution network, Electr. Power Automat. Equipment 43 (3)(2023) 146-158.

[38]Q. Ke, Z. Chen, J. Hu, et al., Fast multi-source data retrieval method for distribution network based on improved decision tree,Comput. Syst. Appl. 30 (2) (2021) 97-102.

[39]Q. Li, X. Bai, L. Zhang, et al.,Data asset management and databased operation of power suppliers, East China Electr. Power 42(3) (2014) 487-490.

[40]X. Liu, C. Yang, R. Xu, et al., Location privacy protection of smart grid MEC based on reinforcemen t learning, Electr. Power Informat. Commun. Technol. 21 (1) (2023) 47-53.

[41]J. Lin, W. Cui, Power- name="ref42" style="font-size: 1em; text-align: justify; text-indent: 2em; line-height: 1.8em; margin: 0.5em 0em;">[42]J. Tong, B. Zhang, Y. Huang, et al., Researc h on the functional requirementsofkeybusinessmodules ofdigital distributionnetwork based on the whole life cycle of assets, in: ‘202 2 IEEE International Conference on Power Systems and Electrical Tech nology (PSET)’2022 IEEE International Conference on Power Systems and Electrical Technology (PSET), 2022, pp. 195-199.

[43]X. Liu, Q. Zhang, Z. Li, et al., Data aggregation and access control method for communication systems of smart grid,Automat. Electr. Power Syst. 40 (14) (2016) 135-144.

[44]K. Sasikumar, S. Nagarajan, Comprehensive review and analysis of cryptography techniques in cloud computing, IEEE Access 12(2024) 52325-52351.

[45]F. Yang, Q. Zhang, J. Liu, et al., Research on the con struction of SEPC data assets security management system, Electr. Power Informat. Commun. Technol. 16 (1) (2018) 90-95.

[46] C. Li, Privacy in internet of things: from principles to technologies, IEEE Internet Things J. 6 (2019) 1.

[47]L. Fang, L. Yin, Y. Guo, et al., A survey of key technologies of attribute-based access control scheme, Chin. J. Comput. 40 (7)(2017) 1680-1698.

[48]L. Zhang, Y. Fang, M. Li, et al., Network multi-channel data transmission security monitoring system based on multi encryption and decryption, Automat. Instrumen t. 1 (2022) 133-136+143.

[49]X. Li, S. Li, M. Liang, et al., Multi-channel-based secure data collection and transmission mechanism for hydropower station,Comput. Appl. Software 40 (5) (2023) 124-128+183.

[50]C. Liu, Y. Wang, Z. Zhou, et al., Sensitive information recognition method combining trigger event and part of speech analysis, Comput. Eng. Appl. 56 (20) (2020) 132-137.

[51]S. Sheng, P. Huang, Y. Liu, et al., Research on the automatic construction technology of asset map based on power data center,Electric Age 12 (2022) 90-93.

[52]H. Harb, A. Makhoul, Energy-efficient sensor data collection approach for industrial process monitoring, IEEE Trans.Ind.Inf.14 (2) (2018) 661-672.

[53]M.A. Mughal, X. Luo, A. Ullah, S. Ullah, Z. Mahmood, A lightweight digital signature-based security scheme for humancentered internet of things, IEEE Access 6 (2018) 31630-31643.

[54]Z. Zhu, J. Ling, P. Lin, Data integrity checking technology of industrial control system based on covert channel, Comput. Eng.Appl. 56 (9) (2020) 125-130.

[55]D. Wang, W. Zhao, Z. Ding, Review of big data security critical technologies, J. Beijing Univ. Technol 43(3)(2017)335-349+322.

[56]Q. Liu, R. Liu, J. Wang, et al., Research on group key management algorithm of ubiquitous power internet of things based on edge computing, Electr. Measur. Instrument. 59 (7)(2022) 48-56.

[57]Data restore vs. backups-what is the difference|rewind.https://rewind.com/blog/ name="ref58" style="font-size: 1em; text-align: justify; text-indent: 2em; line-height: 1.8em; margin: 0.5em 0em;">[58]Atlassian. Disaster recovery plans for IT Ops and DevOps Pros.https://www.atlassian.com/incident-management/itsm/disasterrecovery, accessed June 2024.

[59]Failover mechanisms in system design-geeks for geeks. https://www.geeksforgeeks.org/failover-mechanisms-in-system-design/,accessed June 2024.

[60]T. Zhang, D. Zhao, F. Xue, et al., Research framework of cybersecurity protection technologies for smart terminals in power systems, Automat. Electr. Power Syst. 43 (19) (2019) 1-8+67.

[61]B. Vaidya, D. Makrakis, H.T. Mouftah, Authentication and authorization mechanisms for substation automation in smart grid network, IEEE Netw. 27 (1) (2013) 5-11.

[62]S. Cui, P. Zeng, C. Song, et al.,Low-voltage distribution network topology identification based on constrained least square and graph theory, Soft. Comput. 26 (17) (2022) 8509-8519.

[63]L. Liu, R. Li, Y. Zhou, et al., ETI-ECF: Edge computing framework for distribution network electrical topology identification, in: ‘Proceedings of the 4th International Conference on Computer Science and Application Engineering’CSAE 2020: The 4th Internatio nal Conference on Computer Science and Application Engineering, 2020, pp. 1-6.

[64]J. Jabez, R. Narmadha, S. Porkodi, et al., Mitigation for cloud computing security risks and governance, Int. J. Cloud Comput.11 (5-6) (2022) 560-567.

[65]W. Song, Y. Zhang, J. Wang, et al., Research on characteristics and value analysis of power grid data asset,Procedia Comput.Sci.139 (2018) 158-164.

[66]A. Gregory, Data governance-protecting and unleashing the value of your customer data assets, J. Direct Data Digit. Mark. Pract.12 (3) (2011) 230-248.

[67]H. Hannila, R. Silvola, J. Harkonen, et al., name="ref68" style="font-size: 1em; text-align: justify; text-indent: 2em; line-height: 1.8em; margin: 0.5em 0em;">[68]C. Chen, H. Ma, Y. Zhao, Data security control platform based on hierarchical classification: design and implementation, J.Comput. Appl. 36 (S1) (2016) 265-268.

[69]A.Z. Abduxalimovna, I.I. Nabiyevich, Organizatio n of long-term asset accounting on the basis of international standards, Central Asian J. Innovat. Tourism Manag. Finan. 2 (11) (2021) 86-92.

[70]X. Luo, H. Xu, R. Tong, Research on quantitative value of data assets in power enterprises based on panoramic view, Sichuan Electr. Power Technol. 39 (5) (2016) 90-94.

[71]R.I. Whitfield, A.H.B. Duffy, Extended revenue forecasting within a service industry, Int. J. Prod. Econ. 141 (2) (2013) 505-518.

[72]F. Li, Y. Guan, S. Wang, et al., Data asset management model and value evaluation method of power supply enterprises from the perspective of information ecology, Informat. Sci. 37 (10) (2019)46-52.

[73]J. Cui, Y. Guan, H. Zhang, et al., Research on the management mechanism of enterprise data asset from the perspective of information ecology. Journal of Modern, Information 37 (12)(2017) 24-29+34.

[74]L. Bao, Y. Zha, J. He, et al., Exploration and practice of data assets management and control mode of provincial grid company,Electr. Power Informat. Commun. Technol. 16 (1) (2018) 44-50.

[75]L. Ruan, Y. Shen, Z. Wang, et al., Application of role-based access control in cyber security of substation, Zhejiang Electr.Power 41 (7) (2022) 86-93.

[76]H. Long, L. Sang, Z. Wu, et al., Image-based abnormal data detection and cleaning algorithm via wind power curve, IEEE Trans. Sustain. Energy 11 (2) (2020) 938-946.

[77]A. Goldsteen, G. Ezov, R. Shmelkin, et al.,Data minimization for GDPR compliance in machine learning models, AI Ethics 2 (3)(2022) 477-491.

[78]Q. Gao, N. Jia, H. Meng, et al., Research and application of data security control system of electric power ERP system, in: ‘2023 Power Electronics and Power System Conference (PEPSC)’ 2023 Power Electronics and Power System Conference(PEPSC), 2023,pp. 233-237.

[79]S. Terzi, C. Savvaidis, K. Votis, et al., Securing emission data of smart vehicles with blockchain and self-sovereign identities, in:‘2020 IEEE International Conference on Blockchain(Blockchain)’ 2020 IEEE International Conference on Blockchain (Blockchain), 2020, pp. 462-469.

[80]P. Ramanan, D. Li, N. Gebraeel, Blockchain-based decentralized replay attack detection for large-scale power systems, IEEE Trans. Syst., Man, Cybernet.: Syst. 52 (8) (2022) 4727-4739.

[81]D. Zheng, C. Jing, R. Guo, et al., A traceable blockchain-based access authentication system with privacy preservation in VANETs, IEEE Access 7 (2019) 117716-117726.

[82]L. Shen, B. Hao, Y. Li, et al., Blockchain-based power grid data asset management architecture, in: ‘2020 International Conference on Computer Science and Managemen t Technology (ICCSMT)’2020 International Conference on Compute r Science and Management Technology (ICCSMT), 2020, pp. 207-211.

[83]K. Wang, L. Yu, Y. Yan, et al.,Capitalization and trading system design of power data based on blockchain,J. Northeastern Univ.(Nat. Sci.) 42 (2) (2021) 166-173.

[84]Y. Pang, D. Wang, X. Wang, et al., Blockchain-based reliable traceability system for telecom big data transactions, IEEE Internet Things J. 9 (14) (2022) 12799-12812.

[85]Q. Li, S. Meng, S. Zhang, et al., Safety risk monitori ng of cyberphysical power systems based on ensemble learning alg orithm,IEEE Access 7 (2019) 24788-24805.

[86]W. Liao, B. Bak-Jensen, J. Radhakrishna Pilla, et al.,A review of graph neural networks and their applications in power systems,J.Mod. Power Syst. Clean Energy 10 (2) (2022) 345-360.

[87]V. Khatri, C.V. Brown, Designing data governance, Commun.ACM 53 (1) (2010) 148-152.

[88]N. Gruschka, V. Mavroeidis, K. Vishi, et al., Privacy issues and data protection in big data: a case study analysis under GDPR,in:‘2018 IEEE International Conference on Big Data (Big Data)’2018 IEEE International Conference on Big Data (Big Data),2018, pp. 5027-5033.

[89]L. Zhao, L. Zhong, J. Liu, et al., A regulatable mechanism for transacting data assets, IEEE Int. Things J.10(24)(2023)21615-21632.

[90]D.R. Kuhn, E.J. Coyne, T.R. Weil, Adding attributes to rolebased access control, Computer 43 (6) (2010) 79-81.

[91]B. Yu, X. Tai, Z. Ma, Study on attribute an d trust-based RBAC model in cloud computing, Comput. Eng. Appl.56(9) (2020)84-92.

[92]J. Wang, Z. Wang, J. Song, et al., Attribute and user trust scorebased zero trust access control model in IoV, Electronics 12 (23)(2023) 4825.

[93]J. Jing, L. Jiang, T. Liu, et al., Multi-dimensional graphs extraction method in software reverse analysis process, Comput.Appl. Software 33 (4) (2016) 1-5.

[94]R.S. Sandhu, E.J. Coyne, H.L. Feinstein, et al. Role-based access control: a multi-dimensional view, in: ‘Tenth Annual Computer Security Applicatio ns Conference’ Tenth Annual Computer Security Applications Conference, IEEE Comput. Soc. Press,1994. pp. 54-62.

[95]D. Rosic, U. Novak, S. Vukmirovic, Role-based access control model supporting regional division in smart grid system,in:‘2013 Fifth International Conference on Computational Intelligence,Communication Systems and Networks’ 2013 Fifth International Conference on Computational Intelligence, Communication Systems and Networks, 2013, pp. 197-201.

[96]S. Kang, C. Ma, Y. Huang, et al.,Research on secure interaction of distribution network data assets under privacy protection framework, in: ‘2023 3rd Internationa l Conference on Intelligent Power and Systems (ICIPS)’ 2023 3rd International Conference on Intelligent Power and Systems (ICIPS), 2023, pp. 546-551.

[97]G. Gong, Z. Chang, Z. Chen, et al. Discussion on classification and grading of distribution network data assets from the perspective of network security, Journal of North China Electric Power University (Natural Science Edition), no date, pp. 1-14.

[98]Y. Xia, Research on knowledge base completion and authority management based on graph neural network, Shijiazhuang Tiedao University, 2022, Master Thesis.

[99]J. Yang, Research on the methodology of cyber security defense for smart substation and distribution systems driven by data and model, Zhejiang University, 2023, Doctoral Thesis.

[100]T. Yu, X. Wang, J. Jin, et al., Cloud-orchestrated physical topology discovery of large-scale IoT systems using UAVs, IEEE Trans. Ind. Inf. 14 (5) (2018) 2261-2270.

[101]Y. Bejerano, Y. Breitbart, M. Garofalakis, et al. Physical topology discovery for large multi-subnet networks, in: ‘IEEE INFOCOM 2003. Twenty-second Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE Cat.No.03CH37428)’ IEEE INFOCOM 2003. Twenty-second Annual Joint Conference of the IEEE Computer and Communications Societies, (IEEE, 2003), pp. 342-352.

[102]K. Tasdemir, E. Merenyi, Exploiting data topology in visualization and clustering of self-organizing maps, IEEE Trans. Neural Netw. 20 (4) (2009) 549-562.

[103]L. Guo, J. Shanmugasundaram, G. Yona, Topology search over biological databases. in ‘2007 IEEE 23RD INTERNATIONAL CONFERENCE ON DATA ENGINEER ING, IEEE 23rd International Conference on Data Engineering, 2007, 531-+.

[104]X. Kong, A. Zhang, S. Zhang, et al.,On the controlled consensus protocols with directed graphs, in: ‘PROCEEDINGS OF THE 2012 24TH CHINESE CONTROL AND DECISION CONFERENCE (CCDC)’ 24th Chinese Control and Decision Conference (CCDC), 2012, pp. 14-18.

[105]P. Harremoe¨s, Information topologies with applications, in: I.Csisza´r, G.O.H. Katona, G. Tardos, G. Wiener (Eds.), Entropy,Search, Complexity, Springer, 2007, pp. 113-150.

[106]S. Chen, M. Shao, H. Li, et al., A true test research of topology identification technology for low voltage distribution networks,Zhejiang Electric Power 41 (12) (2022) 30-35.

[107]M. Ismail, M.Y. Sanavullah, Security topology in wireless sensor networks with routing optimisation, in: ‘2008 Fourth International Conference on Wireless Communication and Sensor Networks’ 2008 Fourth Internationa l Conference on Wireless Communication and Sensor Networks (WCSN), 2008,pp. 7-15.

[108]C. Zhang, D. Song, C. Huang, et al., Heterogeneous graph neural network. in ‘Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining’ (Association for Computing Machinery, 2019), pp. 793-803.

[109]X. Wang, H. Ji, C. Shi, et al., Heterogeneous graph attention network, in: ‘The World Wide Web Conference’ WWW ’19: The Web Conference, ACM, 2019, pp. 2022-2032.

[110]Corso, G., Cavalleri, L., Beaini, D., et al. Principal neighbourhood aggregation for graph nets. in ‘Advances in Neural Information Processing Systems’ (Curran Associates,Inc., 2020), pp. 13260-13271.

[111]F. Duan, Research on fraud detection based on heterogeneous graph neural network Master Thesis, East China Jiaotong University, 2023.

[112]K. Cho, B. van Merrienboer, C. Gulcehre, et al., Learning phrase representations using RNN encoder-decoder for statistical machine translation. arxiv preprint arxiv:1406.1078, 2014.

[113]Y. Weng, X. Chen, L. Chen, et al., GAIN: Graph attention &interaction network for inductive semi-supe rvised learning over large-scale graphs, IEEE Trans. Knowl. Data Eng. 34 (9) (2022)4257-4269.

[114]K. Teler, M. Skowron, T. Orłowska-Kowalska, Implementatio n of MLP-based classifier of current sensor faults in vectorcontrolled induction motor drive, IEEE Trans. Ind. Inf. 20 (4)(2024) 5702-5713.

[115]M.F. Saiyed, I. AL-Anbagi, A genetic algorithm- and t-Testbased system for DDoS attack detection in IoT networks, IEEE Access 12 (2024) 25623-25641.

[116]M.N.S.K. Shabbir, X. Liang, S. Chakrabarti,An ANOVA-based fault diagnosis approach for variable frequency drive-fed induction motors, IEEE Trans. Energy Convers. 36 (1) (2021)500-512.

Received 24 October 2024; re删vis除ed 9 March 2025; accepted 30 November 2025

Peer review under the responsibility of Global Energy Interconnection Group Co. Ltd.

* Corres删ponding au除thor.

E-mail addresses:yangjunfeng@hezeu.edu.cn (J. Yang), liu_li@ncepu.edu.cn (L. Liu), nawaraj@ncepu.edu.cn (N.K. Mahato),120232201334@ncepu.edu.cn (L. Li), yangjx@ncepu.edu.cn (J. Yang),gong@ncepu.edu.cn (G. Gong), lujun@ncepu.edu.cn (J. Lu), yangchaoneu@sina.com (C. Yang).

https://doi.org/10.1016/j.gloei.2025.11.003

2096-5117/© 2026 Global Energy Interconnection Group Co. Ltd. Publishing services by Elsevier B.V. on behalf of KeAi Communications Co. Ltd.This is an open access article under the CC BY-NC-ND license(http://creativecommons.org/licenses/by-nc-nd/4.0/).

7a5791347ed1e5f9ca2f293396d5a40d.jpg

Junfeng Yang received the B.E. degree from Liaocheng University, Shandong Province,China, in 2002, and received the M.E. degree from Guizhou University, Guizhou Province,China, in 2009. He is currently pursuing Ph.D.in Electrical Engineering at North China Electric Power University, Beijing, China. He is also Associate Professor and Senior Engineer at Heze University, Shandong Province, China.His research interests include smart distribution networks, artificial intelligence and trusted computing.

  • 目录

    图1