Power grid management safety operation arrangement method and system and medium

By standardizing the specifications and formal language representation of power grid security operations, combining knowledge graph technology, and automatically generating emergency response strategies, we can solve the problems of irregular power grid security operation processes and inefficient emergency response, and achieve intelligent power grid security operations and efficient emergency response.

CN120706758APending Publication Date: 2025-09-26STATE GRID HUBEI ELECTRIC POWER CO LTD WUHAN POWER SUPPLY CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510755658.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

The power grid's security operation processes are not standardized, overly dependent on manual processing, and the emergency response efficiency is inefficient, making it difficult to quickly respond to complex security threats.

Method used

By collecting feedback from frontline power grid personnel, identifying key implementation elements, and standardizing specifications, we automatically generate emergency response strategies by combining formal languages ​​and knowledge graphs, and dynamically update them using threat intelligence libraries and expert experience libraries to build a comprehensive security orchestration architecture.

Benefits of technology

It has achieved standardization, automation and intelligence of power grid security operations, improved emergency response speed and efficiency, lowered the operational threshold, and is suitable for current and future expanded power grid security operation scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120706758A_ABST
    Figure CN120706758A_ABST
Patent Text Reader

Abstract

The invention relates to a power grid management safety operation arrangement method and system and a medium. The method comprises the steps that feedback of power grid first-line safety operation personnel is collected, safety operation key implementation elements are identified, and the safety operation elements are standardized; drawing an existing safety operation flow chart based on the identified elements, and designing a comprehensive safety operation model; on the basis of a formal language development library function, actual safety operation data are automatically converted into formal language description, and symbolized representation and programmable calling are achieved; based on big data support of a threat intelligence library, a vulnerability library and an expert experience library, constructing a knowledge graph containing security entities, event relationships and response strategies; and constructing a comprehensive security arrangement framework, and automatically generating an approximately optimal emergency response strategy by taking a security risk event as input. According to the invention, automatic safe operation arrangement under power grid management is realized, an operator does not need too strong safety knowledge, and the problem of low response efficiency in a traditional operation system is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of secure operation orchestration, and in particular to a method, system, and medium for secure operation orchestration of power grid management. Background Art

[0002] With the rapid development of the global energy internet, the safe and stable operation of power grids, as critical infrastructure, is of great significance to national economic security and the well-being of the people. Currently, power grid security operations face increasingly complex challenges. Traditional power grid operations management relies on manual decision-making and experience, which often results in slow response times and difficulty in providing optimal solutions to sudden security incidents.

[0003] In recent years, the power industry, both domestically and internationally, has been actively exploring how to leverage advanced information technology to improve the security and efficiency of grid operations. For example, this includes increasing investment in smart grids and digital grids, and enhancing grid security monitoring and emergency response capabilities through the introduction of modern information technologies such as big data, cloud computing, and the Internet of Things. While some developed countries have made significant progress in smart grid automation, they still face challenges with technological integration and insufficient standardization. In China, with the advancement of smart grid construction, grid companies are increasingly demanding safe operations, but existing security operations systems still suffer from slow response times and high decision-making dependency. These issues stem from a lack of standardized specifications for the diverse equipment, tools, and operations involved in grid security operations. Traditional security operations rely heavily on manual experience, making them incapable of responding to rapidly evolving security threats. Furthermore, existing emergency response mechanisms often fail to quickly and accurately assess risk events, resulting in inefficient responses. Therefore, a method that can automatically identify security risks and rapidly generate response strategies is urgently needed to improve grid security management and operational efficiency. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to overcome the shortcomings of the existing technology and provide a power grid management security operation arrangement method, system and medium to solve problems such as non-standard power grid security operation processes, excessive reliance on manual processing for security operation methods, and low emergency response efficiency.

[0005] To achieve the above objectives, this application provides the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides a method for orchestrating power grid management security operations, comprising the following steps:

[0007] Step S1: Collect feedback from frontline grid security operators, identify key implementation elements of security operations, and standardize security operation elements;

[0008] Step S2: Draw the existing security operation process map based on the identified elements and design a comprehensive security operation model;

[0009] Step S3: Develop library functions based on formal language to automatically convert actual security operation data into formal language descriptions, achieving symbolic representation and programmable call;

[0010] Step S4: Relying on the big data support of the threat intelligence library, vulnerability library, and expert experience library, a knowledge graph containing security entities, event relationships, and response strategies is constructed;

[0011] Step S5: Build a comprehensive security orchestration architecture, use security risk events as input, and automatically generate a near-optimal emergency response strategy.

[0012] In step S1, the key implementation elements of security operations identified by security experts include information sources, analysis tools, decision support requirements, event detection response and recovery; and standardized systems, personnel, equipment, tools, specific operations, and implementation process content.

[0013] In step S2, the drawn security operation flowchart includes the stages of event reception, analysis, decision-making, and execution of response measures. The security operation model covers the key implementation elements in step S1, the input and output of each stage, the responsible parties, and the technical support content. The model will be adjusted and optimized based on the small-scale pilot.

[0014] In step S3, the formal language defined for security operations includes but is not limited to event description language, policy expression language, and response instruction language. The elements represented should include security operation equipment and tools, security operation operations, and security operation processes. The developed library function Automatically convert normalized operational data into a structured formal language representation suitable for security operations. .

[0015] In step S4, the threat intelligence library, vulnerability library, and expert experience library are dynamically updated and synchronized with the latest intelligence.

[0016] In step S5, the comprehensive security orchestration architecture integrates the formal language representation system in step S3 and the knowledge graph in step S4. The security orchestration algorithm will combine the specific operation scenarios of the power grid, take security risk events as input, consider the urgency of the event, resource availability, and historical case factors, and calculate the approximately optimal response strategy according to certain weights. The calculation method is ,in is the relative weight coefficient of each consideration indicator in this security incident, Score the general importance of each consideration. is the calculated emergency response strategy.

[0017] In a second aspect, an embodiment of the present application provides a power grid management security operation orchestration system, including a memory and a processor, wherein the memory includes a program for a power grid management security operation orchestration method, and when the program for the power grid management security operation orchestration method is executed by the processor, the following steps are implemented: Step S1: Collect feedback from front-line power grid security operation personnel, identify key implementation elements of security operations, and standardize the security operation elements;

[0018] Step S2: Draw the existing security operation process map based on the identified elements and design a comprehensive security operation model;

[0019] Step S3: Develop library functions based on formal language to automatically convert actual security operation data into formal language descriptions, achieving symbolic representation and programmable call;

[0020] Step S4: Relying on the big data support of the threat intelligence library, vulnerability library, and expert experience library, a knowledge graph containing security entities, event relationships, and response strategies is constructed;

[0021] Step S5: Build a comprehensive security orchestration architecture, use security risk events as input, and automatically generate a near-optimal emergency response strategy.

[0022] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores program code, and when the program code is executed by a processor, the steps of the power grid management security operation orchestration method as described above are implemented.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] Standardization and regularization: By standardizing the equipment, tools, and operations involved in grid security operations, we ensure consistency and predictability throughout the entire operation process. Standardizing key implementation elements of safe operations also helps reduce errors and accidents caused by inconsistent operations.

[0025] Automation and Intelligence: By converting elements in the security operations model into a formal language description, symbolic representation of security operations data is achieved, enabling programmatic invocation of security operations orchestration methods. Furthermore, the security orchestration architecture integrates security operations representation modules with knowledge graphs, automatically responding to and outputting near-optimal emergency response strategies, improving the intelligence level of power grid security operations and the speed of emergency response.

[0026] Decision support and dynamic updates: Relying on big data support such as threat intelligence libraries, vulnerability libraries, and expert experience libraries, a knowledge graph is constructed that includes security entities, event relationships, and response strategies. It is dynamically updated to synchronize with the latest intelligence. When responding to security incidents, the security orchestration architecture can consider multiple factors such as the urgency of the incident, resource availability, and historical cases. By calculating, it can arrive at an approximately optimal response decision, ensuring the effectiveness and real-time nature of emergency response measures.

[0027] Ease of Use and Scalability: This invention allows grid operators to utilize this method without requiring extensive security expertise, lowering the barrier to entry and increasing its adoption. Furthermore, this method is not only applicable to current grid security operations but, through its modular design and programmable interface, facilitates future expansion and optimization based on new security requirements and operational scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0029] Figure 1 This is a system structure diagram of the power grid management security operation orchestration method based on formal language representation provided by an embodiment of the present invention.

[0030] Figure 2 This is a safety operation specification modeling diagram in the power grid management safety operation orchestration method based on formal language representation provided by an embodiment of the present invention.

[0031] Figure 3 This is an example diagram of the formal language representation in the power grid management security operation orchestration method based on formal language representation provided by an embodiment of the present invention.

[0032] Figure 4 A knowledge graph structure diagram of the power grid management security operation orchestration method based on formal language representation provided in an embodiment of the present invention.

[0033] Figure 5 This is a diagram of the security operation orchestration architecture in the formal language representation-based power grid management security operation orchestration method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0034] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0035] The terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0036] The terms "first," "second," etc. are only used to distinguish one entity or operation from another entity or operation, and are not to be understood as indicating or implying relative importance, nor are they to be understood as requiring or implying any actual relationship or order between these entities or operations.

[0037] like Figure 1 As shown: The present invention provides a method for orchestrating safe operations of power grid management based on formal language representation. First, it is necessary to standardize and model the safe operation process. The technical solution is to have power grid security operation experts construct a comprehensive safe operation model based on the actual scenario of power grid operation, and standardize the equipment, tools, operations and other contents in the safe operation process. Then, a set of symbol systems is designed based on the formal language to realize the symbolic representation of various elements in the safe operation model, and a library function is developed to automatically convert the actual safe operation data into a formal language description, so as to facilitate programmable calling of the safe operation orchestration method. The security orchestration architecture will combine the technologies of formal language representation and knowledge graph, comprehensively consider factors such as threats, assets, and resource availability, orderly handle multi-source security risk events, help operators provide safety disposal measures and emergency response strategies, and ultimately realize standardized, automated, efficient and intelligent safe and stable operation of the power grid.

[0038] The present invention provides a method for orchestrating power grid management security operations based on formal language representation, comprising the following steps:

[0039] Step S1: Collect feedback from frontline grid safety operation personnel, identify key implementation elements of safety operations, and standardize safety operation elements.

[0040] Specifically, if Figure 2As shown: The key implementation elements of security operations identified by security experts include assets, vulnerabilities, threat surfaces, events, personnel, etc.; and standardized operation and maintenance management of corresponding security operation elements is carried out to standardize systems, tools, equipment, specific operations, implementation processes, etc.

[0041] Step S2: Draw the existing security operation process diagram based on the identified elements and design a comprehensive security operation model.

[0042] Specifically, if Figure 2 As shown: The drawn security operations flowchart includes the stages of incident reception, analysis, decision-making, and response. The security operations model covers the key implementation elements in step S1, the inputs and outputs of each stage, the responsible parties, and technical support. According to the security operations model, when receiving a security risk incident report, the restricted devices or systems of the relevant incident and the risk factors therein should be located, including the threat type, vulnerability, and the value and importance of the affected assets. Subsequently, based on existing vulnerability management, asset management, and threat surface management modules, rapid information integration and in-depth analysis are carried out. Strategies are formulated through resources such as technical support and historical cases, and the optimal emergency response plan is output. This plan not only clearly lists specific response measures and steps, but also defines the relevant execution entities and responsibilities, ensuring rapid response and effective coordination in emergency situations, minimizing the impact of security risks on business operations. The model will be adjusted and optimized based on small-scale pilots.

[0043] Step S3: Develop library functions based on formal language to automatically convert actual security operation data into formal language descriptions to achieve symbolic representation and programmable calls.

[0044] Specifically, the formal languages ​​defined for security operations include but are not limited to event description languages, policy expression languages, and response instruction languages. Figure 3 As shown: The elements of the representation should include security operation equipment and tools, security operation operations, security operation processes, etc. The library function developed Automatically convert normalized operational data into a structured formal language representation suitable for security operations. It's important to note that this library function is based on an example of a programming language. It receives security event data in the form of a dictionary, identifies the type, severity, and impact of the security risk event, and converts it into a defined formal language format. This function can be expanded to support more complex data structures and additional formal language features.

[0045] Step S4: Relying on big data support such as threat intelligence library, vulnerability library, and expert experience library, a knowledge graph containing security entities, event relationships, and response strategies is constructed.

[0046] Specifically, if Figure 4 As shown, the knowledge graph structure consists of three aspects: entities, attributes, and relationships. Entities include physical devices, security tools, operational personnel, security vulnerabilities, threats, standard operating procedures, and security risk events. Attributes describe the state and characteristics of entities, such as device operating status, vulnerability damage, and event priority. Relationships reflect the interactions between entities, such as device connectivity, personnel responsibility, and vulnerability existence. The knowledge graph can draw information from multiple sources, such as threat intelligence libraries, vulnerability libraries, and expert experience libraries, to provide a comprehensive view of the security landscape. These libraries should be dynamically updated to keep pace with the latest intelligence. The creation of the knowledge graph supports the security orchestration architecture's consideration of threats, assets, resource availability, and other factors. Upon receiving a security risk event, security operations personnel use the information in the knowledge graph to determine the impact and severity of the event and formulate an appropriate response strategy.

[0047] Step S5: Build a comprehensive security orchestration architecture, use security risk events as input, and automatically generate a near-optimal emergency response strategy.

[0048] Specifically, if Figure 5 As shown: the comprehensive security orchestration architecture 200 integrates the formal language representation module 210 in step S3 and the knowledge graph module 220 in step S4. The security orchestration algorithm will combine the specific operation scenario of the power grid, take the security risk event 100 as input, and consider the event urgency, resource availability, historical cases and other factors based on the knowledge graph. It calculates the approximately optimal response strategy according to a certain weight. The calculation method is ,in is the relative weight coefficient of each consideration indicator in this security incident, Score the general importance of each consideration. The calculated emergency response strategy is compiled based on different actual scenarios. A corresponding security operation script 230 is compiled. When a security risk event occurs, a near-optimal emergency response strategy 300 can be automatically generated through the script, thereby improving the safety operation efficiency of the power grid management scenario.

[0049] This application proposes an innovative security orchestration method based on formal language representation and knowledge graph technology, designed to help security operators more efficiently respond to security risk events. This method improves automation and operational efficiency and is suitable for power grid security operations.

[0050] An embodiment of the present application provides a power grid management security operation orchestration system, including a memory and a processor. The memory includes a program for a power grid management security operation orchestration method. When the program for the power grid management security operation orchestration method is executed by the processor, the steps of the power grid management security operation orchestration method are implemented:

[0051] An embodiment of the present application provides a computer-readable storage medium storing program code. When the program code is executed by a processor, the steps of the above-mentioned method for orchestrating safe operations of power grid management are implemented.

[0052] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0053] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0054] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0055] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0056] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0057] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0058] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0059] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, various modifications and variations of the present application are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A method for orchestrating safe operation of power grid management, characterized in that: The following steps are involved: Step S1: Collect feedback from frontline grid security operators, identify key implementation elements of security operations, and standardize security operation elements; Step S2: Draw the existing security operation process map based on the identified elements and design a comprehensive security operation model; Step S3: Develop library functions based on formal language to automatically convert actual security operation data into formal language descriptions, achieving symbolic representation and programmable call; Step S4: Relying on the big data support of the threat intelligence library, vulnerability library, and expert experience library, a knowledge graph containing security entities, event relationships, and response strategies is constructed; Step S5: Build a comprehensive security orchestration architecture, use security risk events as input, and automatically generate a near-optimal emergency response strategy.

2. A method for arranging safe operation of power grid management according to claim 1, characterized in that: In step S1, the key implementation elements of security operations identified by security experts include information sources, analysis tools, decision support requirements, event detection response and recovery; and standardized systems, personnel, equipment, tools, specific operations, and implementation process content.

3. A method for arranging safe operation of power grid management according to claim 1, characterized in that: In step S2, the drawn security operation flowchart includes the stages of event reception, analysis, decision-making, and execution of response measures. The security operation model covers the key implementation elements in step S1, the input and output of each stage, the responsible parties, and the technical support content. The model will be adjusted and optimized based on the small-scale pilot.

4. A method for arranging safe operation of power grid management according to claim 1, characterized in that: In step S3, the formal language defined for security operations includes but is not limited to event description language, policy expression language, and response instruction language. The elements represented should include security operation equipment and tools, security operation operations, and security operation processes. The developed library function Automatically convert normalized operational data into a structured formal language representation suitable for security operations. .

5. A method for arranging safe operation of power grid management according to claim 1, characterized in that: In step S4, the threat intelligence library, vulnerability library, and expert experience library are dynamically updated and synchronized with the latest intelligence.

6. A method for orchestrating power grid management security operations according to claim 1, characterized in that: In step S5, the comprehensive security orchestration architecture integrates the formal language representation system in step S3 and the knowledge graph in step S4. The security orchestration algorithm will combine the specific operation scenarios of the power grid, take security risk events as input, consider the urgency of the event, resource availability, and historical case factors, and calculate the approximately optimal response strategy according to certain weights. The calculation method is ,in is the relative weight coefficient of each consideration indicator in this security incident, Score the general importance of each consideration. is the calculated emergency response strategy.

7. A power grid management security operation orchestration system, characterized in that: The system comprises a memory and a processor, wherein the memory comprises a program of a method for orchestrating safe operations of power grid management, and when the program of the method for orchestrating safe operations of power grid management is executed by the processor, the following steps are implemented: Step S1: collecting feedback from frontline safe operations personnel of the power grid, identifying key implementation elements of safe operations, and standardizing the safe operations elements; Step S2: Draw the existing security operation process map based on the identified elements and design a comprehensive security operation model; Step S3: Develop library functions based on formal language to automatically convert actual security operation data into formal language descriptions, achieving symbolic representation and programmable call; Step S4: Relying on the big data support of the threat intelligence library, vulnerability library, and expert experience library, a knowledge graph containing security entities, event relationships, and response strategies is constructed; Step S5: Build a comprehensive security orchestration architecture, use security risk events as input, and automatically generate a near-optimal emergency response strategy.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores program code, and when the program code is executed by a processor, the steps of the power grid management security operation orchestration method according to any one of claims 1 to 6 are implemented.