Method and device for authority security management and control in power monitoring system

By subdividing account types and implementing manual authorization and approval in the power monitoring system, the problem of malicious operation by a single person was solved, the system security and scalability were enhanced, and the difficulty of business transformation was reduced.

CN115270108BActive Publication Date: 2026-05-19NR ENG CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NR ENG CO LTD
Filing Date
2022-05-16
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In existing power monitoring systems, a single person can perform critical operations anytime and anywhere after successfully logging in. There is a lack of effective security measures, which cannot prevent malicious operations that could damage the power grid.

Method used

By adopting a minimal access control configuration, system accounts are divided into system management, business authorization, business operation, business maintenance, and business browsing categories. Manual authorization and approval are carried out through business authorization accounts to enhance access control and prevent malicious operations by a single person.

Benefits of technology

By categorizing account types and implementing manual authorization approval, the security of the power monitoring system has been improved, malicious operations have been prevented, the risk of system account login has been reduced, the scalability of the authorization application function has been improved, and the difficulty of adapting business programs has been reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115270108B_ABST
    Figure CN115270108B_ABST
Patent Text Reader

Abstract

The application discloses a kind of method and device for authority security control in power monitoring system, the method is by the account in power monitoring system is subdivided into five categories, including: system management class, business authorization class, business operation class, business operation and maintenance class and business browsing class;Among them, the account of the on-duty business authorization class has account abnormal behavior login authorization capability and custom key operation authorization capability;Through business authorization class account, prevent the illegal behavior such as misoperation and malicious operation of other four kinds of accounts, and the business authorization class account has shift characteristics, and the next on-duty business authorization class account is specified by the last on-duty business authorization class account;Through authorization application plug-in and authorization approval service, realize the transparency of power monitoring system custom key business operation authorization application and approval, to ensure the controllability of key business operation, further improve the security of power monitoring system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method and apparatus for secure access control in a power monitoring system, belonging to the field of security technology for power monitoring systems. Background Technology

[0002] With the development of computer technology, the intelligent operation and maintenance of power monitoring systems has also been greatly improved. Dispatchers can log in to the system locally to remotely control and modify key equipment and parameters of substations thousands of miles away. Currently, the power monitoring system only performs identity authentication based on two-factor authentication for local logins. After successful login, the account can perform the above-mentioned key operations anytime and anywhere. When a single person is turned against their employer, they have the ability to deliberately perform malicious key operations, and the current security protection strategies cannot effectively prevent such behavior. Summary of the Invention

[0003] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method and device for secure access control in a power monitoring system. By using business authorization accounts to uniformly authorize and approve account logins and key operations manually, the security of access control is enhanced, preventing a single person from deliberately engaging in malicious operations that could damage the power grid, thereby ensuring the security of the power monitoring system.

[0004] To achieve the above objectives, the present invention is implemented using the following technical solution:

[0005] In a first aspect, the present invention provides a method for security management of permissions in a power monitoring system, which divides the system's accounts into system management, business authorization, business operation, business maintenance and maintenance and business browsing categories according to the minimum permission configuration, and approves authorization requests through the business authorization category accounts;

[0006] The method of approving authorization requests through business authorization accounts is applied to the authorization request plugin, including:

[0007] Receive authorization request information sent by the business program, and select the current business authorization class account according to the predetermined matching rules;

[0008] The authorization application information is sent to the authorization approval unit; the authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to the predetermined matching rules and returns the authorization review result to the authorization application plugin.

[0009] The system receives the authorization review result sent by the authorization approval unit and returns the authorization review result to the business program as a return value. The business program then performs the corresponding business logic based on the return value.

[0010] Furthermore, the process of receiving authorization application information sent by the service program and selecting the current service authorization class account according to a predetermined matching rule includes:

[0011] Step 1: Receive authorization request information sent by the business program, including: the account name of the authorization request, the content and type of the authorization request; determine whether the authorization request type is a login authorization request or an operation authorization request; if it is a login authorization request, proceed to Step 2; if it is an operation authorization request, proceed to Step 3.

[0012] Step 2: Determine if the account has any abnormal behavior. If so, proceed to Step 4.

[0013] Step 3: Determine if the operation type is in the custom critical operation list. If so, determine if it is within the authorization window. If not, proceed to Step 4.

[0014] Step 4: Retrieve the list of currently authorized accounts from the real-time permissions database;

[0015] Step 5: Determine if the number of authorized accounts is greater than 1. If not, proceed to step 7.

[0016] Step 6: Determine whether the account name of the authorization application is in the list of currently authorized accounts. If so, remove the application account from the obtained list of currently authorized accounts and display the remaining currently authorized accounts on the authorization application interface, then proceed to Step 8.

[0017] Step 7: Display the list of authorized accounts on duty on the authorization application interface;

[0018] Step 8: The authorized application account responds to the manual selection signal on the authorization application interface and selects an account for the current business authorization category.

[0019] Furthermore, the list of authorized accounts on duty includes one or more of the following: username, online status, and online node of the authorized account on duty.

[0020] Furthermore, the abnormal behavior includes one or more of the following: user being locked out after multiple failed login attempts, user being put into hibernation due to prolonged inactivity, user not granting authorization, and abnormal user login time.

[0021] Furthermore, the authorization approval unit receives authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to a predetermined matching rule and returns the authorization review result to the authorization application plugin, including:

[0022] Step 1: Receive authorization request information, obtain the request type from the authorization request message. If it is a login authorization request, obtain the authorization request account and abnormal behavior, authorization request node and authorization request time from the authorization request message; if it is an operation authorization request, obtain the authorization request account, authorization request operation content, authorization request node and authorization request time from the authorization request message.

[0023] Step 2: Push the authorization approval interface to the monitoring screen of the authorized account on duty, and display the parsed authorization application content on the interface;

[0024] Step 3: The authorized account on duty will conduct a manual review, write the review results into the historical database, and then send the review results to the authorization application plugin.

[0025] Furthermore, the on-duty authorized accounts include the on-duty shift leader and the on-duty shift staff, both of whom have authorization capabilities, and their authority to perform normal business operations is not affected during their shift.

[0026] Furthermore, the first authorized business account to log in to the system directly obtains the authorization capabilities of that type of account and becomes the first on-duty shift leader, who then designates N authorized accounts as on-duty shift members.

[0027] Furthermore, when the authorization approval unit receives the authorization application information, it also includes:

[0028] Step 1: Determine whether this node has received an authorization request message. If not, proceed to Step 2.

[0029] Step 2: Determine if the current shift leader is the current node. If not, skip to Step 1.

[0030] Step 3: Determine if the shift leader is ready to hand over the shift. If not, skip to Step 1.

[0031] Step 4: Push the shift handover interface to the on-duty shift leader and verify their identity. If the verification fails, the shift handover fails.

[0032] Step 5: When the shift leader designates the next shift leader and the next batch of shift workers on the shift handover interface, and grants them authorization capabilities;

[0033] Step 6: Reclaim the authorization capabilities of the previous shift leader and the previous batch of shift workers, and the shift handover is successful.

[0034] Secondly, the present invention provides a method for security management of permissions in a power monitoring system, which divides the system's accounts into system management, business authorization, business operation, business maintenance and maintenance and business browsing categories according to the minimum permission configuration, and approves authorization requests through the business authorization category accounts;

[0035] The method of approving authorization requests through business authorization accounts is applied to the authorization approval unit, including:

[0036] The system receives authorization application information sent by the authorization application plugin, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to a predetermined matching rule. The authorization application plugin is used to receive authorization application information sent by the business program, select the on-duty business authorization account according to the predetermined matching rule, and send the authorization application information to the authorization approval unit.

[0037] The authorization review result is returned to the authorization application plugin. The authorization application plugin receives the authorization review result sent by the authorization approval unit and feeds back the authorization review result to the business program as a return value. The business program performs the corresponding business logic based on the return value.

[0038] Thirdly, the present invention provides a device for access control security management in a power monitoring system, applied to an authorization application plugin, comprising:

[0039] The on-duty business authorization class account selection unit is used to receive authorization application information sent by the business program and select the on-duty business authorization class account according to the predetermined matching rules.

[0040] The authorization application information sending unit is used to send authorization application information to the authorization approval unit. The authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to the predetermined matching rules and returns the authorization review result to the authorization application plugin.

[0041] The authorization review result receiving and feedback unit is used to receive the authorization review result sent by the authorization approval unit and feed the authorization review result back to the business program as a return value. The business program performs corresponding business logic based on the return value.

[0042] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:

[0043] (1) Based on the minimum permission configuration, the system accounts are subdivided into system management, business authorization, business operation, business maintenance and business browsing. The business authorization accounts are responsible for the manual authorization and approval of account login and key operations, which enhances the security of permission control and prevents a single person from deliberately performing malicious operations to damage the power grid, thereby ensuring the security of the power monitoring system.

[0044] (2) By adopting a plug-in approach for authorization applications and a service-oriented approach for authorization approval, the goal of decoupling business procedures from authorization application functions is achieved, thereby improving the scalability of authorization application functions and reducing the difficulty of adapting business procedures. Attached Figure Description

[0045] Figure 1 This is a flowchart of a method for access control security management in a power monitoring system provided by an embodiment of the present invention;

[0046] Figure 2 This is a flowchart of the authorization application plugin provided in an embodiment of the present invention;

[0047] Figure 3 This is a flowchart of the authorization and approval service provided in an embodiment of the present invention. Detailed Implementation

[0048] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.

[0049] Example 1

[0050] This embodiment introduces a method for security control of permissions in a power monitoring system. According to the minimum permission configuration, the system accounts are divided into system management, business authorization, business operation, business maintenance and maintenance and business browsing categories. The authorization application is authorized and approved through the business authorization account.

[0051] The method of approving authorization requests through business authorization accounts is applied to the authorization request plugin, including:

[0052] Receive authorization request information sent by the business program, and select the current business authorization class account according to the predetermined matching rules;

[0053] The authorization application information is sent to the authorization approval unit; the authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to the predetermined matching rules and returns the authorization review result to the authorization application plugin.

[0054] The system receives the authorization review result sent by the authorization approval unit and returns the authorization review result to the business program as a return value. The business program then performs the corresponding business logic based on the return value.

[0055] The contents involved in the above embodiments will be described below with reference to the accompanying drawings.

[0056] This embodiment provides a method for access control in a power monitoring system to prevent abnormal account logins and malicious execution of critical business operations by a single individual that could damage the system. It implements a general authorization confirmation mechanism by providing an authorization application plugin and an authorization approval service. The business program selectively loads the authorization application plugin based on whether the business requires authorization confirmation. The plugin obtains a list of currently active authorized accounts and their corresponding nodes, then pushes an authorization application interface. The user manually selects a currently active authorized account on the application interface. Based on the selection, the plugin sends authorization application information to the authorization approval service. This information includes the user account, application type, and content. Upon receiving the authorization application message, the authorization approval service pushes an authorization approval screen to the currently active authorized account at that node. The user manually reviews the application information on the authorization approval interface. After confirmation, the authorization approval service sends the review result to the corresponding authorization application plugin. The plugin then returns the review result to the business program as a return value. Finally, the business program performs corresponding business logic based on the return value. Specifically, as follows... Figure 1 .

[0057] The specific process for authorizing the plugin is as follows: Figure 2 The steps are as follows:

[0058] 1. The business loads the authorization application plugin as needed and enters the current authorization application message, including: the account name of the authorization application, the content and type of the authorization application. The authorization application plugin first determines the type of authorization application. If it is a login authorization application, it skips to step 2; if it is an operation authorization application, it skips to step 3.

[0059] 2. The authorization application plugin determines whether the account has abnormal behavior. If not, skip to step 10; if so, skip to step 4.

[0060] 3. The authorization application plugin determines whether the operation type is in the list of custom key operations. If not, it skips to step 10.

[0061] 4. Retrieve the list of currently authorized accounts from the real-time permission database, including: username, online status, and online node of the currently authorized accounts;

[0062] 5. Determine if the number of authorized accounts is greater than 1. If not, skip to step 7.

[0063] 6. Determine if the account name in the authorization request is in the list of currently authorized accounts. If so, remove the account from the list of currently authorized accounts, display the remaining currently authorized accounts on the authorization request interface, and then proceed to step 8.

[0064] 7. Display a list of currently authorized accounts on the authorization application interface;

[0065] 8. After the authorized account manually selects an authorized account on the authorization application interface, the authorization application plugin sends an authorization application message and waits for the authorization application result;

[0066] 9. Receive the authorization request result and return it;

[0067] 10. Successful response received;

[0068] The specific procedures for authorized approval application messages and the handover of on-duty authorized accounts are as follows: Figure 3 The steps are as follows:

[0069] 1. Determine if this node has received an authorization request message. If not, skip to step 6.

[0070] 2. Obtain the application type from the authorization application message. If it is a login authorization application, obtain the authorization application account and abnormal behavior, authorization application node and authorization application time from the authorization application message. If it is an operation authorization application, obtain the authorization application account, authorization application operation content, authorization application node and authorization application time from the authorization application message.

[0071] 3. Push the authorization approval interface to the monitoring screen of the authorized account on duty, and display the parsed authorization application content on the interface;

[0072] 4. The authorized account on duty will conduct a manual review and write the review result into the historical database. Then, the review result will be sent to the authorization application plugin. Skip to step 5.

[0073] 5. Authorization approval successful, and return received;

[0074] 6. Determine if the current shift leader is the current node; if not, skip to step 1.

[0075] 7. Determine if the shift leader is ready to hand over the shift. If not, skip to step 1.

[0076] 8. Push the shift handover interface to the on-duty shift leader and verify their identity. If the verification fails, skip to step 12.

[0077] 9. When the shift leader designates the next shift leader and the next batch of shift workers on the shift handover interface, and grants them authorization capabilities;

[0078] 10. Reclaim the authorization capabilities of the previous shift leader and the previous batch of shift workers, and skip to step 11;

[0079] 11. Shift handover successful, and return;

[0080] 12. Shift handover failed, and the employee returned.

[0081] This embodiment provides a method for secure access control in a power monitoring system, preventing a single person from maliciously performing critical business operations to disrupt the system; by monitoring abnormal account behavior and mandating authorized login, it prevents abnormal account login behavior and reduces the risk of system account login; by providing authorization application plugins and authorization approval services, it reduces the difficulty of business transformation and achieves highly scalable, plug-and-play authorization applications.

[0082] Example 2

[0083] This embodiment introduces a method for secure access control in a power monitoring system. The system categorizes accounts into four types: system management, business operation, business maintenance, and business browsing. There are also authorized business accounts. Authorized business accounts have the ability to authorize logins from abnormal accounts and to authorize critical business operations. During shifts, authorized business accounts include the on-duty shift leader and on-duty staff, both of whom possess authorization capabilities, and their normal business execution permissions are not affected during their shifts. Authorized business accounts also feature shift handover functionality, with the previous authorized shift leader designating the next authorized shift leader and the next batch of authorized staff.

[0084] The login box of the power monitoring system has the function of requesting authorization by loading a login authorization plugin. The login authorization plugin determines whether the entered account needs to make a login authorization request. Custom business key operations have the function of requesting operation authorization by loading an operation authorization plugin. The operation authorization plugin makes the operation authorization request based on the information of the key operation.

[0085] The specific method for authorizing and approving business authorization accounts is as follows:

[0086] Step 1: When the system is first started, the first authorized business account to log in to the system directly obtains the authorization capabilities of that type of account and becomes the first on-duty shift leader, and designates N authorized business accounts as on-duty shift members.

[0087] Step 2: After the shift leader or shift worker receives the authorization approval service push interface, they should manually confirm the authorization.

[0088] Step 3: After the shift leader receives the handover interface pushed by the authorization approval service, they shall designate the next shift leader and the next batch of shift members. If no designation is made or the designation fails, the authorization capabilities of the current shift leader and the current shift members will not be revoked. If the designation is successful, the authorization approval service will grant the next shift leader and the next batch of shift members the formal authorization capabilities, and will revoke the authorization capabilities of the previous shift leader and the previous batch of shift members.

[0089] The specific method for requesting login authorization for the abnormal account is as follows:

[0090] Step 1: The user logs in to their account using the login box. After successful identity authentication, the login box loads the login authorization plugin, which determines whether the account has any abnormal behavior. Abnormal behavior includes: the user is locked after multiple failed login attempts, the user is put into a dormant state after a long period of inactivity, the user has not authorized the account, or the user's login time is abnormal. If not, proceed to step 5.

[0091] Step 2: A login authorization application interface will pop up. The list of authorized accounts will be obtained and displayed on the interface along with the corresponding login nodes.

[0092] Step 3: The user selects an authorized account and sends a login authorization request message, including: the account to be logged in, the login node, etc., and waits for the authorization request result; if the login authorization request is successful, proceed to step 5; if the login authorization request fails, proceed to step 4.

[0093] Step 4: User login fails and an error code is returned;

[0094] Step 5: User logs in successfully and is returned;

[0095] The specific method for authorizing the aforementioned key business operations is as follows:

[0096] Step 1: When performing a critical business operation on an online account, if the critical business operation is not in the custom critical operation list, skip to step 5.

[0097] Step 2: Determine if the key business operation is within the sliding window. If so, proceed to Step 5.

[0098] Step 3: A pop-up operation authorization application interface will appear, listing the currently on-duty authorized accounts and their respective nodes.

[0099] Step 4: The user selects an authorized account and sends an operation authorization request message, including: the online account to be operated, the operation node, the operation time, the operation content, etc., and waits for the authorization request result; if the operation authorization request is successful, proceed to step 5; if the login authorization request fails, proceed to step 6.

[0100] Step 5: Allow the operation to be executed and return the operation result;

[0101] Step 6: The operation is not allowed, and an error code is returned.

[0102] Example 3

[0103] This embodiment provides a method for security control of permissions in a power monitoring system. The system accounts are divided into system management, business authorization, business operation, business maintenance, and business browsing categories according to the minimum permission configuration. The authorization application is authorized and approved through the business authorization account.

[0104] The method of approving authorization requests through business authorization accounts is applied to the authorization approval unit, including:

[0105] The system receives authorization application information sent by the authorization application plugin, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to a predetermined matching rule. The authorization application plugin is used to receive authorization application information sent by the business program, select the on-duty business authorization account according to the predetermined matching rule, and send the authorization application information to the authorization approval unit.

[0106] The authorization review result is returned to the authorization application plugin. The authorization application plugin receives the authorization review result sent by the authorization approval unit and feeds back the authorization review result to the business program as a return value. The business program performs the corresponding business logic based on the return value.

[0107] Example 4

[0108] This embodiment provides a device for access control security management in a power monitoring system, applied to an authorization request plugin, including:

[0109] The on-duty business authorization class account selection unit is used to receive authorization application information sent by the business program and select the on-duty business authorization class account according to the predetermined matching rules.

[0110] The authorization application information sending unit is used to send authorization application information to the authorization approval unit. The authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to the predetermined matching rules and returns the authorization review result to the authorization application plugin.

[0111] The authorization review result receiving and feedback unit is used to receive the authorization review result sent by the authorization approval unit and feed the authorization review result back to the business program as a return value. The business program performs corresponding business logic based on the return value.

[0112] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for secure access control in a power monitoring system, characterized in that, The system accounts are divided into system management, business authorization, business operation, business maintenance, and business browsing categories according to the minimum permission configuration. Authorization requests are approved through the business authorization category accounts. The method of approving authorization requests through business authorization accounts is applied to the authorization request plugin, including: Receive authorization request information sent by the business program, and select the current business authorization class account according to the predetermined matching rules; including: Step 1: Receive authorization request information sent by the business program, including: the account name of the authorization request, the content and type of the authorization request; determine whether the authorization request type is a login authorization request or an operation authorization request; if it is a login authorization request, proceed to Step 2; if it is an operation authorization request, proceed to Step 3. Step 2: Determine if the account has any abnormal behavior. If so, proceed to Step 4. Step 3: Determine if the type of the operation is in the list of custom critical operations. If so, determine if it is within the authorization window. If it is not within the authorization window, proceed to Step 4. Step 4: Retrieve the list of currently authorized accounts from the real-time permissions database; Step 5: Determine if the number of authorized accounts is greater than 1. If not, proceed to step 7. Step 6: Determine whether the account name of the authorization application is in the list of currently authorized accounts. If so, remove the account from the obtained list of currently authorized accounts and display the remaining currently authorized accounts on the authorization application interface, then proceed to Step 8. Step 7: Display the list of authorized accounts on duty on the authorization application interface; Step 8: The authorized application account responds to the manual selection signal on the authorization application interface and selects an account for the current business authorization category; The authorization application information is sent to the authorization approval unit; the authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to the predetermined matching rules and returns the authorization review result to the authorization application plugin; including: Step 1: Receive authorization request information, obtain the request type from the authorization request message. If it is a login authorization request, obtain the authorization request account and abnormal behavior, authorization request node and authorization request time from the authorization request message; if it is an operation authorization request, obtain the authorization request account, authorization request operation content, authorization request node and authorization request time from the authorization request message. Step 2: Push the authorization approval interface to the monitoring screen of the authorized account on duty, and display the parsed authorization application content on the interface; Step 3: The authorized account on duty conducts manual review, writes the review results into the historical database, and then sends the review results to the authorization application plugin; The system receives the authorization review result sent by the authorization approval unit and returns the authorization review result to the business program as a return value. The business program then performs the corresponding business logic based on the return value.

2. The method for access control security management in a power monitoring system according to claim 1, characterized in that: The information in the list of authorized accounts on duty includes one or more of the following: username, online status, and online node of the authorized account on duty.

3. The method for access control security management in a power monitoring system according to claim 1, characterized in that: The abnormal behaviors include one or more of the following: user being locked out after multiple failed login attempts, user being put into hibernation due to prolonged inactivity, user not granting authorization, and abnormal user login time.

4. The method for access control security management in a power monitoring system according to claim 1, characterized in that: The authorized accounts for on-duty business include the on-duty shift leader and the on-duty shift staff, all of whom have authorization capabilities, and their authority to perform normal business operations is not affected during their shift.

5. The method for access control security management in a power monitoring system according to claim 1, characterized in that: The first authorized account to log in to the system directly obtains the authorization capabilities of that type of account and becomes the first on-duty shift leader, who then designates N authorized accounts as on-duty shift members.

6. The method for access control security management in a power monitoring system according to claim 5, characterized in that: When the authorization approval unit receives the authorization application information, it also includes: Step 1: Determine whether this node has received an authorization request message. If not, proceed to Step 2. Step 2: Determine if the current shift leader is the current node. If not, skip to Step 1. Step 3: Determine if the shift leader is ready to hand over the shift. If not, skip to Step 1. Step 4: Push the shift handover interface to the on-duty shift leader and verify their identity. If the verification fails, the shift handover fails. Step 5: When the shift leader designates the next shift leader and the next batch of shift workers on the shift handover interface, and grants them authorization capabilities; Step 6: Reclaim the authorization capabilities of the previous shift leader and the previous batch of shift workers, and the shift handover is successful.

7. A method for secure access control in a power monitoring system, characterized in that, The system accounts are divided into system management, business authorization, business operation, business maintenance, and business browsing categories according to the minimum permission configuration. Authorization requests are approved through the business authorization category accounts. The method of approving authorization requests through business authorization accounts is applied to the authorization approval unit, including: The system receives authorization application information from the authorization application plugin, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to pre-determined matching rules. The authorization application plugin receives authorization application information from business programs and selects the on-duty business authorization account according to pre-determined matching rules, including: Step 1: Receive authorization request information sent by the business program, including: the account name of the authorization request, the content and type of the authorization request; determine whether the authorization request type is a login authorization request or an operation authorization request; if it is a login authorization request, proceed to Step 2; if it is an operation authorization request, proceed to Step 3. Step 2: Determine if the account has any abnormal behavior. If so, proceed to Step 4. Step 3: Determine if the type of the operation is in the list of custom critical operations. If so, determine if it is within the authorization window. If it is not within the authorization window, proceed to Step 4. Step 4: Retrieve the list of currently authorized accounts from the real-time permissions database; Step 5: Determine if the number of authorized accounts is greater than 1. If not, proceed to step 7. Step 6: Determine whether the account name of the authorization application is in the list of currently authorized accounts. If so, remove the account from the obtained list of currently authorized accounts and display the remaining currently authorized accounts on the authorization application interface, then proceed to Step 8. Step 7: Display the list of authorized accounts on duty on the authorization application interface; Step 8: The authorized application account responds to the manual selection signal on the authorization application interface and selects an account for the current business authorization category; In addition, the authorization application information is sent to the authorization approval unit; wherein, the authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to the predetermined matching rules and returns the authorization review result to the authorization application plugin; including: Step 1: Receive authorization request information, obtain the request type from the authorization request message. If it is a login authorization request, obtain the authorization request account and abnormal behavior, authorization request node and authorization request time from the authorization request message; if it is an operation authorization request, obtain the authorization request account, authorization request operation content, authorization request node and authorization request time from the authorization request message. Step 2: Push the authorization approval interface to the monitoring screen of the authorized account on duty, and display the parsed authorization application content on the interface; Step 3: The authorized account on duty conducts manual review, writes the review results into the historical database, and then sends the review results to the authorization application plugin; The authorization application plugin receives the authorization review result sent by the authorization approval unit and returns the authorization review result to the business program as a return value. The business program then performs the corresponding business logic based on the return value.

8. A device for secure access control in a power monitoring system, characterized in that, Applied to the license application plugin, including: The on-duty business authorization class account selection unit is used to receive authorization application information sent by the business program and select the on-duty business authorization class account according to a predetermined matching rule; including: Step 1: Receive authorization request information sent by the business program, including: the account name of the authorization request, the content and type of the authorization request; determine whether the authorization request type is a login authorization request or an operation authorization request; if it is a login authorization request, proceed to Step 2; if it is an operation authorization request, proceed to Step 3. Step 2: Determine if the account has any abnormal behavior. If so, proceed to Step 4. Step 3: Determine if the type of the operation is in the list of custom critical operations. If so, determine if it is within the authorization window. If it is not within the authorization window, proceed to Step 4. Step 4: Retrieve the list of currently authorized accounts from the real-time permissions database; Step 5: Determine if the number of authorized accounts is greater than 1. If not, proceed to step 7. Step 6: Determine whether the account name of the authorization application is in the list of currently authorized accounts. If so, remove the account from the obtained list of currently authorized accounts and display the remaining currently authorized accounts on the authorization application interface, then proceed to Step 8. Step 7: Display the list of authorized accounts on duty on the authorization application interface; Step 8: The authorized application account responds to the manual selection signal on the authorization application interface and selects an account for the current business authorization category; The authorization application information sending unit is used to send authorization application information to the authorization approval unit. The authorization approval unit receives the authorization application information, parses the authorization application content, and pushes it to the on-duty business authorization account. The on-duty business authorization account matches the authorization review result according to a pre-determined matching rule and returns the authorization review result to the authorization application plugin. This includes: Step 1: Receive authorization request information, obtain the request type from the authorization request message. If it is a login authorization request, obtain the authorization request account and abnormal behavior, authorization request node and authorization request time from the authorization request message; if it is an operation authorization request, obtain the authorization request account, authorization request operation content, authorization request node and authorization request time from the authorization request message. Step 2: Push the authorization approval interface to the monitoring screen of the authorized account on duty, and display the parsed authorization application content on the interface; Step 3: The authorized account on duty conducts manual review, writes the review results into the historical database, and then sends the review results to the authorization application plugin; The authorization review result receiving and feedback unit is used to receive the authorization review result sent by the authorization approval unit and feed the authorization review result back to the business program as a return value. The business program performs corresponding business logic based on the return value.