Power monitoring system access right control method and access control method and device

By dynamically dividing and allocating permissions according to user attributes and equipment attributes in the power monitoring system, and dynamic constraints are combined with access constraint rules, the problem that the traditional RBAC model cannot meet the access control needs of the complex role of the power system is solved, and efficient permission management and the security and reliability of the power monitoring system are achieved.

CN115883175BActive Publication Date: 2025-05-09SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211499651.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-05-09
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

The traditional RBAC model cannot meet the complex role access control needs of the power system, especially in the power monitoring system, where there are many types of equipment and frequent changes, and the allocation and maintenance of role permissions are complex.

Method used

By determining the user role and permission level based on the user's user attributes in the current scenario, dividing the device into a single accessed object and the type of accessed object with the same characteristics according to the attributes of the power monitoring system equipment, determining the object permissions and type permissions, expanding the user's initial permissions, assigning permissions to the user roles, and dynamically constraining based on the access constraint rules to determine the target access permissions.

Benefits of technology

This method refines the granularity of resources, improves the efficiency of resource management, simplifies user permission management, improves the security and reliability of the power monitoring system, and provides important technical support for the defense of the intranet security of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883175B_ABST
    Figure CN115883175B_ABST
Patent Text Reader

Abstract

The present application relates to an access control method for an electric power monitoring system and an access control method and device. The access control method includes: determining the user role and the permission level of the user role in the current scenario according to the user attributes of the user in the current scenario; dividing each device according to the accessed object and the type of the accessed object according to the attributes of each device in the electric power monitoring system in the current scenario; determining the object permissions of each accessed object after the division, and the type permissions of each type of the accessed object; expanding the initial permissions of the user in the current scenario based on the object permissions and type permissions to obtain an extended permission set; assigning permissions to the user role according to the permission level of the user role in the current scenario and the attributes of each device; dynamically constraining the access permissions based on the access constraint rules to obtain the constrained target access permissions. It simplifies user permission management, refines the granularity of resources, and improves resource management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of access control and information security technology, and in particular to a method for access control of an electric power monitoring system, an access control method, a computer device, a storage medium and a computer program product. Background Art

[0002] With the construction of smart grids, the application of highly integrated equipment and intelligent technologies has brought new challenges to information security. When users interact with the power system, there may be security threats such as vulnerabilities in mobile terminals, identity fraud, and information tampering, causing the intranet to be maliciously attacked. Power security is one of the important aspects of critical information infrastructure protection. The safe and stable operation of the power system is related to national energy security and the lifeline of the national economy. It is also a key target of cyber attacks. The state estimation, monitoring, control and protection of smart grids can be completed through a wide-area monitoring and control system based on phasor measurement units (PMUs). Voltage instability in smart grids is monitored by regularly recording parameters such as voltage and current phasors, frequency, and rate of change of frequency (ROCOF) that are dynamically related to the power system.

[0003] As an electrical parameter collector, the PMU device sends data together with GPS (Global Positioning System) synchronized time stamp data to the phasor data concentrator (PDC) for subsequent processing and analysis. Therefore, ensuring the security of information transmission between PMU and PDC is the top priority of the entire smart grid security. How to prevent man-in-the-middle attacks and information theft that lead to large-scale power outages caused by voltage instability is something that both enterprises and researchers need to consider.

[0004] In 1992, Kuhn et al. proposed the concept of RBAC, followed by Sandhu et al. who gave the formal definition of the RBAC model, the RBAC96 model. This model maps users to their roles and then to their permissions, so that users can obtain certain permissions through the role. By introducing an intermediate role Role between users and permissions, the RBAC model divides access control management into two parts: user role mapping and role permission mapping, thereby effectively simplifying role access control management. On the one hand, the model further simplifies access control management by defining role inheritance relationships. On the other hand, it further improves the security of access control management by introducing constraints to achieve management security. However, there are many types of objects in the power grid system, which change frequently, and the allocation and maintenance of role permissions are complex. The traditional RBAC model cannot meet the role access control requirements of the power system. Summary of the invention

[0005] Based on this, it is necessary to provide an access rights control method for an electric power monitoring system and an access control method, a computer device, a storage medium and a computer program product that can meet the role access control requirements of the electric power system in response to the above technical problems.

[0006] In a first aspect, the present application provides a method for controlling access rights of an electric power monitoring system, the method comprising:

[0007] Determine the user role and the permission level of the user role in the current scenario according to the user attributes in the current scenario;

[0008] According to the properties of each device in the power monitoring system in the current scenario, each of the devices is divided into a single accessed object and a type of accessed object with the same characteristics;

[0009] Determine the object authority of each of the accessed objects after the division, and the type authority of each type of the accessed object;

[0010] Expanding the initial permissions of the user in the current scenario based on the object permissions and the type permissions to obtain an extended permission set;

[0011] According to the permission level of the user role in the current scenario and the attributes of each of the devices, the permissions in the extended permission set are allocated to the user role to obtain the user's access rights in the current scenario;

[0012] The access rights are dynamically constrained based on the access constraint rules to obtain constrained target access rights.

[0013] In one of the embodiments, the power monitoring system includes: at least one of a phasor measurement unit, a phasor data concentrator, a synchronous phasor auxiliary analysis system, a switch or a time synchronization device.

[0014] In one embodiment, the power monitoring system access authority control method further includes:

[0015] In response to a device access authorization operation for the user, the access permission of the user is updated.

[0016] In one embodiment, devices corresponding to accessed object types having the same characteristics have the same permissions.

[0017] In a second aspect, a method for access control of a power monitoring system is provided, the method comprising:

[0018] Obtain access requests to power monitoring systems;

[0019] Parsing the access request to determine a target device in the power monitoring system and permissions required to allow access to the target device;

[0020] If the permission required to allow access to the target device is within the target access permission range of the user in the current scenario, then the operation on the resources of the target device is allowed;

[0021] The access rights of the user in the current scenario are determined by executing the steps of the above-mentioned method for controlling access rights of the power monitoring system.

[0022] In one embodiment, the power monitoring system access control method further includes:

[0023] If the permission required to allow access to the target device is not within the target access permission range of the user in the current scenario, operation on the resources of the target device is prohibited.

[0024] In a third aspect, a device for controlling access rights of a power monitoring system is provided, the device comprising:

[0025] A scenario-based user role determination module, used to determine the user role and the permission level of the user role in the current scenario according to the user attributes of the user in the current scenario;

[0026] The device-side classification module is used to classify each device according to the attributes of each device in the power monitoring system in the current scenario into a single accessed object and a type of accessed object with the same characteristics;

[0027] A device-side permission module, used to determine the object permission of each of the accessed objects after the division, and the type permission of each type of the accessed object;

[0028] A permission extension module, used to extend the initial permission of the user in the current scenario based on the object permission and the type permission to obtain an extended permission set;

[0029] A preliminary permission determination module, used to assign permissions in the extended permission set to the user role according to the permission level of the user role in the current scenario and the attributes of each of the devices, so as to obtain the user's access rights in the current scenario;

[0030] The target permission determination module is used to dynamically constrain the access permission based on the access constraint rules to obtain the constrained target access permission.

[0031] In a fourth aspect, a power monitoring system access control device is provided, the device comprising:

[0032] An access request acquisition module, used to acquire an access request for a power monitoring system;

[0033] A required authority determination module, used to parse the access request, determine the target device in the power monitoring system and the authority required to allow access to the target device;

[0034] A permission comparison module, used to allow operation on resources of the target device when the permission required for allowing access to the target device is within the target access permission range of the user in the current scenario;

[0035] The access rights of the user in the current scenario are determined by executing the steps of the above-mentioned method for controlling access rights of the power monitoring system.

[0036] In a fifth aspect, a computer device is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.

[0037] In a sixth aspect, a computer-readable storage medium is provided, on which a computer program is stored, and the computer program implements the steps of the above method when executed by a processor.

[0038] The above-mentioned power monitoring system access permission control method and access control method, device computer equipment, storage medium and computer program product have at least the following beneficial effects:

[0039] The permission control method determines the user role and the permission level of the user role in the current scenario according to the user attributes of the user in the current scenario; divides each device according to a single accessed object and an accessed object type with the same characteristics according to the attributes of each device in the power monitoring system in the current scenario; determines the object permissions of each accessed object after the division, and the type permissions of each accessed object type; expands the initial permissions of the user in the current scenario based on the object permissions and the type permissions to obtain an extended permission set; allocates permissions in the extended permission set to the user role according to the permission level of the user role in the current scenario and the attributes of each device, and obtains the access rights of the user in the current scenario; and dynamically constrains the access rights based on access constraint rules to obtain the constrained target access rights. By dividing permissions according to the accessed object and type on the power monitoring system side device, the initial permissions determined based on the user attributes and role division are expanded, and in combination with specific scenarios, permissions are allocated to the user role from the extended set according to the level of the user role in the current scenario and the attributes of the device, and the access rights are constrained based on constraint rules, and the target access rights of the user in the current scenario are determined, and which resources can be accessed by which permissions the user has. This permission control method refines the granularity of resources, improves the efficiency of resource management, simplifies user permission management, and improves the security and reliability of the power monitoring system. It provides important technical support for the defense of power system intranet security and has far-reaching significance for accelerating the construction of substation measurement and control and secure access to PMU and other equipment. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 A diagram of an access control method for a power monitoring system and an application environment of the access control method in one embodiment;

[0041] Figure 2 This is one of the flowcharts of a method for controlling access rights of a power monitoring system in one embodiment;

[0042] Figure 3 A schematic diagram of the correspondence between user attributes, user roles, and user permissions in one embodiment;

[0043] Figure 4 A schematic diagram of dividing the power monitoring system equipment according to the accessed objects and the accessed object types in one embodiment;

[0044] Figure 5 This is a second flow chart of a method for controlling access rights of a power monitoring system in one embodiment;

[0045] Figure 6 A schematic diagram of a flow chart of a method for access control of a power monitoring system in one embodiment;

[0046] Figure 7 A schematic diagram of the structure of an access rights control device for a power monitoring system in one embodiment;

[0047] Figure 8 A schematic diagram of the structure of an access control device for a power monitoring system in one embodiment;

[0048] Fig. 9 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0050] The permission control method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network, and the server 104 communicates with the equipment of the power monitoring system. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. The server 104 obtains the user attributes of the user in the current scene from the terminal 102, and assigns the user role based on the user attributes. The user's role in different scenes may be different. When determining the user role, the permission level of the user role is further determined to provide a basis for subsequent permission determination. In addition, considering that the power monitoring system has the characteristics of a large number of devices and a large number of types, there are many devices with the same characteristics among the numerous devices, such as PMUs with the same characteristics. Therefore, on the device side, according to the attributes of the device in the current scene, the device is divided according to a single accessed object and a type of accessed object with the same characteristics. After the division, the corresponding object permissions and type permissions are determined, and the initial permissions are extended for the accessed object and the type of accessed object to obtain an extended permission set, which provides a data source for the determination of user permissions. Then, combined with the permission level of the user role determined previously and the attributes of each device, the permissions in the extended permission set are assigned to the user role. Since there is a corresponding relationship between user role -> user attribute -> user, the access rights of the user role are determined, which means the access rights of the user are determined. Considering that the user has different roles in different scenarios, and thus has different permissions, some permissions are conflicting. Therefore, in order to ensure the security of resource access, the access rights of the obtained user are further constrained to obtain the target access rights. Among them, the terminal 102 can be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented with an independent server or a server cluster consisting of multiple servers.

[0051] In one embodiment, Figure 2 As shown, a method for controlling access rights of an electric power monitoring system is provided, which can be applied in Figure 1 The server 104 side in the example is used for explanation. Figure 2 As shown, the method includes:

[0052] S202, according to the user attributes of the user in the current scenario, determine the user role in the current scenario and the authority level of the user role. The current scenario refers to the scenario in which the user is in when issuing an access request when accessing resources. In different scenarios, the attribute factors that affect the user's secure access to resources are different. For example, in a scenario where a user needs to access the data collected by the PMU in the power monitoring system of a municipal power plant, the user attributes that affect the security of the resource access process may include the user account, user authority level, location of the monitoring system, the device to be accessed (PMU) and the data range of the domain access device, etc. At this time, the user plays the role of an administrator. When the user is performing power maintenance, the attribute factors that affect the security of the user's access to resources may include the maintenance location, user account, and the device to be repaired, etc. At this time, the user plays the role of a maintenance worker. Based on this, it can be understood that the user attributes in the current scenario refer to the attributes that affect the security of resource access when accessing each device in the power monitoring system in the current scenario. The user has different user roles in different scenarios, and the corresponding authority levels are also different, and the final authority is also different. The division of permission levels can be based on pre-configuration, for example, by configuring a mapping table of user attributes, user roles, and permission levels, user roles can be quickly assigned and the permission levels of user roles can be determined based on the mapping table and the user attributes of the user in the current scenario. Figure 3 shown.

[0053] S204 , according to the attributes of each device in the power monitoring system in the current scenario, classify each device into a single accessed object and a type of accessed object with the same characteristics.

[0054] Among them, considering that the power monitoring system, such as the PMU power monitoring system, has a large number of devices, but many PMUs have the same characteristics (referring to the characteristics that determine access rights), so the devices with the same characteristics are divided into the same accessed object type, and other single devices that do not have common characteristics are divided into single accessed objects. When performing subsequent permission management, for devices divided by type, the permissions of all devices of the type can be quickly determined based on the type permissions corresponding to the accessed object type.

[0055] S206, determine the object rights of each of the accessed objects after the division, and the type rights of each type of the accessed objects. The object rights of the accessed objects can be determined based on the resource access requirements of the device corresponding to the accessed objects. The type rights of the accessed object type can be determined based on the common security access rules for resource access of the device of that type. Figure 4 to understand, but it needs to be emphasized that Figure 4This is only an example for those skilled in the art to understand object permissions and type permissions. The number of type permissions and object permissions and the corresponding relationship between them and devices may vary depending on the actual application scenario.

[0056] S208, based on the object permission and the type permission, the initial permission of the user in the current scenario is extended to obtain an extended permission set. The initial permission of the user can be the permission assigned by default when the user account is newly created, or the permission obtained after initialization in the current scenario.

[0057] S210, according to the permission level of the user role in the current scenario and the attributes of each device, assign the permissions in the extended permission set to the user role to obtain the user's access rights in the current scenario. Different permission levels and device attributes will result in different permissions for the user in the current scenario. The attributes of the device can correspond to object permissions and type permissions based on the device attributes. The permission level determines which permissions in the extended permission set the user can have at this user level. The permissions the user has determine the resource access operations that correspond to the permissions.

[0058] For example, the initial permissions include dimensions such as location and level. For example, the initial permissions of the A City Power Grid Administrator include the A City District (location), the A City Power Grid PMU equipment (object type permissions), the A City Power Grid PDC equipment, and employee account management permissions (other permissions besides access to the power monitoring system). During the permission allocation process, the "access rights to the PMU equipment type of the A City Power Grid" can be determined from the extended permission set, and based on the level of the A City Power Grid Administrator, the access rights to the PMU equipment of the power grid in all subordinate areas within the A City District can be obtained. Therefore, the "access rights to the PMU equipment of the power grid in all subordinate areas within the A City District" are further allocated to the user role.

[0059] S212: Dynamically constrain the access rights based on access constraint rules to obtain constrained target access rights.

[0060] Users have different roles and permissions in different scenarios, which may lead to conflicts between the permissions corresponding to users. Based on this, it is necessary to constrain the polarity of the user's access rights in the current scenario and determine the target access rights based on the constraint rules. The constraint rules can be updated dynamically.

[0061] The method for access control of the power monitoring system provided in the embodiment of the present application divides the permissions according to the accessed objects and types on the power monitoring system side device, expands the initial permissions determined based on user attributes and role division, and in combination with specific scenarios, allocates permissions to user roles from the extended set according to the level of the user role and the attributes of the device in the current scenario, and constrains the access permissions based on constraint rules to determine the user's target access permissions in the current scenario. Which permissions determine which resources can be accessed. This permission control method refines the granularity of resources, improves the efficiency of resource management, simplifies user permission management, and improves the security and reliability of the power monitoring system. It provides important technical support for the defense of the security of the power system intranet, and has far-reaching significance for accelerating the construction of substation measurement and control and secure access to PMU and other equipment.

[0062] In one of the embodiments, the power monitoring system includes: at least one of a phasor measurement unit, a phasor data concentrator, a synchronous phasor auxiliary analysis system, a switch or a time synchronization device.

[0063] Among them, the phasor measurement unit is a phasor measurement unit that uses the global positioning system (GPS) second pulse as a synchronous clock. The PMU based on the GPS clock can measure phasor data such as voltage phase and current phase at the hub of the power system. Through access to the phasor data, based on the acquired data, power system state estimation, dynamic monitoring, stability prediction and control, model verification, relay protection, fault location, etc. can be performed. The installation location and role of equipment such as phasor data concentrators, synchronous phasor auxiliary analysis systems, switches or time synchronization devices in the power system will not be elaborated here. It should be understood that in the present application scheme, resource access to these devices refers to access to multi-dimensional data such as data collected by these devices and data stored by themselves.

[0064] In one embodiment, if Figure 5 As shown, the power monitoring system access rights control method also includes:

[0065] S502: In response to the device access authorization operation for the user, update the target access permission of the user.

[0066] In actual application, the user can also be granted access rights to the equipment in the power monitoring system in the current scenario by directly authorizing the user. The authorization can be an authorization from a user with a high authority level to a user with a low authority level. It can also be an authorization from a manager with authority management authority to a user. The authorization operation can be performed by sending an authorization command from the terminal 102 to the server 104, and the authorization command carries the content of the granted authority. In response to the authorization operation, the server 104 updates the user's target access rights.

[0067] In one embodiment, devices corresponding to the accessed object type with the same characteristics correspond to the same permissions. Based on this, the amount of data that needs to be processed during the permission allocation process can be greatly reduced, and the access permissions of the user role to multiple devices of the same type can be determined.

[0068] In a second aspect, a method for controlling access to a power monitoring system is provided. Figure 6 As shown, the method includes:

[0069] S602: Obtain an access request for the power monitoring system.

[0070] S604, parse the access request to determine the target device in the power monitoring system and the permissions required to allow access to the target device. Parsing the access request to determine the target device that the user wants to access and the permissions required to access the target device can be determined based on the access rules and access policies configured by the access control center. For example, for data access to PMU devices, only user roles with the "administrator" role are allowed to access. The access request can carry the device that the user wants to access, account ID, etc., parse the relevant data in the access request, and query the user attributes required for secure access based on the data. The access permissions required for secure access can be determined based on the required user attributes. Only when the user has the access permission can he successfully access the resource.

[0071] S606, if the permission required for allowing access to the target device is within the target access permission range of the user in the current scenario, then allowing the operation on the resources of the target device;

[0072] The access rights of the user in the current scenario are determined by executing the steps of the above-mentioned method for controlling access rights of the power monitoring system.

[0073] Specifically, after receiving the access request, the access control center of the server 104 determines the required permissions for security access and the target access permissions actually possessed by the user. If the target access permissions cover the required permissions, it means that the user has access rights, and the user is allowed to access the device resources. Furthermore, the target access permissions also include the scope of access to a certain device resource and the scope of operation. For example, having the permission to view the data of a certain device does not necessarily mean having the permission to download the data.

[0074] In order to better help those skilled in the art understand the implementation process of the access control method, a specific embodiment is given here for illustration, but the example here does not limit the number of the above parameters. Figure 3As shown, user attributes are represented by uan, and the user attribute value range is represented by rang. After receiving the access request, the access control center of server 104 first queries the user attributes. Then, roles are assigned to users based on user attributes, and system permissions can also be directly obtained. The device attributes of the power monitoring system are represented by ran, the device resource operation permissions of the power monitoring system are represented by p, and the permission set is represented by P = {p1, p2, p3, ... p n}. The generation of roles is based on permissions. The number of roles is determined by the number of permissions. Therefore, the role generation problem is transformed into the permission division problem.

[0075] Since PMUs in systems such as PMU power monitoring systems have the same properties and are large in number, PMU can be regarded as an access object type, and the access permission to PMU can be set as access object type permission. Other individual devices can be regarded as access objects (that is, those devices that do not have the same characteristics and cannot be operated in the same manner), and the corresponding access permissions can be set as access object permissions.

[0076] uan represents user attributes, rang n Indicates the scope of the permission, Pn indicates the corresponding permission, and rolen indicates the role assigned to the permission. The user role assignment rule is: Allow(assign rolen to user)←((value(user,uan)∈rang n Among them, value(user,uan) is the attribute value function, and the function returns the value of the uan attribute of user.

[0077] In one embodiment, the power monitoring system access control method further includes:

[0078] If the permission required to allow access to the target device is not within the target access permission range of the user in the current scenario, operation on the resources of the target device is prohibited.

[0079] To further improve security, when the target access rights actually possessed by the user do not include the rights required to access the target device, operations on the resources of the target device are prohibited, thereby improving security. At this time, a reminder message can also be sent from the background to the terminal of the administrator for reminder.

[0080] In one of the embodiments, after receiving the access request, the access control center of the server 104 queries the relevant user attributes, adds the relevant user attribute information to the original access request to form a new attribute-based access request ARe, and compares ARe with the permissions in the user's target access permissions (multiple permissions, stored in a set form) determined based on the above-mentioned power monitoring system access permission control method, and the result determines whether the user can operate the resource.

[0081] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0082] In summary, this application proposes a role access control method suitable for an electric power monitoring system. Considering that there are many devices such as PMU in the electric power monitoring system and that they have the same attributes, the attributes of the access object type are introduced, and the access rights are extended to access object rights and access object type rights. The corresponding roles are generated by the division of rights. Users obtain rights through roles according to their attributes, thereby having the possibility to operate the corresponding resources. Then, the rights are screened through constraint rules (which can be constraint sets, and there are conflicting permission relationship descriptions in the constraint sets) to obtain the user's target access rights.

[0083] Based on the traditional RBAC model, the model is improved in combination with the characteristics of the power monitoring system, and the attributes of the access object type are introduced. This makes the access control applicable to the power monitoring system more flexible and the role management more convenient. It enhances the security protection of the substation measurement and control and PMU equipment application function level. It improves the security of the overall power grid monitoring system and lays a solid technical foundation for the construction of a digital power grid and the acceleration of the dispatching information resources.

[0084] Based on the same inventive concept, the embodiment of the present application also provides a power monitoring system access control device for implementing the power monitoring system access control method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more power monitoring system access control device embodiments provided below can refer to the limitations of the power monitoring system access control method above, and will not be repeated here.

[0085] In a third aspect, a device for controlling access rights of a power monitoring system is provided, such as Figure 7 As shown, the device comprises:

[0086] A scenario-based user role determination module 702, used to determine the user role and the authority level of the user role in the current scenario according to the user attributes of the user in the current scenario;

[0087] The device-side classification module 704 is used to classify each device according to the properties of each device in the power monitoring system in the current scenario into a single accessed object and a type of accessed object with the same characteristics;

[0088] The device-side permission module 706 is used to determine the object permission of each of the accessed objects after the division, and the type permission of each type of the accessed object;

[0089] The permission extension module 708 is used to extend the initial permission of the user in the current scenario based on the object permission and the type permission to obtain an extended permission set;

[0090] A preliminary permission determination module 710 is used to assign permissions in the extended permission set to the user role according to the permission level of the user role in the current scenario and the attributes of each of the devices, so as to obtain the user's access rights in the current scenario;

[0091] The target permission determination module 712 is used to dynamically constrain the access permission based on the access constraint rules to obtain the constrained target access permission.

[0092] Based on the same inventive concept, the embodiment of the present application also provides a power monitoring system access control device for implementing the power monitoring system access control method involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more power monitoring system access control device embodiments provided below can refer to the limitations of the power monitoring system access control method above, and will not be repeated here.

[0093] In a fourth aspect, a power monitoring system access control device is provided, such as Figure 8As shown, the device comprises

[0094] An access request acquisition module 802, used to acquire an access request for a power monitoring system;

[0095] A required authority determination module 804, configured to parse the access request, determine a target device in the power monitoring system and the authority required to allow access to the target device;

[0096] The permission comparison module 806 is used to allow the operation on the resources of the target device when the permission required for allowing the access to the target device is within the target access permission range of the user in the current scenario;

[0097] The access rights of the user in the current scenario are determined by executing the steps of the above-mentioned method for controlling access rights of the power monitoring system.

[0098] Each module in the above-mentioned device can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each of the above modules. It should be noted that the device provided in the embodiment of the present application may also include other units or modules to perform other steps in the above-mentioned method embodiment to achieve corresponding functions and beneficial effects, which will not be described in detail here.

[0099] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Fig. 9 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as the target access rights of users in various application scenarios determined based on the power monitoring system access rights control method. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in the above method embodiment are implemented and the corresponding beneficial effects are achieved.

[0100] Those skilled in the art will understand that Fig. 9 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0101] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the method steps in the above method embodiment are implemented and corresponding beneficial effects are achieved, which are not described in detail here.

[0102] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method steps in the above method embodiment are implemented and corresponding beneficial effects are achieved, which are not elaborated here.

[0103] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the method steps in the above method embodiment are implemented and corresponding beneficial effects are achieved, which are not described in detail here.

[0104] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0105] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0106] The technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0107] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for controlling access rights of an electric power monitoring system, characterized in that: The method comprises: Determine the user role and the permission level of the user role in the current scenario according to the user attributes in the current scenario; According to the properties of each device in the power monitoring system in the current scenario, each of the devices is divided into a single accessed object and a type of accessed object with the same characteristics; Determine the object authority of each of the accessed objects after the division, and the type authority of each type of the accessed object; Expanding the initial permissions of the user in the current scenario based on the object permissions and the type permissions to obtain an extended permission set; According to the permission level of the user role in the current scenario and the attributes of each of the devices, the permissions in the extended permission set are allocated to the user role to obtain the user's access rights in the current scenario; The access rights are dynamically constrained based on the access constraint rules to obtain constrained target access rights.

2. The method according to claim 1, characterized in that The power monitoring system comprises: at least one of a phasor measurement unit, a phasor data concentrator, a synchronous phasor auxiliary analysis system, a switch or a time synchronization device.

3. The method according to claim 1, characterized in that The method further comprises: In response to a device access authorization operation for the user, the target access permission of the user is updated.

4. The method according to claim 1, characterized in that Devices corresponding to accessed object types with the same characteristics have the same permissions.

5. A method for access control of a power monitoring system, characterized in that: The method comprises: Obtain access requests to power monitoring systems; Parsing the access request to determine a target device in the power monitoring system and permissions required to allow access to the target device; If the permission required to allow access to the target device is within the target access permission range of the user in the current scenario, then the operation on the resources of the target device is allowed; The access rights of the user in the current scenario are determined by executing the steps of the method for controlling access rights of the power monitoring system according to any one of claims 1 to 4.

6. The method according to claim 5, characterized in that The method further comprises: If the permission required to allow access to the target device is not within the target access permission range of the user in the current scenario, operation on the resources of the target device is prohibited.

7. A power monitoring system access rights control device, characterized in that: The device comprises: A scenario-based user role determination module, used to determine the user role and the permission level of the user role in the current scenario according to the user attributes of the user in the current scenario; The device-side classification module is used to classify each device according to the attributes of each device in the power monitoring system in the current scenario into a single accessed object and a type of accessed object with the same characteristics; A device-side permission module, used to determine the object permission of each of the accessed objects after the division, and the type permission of each type of the accessed object; A permission extension module, used to extend the initial permission of the user in the current scenario based on the object permission and the type permission to obtain an extended permission set; A preliminary permission determination module, used to assign permissions in the extended permission set to the user role according to the permission level of the user role in the current scenario and the attributes of each of the devices, so as to obtain the user's access rights in the current scenario; The target permission determination module is used to dynamically constrain the access permission based on the access constraint rules to obtain the constrained target access permission.

8. An access control device for a power monitoring system, characterized in that: The device comprises An access request acquisition module, used to acquire an access request for a power monitoring system; A required authority determination module, used to parse the access request, determine the target device in the power monitoring system and the authority required to allow access to the target device; A permission comparison module, used to allow operation on resources of the target device when the permission required for allowing access to the target device is within the target access permission range of the user in the current scenario; The access rights of the user in the current scenario are determined by executing the steps of the method for controlling access rights of the power monitoring system according to any one of claims 1 to 4.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Role-based access control situation awareness defense method and system

    CN113411295A

  • Hybrid role and attribute based access control system

    US20190362087A1