Industrial Park Safety Risk Management Method and System

By obtaining the system topology in the industrial park and determining key equipment and hiding key equipment, the management terminal can monitor and analyze the equipment status with low overhead, solving the problem of overhead in the existing technology, and achieving effective security risk control.

CN119624144BActive Publication Date: 2025-05-23CHINA MOBILE (XIONGAN) ICT CO LTD

Patent Information

Application Number
CN202510162730.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-23
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

When the prior art monitors the status of equipment in industrial parks to manage safety risks, the overhead is high and it is difficult to achieve low overhead risk control.

Method used

By obtaining the system topology of the industrial park, the management terminal determines key equipment and hides key equipment, and conducts monitoring and analysis to determine the safety risk situation of the industrial park.

Benefits of technology

It realizes low-overhead safety risk control in industrial parks, can effectively monitor and analyze the operating data of key equipment and hide the key equipment, and timely identify security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119624144B_ABST
    Figure CN119624144B_ABST
Patent Text Reader

Abstract

The present application provides a method and system for industrial park security risk management, which belongs to the field of data processing technology, to achieve low-overhead industrial park security risk management. The method includes: the management terminal obtains the system topology in the designated industrial park, the designated industrial park is the industrial park managed by the management terminal, the system topology is used to indicate the working dependency of multiple devices in the designated industrial park, and each of the multiple devices corresponds to a node in the system topology; the management terminal determines the key devices and hidden key devices in the multiple devices from the system topology, and the key devices and hidden key devices are devices that affect the work of at least two devices in the multiple devices; the management terminal monitors and analyzes the key devices and hidden key devices to determine the security risk situation of the designated industrial park.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing, and in particular to a method and system for controlling safety risks in industrial parks. Background Art

[0002] In the context of globalization and rapid technological development, risk management in industrial parks has become a key factor in ensuring production safety and efficiency. With the advent of the Industrial 4.0 era, industrial parks are facing a more complex and dynamic risk environment. Traditional risk management methods often rely on manual monitoring and regular inspections, which to a certain extent cannot meet the needs of modern industry. Therefore, monitoring equipment status as an important part of risk management has gradually received widespread attention in the industry.

[0003] Monitoring equipment status is the basis of risk management in industrial parks. By monitoring the working status and performance parameters of key equipment in real time, abnormal conditions can be detected in time to prevent potential failures and accidents. This not only helps to reduce downtime and production losses, but also effectively avoids safety accidents caused by equipment failure. In addition, the monitoring data of equipment status can also be used for equipment maintenance and optimization management, improving the reliability and service life of equipment.

[0004] At present, the technical means of monitoring the status of equipment in industrial parks mainly include sensor technology, Internet of Things (IoT), big data analysis and artificial intelligence (AI). Sensor technology can collect key parameters such as temperature, pressure, vibration, etc. of equipment in real time; IoT technology connects these sensors through the network to achieve remote transmission and centralized management of data; big data analysis is used to process and analyze massive data and predict the safety risks of equipment. However, this method is relatively expensive, and how to achieve low-cost industrial park safety risk management is a current research issue. Summary of the invention

[0005] The embodiments of the present application provide a method and system for industrial park security risk management and control to achieve low-cost industrial park security risk management and control.

[0006] In order to achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, a method for controlling security risks in an industrial park is provided, which is applied to a management terminal, and the method includes: the management terminal obtains a system topology within a specified industrial park, and the specified industrial park is an industrial park managed by the management terminal, and the system topology is used to indicate the working dependencies of multiple devices in the specified industrial park, and each of the multiple devices corresponds to a node in the system topology; the management terminal determines key devices and hidden key devices among the multiple devices from the system topology, and the key devices and hidden key devices are devices that affect the work of at least two of the multiple devices; the management terminal monitors and analyzes the key devices and hidden key devices to determine the security risk situation of the specified industrial park.

[0008] Optionally, the system topology includes multiple branches, and the management terminal determines the key devices and hidden key devices among the multiple devices from the system topology, including: the management terminal determines the root node of each branch among the multiple branches as the key node, and determines the device represented by the key node as the key device, and at least two branches among the multiple branches share the same root node; the management terminal determines the hidden key device based on the topological relationship of the key devices in the system topology.

[0009] Optionally, the management terminal determines the hidden key device based on the topological relationship of the key device in the system topology, including: the management terminal determines the nodes that belong to the same branch as the key device, are separated from the key device by at least one node, and do not belong to other branches as hidden key nodes, and determines the devices corresponding to the hidden key nodes as hidden key devices. For each branch among multiple branches that has the function of selecting a hidden key device, the branch is only allowed to select one hidden key device.

[0010] Optionally, for each branch with a hidden key device in the multiple branches, the branch includes K child nodes. If the last child node among the K child nodes is not the root node of other branches, and K is an integer greater than 2, then the last child node among the K child nodes is the root node of other branches. The child node is determined as a hidden key node. If the last child node among the K child nodes is the root node of other branches, and K is an integer greater than 3, then the first child node among the K child nodes is the root node of other branches. child nodes are identified as hidden key nodes. Indicates rounding down.

[0011] Optionally, the management terminal monitors and analyzes key equipment and hidden key equipment to determine the security risk situation of the designated industrial park, including: the management terminal obtains the operating data of the key equipment from the key equipment, and analyzes the operating data of the key equipment to determine whether there is a security risk in the operation of the key equipment; the management terminal obtains the operating data of the hidden key equipment from the hidden key equipment, and analyzes the operating data of the hidden key equipment to determine whether there is a security risk in the operation of the hidden key equipment; wherein the security risk situation of the designated industrial park includes: whether there is a security risk in the operation of the key equipment and whether there is a security risk in the operation of the hidden key equipment.

[0012] Optionally, the management terminal monitors and analyzes key devices and hidden key devices to determine the security risk situation of the designated industrial park, including: the management terminal jointly monitors and analyzes key devices and hidden key devices with topological coupling relationships to determine the security risk situation of the designated industrial park.

[0013] Optionally, the management terminal conducts joint monitoring and analysis on key devices and hidden key devices with topological coupling relationships to determine the security risk situation of a designated industrial park, including: for key devices and hidden key devices belonging to the same branch among multiple branches, the management terminal obtains the operating data of the key devices from the key devices, and obtains the operating data of the hidden key devices from the hidden key devices, and the operating data of the key devices and the operating data of the hidden key devices are data within the same time period; the management terminal conducts a coupling degree analysis on the operating data of the key devices and the operating data of the hidden key devices to determine whether there are security risks in the branches where the key devices and the hidden key devices are located; wherein the security risk situation of a designated industrial park includes: whether there are security risks in the branches where the key devices and the hidden key devices are located.

[0014] Optionally, the management terminal performs a coupling degree analysis on the operating data of the key device and the operating data of the hidden key device to determine whether there is a security risk in the branch where the key device and the hidden key device are located, including: the management terminal maps the operating data of the key device to a first vector matrix based on a mapping rule, and maps the operating data of the hidden key device to a second vector matrix based on the mapping rule; wherein each column vector in the first vector matrix corresponds to a type of operating data in the operating data of the key device, each vector in the first vector matrix corresponds to an operating data in the operating data of the key device, each column vector in the second vector matrix corresponds to a type of operating data in the operating data of the hidden key device, and each vector in the second vector matrix corresponds to an operating data in the operating data of the hidden key device; the management terminal determines the vector inner product of the first vector matrix and the second vector matrix, if the vector inner product is greater than or equal to a preset inner product threshold, it indicates that there is a security risk in the branch where the key device and the hidden key device are located, if the vector inner product is less than the preset inner product threshold, it indicates that there is no security risk in the branch where the key device and the hidden key device are located.

[0015] Optionally, the management terminal obtains the system topology in the specified industrial park, including: the management terminal obtains the system topology in the specified industrial park from the cloud system.

[0016] In a second aspect, a security risk management and control system for an industrial park is provided, which includes a management terminal, and the management terminal is configured as follows: the management terminal obtains a system topology within a specified industrial park, and the specified industrial park is an industrial park managed by the management terminal, and the system topology is used to indicate the working dependencies of multiple devices within the specified industrial park, and each of the multiple devices corresponds to a node in the system topology; the management terminal determines key devices and hidden key devices among the multiple devices from the system topology, and the key devices and hidden key devices are devices that affect the work of at least two of the multiple devices; the management terminal monitors the key devices and hidden key devices to determine the security risk situation of the specified industrial park.

[0017] Optionally, the system topology includes multiple branches, and the management terminal determines the key devices and hidden key devices among the multiple devices from the system topology, including: the management terminal determines the root node of each branch among the multiple branches as the key node, and determines the device represented by the key node as the key device, and at least two branches among the multiple branches share the same root node; the management terminal determines the hidden key device based on the topological relationship of the key devices in the system topology.

[0018] Optionally, the management terminal determines the hidden key device based on the topological relationship of the key device in the system topology, including: the management terminal determines the nodes that belong to the same branch as the key device, are separated from the key device by at least one node, and do not belong to other branches as hidden key nodes, and determines the devices corresponding to the hidden key nodes as hidden key devices. For each branch among multiple branches that has the function of selecting a hidden key device, the branch is only allowed to select one hidden key device.

[0019] Optionally, for each branch with a hidden key device in the multiple branches, the branch includes K child nodes. If the last child node among the K child nodes is not the root node of other branches, and K is an integer greater than 2, then the last child node among the K child nodes is the root node of other branches. The child node is determined as a hidden key node. If the last child node among the K child nodes is the root node of other branches, and K is an integer greater than 3, then the first child node among the K child nodes is the root node of other branches. child nodes are identified as hidden key nodes. Indicates rounding down.

[0020] Optionally, the management terminal monitors and analyzes key equipment and hidden key equipment to determine the security risk situation of the designated industrial park, including: the management terminal obtains the operating data of the key equipment from the key equipment, and analyzes the operating data of the key equipment to determine whether there is a security risk in the operation of the key equipment; the management terminal obtains the operating data of the hidden key equipment from the hidden key equipment, and analyzes the operating data of the hidden key equipment to determine whether there is a security risk in the operation of the hidden key equipment; wherein the security risk situation of the designated industrial park includes: whether there is a security risk in the operation of the key equipment and whether there is a security risk in the operation of the hidden key equipment.

[0021] Optionally, the management terminal monitors and analyzes key devices and hidden key devices to determine the security risk situation of the designated industrial park, including: the management terminal jointly monitors and analyzes key devices and hidden key devices with topological coupling relationships to determine the security risk situation of the designated industrial park.

[0022] Optionally, the management terminal conducts joint monitoring and analysis on key devices and hidden key devices with topological coupling relationships to determine the security risk situation of a designated industrial park, including: for key devices and hidden key devices belonging to the same branch among multiple branches, the management terminal obtains the operating data of the key devices from the key devices, and obtains the operating data of the hidden key devices from the hidden key devices, and the operating data of the key devices and the operating data of the hidden key devices are data within the same time period; the management terminal conducts a coupling degree analysis on the operating data of the key devices and the operating data of the hidden key devices to determine whether there are security risks in the branches where the key devices and the hidden key devices are located; wherein the security risk situation of a designated industrial park includes: whether there are security risks in the branches where the key devices and the hidden key devices are located.

[0023] Optionally, the management terminal performs a coupling degree analysis on the operating data of the key device and the operating data of the hidden key device to determine whether there is a security risk in the branch where the key device and the hidden key device are located, including: the management terminal maps the operating data of the key device to a first vector matrix based on a mapping rule, and maps the operating data of the hidden key device to a second vector matrix based on the mapping rule; wherein each column vector in the first vector matrix corresponds to a type of operating data in the operating data of the key device, each vector in the first vector matrix corresponds to an operating data in the operating data of the key device, each column vector in the second vector matrix corresponds to a type of operating data in the operating data of the hidden key device, and each vector in the second vector matrix corresponds to an operating data in the operating data of the hidden key device; the management terminal determines the vector inner product of the first vector matrix and the second vector matrix, if the vector inner product is greater than or equal to a preset inner product threshold, it indicates that there is a security risk in the branch where the key device and the hidden key device are located, if the vector inner product is less than the preset inner product threshold, it indicates that there is no security risk in the branch where the key device and the hidden key device are located.

[0024] Optionally, the management terminal obtains the system topology in the specified industrial park, including: the management terminal obtains the system topology in the specified industrial park from the cloud system.

[0025] In a third aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are executed on a computer, the computer is caused to execute the method described in the first aspect.

[0026] According to a fourth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed on a computer, causes the computer to execute the method described in the first aspect.

[0027] In summary, by obtaining the system topology within the specified industrial park, the management terminal can determine the key devices and hidden key devices among multiple devices from the system topology, that is, the devices that affect the operation of at least two devices among the multiple devices; thus, the management terminal can determine the security risk situation of the specified industrial park by monitoring and analyzing only the key devices and hidden key devices, thereby realizing low-overhead industrial park security risk management. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 A schematic diagram of the architecture of a monitoring system provided in an embodiment of the present application;

[0029] Figure 2 A schematic diagram of a process for industrial park safety risk management and control method provided in an embodiment of the present application;

[0030] Figure 3 A schematic diagram of an application scenario of an industrial park safety risk management method provided in an embodiment of the present application;

[0031] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] In view of the above technical problems, the embodiments of the present application propose the following technical solutions. The technical solutions in the present application will be described below in conjunction with the accompanying drawings.

[0033] The present application will present various aspects, embodiments or features around a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. In addition, combinations of these schemes may also be used.

[0034] In addition, in the embodiments of the present application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present concepts in a concrete way.

[0035] First, in this application, "used to indicate" may include being used to indicate directly or indirectly. When describing that a certain "information" is used to indicate A, it may include that the information directly indicates A or indirectly indicates A, but it does not mean that the information must contain A.

[0036] The information indicated by a piece of information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, directly indicating the information to be indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified by the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0037] In addition, the specific indication method may also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can refer to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, different indication methods may be used for different information. In the specific implementation process, the desired indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0038] Second, in the embodiments shown below, the first, second and various digital numbers are only used for the convenience of description and are not used to limit the scope of the embodiments of the present application. For example, to distinguish different indication information.

[0039] Third, "pre-set", "pre-defined", or "pre-configured" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in a device (for example, including a terminal device and a network device), or can be pre-specified in a protocol. The present application does not limit its specific implementation method. Among them, "save" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, which is not limited by the present application.

[0040] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person of ordinary skill in the art can appreciate that with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0041] To facilitate understanding of the embodiments of the present application, first Figure 1 The monitoring system shown in the example is used to describe in detail the communication system applicable to the embodiment of the present application. Figure 1 A schematic diagram of the architecture of a monitoring system applicable to the method provided in an embodiment of the present application.

[0042] like Figure 1 As shown, the monitoring system includes: a management terminal and equipment.

[0043] The management terminal is the terminal device, or terminal.

[0044] The terminal may also be called user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device. The terminal in the embodiments of the present application may be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle terminal, an RSU with terminal function, etc. The terminal of the present application may also be a vehicle module, a vehicle module, a vehicle component, a vehicle chip or a vehicle unit built into a vehicle as one or more components or units.

[0045] Equipment can specify equipment in an industrial park. Designate an industrial park as an industrial park managed by the management terminal. For different industrial parks, the type of equipment can also be different. For example, for a power park (such as a power plant), the equipment can be power generation equipment, substation equipment, distribution equipment, transmission equipment, etc. For another example, for an industrial park, the equipment can be various equipment on a production line, without specific restrictions.

[0046] The device can be connected to the management terminal through a network (such as a wireless network or a wired network).

[0047] For example, Figure 2 The flowchart of the industrial park security risk management method provided in the embodiment of the present application is shown in FIG. The industrial park security risk management method can be applied to the communication between the management terminal and the device in the above-mentioned monitoring system. Figure 2As shown in the figure, the process of the industrial park safety risk management method is as follows:

[0048] S201, the management terminal obtains the system topology in the designated industrial park.

[0049] The designated industrial park is the industrial park managed by the management terminal. The system topology is used to indicate the working dependencies of multiple devices in the designated industrial park. Each of the multiple devices corresponds to a node in the system topology. For example, two connected nodes in the system topology are parent-child nodes, indicating that the output result of the device corresponding to the parent node, such as information / energy / product, needs to be further processed by the device corresponding to the child node. For example, in the power scenario, the generator (i.e., the device) outputs power to the transformer (i.e., the device), which is stepped up by the transformer and then input to the distribution device (i.e., the device), etc.

[0050] The management terminal obtains the system topology in the specified industrial park from the cloud system, such as sending the identifier of the specified industrial park and the requested topology information to the cloud system, so that the cloud system returns the system topology in the specified industrial park to the management terminal.

[0051] S202: The management terminal determines key devices and hidden key devices among multiple devices from the system topology.

[0052] The key device and the hidden key device are devices that affect the operation of at least two devices among the multiple devices, that is, devices that are directly connected to the devices corresponding to at least two nodes.

[0053] For example, the system topology includes multiple branches, and the management terminal determines the root node of each of the multiple branches as a key node, and determines the device represented by the key node as a key device, and at least two branches among the multiple branches share the same root node. The management terminal can determine the hidden key device based on the topological relationship of the key device in the system topology. Specifically, the management terminal determines the node that belongs to the same branch as the key device, is separated from the key device by at least one node, and does not belong to other branches as a hidden key node, and determines the device corresponding to the hidden key node as a determined hidden key device. For each branch in the multiple branches that has the ability to select a hidden key device, the branch is only allowed to select one hidden key device. Among them, for each branch in the multiple branches that has the ability to select a hidden key device, the branch includes K child nodes. If the last child node among the K child nodes is not the root node of other branches, and K is an integer greater than 2, then the first child node among the K child nodes is not the root node of other branches. The child node is determined as a hidden key node. If the last child node among the K child nodes is the root node of other branches, and K is an integer greater than 3, then the first child node among the K child nodes is the root node of other branches. child nodes are identified as hidden key nodes. Indicates rounding down.

[0054] For ease of understanding, the following is an example. Figure 3 As shown, the system topology can be Figure 3 As shown in the figure, the system topology is a tree structure, including 8 branches, such as branch 1 to branch 8. For a branch, the first node of the branch is the root node. If it forks at the last node of the branch, that is, other branches are generated, then the last node of the branch is the root node of other branches. Therefore, there are 4 root nodes in total from branch 1 to branch 8, among which branches 4, branch 3, and branch 7 share the root node, branches 5 and branch 6 share the root node, and branches 2 and branch 8 share the root node. These 4 root nodes are used as key nodes. Branch 6 has 4 child nodes, that is, K=4. According to , that is, the third node is a hidden key node. Branch 3 has 4 child nodes, that is, K=3. , that is, the second node is used as a hidden key node.

[0055] It can be seen that the hidden key node needs to be located in the middle of the branch and slightly behind. For example, for branch 6, the third node is selected instead of the second node because the first node can be affected by the key node, while the second node can only affect the third node and cannot be directly affected by the root node, so the third node is selected.

[0056] S203, the management terminal monitors and analyzes key equipment and hidden key equipment to determine the security risk situation of the designated industrial park.

[0057] In one possible way, the management terminal obtains the operating data of the key equipment from the key equipment, and analyzes the operating data of the key equipment to determine whether there is a security risk in the operation of the key equipment. For example, the operating data of the key equipment may include various indicators of the key equipment, such as temperature, load, power, voltage, current, efficiency, etc., which may vary according to the type of equipment and are not limited. The management terminal may calculate the difference between each data in the operating data of the key equipment and the corresponding threshold data. If the data exceeding the proportion exceeds the threshold data, it is considered that there is a security risk. Similarly, the management terminal may also obtain the operating data of the hidden key equipment from the hidden key equipment, and analyze the operating data of the hidden key equipment to determine whether there is a security risk in the operation of the hidden key equipment. Therefore, the security risk situation of the designated industrial park includes: whether there is a security risk in the operation of the key equipment and whether there is a security risk in the operation of the hidden key equipment.

[0058] In another possible approach, the management terminal conducts joint monitoring and analysis on key devices and hidden key devices with topological coupling relationships to determine the security risk situation of a designated industrial park.

[0059] For example, for key devices and hidden key devices belonging to the same branch in multiple branches, such as Figure 3 The root node and the third node in the . The management terminal can obtain the operating data of the key equipment from the key equipment, and obtain the operating data of the hidden key equipment from the hidden key equipment. The operating data of the key equipment and the operating data of the hidden key equipment are data within the same time period, and can contain the same type of operating data, such as temperature, load, voltage, and current. The management terminal performs a coupling analysis on the operating data of the key equipment and the operating data of the hidden key equipment to determine whether there are security risks in the branches where the key equipment and the hidden key equipment are located. Among them, the security risk situation of the designated industrial park includes: whether there are security risks in the branches where the key equipment and the hidden key equipment are located.

[0060] For example, the management terminal maps the operation data of the key equipment to the first vector matrix based on the mapping rule, and maps the operation data of the hidden key equipment to the second vector matrix based on the mapping rule. Among them, each column vector in the first vector matrix corresponds to a type of operation data in the operation data of the key equipment, and each vector in the first vector matrix corresponds to an operation data in the operation data of the key equipment, that is, one type of operation data, such as each data collected at different times, is mapped to a vector, that is, a column vector is obtained, and multiple types of operation data are mapped to obtain multiple column vectors, thereby obtaining the first vector matrix. For example, the temperature data includes the temperatures collected at 100 times, and the corresponding mapping to a column vector includes 100 vectors. The number of rows of the first vector matrix can depend on the type of operation data with the largest number of data in the operation data, such as X. The number of data of other types of operation data (such as Y) is less than X, so filling can be used during mapping, such as filling XY 0 vectors to ensure the consistency of the matrix structure. Each column vector in the second vector matrix corresponds to one of the operating data of the hidden key device, and each vector in the second vector matrix corresponds to one of the operating data of the hidden key device. The principle is similar to the first vector matrix mentioned above, please refer to it for understanding. The management terminal determines the vector inner product of the first vector matrix and the second vector matrix. If the vector inner product is greater than or equal to the preset inner product threshold, it indicates that the branch where the key device and the hidden key device are located has a security risk. If the vector inner product is less than the preset inner product threshold, it indicates that the branch where the key device and the hidden key device are located does not have a security risk.

[0061] That is to say, for the key equipment and hidden key equipment of the same branch, the changes in their operating status over a period of time should be similar. For example, if the load of the key equipment increases over a period of time, the load of the hidden key equipment will usually increase during this period of time. Therefore, this correlation can be reflected by calculating the inner product of the vector. If the operating status changes are close, the inner product of the vector is usually smaller. Otherwise, it is larger, which also indicates that there is a security risk.

[0062] In summary, by obtaining the system topology within the specified industrial park, the management terminal can determine the key devices and hidden key devices among multiple devices from the system topology, that is, the devices that affect the operation of at least two devices among the multiple devices; thus, the management terminal can determine the security risk situation of the specified industrial park by monitoring and analyzing only the key devices and hidden key devices, thereby realizing low-overhead industrial park security risk management.

[0063] Combination of the above Figure 2 The industrial park safety risk management method provided by the embodiment of the present application is described in detail. The industrial park safety risk management system used to execute the method provided by the embodiment of the present application is described in detail below.

[0064] The industrial park security risk management and control system includes a management terminal, which is configured as follows: the management terminal obtains a system topology within a designated industrial park, the designated industrial park is an industrial park managed by the management terminal, the system topology is used to indicate the working dependencies of multiple devices within the designated industrial park, and each of the multiple devices corresponds to a node in the system topology; the management terminal determines key devices and hidden key devices among the multiple devices from the system topology, and the key devices and hidden key devices are devices that affect the work of at least two of the multiple devices; the management terminal monitors the key devices and hidden key devices to determine the security risk situation of the designated industrial park.

[0065] Optionally, the system topology includes multiple branches, and the management terminal determines the key devices and hidden key devices among the multiple devices from the system topology, including: the management terminal determines the root node of each branch among the multiple branches as the key node, and determines the device represented by the key node as the key device, and at least two branches among the multiple branches share the same root node; the management terminal determines the hidden key device based on the topological relationship of the key devices in the system topology.

[0066] Optionally, the management terminal determines the hidden key device based on the topological relationship of the key device in the system topology, including: the management terminal determines the nodes that belong to the same branch as the key device, are separated from the key device by at least one node, and do not belong to other branches as hidden key nodes, and determines the devices corresponding to the hidden key nodes as hidden key devices. For each branch among multiple branches that has the function of selecting a hidden key device, the branch is only allowed to select one hidden key device.

[0067] Optionally, for each branch with a hidden key device in the multiple branches, the branch includes K child nodes. If the last child node among the K child nodes is not the root node of other branches, and K is an integer greater than 2, then the last child node among the K child nodes is the root node of other branches. The child node is determined as a hidden key node. If the last child node among the K child nodes is the root node of other branches, and K is an integer greater than 3, then the first child node among the K child nodes is the root node of other branches. child nodes are identified as hidden key nodes. Indicates rounding down.

[0068] Optionally, the management terminal monitors and analyzes key equipment and hidden key equipment to determine the security risk situation of the designated industrial park, including: the management terminal obtains the operating data of the key equipment from the key equipment, and analyzes the operating data of the key equipment to determine whether there is a security risk in the operation of the key equipment; the management terminal obtains the operating data of the hidden key equipment from the hidden key equipment, and analyzes the operating data of the hidden key equipment to determine whether there is a security risk in the operation of the hidden key equipment; wherein the security risk situation of the designated industrial park includes: whether there is a security risk in the operation of the key equipment and whether there is a security risk in the operation of the hidden key equipment.

[0069] Optionally, the management terminal monitors and analyzes key devices and hidden key devices to determine the security risk situation of the designated industrial park, including: the management terminal jointly monitors and analyzes key devices and hidden key devices with topological coupling relationships to determine the security risk situation of the designated industrial park.

[0070] Optionally, the management terminal conducts joint monitoring and analysis on key devices and hidden key devices with topological coupling relationships to determine the security risk situation of a designated industrial park, including: for key devices and hidden key devices belonging to the same branch among multiple branches, the management terminal obtains the operating data of the key devices from the key devices, and obtains the operating data of the hidden key devices from the hidden key devices, and the operating data of the key devices and the operating data of the hidden key devices are data within the same time period; the management terminal conducts a coupling degree analysis on the operating data of the key devices and the operating data of the hidden key devices to determine whether there are security risks in the branches where the key devices and the hidden key devices are located; wherein the security risk situation of a designated industrial park includes: whether there are security risks in the branches where the key devices and the hidden key devices are located.

[0071] Optionally, the management terminal performs a coupling degree analysis on the operating data of the key device and the operating data of the hidden key device to determine whether there is a security risk in the branch where the key device and the hidden key device are located, including: the management terminal maps the operating data of the key device to a first vector matrix based on a mapping rule, and maps the operating data of the hidden key device to a second vector matrix based on the mapping rule; wherein each column vector in the first vector matrix corresponds to a type of operating data in the operating data of the key device, each vector in the first vector matrix corresponds to an operating data in the operating data of the key device, each column vector in the second vector matrix corresponds to a type of operating data in the operating data of the hidden key device, and each vector in the second vector matrix corresponds to an operating data in the operating data of the hidden key device; the management terminal determines the vector inner product of the first vector matrix and the second vector matrix, if the vector inner product is greater than or equal to a preset inner product threshold, it indicates that there is a security risk in the branch where the key device and the hidden key device are located, if the vector inner product is less than the preset inner product threshold, it indicates that there is no security risk in the branch where the key device and the hidden key device are located.

[0072] Optionally, the management terminal obtains the system topology in the specified industrial park, including: the management terminal obtains the system topology in the specified industrial park from the cloud system.

[0073] For example, Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may be a terminal, or a chip (system) or other components or assemblies that may be provided in a terminal. Figure 4 As shown, the electronic device 1000 may include a processor 1001. Optionally, the electronic device 1000 may further include a memory 1002 and / or a transceiver 1003. The processor 1001 is coupled with the memory 1002 and the transceiver 1003, such as being connected via a communication bus.

[0074] Combine the following Figure 4The components of the electronic device 1000 are described in detail:

[0075] The processor 1001 is the control center of the electronic device 1000, and may be a processor or a general term for multiple processing elements. For example, the processor 1001 is one or more central processing units (CPUs), or may be application specific integrated circuits (ASICs), or may be one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (digital signal processors, DSPs), or one or more field programmable gate arrays (FPGAs).

[0076] Optionally, the processor 1001 can execute various functions of the electronic device 1000 by running or executing the software program stored in the memory 1002 and calling the data stored in the memory 1002, such as executing the above Figure 2 The method shown.

[0077] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as Figure 4 CPU0 and CPU1 are shown in FIG.

[0078] In a specific implementation, as an embodiment, the electronic device 1000 may also include multiple processors, such as Figure 4 1 and 1004. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0079] The memory 1002 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 1001. The specific implementation method can refer to the above method embodiment, which will not be repeated here.

[0080] Optionally, the memory 1002 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1002 may be integrated with the processor 1001, or may exist independently and access the computer through the interface circuit ( Figure 4 1002 is coupled to the processor 1001, which is not specifically limited in this embodiment of the present application.

[0081] The transceiver 1003 is used for communication with other electronic devices. For example, if the electronic device 1000 is a terminal, the transceiver 1003 can be used to communicate with a network device, or with another terminal device. For another example, if the electronic device 1000 is a network device, the transceiver 1003 can be used to communicate with a terminal, or with another network device.

[0082] Optionally, the transceiver 1003 may include a receiver and a transmitter ( Figure 4 The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0083] Optionally, the transceiver 1003 may be integrated with the processor 1001, or may exist independently and communicate with the electronic device 1000 through an interface circuit ( Figure 4 1002 is coupled to the processor 1001, which is not specifically limited in this embodiment of the present application.

[0084] It should be noted that Figure 4 The structure of the electronic device 1000 shown in the figure does not constitute a limitation on the electronic device, and the actual electronic device may include more or less components than those shown in the figure, or combine certain components, or arrange the components differently.

[0085] In addition, the technical effects of the electronic device 1000 can refer to the technical effects of the channel state information feedback method described in the above method embodiment, which will not be repeated here.

[0086] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0087] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0088] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.

[0089] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.

[0090] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0091] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0092] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0093] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0094] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0095] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0096] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0097] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program codes.

[0098] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method for safety risk management and control in an industrial park, characterized in that: Applied to a management terminal, the method comprises: The management terminal acquires a system topology in a designated industrial park, where the designated industrial park is an industrial park managed by the management terminal, and the system topology is used to indicate a working dependency relationship between multiple devices in the designated industrial park, where the system topology includes multiple branches, and each of the multiple devices corresponds to a node in the system topology; The management terminal determines the key devices and hidden key devices among the multiple devices from the system topology, including: the management terminal determines the root node of each of the multiple branches as the key node, and determines the device represented by the key node as the key device, and at least two of the multiple branches share the same root node; the management terminal determines the hidden key device according to the topological relationship of the key device in the system topology, the method is: the management terminal determines the node that belongs to the same branch as the key device, is separated from the key device by at least one node, and does not belong to other branches as a hidden key node, and determines the device corresponding to the hidden key node as the hidden key device, and for each branch in the multiple branches that has the ability to select the hidden key device, the branch is only allowed to select one of the hidden key devices; The key device and the hidden key device are devices that affect the operation of at least two devices among the multiple devices; The management terminal monitors and analyzes the key equipment and the hidden key equipment to determine the security risk situation of the designated industrial park.

2. The industrial park safety risk management method according to claim 1 is characterized in that: For each branch of the plurality of branches that has the function of selecting the hidden key device, the branch includes K child nodes. If the last child node of the K child nodes is not the root node of other branches, and K is an integer greater than 2, then the last child node of the K child nodes is the root node of other branches. The child node is determined as the hidden key node. If the last child node among the K child nodes is used as the root node of other branches, and K is an integer greater than 3, then the last child node among the K child nodes is the root node of other branches. child nodes are determined as the hidden key nodes, Indicates rounding down.

3. The industrial park safety risk management method according to claim 1 is characterized in that: The management terminal monitors and analyzes the key equipment and the hidden key equipment to determine the security risk situation of the designated industrial park, including: The management terminal obtains the operation data of the key equipment from the key equipment, and analyzes the operation data of the key equipment to determine whether there is a safety risk in the operation of the key equipment; The management terminal obtains the operation data of the hidden key device from the hidden key device, and analyzes the operation data of the hidden key device to determine whether there is a security risk in the operation of the hidden key device; Among them, the safety risk situation of the designated industrial park includes: whether there are safety risks in the operation of the key equipment and whether there are safety risks in the operation of the hidden key equipment.

4. The industrial park safety risk management method according to claim 1 is characterized in that: The management terminal monitors and analyzes the key equipment and the hidden key equipment to determine the security risk situation of the designated industrial park, including: The management terminal jointly monitors and analyzes the key devices and the hidden key devices having a topological coupling relationship to determine the security risk situation of the designated industrial park.

5. The industrial park safety risk management method according to claim 4 is characterized in that: The management terminal performs joint monitoring and analysis on the key devices and the hidden key devices having a topological coupling relationship to determine the security risk situation of the designated industrial park, including: For the key device and the hidden key device belonging to the same branch among the multiple branches, the management terminal obtains the operation data of the key device from the key device, and obtains the operation data of the hidden key device from the hidden key device, and the operation data of the key device and the operation data of the hidden key device are data within the same time period; The management terminal performs coupling analysis on the operation data of the key device and the operation data of the hidden key device to determine whether there is a security risk in the branch where the key device and the hidden key device are located; The security risk situation of the designated industrial park includes: whether there are security risks in the branches where the key equipment and the hidden key equipment are located.

6. The industrial park safety risk management method according to claim 5 is characterized in that: The management terminal performs coupling analysis on the operation data of the key device and the operation data of the hidden key device to determine whether there is a security risk in the branch where the key device and the hidden key device are located, including: The management terminal maps the operation data of the key device into a first vector matrix based on a mapping rule, and maps the operation data of the hidden key device into a second vector matrix based on the mapping rule; Wherein, each column vector in the first vector matrix corresponds to one type of operating data of the key device, each vector in the first vector matrix corresponds to one type of operating data of the key device, each column vector in the second vector matrix corresponds to one type of operating data of the hidden key device, and each vector in the second vector matrix corresponds to one type of operating data of the hidden key device; The management terminal determines the vector inner product of the first vector matrix and the second vector matrix. If the vector inner product is greater than or equal to a preset inner product threshold, it indicates that there is a security risk in the branch where the key device and the hidden key device are located. If the vector inner product is less than the preset inner product threshold, it indicates that there is no security risk in the branch where the key device and the hidden key device are located.

7. The industrial park safety risk management method according to claim 1 is characterized in that: The management terminal obtains the system topology in the specified industrial park, including: The management terminal obtains the system topology within the designated industrial park from the cloud system.

8. An industrial park safety risk management and control system, characterized in that: The system includes a management terminal, which is configured to: The management terminal acquires a system topology in a designated industrial park, where the designated industrial park is an industrial park managed by the management terminal, and the system topology is used to indicate a working dependency relationship between multiple devices in the designated industrial park, where the system topology includes multiple branches, and each of the multiple devices corresponds to a node in the system topology; The management terminal determines the key devices and hidden key devices among the multiple devices from the system topology, including: the management terminal determines the root node of each of the multiple branches as the key node, and determines the device represented by the key node as the key device, and at least two of the multiple branches share the same root node; the management terminal determines the hidden key device according to the topological relationship of the key device in the system topology, the method is: the management terminal determines the node that belongs to the same branch as the key device, is separated from the key device by at least one node, and does not belong to other branches as a hidden key node, and determines the device corresponding to the hidden key node as the hidden key device, and for each branch in the multiple branches that has the ability to select the hidden key device, the branch is only allowed to select one of the hidden key devices; The key device and the hidden key device are devices that affect the operation of at least two devices among the multiple devices; The management terminal monitors the key equipment and the hidden key equipment to determine the security risk situation of the designated industrial park.

Citation Information

Patent Citations

  • Method and system for detecting stable operation of distribution network equipment

    CN118249515A

  • Monitoring and early warning method and device, electronic equipment, storage medium and computer program product

    CN118827316A

Cited By

  • Industrial park security situation visual monitoring system based on digital twinning

    CN122413022A