Security Authorization Identification Method and Device for Power Grid Substation Facilities
By obtaining task information and visiting personnel identification information in the power grid substation, using the authority information database to confirm identity and permissions, and judging the authenticity of the task based on the equipment status, the inefficiency and safety hazards of the traditional authorization identification method are solved, and efficient and reliable security authorization identification is achieved.
Patent Information
- Application Number
- CN202510281453.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-03-11
AI Technical Summary
The personnel safety authorization identification method of traditional power grid substations has the problems of human error risk, inefficiency and inability to accurately record personnel entry and exit. In addition, the intelligent gate management APP relies on manual approval, which reduces the efficiency of real-time approval.
Obtain task information and visitor identification information through the substation intranet, use the permission information database to confirm the identity of visitor and task execution permissions, and judge the authenticity of the task information based on the equipment status information. If it matches, permissions to enter the area where the execution facility is located are granted.
It realizes efficient and reliable personnel identity verification and access control when the substation's intranet is isolated from the outside, reduces security risks and human error risks, and improves the efficiency and accuracy of the authorization process.
Smart Images

Figure CN119785465B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power grid equipment management, and more particularly, to a method and device for secure authorization identification of power grid substation facilities. Background Art
[0002] For power grid substations, the secure authorization identification of personnel entry is a crucial link in ensuring site safety management and the stable operation of the power system. As the hub of power transmission and distribution, the importance of substations is self-evident. Any unauthorized or inadequately vetted personnel entry may pose safety hazards, including but not limited to equipment damage, accidents caused by operational errors, and information leakage risks.
[0003] In traditional manned substations, the method of relying on security personnel to verify and control incoming personnel has a significant risk of human error, such as security vulnerabilities caused by incorrect identity verification or negligence. In unmanned substations, although the labor cost is reduced and the degree of automation is increased, the traditional management mode still faces challenges: for example, the inefficiency caused by a single person being responsible for the gate opening and closing operations of multiple sites, the long waiting time for incoming staff, the inability to accurately record personnel entry and exit, the difficulty in retrospective investigation, and the slow response to emergencies.
[0004] The current method of using an intelligent gating management APP has improved the level of automation to some extent, but still relies on manual approval by management personnel. This not only reduces the efficiency of real-time approval but also retains a certain degree of risk of human intervention and subjective judgment, which may lead to misjudgment or delay in the authorization process.
[0005] Therefore, how to provide an efficient and reliable method for personnel secure authorization identification is an urgent problem to be solved currently. Summary of the Invention
[0006] To address the above problems, the present invention provides a method and device for secure authorization identification of power grid substation facilities.
[0007] In a first aspect of an embodiment of the present invention, a method for secure authorization identification of power grid substation facilities is provided, the method comprising:
[0008] The intranet of the substation obtains the current task information to be executed, the task information including the executing personnel, the executing facilities, the executing operation, and the task release time, and obtains the identification information of the visiting personnel obtained through a scanning device;
[0009] Identify the identification information of the visiting personnel according to the permission information database pre-stored in the intranet of the substation to confirm the identity of the visiting personnel;
[0010] After the identity of the visitor is successfully confirmed, obtain the device status information of the execution facility, and identify the authenticity of the task information according to the device status information;
[0011] If the authenticity of the task information is confirmed, identify the task execution authority of the visitor according to the permission information database;
[0012] If the task execution authority of the visitor matches the task information, grant the visitor the permission to enter the area where the execution facility is located.
[0013] Optionally, the visitor identification information includes the visitor's electronic identity information and the visitor's biometric information. The step of obtaining the visitor identification information through the scanning device specifically includes:
[0014] Obtain the visitor's electronic identity information through a signal scanning device;
[0015] Collect the visitor's biometric information through an image acquisition device or a biometric acquisition device.
[0016] Optionally, the step of identifying the visitor identification information according to the permission information database pre-stored in the substation intranet and confirming the identity of the visitor specifically includes:
[0017] Retrieve the personnel information matching the visitor's electronic identity information in the permission information database. The personnel information includes the basic personnel information and the biometric identification information;
[0018] Match the biometric identification information with the collected biometric information of the visitor;
[0019] If the match is successful, confirm the identity of the visitor. If the match fails, prompt that the identity confirmation of the visitor fails and stop the subsequent identification actions.
[0020] Optionally, the step of obtaining the device status information of the execution facility and identifying the authenticity of the task information according to the device status information specifically includes:
[0021] Obtain the device status information corresponding to the execution facility;
[0022] Judge the rationality of performing the execution operation according to the device status information;
[0023] If there is rationality in performing the execution operation, confirm the authenticity of the task information.
[0024] Optionally, the step of judging the rationality of performing the execution operation according to the device status information specifically includes:
[0025] Determine the device status of the execution facility according to the device status information, wherein the device status includes an abnormal state and a normal state;
[0026] The execution operation includes a repair operation and a maintenance operation. When the equipment state is an abnormal state, if the execution operation is a repair operation, the rationality of the execution operation is judged. When the equipment state is a normal state, if the execution operation is a maintenance operation, the rationality of the execution operation is judged.
[0027] Optionally, the step of judging the rationality of executing the execution operation according to the device status information specifically further includes:
[0028] When the equipment state is an abnormal state and the execution operation is a maintenance operation, further obtaining the abnormal time point when the execution facility enters the abnormal state, and judging whether the abnormal time point is earlier than the task release time, and if so, judging the rationality of the existence of the execution operation;
[0029] When the equipment status is normal and the execution operation is a maintenance operation, further obtain the most recent maintenance time point when the execution facility last performed a maintenance operation, and determine whether the interval between the most recent maintenance time point and the task release time conforms to the normal maintenance cycle of the execution facility. If so, determine the rationality of the existence of the execution operation.
[0030] Optionally, the step of judging the rationality of executing the execution operation according to the device status information specifically further includes:
[0031] When the device state is an abnormal state and the executed operation is a maintenance operation, determining whether the maintenance operation is an operation to relieve the corresponding abnormal state;
[0032] If yes, then determine whether the execution operation is reasonable.
[0033] Optionally, the step of identifying the visitor's task execution authority according to the authority information database specifically includes:
[0034] Extracting a list of personnel with corresponding authority from the authority information database according to the execution facility and the execution operation;
[0035] Determine whether the visitor whose identity is successfully confirmed is on the list of persons;
[0036] If so, it is determined that the visitor's task execution authority matches the task information.
[0037] Optionally, the step of identifying the visitor's task execution authority according to the authority information database specifically includes:
[0038] When the number of performers in the task information is two or more, determine whether all the visiting personnel are in the said personnel list;
[0039] If all are in, determine that the task execution authority of the visiting personnel matches the said task information.
[0040] In the second aspect of the embodiments of the present invention, a safety authorization identification device for power grid substation facilities is provided, including:
[0041] An information acquisition unit, configured to acquire the currently to-be-executed task information from the substation intranet, where the task information includes performers, execution facilities, execution operations, and task release time, and acquire the visiting personnel identification information obtained through a scanning device;
[0042] An identity identification unit, configured to identify the visiting personnel identification information according to the authority information library pre-stored in the substation intranet to confirm the identity of the visiting personnel;
[0043] A task identification unit, configured to, after the identity of the visiting personnel is successfully confirmed, acquire the device status information of the execution facilities, and identify the authenticity of the task information according to the device status information;
[0044] An authority identification unit, configured to, if the authenticity of the task information is confirmed, identify the task execution authority of the visiting personnel according to the said authority information library;
[0045] An authority granting unit, configured to, if the task execution authority of the visiting personnel matches the said task information, grant the visiting personnel the authority to enter the area where the execution facilities are located.
[0046] In the third aspect of the embodiments of the present invention, an electronic device is provided, including:
[0047] One or more processors; a memory; one or more applications, where the one or more applications are stored in the memory and are configured to be executed by the one or more processors, and the one or more applications are configured to execute the method as described in the first aspect.
[0048] In the fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided, where program code is stored in the computer-readable storage medium, and the program code can be called by a processor to execute the method as described in the first aspect.
[0049] In summary, the present invention provides a method and apparatus for secure authorization identification of power grid substation facilities. Considering the characteristics of the isolation between the internal network and the external network of the substation, the secure authorization identification is comprehensively performed from three perspectives: the identity of the visitor, the authenticity of the task, and the task execution authority, so that the power grid substation facilities can not only achieve effective isolation at the physical and logical levels, but also provide an efficient and reliable identity authentication and access control mechanism. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0051] Figure 1 is a flowchart of the method for secure authorization identification of power grid substation facilities according to an embodiment of the present invention;
[0052] Figure 2 is a block diagram of the functional modules of the apparatus for secure authorization identification of power grid substation facilities according to an embodiment of the present invention;
[0053] Figure 3 is a block diagram of the structure of an electronic device for executing the method for secure authorization identification of power grid substation facilities according to an embodiment of the present application.
[0054] Figure 4 is a block diagram of the structure of a computer-readable storage medium for storing or carrying program code for implementing the method for identifying abnormal vessels according to an embodiment of the present application.
[0055] REFERENCE NUMERALS:
[0056] Information acquisition unit 110; identity identification unit 120; task identification unit 130; permission identification unit 140; permission granting unit 150; electronic device 300; processor 310; memory 320; computer-readable storage medium 400; program code 410. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0057] For power grid substations, the secure authorization identification of personnel entry is a key link to ensure the safety management of the site and the stable operation of the power system. As the hub of power transmission and distribution, the importance of the substation is self-evident. Any unauthorized or inadequately reviewed personnel entry may pose safety hazards, including but not limited to equipment damage, accidents caused by operation errors, and information leakage risks.
[0058] In traditional manned substations, the method of relying on security personnel to verify and control the incoming personnel has a significant risk of human error, such as security loopholes caused by incorrect identity verification or negligence. In unmanned substations, although the labor cost is reduced and the degree of automation is improved, the traditional management mode still faces challenges: for example, the inefficiency caused by a single person being responsible for the opening and closing operations of the gates of multiple stations, the long waiting time of the incoming staff, the inability to accurately record the personnel's entry and exit, the difficulty in retrospective investigation afterwards, and the slow response to emergencies.
[0059] Although the current method of using an intelligent gating management APP has improved the level of automation to some extent, it still relies on the manual approval of the management personnel. This not only reduces the efficiency of real-time approval, but also retains a certain degree of risk of human intervention and subjective judgment, which may lead to misjudgment or delay in the authorization process.
[0060] Therefore, how to provide an efficient and reliable method for personnel security authorization and identification is an urgent problem to be solved at present.
[0061] In view of this, the designer of the present invention has designed a method and device for security authorization and identification of power grid substation facilities.
[0062] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0063] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the present invention claimed, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0064] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0065] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by terms such as "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.
[0066] In the description of the present invention, it should also be noted that unless otherwise clearly specified and limited, the terms "set", "installed", "connected", "coupled" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0067] It should be noted that, without conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.
[0068] Next, a specific description will be given to the security authorization identification method for power grid substation facilities provided in this embodiment.
[0069] Please refer to Figure 1 , the security authorization identification method for power grid substation facilities provided in this embodiment, the method includes:
[0070] Step S101, the substation internal network obtains the currently to-be-executed task information, the task information includes the executor, the execution facility, the execution operation, and the task release time, and obtains the identification information of the visiting personnel obtained through the scanning device.
[0071] Under normal circumstances, the substation internal network maintains isolation from the external network and interacts with the external through a pre-set data interaction interface to obtain task information or update other data in the internal network.
[0072] In this embodiment, the way for the substation internal network to obtain task information can be to directly obtain the task information transmitted by an external task release system through a pre-configured communication interface.
[0073] On the other hand, the task information of the substation internal network can also be obtained through on-site acquisition. That is, after the external task publishing system generates the task information, it is sent to the executor. The intelligent terminal carried by the executor generates a corresponding identification password or QR code according to the task information, and the mapping relationship between the identification password or QR code and the task information is unique. When the executor comes to the substation as a visitor, the substation internal network collects the identification password or QR code shown by the visitor through a device that has established a signal connection with the substation internal network, and obtains the task information corresponding to the identification password or QR code according to the pre-saved mapping relationship. As a preferred method, the mapping relationship can be updated regularly to reduce the probability of being cracked.
[0074] The task information includes the specific content of the operation task that the executor needs to perform at the current substation. Among them, the executor corresponds to the person who comes to perform the task. It should be noted that according to the different tasks, the executor can be one person or multiple people. The execution facility corresponds to the equipment that needs to be operated for the current task, and can be identified by a specific equipment number. The execution operation is the specific operation action that needs to be performed on the equipment. The task release time corresponds to the time when the external task publishing system generates the task information. As a preferred implementation method, considering that the task publishing system usually publishes execution tasks for multiple different substations, the substation number used to identify the substation where the task is to be executed can also be included in the task information. After the substation internal network obtains the current task information to be executed, it first checks whether the substation number is consistent with its own number. If they are inconsistent, it stops performing the subsequent identification actions and prompts the sending source of the task information.
[0075] It should be noted that there are two ways to generate the task information. One is that the visitor reports the task content to be executed to the task publishing system according to work needs (it can be reported by filling in relevant information through the mobile APP or by logging in to the relevant system on the computer), including the execution time, location, execution object, execution operation, etc. The task publishing system generates the corresponding task information according to the content reported by the visitor. The other way is that the task publishing system generates the corresponding task information according to the periodic regular work arrangement or the temporary needs of the substation.
[0076] The visitor identification information is also collected through a scanning device that has established a signal connection with the substation internal network. When the on-site acquisition method is used to obtain the task information, a device integrated with multiple information collection functions can be used to obtain both the task information and the visitor identification information at the same time.
[0077] As a preferred embodiment of the present invention, the visitor identification information includes the visitor's electronic identity information and biometric information. The electronic identity information and the biometric information are bound to each other. For the electronic identity information and biometric information of the substation employees, they are pre-stored in the permission information database of the substation intranet to facilitate the identity identification and verification of visitors when the substation intranet is isolated from the external network.
[0078] Specifically, the visitor's electronic identity information is obtained through a signal scanning device; the visitor's biometric information is collected through an image acquisition device or a biometric acquisition device. The visitor's electronic identity information is usually provided by a device carried by the visitor, such as RFID. When the signal scanning device scans the device, the corresponding electronic identity information is read. The biometric information includes face image data, fingerprints, palm veins, iris features, etc. According to the biometric used, the corresponding acquisition device can be selected.
[0079] In actual applications, there are often cases where a visitor holds the RFID of another person with access permission and tries to enter. To effectively avoid this situation, it is necessary to collect both the visitor's electronic identity information and biometric information at the same time.
[0080] Step S102, identify the visitor identification information according to the permission information database pre-stored in the substation intranet to confirm the identity of the visitor.
[0081] The identity identification of the visitor is the first step in the entire security authorization identification process, aiming to confirm the identity of the visitor. Since the permission information database of the substation intranet has pre-stored staff information, the obtained visitor identification information can be matched with the information in the permission information database to confirm their identity.
[0082] To address the above situation where a visitor misuses the electronic identity information of another person with access permission, as a preferred embodiment of the present invention, step S102 specifically includes:
[0083] Retrieve the personnel information matching the visitor's electronic identity information in the permission information database, and the personnel information includes basic personnel information and biometric identification information;
[0084] Match the biometric identification information with the collected biometric information of the visitor;
[0085] If the match is successful, the identity of the visitor is confirmed. If the match fails, the visitor is prompted that the identity confirmation fails and the subsequent identification actions are stopped.
[0086] It should be noted that when verifying the identity of the visiting personnel, it is also possible to first match the biometric recognition information with the biometric information of the visiting personnel, and then compare and verify based on the personnel basic information corresponding to the matched biometric recognition information and the electronic identity information of the visiting personnel.
[0087] Both methods require verifying that the electronic identity information and biometric information of the visiting personnel provided are the same as the personnel information of the same person in the permission information database. In this way, the identity of the visiting personnel is confirmed. If any one of the matches fails, it is considered that the identity confirmation of the visiting personnel fails. A prompt needs to be sent out and subsequent recognition actions need to be stopped.
[0088] On the basis of the above, if there are two or more visiting personnel, the identity of each visiting personnel needs to be confirmed in turn.
[0089] Step S103, after the identity of the visiting personnel is successfully confirmed, obtain the device status information of the execution facility, and identify the authenticity of the task information based on the device status information.
[0090] After the identity of the visiting personnel is successfully confirmed, the second step of the security authorization recognition process is to confirm the authenticity of the task information.
[0091] In practical applications, visiting personnel who intend to illegally obtain security authorization may achieve this by forging task information. However, the task information generated by the task publishing system is usually related to the specific status of the grid substation facilities. Considering the isolation of the internal network, it is relatively difficult to directly obtain the device status of the substation facilities from the outside. Therefore, the authenticity of the task information can be identified through the device status information of the execution facility in the task information. Specifically, as a preferred method of the embodiment of the present invention, step S103 specifically includes:
[0092] Obtain the device status information corresponding to the execution facility;
[0093] Judge the rationality of performing the execution operation according to the device status information;
[0094] If there is rationality in performing the execution operation, confirm the authenticity of the task information.
[0095] The execution operation in the task information generated by the task publishing system is directly associated with the device status information of the execution facility. If an unreasonable execution operation appears, it indicates that there is a problem with the authenticity of the task information.
[0096] It should be noted that the acquisition of the device status information corresponding to the execution facility is completed by the intranet of the substation. Through certain monitoring strategies, the device status information of each facility in the substation is obtained regularly to realize the real-time monitoring of the device status, so as to ensure that corresponding measures are taken immediately when abnormalities occur.
[0097] As a preferred embodiment of the present invention, the method for judging the rationality of the execution operation according to the device status information specifically includes:
[0098] Judge the device status of the execution facility according to the device status information, and the device status includes abnormal status and normal status;
[0099] The execution operations include repair operations and maintenance operations. When the device status is abnormal, if the execution operation is a repair operation, then judge the rationality of the existence of the execution operation. When the device status is normal, if the execution operation is a maintenance operation, then judge the rationality of the existence of the execution operation.
[0100] In the actual scenario, the execution operations of the executors can be divided into two categories. One is the repair operation, which is for the devices in the abnormal state. When the device fails and is in the abnormal state. Normally, when the intranet monitors that a certain facility is in the abnormal state, through the fixed communication interface between the intranet and the outside, the warning information is fed back to the task publishing system. The task publishing system generates corresponding task information according to the situation of the facility and arranges the corresponding executor to go to the substation for repair. In the task information generated at this time, the execution facility is the facility in the abnormal state, the execution operation is the repair operation corresponding to the abnormal state, and the task publishing time is a time point after the task publishing system receives the warning information. The other type of operation is the maintenance operation, which is for the regular maintenance of various facilities in the substation. Usually, the maintenance operation is carried out when the device is in the normal state. At this time, in the task information generated by the task publishing system, the execution facility is the facility in the normal state to be maintained, the execution operation is the normal maintenance operation of the facility, and the task publishing time is related to the maintenance frequency of the facility, and there are fixed cycles and time intervals.
[0101] Based on the above content, in addition to judging the authenticity of the task information based on the rationality of the type of the execution operation, the rationality of the execution operation can also be judged based on the task publishing time. As a preferred embodiment of the present invention, the specific judgment method includes:
[0102] When the device status is abnormal and the execution operation is a repair operation, further obtain the abnormal time point when the execution facility enters the abnormal state, and judge whether the abnormal time point is earlier than the task publishing time. If so, then judge the rationality of the existence of the execution operation;
[0103] When the equipment status is normal and the execution operation is a maintenance operation, further obtain the most recent maintenance time point when the execution facility last performed a maintenance operation, and determine whether the interval between the most recent maintenance time point and the task release time conforms to the normal maintenance cycle of the execution facility. If so, determine the rationality of the existence of the execution operation.
[0104] When the equipment status is abnormal, the execution operation in the task information of the facility should be a maintenance operation, and the task release time should lag behind the abnormal time point when the execution facility enters the abnormal state, otherwise it is logically unreasonable. When the equipment status is normal, the execution operation in the task information of the facility should be a maintenance operation, and the task release time should be within the normal maintenance cycle of the facility, otherwise it is logically unreasonable. The authenticity of the task information can be effectively judged through the normal logical correspondence between the equipment status and the execution operation, as well as the normal logical relationship between the task release time.
[0105] In order to further improve the accuracy of judging the authenticity of task information, as a preferred implementation, when the equipment status is abnormal and the execution operation is a maintenance operation, it is judged whether the maintenance operation is an operation to release the corresponding abnormal status; if so, the rationality of the existence of the execution operation is judged. When judging, the execution operation of the task information can be compared with the content of the maintenance or maintenance manual of the execution facility. In the maintenance or maintenance manual, there is a clear description of the abnormal status of the execution facility. Different abnormal states correspond to specific types of faults, and how many execution personnel are required to perform what operations. After obtaining the actual equipment status information, the corresponding number of execution personnel and maintenance operations are obtained according to the content of the maintenance or maintenance manual, and compared with the execution personnel and execution operations in the task information. If there is a mismatch, it can also indicate that there is a problem with the authenticity of the task information.
[0106] Step S104: If the authenticity of the task information is confirmed, the task execution authority of the visitor is identified according to the authority information database.
[0107] After the authenticity of the task information is confirmed, the third step of the security authorization identification process is to confirm the visitor's task execution authority. The identity of the visitor is confirmed through the above step S102, and the authenticity of the task information is verified through step S103. On this basis, if it is confirmed that the visitor has the task execution authority to execute the task, it means that the visitor can obtain security authorization to enter the substation.
[0108] In actual work, the principle of least privilege is usually adopted, that is, only the minimum permissions required to complete the work are granted. At the same time, there are clear restrictions on the facilities that employees at different levels or in different job types can operate. Specifically, the above step S104 specifically includes:
[0109] Extract the list of personnel with corresponding permissions from the permission information database according to the execution facility and the execution operation;
[0110] Determine whether the visiting personnel with successful identity confirmation are in the list of personnel;
[0111] If so, determine that the task execution permission of the visiting personnel matches the task information.
[0112] In the permission information database, for the operation permissions of each facility, there is a pre-saved list of personnel. The people in this list of personnel all have the operation permissions for the facility. Therefore, when comparing the visiting personnel with the list of personnel for the execution facility, if they are in the list, it means that the task execution permission of the visiting personnel matches the task information.
[0113] It should be noted that when the number of execution personnel in the task information is two or more, in addition to checking that the number and identity of the visiting personnel are both consistent with the execution personnel in the task information at the same time, it is also necessary to determine that the visiting personnel all have the task execution permission for the execution facility at the same time. That is, when the number of execution personnel in the task information is two or more, determine whether all the visiting personnel are in the list of personnel; if so, determine that the task execution permission of the visiting personnel matches the task information.
[0114] Step S105, if the task execution permission of the visiting personnel matches the task information, grant the visiting personnel the permission to enter the area where the execution facility is located.
[0115] In a substation, the areas where different execution facilities are located may be different. When the security authorization identification process for a certain task information is completed, only grant the visiting personnel the permission to enter the area where the execution facility is located to prevent them from entering other areas.
[0116] As a preferred method, after authorizing the visiting personnel, the identity information of the visiting personnel (which can include face information, name, license plate information, etc.) and the authorization scope can be synchronized to the security personnel in the substation area, so that the security personnel can view the situation of authorized visiting personnel in each area at any time. At the same time, when encountering visiting personnel, the security personnel can obtain the information again through methods such as scanning a QR code and compare it with the synchronized authorization information to facilitate the confirmation of the identity and permissions of the visiting personnel.
[0117] The following uses two specific cases to illustrate the safety authorization identification method for power grid substation facilities provided by the embodiments of the present invention:
[0118] The application scenario is the access control system of the State Grid substation park.
[0119] Case 1: On a certain day, when the internal local area network of the park detected internal facilities, it was found that Facility A had an m-type fault at 15:35. An early warning message was sent to the external task distribution system through the internal local area network. The task distribution system generated task information, which specifically included executors a and b, execution of Facility A, execution of operation m-type fault, and task release time of 15:40. This task information was sent to the mobile phones of executors a and b. Through an independent app or built-in mini-program installed on the mobile phones, an identification password or QR code corresponding to the task information was generated. After executors a and b arrived at the entrance of the substation park, the access control system scanned their work permits and face information to obtain the electronic identity information and biometric information of the visiting personnel, and then obtained the task information by scanning the QR code generated on a's mobile phone. First, the electronic identity information and biometric information of the visiting personnel of a and b were compared with the information in the pre-stored permission information database to confirm that the executors were a and b, and both a and b were themselves. Then, the device status information of Facility A was obtained according to the task information, and it was found that Facility A did have an m-type fault at 15:35, verifying the authenticity of the task information. Next, the list of personnel who could perform m-type fault repairs on Facility A was extracted from the permission information database, and it was confirmed by comparison that both a and b were on the list. Finally, permissions to enter the area where Facility A is located were granted to a and b.
[0120] Case 2:
[0121] On a certain day, executor c needed to perform an inspection task. The relevant information of the inspection content was filled in and reported through the mobile phone app or built-in mini-program, and the task information was generated by the task distribution system and then sent back to generate the corresponding identification password or QR code. After executor c arrived at the substation park, the access control system scanned the QR code shown by him to obtain the electronic identity information, biometric information, and task information of the visiting personnel. According to the identity permissions of the inspection task object, the verification was carried out, and at the same time, it was judged that these facilities were indeed in a state that needed to be inspected. Then, permissions to enter the area where the facilities to be inspected were located were granted to executor c. After authorizing executor c, his identity information and access permissions were synchronized to other security personnel in the park. When the security personnel encountered executor c in the park, they could require him to show the QR code or directly identify his biometric information to confirm whether the identity of executor c and the area where he was located were consistent with the authorization.
[0122] In practical applications, the method and device are not limited to inspection tasks, but can also be other tasks such as patrol, maintenance, and construction.
[0123] In summary, the present invention provides a method for secure authorization identification of power grid substation facilities. Considering the characteristics of the isolation between the internal network of the substation and the external network, the secure authorization identification is comprehensively performed from three aspects: the identity of the visitor, the authenticity of the task, and the task execution authority. This enables the power grid substation facilities to not only achieve effective isolation at the physical and logical levels, but also provide an efficient and reliable identity verification and access control mechanism.
[0124] As Figure 2 shown, the secure authorization identification device for power grid substation facilities provided by the embodiment of the present invention includes:
[0125] An information acquisition unit 110, configured to acquire the task information to be executed currently from the internal network of the substation. The task information includes the executor, the execution facility, the execution operation, and the task release time, and acquire the identification information of the visitor obtained through the scanning device;
[0126] An identity identification unit 120, configured to identify the identification information of the visitor according to the permission information database pre-stored in the internal network of the substation to confirm the identity of the visitor;
[0127] A task identification unit 130, configured to acquire the device status information of the execution facility after the identity of the visitor is successfully confirmed, and identify the authenticity of the task information according to the device status information;
[0128] A permission identification unit 140, configured to, if the authenticity of the task information is confirmed, identify the task execution permission of the visitor according to the permission information database;
[0129] A permission granting unit 150, configured to, if the task execution permission of the visitor matches the task information, grant the visitor the permission to enter the area where the execution facility is located.
[0130] The secure authorization identification device for power grid substation facilities provided by the embodiment of the present invention is used to implement the above-mentioned method for secure authorization identification of power grid substation facilities. Therefore, the specific implementation manner is the same as the above method and will not be repeated here.
[0131] As Figure 3As shown in the figure, a structural block diagram of an electronic device 300 provided by an embodiment of the present invention is shown. The electronic device 300 may be an electronic device 300 such as a smart phone, a tablet computer, an e-book, etc. that can run application programs. The electronic device 300 in this application may include one or more of the following components: a processor 310, a memory 320, and one or more application programs, where one or more application programs may be stored in the memory 320 and configured to be executed by one or more processors 310, and one or more programs are configured to execute the methods described in the foregoing method embodiments.
[0132] The processor 310 may include one or more processing cores. The processor 310 connects various parts within the entire electronic device 300 through various interfaces and lines, and executes various functions of the electronic device 300 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 320, and calling data stored in the memory 320. Optionally, the processor 310 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 310 may integrate one or several combinations of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the display content; the modem is used to process wireless communication. It can be understood that the above modem may not be integrated into the processor 310 and may be implemented separately through a communication chip.
[0133] The memory 320 may include random access memory (RAM), and may also include read-only memory. The memory 320 may be used to store instructions, programs, codes, code sets, or instruction sets. The memory 320 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for implementing at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the following various method embodiments, etc. The data storage area may also store data created during the use of the terminal (such as phone book, audio and video data, chat record data, etc.).
[0134] Such as Figure 4As shown, it is a structural block diagram of a computer-readable storage medium 400 provided by an embodiment of the present invention. Program code 410 is stored in the computer-readable medium, and the program code 410 can be called by a processor to execute the method described in the above method embodiment.
[0135] The computer-readable storage medium 400 can be an electronic memory such as a flash memory, EEPROM (electrically erasable programmable read-only memory), EPROM, hard disk, or ROM. Optionally, the computer-readable storage medium 400 includes a non-transitory computer-readable storage medium. The computer-readable storage medium 400 has a storage space for the program code 410 that executes any method step in the above method. These program codes 410 can be read out from or written into one or more computer program products. The program code 410 can be compressed in an appropriate form, for example.
[0136] In summary, the present invention provides a method and device for secure authorization identification of power grid substation facilities. Considering the characteristics of the isolation between the internal network and the external network of the substation, security authorization identification is comprehensively performed from three aspects: the identity of the visitor, the authenticity of the task, and the task execution permission, so that the power grid substation facilities can not only achieve effective isolation at the physical and logical levels, but also provide an efficient and reliable identity authentication and access control mechanism.
[0137] In several embodiments disclosed in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the module, the program segment, or the part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0138] In addition, each functional module in various embodiments of the present application may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.
[0139] If the above-mentioned function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
Claims
1. A method for secure authorization identification of power grid substation facilities, characterized in that: The method comprises: The substation intranet obtains the task information to be executed, including the executor, execution facility, execution operation, task release time, and the visitor identification information obtained by scanning equipment; Identify the visitor's identification information according to the authority information database pre-stored in the substation intranet to confirm the visitor's identity; After the visitor's identity is successfully confirmed, the equipment status information of the execution facility is obtained, and the authenticity of the task information is identified based on the equipment status information. The rationality of the execution operation is judged based on the type of execution operation and the task release time. If the execution operation is reasonable, the authenticity of the task information is confirmed; The equipment status of the execution facility is judged according to the equipment status information, and the equipment status includes an abnormal status and a normal status; when the equipment status is a normal status, if the execution operation is a maintenance operation, the most recent maintenance time point when the execution facility last performed a maintenance operation is further obtained, and it is judged whether the interval between the most recent maintenance time point and the task release time conforms to the normal maintenance cycle of the execution facility. If so, the rationality of the existence of the execution operation is judged; when the equipment status is an abnormal status and the execution operation is a maintenance operation, the abnormal time point when the execution facility enters the abnormal status is further obtained, and it is judged whether the abnormal time point is earlier than the task release time. If so, the rationality of the existence of the execution operation is judged; when the equipment status is an abnormal status and the execution operation is a maintenance operation, it is judged whether the maintenance operation is an operation to release the corresponding abnormal status. If so, the rationality of the existence of the execution operation is judged. When judging, the fault type corresponding to the abnormal status, as well as the number of execution personnel and maintenance operations required to release the fault are determined, and compared with the execution personnel and execution operation in the task information. If they match, the rationality of the existence of the execution operation is judged; If the authenticity of the task information is confirmed, the task execution authority of the visitor is identified according to the authority information database; If the task execution authority of the visitor matches the task information, the visitor is granted authority to enter the area where the execution facility is located.
2. The method for security authorization identification of power grid substation facilities according to claim 1, characterized in that: The visitor identification information includes the visitor's electronic identity information and the visitor's biometric information. The step of obtaining the visitor identification information obtained by the scanning device specifically includes: Obtain the electronic identity information of visitors through signal scanning equipment; Collect the visitor's biometric information through image acquisition equipment or biometric acquisition equipment.
3. The method for security authorization identification of power grid substation facilities according to claim 2, characterized in that: The step of identifying the visitor's identification information according to the authority information database pre-stored in the substation intranet and confirming the visitor's identity specifically includes: Retrieving personnel information matching the electronic identity information of the visitor from the authority information database, wherein the personnel information includes basic personnel information and biometric identification information; Matching the biometric identification information with the collected biometric information of the visitor; If the match is successful, the visitor's identity is confirmed. If the match fails, the visitor's identity confirmation fails and subsequent recognition actions are stopped.
4. The method for security authorization identification of power grid substation facilities according to any one of claims 1 to 3, characterized in that: The step of identifying the visitor's task execution authority according to the authority information database specifically includes: Extracting a list of personnel with corresponding authority from the authority information database according to the execution facility and the execution operation; Determine whether the visitor whose identity is successfully confirmed is on the list of persons; If so, it is determined that the visitor's task execution authority matches the task information.
5. The method for security authorization identification of power grid substation facilities according to claim 4, characterized in that: The step of identifying the visitor's task execution authority according to the authority information database specifically includes: When the number of executors in the task information is two or more, determine whether all the visiting personnel are in the personnel list; If both are present, it is determined that the visitor's task execution authority matches the task information.
6. A security authorization identification device for a power grid substation facility, characterized in that: include: An information acquisition unit is used to acquire the task information to be executed in the substation intranet, wherein the task information includes the executor, the execution facility, the execution operation, the task release time, and the visitor identification information obtained by the scanning device; The identity recognition unit is used to identify the visitor's identification information according to the authority information database pre-stored in the substation intranet and confirm the visitor's identity; The task identification unit is used to obtain the equipment status information of the execution facility after the identity of the visitor is successfully confirmed, identify the authenticity of the task information based on the equipment status information, and judge the rationality of the execution operation based on the type of execution operation and the task release time. If the execution operation is reasonable, the authenticity of the task information is confirmed; The task identification unit is further used to determine the equipment status of the execution facility according to the equipment status information, wherein the equipment status includes an abnormal status and a normal status; when the equipment status is a normal status, if the execution operation is a maintenance operation, further obtain the most recent maintenance time point when the execution facility last performed a maintenance operation, and determine whether the interval between the most recent maintenance time point and the task release time conforms to the normal maintenance cycle of the execution facility, and if so, determine the rationality of the existence of the execution operation; when the equipment status is an abnormal status and the execution operation is a maintenance operation, further obtain the abnormal time point when the execution facility enters the abnormal status, and determine whether the abnormal time point is earlier than the task release time, and if so, determine the rationality of the existence of the execution operation; When the equipment state is abnormal and the execution operation is a maintenance operation, determine whether the maintenance operation is an operation to resolve the corresponding abnormal state. If yes, determine the rationality of the execution operation. When determining, determine the fault type corresponding to the abnormal state, as well as the number of execution personnel and maintenance operations required to resolve the fault, and compare them with the execution personnel and execution operation in the task information. If they match, determine the rationality of the execution operation. The authority identification unit is used to identify the task execution authority of the visitor according to the authority information database if the authenticity of the task information is confirmed; The authority granting unit is used to grant the visitor the authority to enter the area where the execution facility is located if the visitor's task execution authority matches the task information.
Citation Information
Patent Citations
Safety monitoring method and device for personnel entering transformer substation to work
CN113568328A
Distributed multi-community big data comprehensive management platform and method
CN116050697A