Method for managing access perigents to unit in regenerative power generation system

By automatically comparing the actual operation and predefined operations of the user's renewable power generation system, and automatically adjusting access rights according to differences, the problem of excessive user permissions is solved and the security of the system is improved.

CN119939546APending Publication Date: 2025-05-06VESTAS WIND SYSTEMS AS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411537331.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-01
Filing Date
2024-10-31
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to effectively manage users' access rights to units in renewable power generation systems, resulting in users' possible access rights and increasing the potential attack surface of the system.

Method used

By assigning access rights to a set of predefined operations to the user, recording the actions actually performed by the user and comparing them with the predefined operations, if a difference is found, the user's access rights are automatically adjusted to remove access rights related to the predefined operations that are not executed.

Benefits of technology

Ensure that users only gain access rights required to perform their normal tasks, improve system security and reduce potential attack surfaces.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939546A_ABST
    Figure CN119939546A_ABST
Patent Text Reader

Abstract

A method for managing access rights to a unit (11) in a renewable power generation system (1), such as a wind turbine or wind power plant, is disclosed. A set of access permissions is assigned to the user (2), the set of access permissions granting the user (2) permission to perform a set of predefined operations on the renewable power generation system (1). The operations performed by the user (2) on the renewable power generation system (1) are recorded and compared to the set of predefined operations related to the set of access permissions. If the result of the comparison reveals a difference between the performed operation and the set of predefined operations associated with the set of access permissions, a set of access permissions assigned to the user (2) is automatically adjusted by removing at least some access permissions associated with unperformed predefined operations. This ensures that the user (2) is permitted to perform the necessary operations, while effectively avoiding the user (2) from being privileged too high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for managing user access rights to units in a renewable electricity generation system. The method according to the present invention effectively ensures that users are only allowed access to the extent required by the users to perform their normal tasks. Background Art

[0002] Various users may need access to an organization's digital infrastructure. To do this, users are granted access rights that define the actions that individual users are allowed to perform against the digital infrastructure. Not all users need to perform all possible actions or tasks. Therefore, attempts are often made to provide each user with access rights that allow the user to perform the tasks they need, but no more. For example, particularly critical or high-impact operations may require special access rights that go beyond the standard user access rights.

[0003] Despite all the effort put into granting user access rights, situations may arise where some users are provided access rights beyond what is required to successfully perform their assigned tasks and responsibilities, or even far beyond that. This situation may be referred to as over-permission, over-privileged access, or unnecessary privileges, and it may occur gradually, for example, as users transition between roles, requiring adjustments to their access requirements without resulting in a corresponding reduction in granted access rights. Furthermore, it can be a difficult task to keep track of which access rights have been granted to which users, and to track whether the nature of the tasks performed by individual users has changed. This is particularly true in large organizations, where a large number of users require access to digital infrastructure to perform their assigned tasks.

[0004] From a security perspective, the above situation is highly undesirable because users with too many permissions to access digital infrastructure constitute a vulnerability in the system, as if such users were compromised, this could result in the malicious party gaining access to large portions of the system, perhaps even very sensitive or critical parts of the system. Thus, excessive user permissions expand the potential attack surface of the system, making the system and the data it contains vulnerable to exploitation by malicious parties. In addition, excessive user permissions may inadvertently compromise the confidentiality, integrity and availability of critical resources, which may lead to data breaches, unauthorized changes and / or operational disruptions.

[0005] Unauthorized access to a digital infrastructure that a user accesses forms part of a renewable electricity generation system (such as a wind turbine, wind farm, photovoltaic unit, solar power plant, etc.) is particularly problematic, as such systems may be considered critical infrastructure. Security requirements for such systems are therefore particularly stringent. Summary of the invention

[0006] It is an object of embodiments of the present invention to provide a method for managing access rights to units in a renewable electricity generation system which automatically ensures a high security level.

[0007] The present invention provides a method for managing access rights to units in a renewable electricity generation system, the method comprising the following steps:

[0008] - assigning a set of access rights to the user, which grants the user permission to perform a set of predefined operations (actions) on the renewable electricity generation system,

[0009] - recording the actions performed by the user on the renewable electricity generation system and comparing the performed actions with the set of predefined actions associated with the set of access rights, and

[0010] If the comparison reveals differences between the performed operations and the set of predefined operations associated with the set of access rights, automatically adjusting the set of access rights assigned to the user by removing at least some of the access rights associated with the non-performed predefined operations.

[0011] Thus, the method according to the invention is a method for managing access rights to units in a renewable electricity generation system. In the present context, the term "renewable electricity generation system" should be interpreted as referring to an entity capable of generating electricity from renewable energy sources. Thus, the renewable electricity generation system may, for example, take the form of a wind turbine, a wind power plant, a photovoltaic unit, a solar power plant, a hybrid power plant or any other suitable type of electricity generation system relying on renewable energy sources.

[0012] The accessed unit is a digitally accessible part of a renewable power generation system, for example, forming part of a control system of the renewable power generation system. Thus, the unit may be, for example, a controller of a wind turbine, a photovoltaic unit, etc., an associated switch, a power plant controller (PPC), a supervisory control and data acquisition (SCADA) server, or any other suitable type of digitally accessible part of a renewable power generation system. In any case, the unit should be interpreted as a physical unit located "on-site", i.e., a physical unit located in or in close proximity to a renewable power generation system. In the case where the renewable power generation system is a renewable power plant (such as a wind power plant, a solar power plant or a hybrid power plant), the unit may be located within the boundaries of the renewable power plant.

[0013] In the method according to the invention, a set of access rights is initially assigned to a user. The set of access rights grants the user permission to perform a set of predefined operations on the renewable power generation system, in particular on the units in the renewable power generation system. Thus, once the set of access rights is assigned to the user, the user will be allowed to access the units in the renewable power generation system and perform each of the operations defined by the set of access rights. Thus, the set of access rights assigned to the user can advantageously be carefully selected to ensure that the user is able to perform tasks that are expected to form part of the user's normal duties, while preventing the user from being able to perform tasks or operations that are not expected to form part of the user's normal duties.

[0014] Thus, when this set of access rights is assigned to a user, the user will access the units in the renewable power generation system when necessary and perform any operations on the renewable power generation system that are necessary for the user to complete the tasks entrusted to the user. During this time, the operations actually performed by the user on the renewable power generation system will be recorded. This can be done, for example, with the help of a standard recording tool installed on the renewable power generation system for other purposes.

[0015] The operations actually performed by the user as seen from the log are compared with the set of predefined operations associated with the set of access rights. Thus, the operations actually performed by the user when performing the tasks delegated to the user and during the user's normal work are compared with the set of operations that the user is permitted to perform on the renewable electricity generation system according to the access rights assigned to the user. The result of this comparison will reveal whether the user actually uses all the privileges assigned to him or her.

[0016] If the comparison reveals discrepancies between the actions actually performed and the set of predefined actions associated with the set of access rights, this indicates that the user is not actually using all of the privileges assigned to him or her, and the user may be considered overprivileged. In addition, the comparison will reveal which predefined actions the user needs to perform in order to handle the tasks delegated to the user, and which actions are not required.

[0017] Therefore, if the comparison reveals differences as described above, the set of access rights assigned to the user is automatically adjusted. This is achieved by removing at least some of the access rights associated with the predefined operations not performed by the user.

[0018] As a result, permissions for users to perform actions that are not required for the execution of tasks delegated to the user during their normal work are automatically removed. Furthermore, this is achieved based on an analysis of the user's actual behavior, so it can be assumed that the adjusted set of access rights closely reflects the user's actual needs. Thus, it is effectively and automatically ensured that only the required access rights are provided to the user, thereby increasing the security of the system against malicious attacks. Furthermore, this is obtained dynamically and based on the actual behavior of individual users.

[0019] The step of automatically adjusting the set of access rights assigned to the user may include reducing the set of predefined operations that the user is permitted to perform on the renewable electricity generating system.

[0020] According to this embodiment, the access rights removed when adjusting the set of access rights take the form of predefined operations removed from a set of predefined operations that the user is permitted to perform on the renewable power generation system. Thus, after the adjustment, the user will no longer be permitted to perform certain operations.

[0021] For example, removal of access rights may be performed based on the "principle of least privilege," wherein a predefined set of operations a user is allowed to perform corresponds to the minimum set of operations required for the user to perform his or her normal duties, thereby preventing the user from having excessive privileges.

[0022] The method may further include the step of temporarily granting, upon request, a user permission to perform additional operations on the renewable electricity generation system.

[0023] Circumstances may arise where a given user occasionally needs to perform operations on the renewable electricity generation system that do not form part of the normal day-to-day duties of that user. In such cases, it would not be appropriate to grant the user permission to perform such operations as a general rule or on a permanent basis. Therefore, according to this embodiment, the user would not normally be permitted to perform such operations. However, when the need for the user to perform such operations arises, the user may be provided with access rights that permit the operation to be performed, and when the operation is completed, these access rights may be removed again to ensure that the user is not permanently permitted to perform additional operations.

[0024] This ensures that users are allowed to perform any desired actions without introducing too many obstacles to the user or overly permanently expanding the user's access rights.

[0025] The step of temporarily granting the user permission to perform additional operations on the renewable electricity generation system may require separate authentication of the user. For example, the user may be required to enter a specific administrator password to obtain additional temporary access rights, or the user may be required to enter the user's normal password separately.

[0026] As an alternative, users who occasionally need to perform additional actions can be flagged in the system to ensure that their access rights are not adjusted even if the comparison reveals that this is appropriate.

[0027] The step of assigning a set of access rights to the user may include classifying (categorizing) the user into a predefined user profile, and the step of automatically adjusting the set of access rights assigned to the user may include classifying the user into another predefined user profile.

[0028] According to this embodiment, the user's access rights are managed by classifying each user into one of two or more predefined user profiles or roles. Each predefined user profile defines a set of predefined operations, and each user classified into a given user profile will be permitted to perform the predefined operations defined by the user profile.

[0029] If the comparison reveals differences between the operations performed by the user and the set of predefined operations defined by the user profile into which the user is classified, the user is classified into another predefined user profile of the predefined user profiles, the other predefined user profile defining a reduced set of predefined operations.

[0030] For example, a user may initially be classified as an "Administrator," but recorded actions may reveal that the user is actually behaving in a manner expected of a "Standard" user. Thus, in this case, the user is reclassified from "Administrator" to "Standard."

[0031] Defining user profiles or roles is a widely used model for managing access rights, and it is an easy and transparent way to keep track of which access rights are assigned to which users.

[0032] Alternatively, access rights may be assigned in a manual or customized manner that matches the individual requirements of each user.

[0033] In case the access rights are assigned by categorizing the users into predefined user profiles, the method may further comprise the following steps:

[0034] - recording actions performed on the renewable electricity generating system by a user classified into a certain user profile and comparing the performed actions with the set of predefined actions associated with the user profile, and

[0035] -If the comparison reveals a difference between the performed operation and a set of predefined operations associated with the user profile, automatically adjusting the set of access rights associated with the user profile by removing at least some of the access rights associated with the predefined operations that were not performed, thereby automatically adjusting the user rights assigned to all users classified into the user profile.

[0036] According to this embodiment, the operations performed by users are recorded among all users who are classified into a certain user profile and who may therefore be expected to have similar needs regarding those operations they need to be able to perform on the renewable electricity generation system in order for them to be able to perform their normal day-to-day duties and tasks that are usually assigned to them. This therefore results in a large data set relating to the behavior of users who may be considered similar and who are assigned the same set of access rights.

[0037] The recorded performed operations are compared with the set of predefined operations associated with the user profile, thereby comparing the recorded performed operations with a set of predefined operations that the user is permitted to perform on the renewable electricity generation system according to the access rights assigned to each user. This is very similar to the situation described above, where the recorded operations of a single user are compared with a set of predefined operations, so the comments set out above also apply here.

[0038] If the comparison reveals a difference between the performed operation and the set of predefined operations, the set of access rights associated with the user profile is automatically adjusted by removing at least some of the access rights associated with the predefined operations that were not performed. This is also similar to the situation described above with reference to a single user, and the comments made in this regard apply equally here. However, in this case, the adjustment of the access rights is immediately applicable to all users classified into the relevant user profile. Furthermore, it is ensured that users classified into the user profile at a later point in time are assigned a reduced set of access rights.

[0039] Thus, according to this embodiment, adjustment of access rights is performed at the user profile level rather than at the individual user level, or in addition to the individual user level. This ensures that the decision whether to adjust access rights is made based on a large amount of data in the form of recorded actions performed by multiple users. It can therefore be assumed that the final adjusted set of access rights accurately reflects the needs of the users classified into the given user profile. Furthermore, this reduces the risk of over-privileging new users, and access rights for a given user can be adjusted before a sufficient number of actions performed by that user have been recorded to determine that the user's access rights need to be adjusted.

[0040] A renewable energy generation system may be a wind turbine or a wind power plant. In the present context, the term "wind power plant" should be interpreted as referring to a group of at least two wind turbines that share an infrastructure for transmitting electricity to a power grid. Thus, a wind power plant may include a plurality of wind turbines that may be arranged at a geographical site and that may be controlled with the aid of a central control unit, sometimes referred to as a power plant controller (PPC).

[0041] If the renewable energy generation system is a wind turbine, the accessed unit may be, for example, a controller, a switch, a sensor or any other suitable type of digitally accessible unit in the wind turbine. If the renewable energy generation system is a wind power plant, the accessed unit may be a unit as described above in one of the wind turbines of the wind power plant. Alternatively, the accessed unit may be a unit associated with the overall operation of the wind power plant, such as a PPC or a SCADA server.

[0042] Thus, according to this embodiment, the access rights are related to the permission of the user to perform operations on at least one wind turbine. Wind turbines and wind power plants are relevant examples of entities that are capable of generating electricity from renewable energy sources, i.e. wind, and that can be considered as critical infrastructure. Therefore, it is suitable to apply the method according to the invention to manage access rights to units in a wind turbine or a wind power plant.

[0043] The access rights may for example relate to the user's access to a control system (eg a PPC) of a wind turbine and / or a wind power plant.

[0044] Alternatively or additionally, the renewable electricity generating system may be or include one or more photovoltaic units, a solar power plant, a hybrid power plant or any other suitable type of renewable electricity generating system.

[0045] The step of recording actions performed by the user may include performing artificial intelligence (AI) driven analysis on the recorded data.

[0046] According to the embodiment, analysis of data related to recorded operations and comparison between the performed operations and a set of predefined operations is performed with the aid of a trained AI engine. For example, the AI-driven analysis may include identifying patterns in operations performed by users and comparing the identified patterns to expected behavior of the entire set of users who require assigned access rights.

[0047] AI systems are suitable for processing large amounts of data and identifying patterns in the data. Therefore, AI systems are also suitable for revealing whether there are discrepancies between a user's actual behavior and the user's expected behavior. Therefore, applying an AI system to analyze recorded data and automatically adjusting the user's access rights based on the output of the AI ​​system can be assumed to result in the adjusted access rights accurately reflecting the user's actual needs. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The present invention will now be described in further detail with reference to the accompanying drawings, in which:

[0049] Figure 1 is a schematic diagram illustrating a method according to an embodiment of the present invention, and

[0050] Figure 2 is a flow chart illustrating a method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0051] Figure 1 is a schematic diagram illustrating a method according to an embodiment of the present invention in which access rights to units 11 in a renewable electricity generation system 1 (which takes the form of a wind power plant) are managed. An access manager 3 initially assigns a set of access rights to a user 2. The set of access rights specifies a set of predefined operations that the user 2 is permitted to perform on the renewable electricity generation system 1. For example, the access rights may be assigned to the user 2 by categorizing the user 2 into a predefined user profile. In any case, the set of access rights initially assigned is selected in a manner that is considered to match the needs of the user 2 in relation to performing operations on the renewable electricity generation system 1 as part of the normal duties of the user 2.

[0052] The user 2 then performs his or her normal duties, including accessing the unit 11 in the renewable electricity generation system 1 and performing the required operations on the unit 11 when required and to the extent necessary to perform the tasks entrusted to the user 2. During this time, the operations performed by the user 2 are recorded by the recording agent 4, and the recorded data is provided to the analysis unit 5 (e.g., including an AI engine).

[0053] Then, the analysis unit 5 analyzes the recorded data and compares the operations actually performed by the user 2 with a set of predefined operations defined by a set of access rights originally assigned to the user 2. The comparison result reveals whether there are differences between the operations actually performed and the set of predefined operations. In addition, in the case of differences, the comparison result also reveals which predefined operations the user 2 does not usually perform.

[0054] The results of the analysis and comparison are transmitted to the access manager 3. Based on this, the access manager 3 automatically adjusts the set of access rights of the user by removing at least some of the operations not currently performed by the user 2 from the set of predefined access rights. For example, this can be achieved by classifying the user into another user profile with a lower access level.

[0055] The adjusted set of access rights is communicated to the user 2 , and the user 2 will no longer be permitted to perform operations on the renewable electricity generating system 1 that are removed from the set of predefined operations.

[0056] It is thus ensured that the user 2 is authorized to perform operations on the renewable power generation system 1 that are necessary for the user 2 to handle the tasks entrusted to the user 2 as part of his or her normal daily duties, but not beyond this. Thus, excessive user rights can be avoided in an easy and accurate manner.

[0057] Figure 2 is a flow chart illustrating a method according to an embodiment of the present invention. The process starts from step 6. In step 7, a set of access rights is assigned to the user. The set of access rights defines a set of predefined operations on the renewable power generation system and grants the user permission to perform these predefined operations.

[0058] In step 8, the operations performed by the user on the renewable electricity generation system while performing his or her normal duties are recorded. Furthermore, the recorded operations (i.e. the operations actually performed by the user) are compared with the set of predefined operations associated with the set of access rights assigned to the user. This may be performed, for example, with the aid of an AI-driven analysis, which for example comprises identifying patterns in the operations performed by the user and comparing the identified patterns with the expected behavior of the user for the entire set of assigned access rights.

[0059] In step 9, it is investigated whether there are discrepancies between the operations actually performed by the user and a set of predefined operations that the user is permitted to perform according to the assigned set of access rights. If there are no discrepancies, it can be concluded that the assigned set of access rights is a good match for the user's needs, and the process returns to step 8 to continue recording the operations performed by the user on the renewable electricity generation system.

[0060] If step 9 reveals a discrepancy between the operations actually performed and the set of predefined operations, this indicates that the set of operations that the user is permitted to perform according to the assigned set of access rights does not match the operations that the user actually needs to perform as part of his or her normal duties. This is therefore an indication that the user is in fact overprivileged. Thus, in this case, the flow will move to step 10, where the set of access rights is automatically adjusted by removing at least some of the operations that the user does not appear to be performing from the set of predefined operations. As a result, the user will no longer be permitted to perform these operations and may no longer be considered overprivileged.

[0061] Finally, the process returns to step 7, where the adjusted set of access rights is assigned to the user.

Claims

1. A method for managing access rights to a unit (11) in a renewable electricity generation system (1), the method comprising the following steps: - assigning a set of access rights to a user (2), said set of access rights granting said user (2) permission to perform a set of predefined operations on said renewable electricity generation system (1), - recording operations performed by the user (2) on the renewable electricity generation system (1) and comparing the performed operations with the set of predefined operations associated with the set of access rights, and - If the comparison reveals differences between the performed operations and the set of predefined operations associated with the set of access rights, automatically adjusting the set of access rights assigned to the user (2) by removing at least some of the access rights associated with the non-performed predefined operations.

2. The method according to claim 1, wherein: The step of automatically adjusting the set of access rights assigned to the user (2) comprises reducing the set of predefined operations that the user (2) is permitted to perform on the renewable electricity generation system (1).

3. The method according to claim 1 or 2, further comprising the following steps: Upon request, the user (2) is temporarily granted permission to perform additional operations on the renewable power generation system (1).

4. The method according to claim 3, wherein: The step of temporarily granting the user (2) permission to perform additional operations on the renewable power generation system (1) requires separate authentication of the user (2).

5. A method according to any one of the preceding claims, wherein: The step of assigning a set of access rights to the user (2) comprises classifying the user (2) into a predefined user profile, and wherein the step of automatically adjusting the set of access rights assigned to the user (2) comprises classifying the user (2) into another predefined user profile.

6. The method according to claim 5, further comprising the steps of: - recording operations performed on the renewable electricity generation system (1) by a user (2) classified into a certain user profile and comparing the performed operations with the set of predefined operations associated with the user profile, and - If the comparison reveals a difference between the performed operation and the set of predefined operations associated with the user profile, automatically adjusting the set of access rights associated with the user profile by removing at least some of the access rights associated with the predefined operations that were not performed, thereby automatically adjusting the user rights assigned to all users (2) classified into the user profile.

7. A method according to any one of the preceding claims, wherein: The renewable energy power generation system (1) is a wind turbine or a wind power plant.

8. A method according to any one of the preceding claims, wherein: The step of recording the actions performed by the user (2) includes performing artificial intelligence (AI) driven analysis on the recorded data.

9. The method according to claim 8, wherein: The AI-driven analysis includes identifying patterns in actions performed by the user (2) and comparing the identified patterns to expected behavior of a user (2) requiring the entire set of assigned access rights.