User authority control system for power system
By designing a user permission control system for multi-level organization and user management modules, data resource management modules, dynamic permission management modules and monitoring and audit modules, the existing power system information system permission management solution is solved in the insufficient performance of the existing power system information system permission management solution in the face of dynamic data changes and user behavior complexity, and efficient, safe and flexible permission management is achieved.
Patent Information
- Application Number
- CN202510100669.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-16
AI Technical Summary
When facing dynamic data changes, data sensitivity differences, business compliance requirements and user behavior complexity, the existing power system information system authority management solution has poor overall performance, and there are problems such as rough permission division, lack of dynamic adjustment mechanism, insufficient audit and monitoring, and poor scalability and compatibility.
A user permission control system including multi-level organization and user management module, data resource management module, dynamic permission management module and monitoring and audit module is designed. The system realizes fine division and strict control of user permissions through a multi-level role model, data classification and labeling system, and functional permission matrix, and supports dynamic policy engines and permission inheritance and coverage mechanisms.
It realizes efficient control of user rights of the power system, improves the security, flexibility and compliance of the system, optimizes the user experience, and improves the scalability and compatibility of the system.
Smart Images

Figure CN120013473A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of electrical automation, and in particular relates to a user authority control system for an electric power system. Background Art
[0002] With the development of economy and technology and the improvement of people's lives, electricity has become an indispensable secondary energy source in people's production and life, bringing endless convenience to people's production and life. Therefore, ensuring the stable and reliable supply of electricity has become one of the most important tasks of the power system.
[0003] At present, the information system of the power system itself is becoming increasingly complex, involving an extremely large amount of data and a large number of functional modules. At present, the authority management scheme of the information system of the power system itself adopts the traditional and commonly used role-based access control (RBAC). Although such schemes have simplified the process of authority management to a certain extent, they have poor overall performance when facing dynamic changes in data, differences in data sensitivity, business compliance requirements, and the complexity of user behavior. In addition, there are many problems, including rough authority division, lack of dynamic adjustment mechanism, insufficient auditing and monitoring, and poor scalability and compatibility. Summary of the invention
[0004] The object of the present invention is to provide a user authority control system for an electric power system with high reliability, good compatibility and good scalability.
[0005] The user authority control system for an electric power system provided by the present invention comprises a multi-level organization and user management module, a data resource management module, a dynamic authority control module and a monitoring and auditing module; the multi-level organization and user management module, the data resource management module, the dynamic authority control module and the monitoring and auditing module are all interconnected; the multi-level organization and user management module is used to realize organizational maintenance, position management and employee management with several levels of organization, position and employee management as the core; the data resource management module controls controlled resources to realize controlled resource management and business data management; the dynamic authority control module controls dynamic permissions to realize authority allocation, role life cycle management, authority inheritance management, organization and authority transfer management and data authority management; the monitoring and auditing module is used to realize authority usage records, audit log records, abnormal behavior monitoring, data classification management, functional authority management, dynamic authority control and logic expansion.
[0006] The user authority control system for the power system, the system elements include objects, resources, operations and data; the objects include users, roles, user groups, organizations and positions; the resources include objects that can be viewed and operated; the operations include operations that users can perform; the data include the scope of data that users can view.
[0007] The multi-level organization and user management module includes the following contents:
[0008] The functions of the multi-level organization and user management module include:
[0009] Maintain the organizational structure: build a tree or mesh organizational structure to achieve expandable organizational maintenance functions; maintain the organizational hierarchy; implement add, delete, modify and query operations, and perform tagging and classification maintenance functions;
[0010] Conduct job management: classify and summarize employees’ work based on their natural attributes to abstract job categories; define and maintain jobs, and define job attributes;
[0011] Conduct employee management: manage internal and external employees, and define, add, delete, modify, query and mark employee attributes.
[0012] The data resource management module includes the following contents:
[0013] The functions of the data resource management module include:
[0014] Controlled resource management: unified management and control of operable function buttons, page menus, and page editing capabilities; unified registration and control of controllable functions to achieve the management of controlled resources;
[0015] Business data management: Perform hierarchical management of data, including data authority management and feature management. Data authority management is defined through the organizational attributes of the data. Feature management is managed through data feature definitions.
[0016] The dynamic permission control module includes the following contents:
[0017] The functions of the dynamic permission management module include:
[0018] Automatic authority allocation: For new employees, after they are assigned to the corresponding organizational unit, the corresponding authority is automatically allocated to them; when an employee is transferred to another position, after the organizational unit is adjusted, the authority of the employee is automatically modified accordingly;
[0019] Role lifecycle management: Implement full lifecycle management of roles, including role creation, modification, deletion, activation, and deactivation, to achieve flexibility and security in role management;
[0020] Permission inheritance management: define several levels of roles to form a role hierarchy; the top-level role has the highest permissions and can assign or revoke permissions to sub-roles; sub-roles can inherit certain permissions from the parent role and can be adjusted or expanded according to business needs;
[0021] Organization and authority transfer management: when an employee leaves the original department and a new employee takes over the job, the organization and authority transfer is automatically realized;
[0022] Data permission management: Associate roles with organizations and ensure that organization members can only access data within their organizational level, and ensure that members of each department can only view data directly related to their own organization to achieve isolation and protection of cross-departmental data.
[0023] The monitoring and auditing module specifically includes the following contents:
[0024] The functions of the monitoring and auditing module include:
[0025] Record the permission usage of all users, including access time, access object, operation type and operation result;
[0026] Provide audit log query and export functions;
[0027] Abnormal behavior monitoring: Through pre-trained machine learning algorithms and set rule engines, users' access behaviors are monitored and analyzed in real time, and abnormal behaviors are identified.
[0028] The user authority control system for the power system further includes the following contents:
[0029] Data classification and label control: classify data according to its dimensions, including sensitivity, importance, and business relevance; label each type of data to facilitate subsequent permission control based on the label; dynamically manage data labels and adjust labels according to changes in data content; formulate data access rules based on data classification and labels;
[0030] Functional authority matrix management and control: define authority points for each functional module and specific operation to form a functional authority matrix; the rows of the matrix represent functional modules, and the columns of the matrix represent operation authorities; by checking or unchecking the authority points in the matrix, corresponding functional authorities can be assigned or revoked for different roles; support the authority inheritance relationship between roles, and the child role can inherit several functional authorities of the parent role, and can cover or adjust the authority of the child role to meet business needs;
[0031] Dynamic permission control: allows administrators to define dynamic permission adjustment rules based on business needs and security policies; the dynamic policy engine is responsible for parsing and executing policy rules. When a user initiates an access request, the engine dynamically calculates the user's permission set based on the user's current information and decides whether to allow access; the user's current information includes role, attributes, current time and operating environment; the policy rules can be automatically adjusted based on security events, user behavior analysis or business changes; it provides policy auditing functions and records the execution and effect of the policy;
[0032] Control logic expansion control: realize standardized operation and data control through hierarchical control of organizational roles, functional roles and user roles; set organizational roles according to organizational structure and functional roles according to positions; obtain the user role possessed by logging in to the user information, thereby obtaining the organizational role and functional role possessed, and obtaining the corresponding operation and data permissions.
[0033] The user authority control system for the power system provided by the present invention not only realizes the control of user authority of the power system through organization and user management, data resource management, dynamic authority management and monitoring audit, but also has higher reliability, better compatibility and better scalability. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 Schematic diagram of the functional modules of the system of the present invention. DETAILED DESCRIPTION
[0035] like Figure 1 The figure shows a schematic diagram of the functional modules of the system of the present invention: the user authority control system for the power system provided by the present invention comprises a multi-level organization and user management module, a data resource management module, a dynamic authority control module and a monitoring and auditing module; the multi-level organization and user management module, the data resource management module, the dynamic authority control module and the monitoring and auditing module are all interconnected; the multi-level organization and user management module is used to realize organizational maintenance, position management and employee management with several levels of organization, position and employee management as the core; the data resource management module controls the controlled resources to realize the controlled resource management and business data management; the dynamic authority control module controls the dynamic authority to realize the authority allocation, role life cycle management, authority inheritance management, organization and authority transfer management and data authority management; the monitoring and auditing module is used to realize the authority usage record, audit log record, abnormal behavior monitoring, data classification management, functional authority management, dynamic authority control and logic expansion.
[0036] Among them, the system elements of the user authority control system for the power system include objects, resources, operations and data; the objects include users, roles, user groups, organizations and positions; the resources include objects that can be viewed and operated; the operations include operations that users can perform, such as whether they can add, delete, edit, etc.; the data includes the scope of data that users can view, for example, the superior unit can see all subordinate data, and the same level and subordinate units cannot view and operate the data, etc.
[0037] In specific implementation, the multi-level organization and user management module includes the following contents:
[0038] The functions of the multi-level organization and user management module include:
[0039] Since the power system has a specific organizational structure, there are many positions under one organization. For example, in terms of finance, there are positions such as financial director, financial supervisor, accountant, cashier, etc. Each position requires different permissions, and permission control is divided into subdivisions based on this structure.
[0040] Maintain the organizational structure: build a tree or mesh organizational structure to achieve expandable organizational maintenance functions; maintain the organizational hierarchy; implement add, delete, modify and query operations, and perform tagging and classification maintenance functions;
[0041] Conduct job management: classify and summarize employees’ work based on their natural attributes to abstract job categories; define and maintain jobs, and define job attributes;
[0042] Conduct employee management: manage internal and external employees, and define, add, delete, modify, query and mark employee attributes.
[0043] In specific implementation, the data resource management module includes the following contents:
[0044] The functions of the data resource management module include:
[0045] Controlled resource management: unified management and control of operable function buttons, page menus, and page editing capabilities; unified registration and control of controllable functions to achieve the management of controlled resources;
[0046] Business data management: Perform hierarchical data management, including data authority management and feature management. Data authority management is defined through the organizational attributes of the data. Feature management is managed through data feature definitions, such as personal data, confidential data, etc., which are mainly implemented through data feature definitions.
[0047] The dynamic permission control module includes the following contents:
[0048] Provides an administrator interface that supports role management, permission allocation, policy definition, audit query and other operations through a graphical interface and drag-and-drop operations, reducing management difficulty and complexity;
[0049] The functions of the dynamic permission management module include:
[0050] Automatic authority allocation: For new employees, after they are assigned to the corresponding organizational unit, the corresponding authority is automatically allocated to them; when an employee is transferred to another position, after the organizational unit is adjusted, the authority of the employee is automatically modified accordingly;
[0051] Role lifecycle management: Implement full lifecycle management of roles, including role creation, modification, deletion, activation, and deactivation, to achieve flexibility and security in role management;
[0052] Permission inheritance management: define several levels of roles to form a role hierarchy; the top-level role has the highest permissions and can assign or revoke permissions to sub-roles; sub-roles can inherit certain permissions from the parent role and can be adjusted or expanded according to business needs;
[0053] Organization and authority transfer management: When an employee leaves the original department and a new employee takes over the job, the organization and authority transfer is automatically realized; the content transferred is generally roles and menus, and more refined content can be divided into subordinates, to-do, done, documents, customers, etc.;
[0054] Data permission management: Associate roles with organizations and ensure that organization members can only access data within their organizational level, and ensure that members of each department can only view data directly related to their own organization to achieve isolation and protection of cross-departmental data.
[0055] In specific implementation, the monitoring and auditing module includes the following contents:
[0056] The functions of the monitoring and auditing module include:
[0057] Record the permission usage of all users, including access time, access object, operation type and operation result;
[0058] Provide audit log query and export functions;
[0059] Abnormal behavior monitoring: Through pre-trained machine learning algorithms and set rule engines, users' access behaviors are monitored and analyzed in real time, and abnormal behaviors (such as frequent access to sensitive data, attempts at illegal operations, etc.) are identified. Once abnormal behavior is detected, the alarm mechanism is immediately triggered to notify the administrator for processing.
[0060] In addition, the user authority control system for the power system provided by the present invention also includes the following contents:
[0061] Data classification and label control: Classify data according to its dimensions, for example, classify financial data, customer information, project information, etc. into sensitive data, important data, and general data respectively; the dimensions include sensitivity, importance, and business relevance; label each type of data to facilitate subsequent permission control based on the label, such as "confidential", "internal use", "public", etc.; dynamically manage data labels and adjust labels according to changes in data content; formulate data access rules based on data classification and labels, for example, stipulate that only users with specific roles can access sensitive data, or only users who meet specific conditions can view or modify data with confidential labels;
[0062] Functional authority matrix management and control: define authority points for each functional module and specific operation to form a functional authority matrix; the rows of the matrix represent functional modules, and the columns of the matrix represent operation authorities; by checking or unchecking the authority points in the matrix, corresponding functional authorities can be assigned or revoked for different roles; support the authority inheritance relationship between roles, and the child role can inherit several functional authorities of the parent role, and can cover or adjust the authority of the child role to meet business needs;
[0063] Dynamic permission control: allows administrators to define dynamic permission adjustment rules based on business needs and security policies. For example, it stipulates that only users with specific roles can access certain sensitive data within a specific time period. The dynamic policy engine is responsible for parsing and executing policy rules. When a user initiates an access request, the engine dynamically calculates the user's permission set based on the user's current information and decides whether to allow access. The user's current information includes role, attributes, current time and operating environment. It can automatically adjust policy rules based on security events, user behavior analysis or business changes. It provides policy auditing functions and records the execution and effects of policies. At the same time, it improves the accuracy and effectiveness of permission management by continuously learning and adjusting policy rules.
[0064] Control logic expansion control: realize standardized operation and data control through hierarchical control of organizational roles, functional roles and user roles; set organizational roles according to organizational structure and functional roles according to positions; obtain the user role possessed by logging in to the user information, thereby obtaining the organizational role and functional role possessed, and obtaining the corresponding operation and data permissions.
[0065] The advantages of the solution of the present invention include:
[0066] High security: Through the multi-level role model, data classification and labeling system, and functional permission matrix, the user rights are finely divided and strictly controlled, effectively preventing data leakage and illegal operations, and improving the security of the system.
[0067] High flexibility: Supports dynamic policy engine and permission inheritance and override mechanism, timely adjusts permissions according to business changes, user behavior or security incidents, meets the dynamic needs of the enterprise, and improves management efficiency.
[0068] Improve compliance: Through the audit and monitoring module, all permission usage and abnormal behaviors are recorded to facilitate security analysis and compliance checks, helping enterprises comply with industry standards and legal and regulatory requirements.
[0069] Optimize user experience: Provide an intuitive and easy-to-use user interface and interactive design to reduce management difficulty and user learning costs, and improve user experience and satisfaction.
[0070] High scalability and compatibility: The system adopts a modular design, which supports the rapid access of new functional modules and the smooth upgrade of old functional modules, improving the scalability and compatibility of the system.
Claims
1. A user authority control system for a power system, characterized in that It includes a multi-level organization and user management module, a data resource management module, a dynamic permission control module and a monitoring and auditing module; the multi-level organization and user management module, the data resource management module, the dynamic permission control module and the monitoring and auditing module are all interconnected; the multi-level organization and user management module is used to realize organizational maintenance, position management and employee management with several levels of organization, position and employee management as the core; the data resource management module controls controlled resources to realize controlled resource management and business data management; the dynamic permission control module controls dynamic permissions to realize permission allocation, role life cycle management, permission inheritance management, organization and permission transfer management and data permission management; the monitoring and auditing module is used to realize permission usage records, audit log records, abnormal behavior monitoring, data classification management, functional permission management, dynamic permission control and logical extension.
2. The user authority control system for the power system according to claim 1, characterized in that System elements include objects, resources, operations and data; the objects include users, roles, user groups, organizations and positions; the resources include objects that can be viewed and operated; the operations include operations that users can perform; and the data include the scope of data that users can view.
3. The user authority control system for the power system according to claim 2 is characterized in that The multi-level organization and user management module includes the following contents: The functions of the multi-level organization and user management module include: Maintain the organizational structure: build a tree or mesh organizational structure to achieve expandable organizational maintenance functions; maintain the organizational hierarchy; implement add, delete, modify and query operations, and perform tagging and classification maintenance functions; Conduct job management: classify and summarize employees’ work based on their natural attributes to abstract job categories; define and maintain jobs, and define job attributes; Conduct employee management: manage internal and external employees, and define, add, delete, modify, query and mark employee attributes.
4. The user authority control system for the power system according to claim 2, characterized in that The data resource management module includes the following contents: The functions of the data resource management module include: Controlled resource management: unified management and control of operable function buttons, page menus, and page editing capabilities; unified registration and control of controllable functions to achieve the management of controlled resources; Business data management: Perform hierarchical management of data, including data authority management and feature management. Data authority management is defined through the organizational attributes of the data. Feature management is managed through data feature definitions.
5. The user authority control system for the power system according to claim 2, characterized in that The dynamic permission control module includes the following contents: The functions of the dynamic permission management module include: Automatic authority allocation: For new employees, after they are assigned to the corresponding organizational unit, the corresponding authority is automatically allocated to them; when an employee is transferred to another position, after the organizational unit is adjusted, the authority of the employee is automatically modified accordingly; Role lifecycle management: Implement full lifecycle management of roles, including role creation, modification, deletion, activation, and deactivation, to achieve flexibility and security in role management; Permission inheritance management: define several levels of roles to form a role hierarchy; the top-level role has the highest permissions and can assign or revoke permissions to sub-roles; sub-roles can inherit certain permissions from the parent role and can be adjusted or expanded according to business needs; Organization and authority transfer management: when an employee leaves the original department and a new employee takes over the job, the organization and authority transfer is automatically realized; Data permission management: Associate roles with organizations and ensure that organization members can only access data within their organizational level, and ensure that members of each department can only view data directly related to their own organization to achieve isolation and protection of cross-departmental data.
6. The user authority control system for the power system according to claim 2, characterized in that The monitoring and auditing module specifically includes the following contents: The functions of the monitoring and auditing module include: Record the permission usage of all users, including access time, access object, operation type and operation result; Provide audit log query and export functions; Abnormal behavior monitoring: Through pre-trained machine learning algorithms and set rule engines, users' access behaviors are monitored and analyzed in real time, and abnormal behaviors are identified.
7. The user authority control system for the power system according to claim 1, characterized in that Also includes the following: Data classification and label control: classify data according to its dimensions, including sensitivity, importance, and business relevance; label each type of data to facilitate subsequent permission control based on the label; dynamically manage data labels and adjust labels according to changes in data content; formulate data access rules based on data classification and labels; Functional authority matrix management and control: define authority points for each functional module and specific operation to form a functional authority matrix; the rows of the matrix represent functional modules, and the columns of the matrix represent operation authorities; by checking or unchecking the authority points in the matrix, corresponding functional authorities can be assigned or revoked for different roles; support the authority inheritance relationship between roles, and the child role can inherit several functional authorities of the parent role, and can cover or adjust the authority of the child role to meet business needs; Dynamic permission control: allows administrators to define dynamic permission adjustment rules based on business needs and security policies; the dynamic policy engine is responsible for parsing and executing policy rules. When a user initiates an access request, the engine dynamically calculates the user's permission set based on the user's current information and decides whether to allow access; the user's current information includes role, attributes, current time and operating environment; the policy rules can be automatically adjusted based on security events, user behavior analysis or business changes; it provides policy auditing functions and records the execution and effect of the policy; Control logic expansion control: realize standardized operation and data control through hierarchical control of organizational roles, functional roles and user roles; set organizational roles according to organizational structure and functional roles according to positions; By logging in to the user information, you can obtain the user role you have, and then obtain the organizational role and functional role you have, and obtain the corresponding operation and data permissions.
Citation Information
Patent Citations
Centralized identity and management method aiming at electric power information system
CN104125219A
Enterprise sensitive data security access management method and system
CN118656870A
Cited By
Power station material management method, device and equipment based on smart storage
CN120278645A
Data authority grouping management method and system
CN120811666A
Power station material access control method and authentication system based on dynamic permission configuration
CN121664544A