Data management method and system for complex heterogeneous power terminal equipment

By storing data files in the visual management unit and monitoring management unit in the data management platform, and setting up review permissions according to the control level, problems such as data dispersion and low security in the data management of complex heterogeneous power terminal equipment are solved, and data security and controllability are achieved.

CN120180478AActive Publication Date: 2025-06-20NINGBO TRANSMISSION & DISTRIBUTION CONSTR
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510638581.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-06-20
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

Existing power data management systems are difficult to effectively manage data from complex heterogeneous power terminal equipment, and there are problems such as data dispersion, redundancy, low security, poor permission management, inflexible update and maintenance mechanisms, and incomplete data access monitoring.

Method used

The data management platform is used to store data files in the visual management unit and the monitoring management unit, set the review permissions according to the control level, verify the access rights of the data query personnel through the supervision module, and monitor the control files in real time.

Benefits of technology

The classification management of data is realized, the security and controllability of data is ensured, the efficiency and reliability of data management are improved, and the storage conditions judgment of new files and iterative files can be handled more accurately.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180478A_ABST
    Figure CN120180478A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data management, in particular to a data management method and system for complex heterogeneous power terminal equipment, and aims to solve the problem of how to effectively manage data of the complex heterogeneous power terminal equipment and ensure the safety and controllability of the data. The embodiment of the invention provides a data management method for complex heterogeneous power terminal equipment. The data management method comprises the steps that a data file is stored in a data management platform, and the data file is stored in a visual management unit and a monitoring management unit in the data management platform; recording the data file in the visual management unit as a general file, recording the data file in the monitoring management unit as a management and control file, and setting a lookup permission for the management and control file according to the management and control level; and when the management and control file receives a query request, a supervision module in the data management platform checks the access permission of the data query personnel, and sets the display state of the management and control file according to the access permission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and in particular, to a data management method and system for complex heterogeneous power terminal devices. Background Art

[0002] As an advanced productive force and basic industry, the power industry plays an important role in promoting the development of the national economy and social progress, and has a very close relationship with social economy and social development. Therefore, it is necessary to store and monitor power data to effectively ensure the normal operation of power. The leakage of power data is mainly caused by external attacks or internal personnel leakage. Therefore, strengthening the defense against external attacks and the classified management of internal personnel permissions are the key ways to effectively protect these power data.

[0003] However, the data management challenges faced by the current power industry are becoming increasingly complex. With the continuous expansion of the scale of the power system and the improvement of the degree of intelligence, the amount of data generated has increased exponentially, and the data types have become more and more diverse. These data come from different terminal devices, including various links such as power generation, transmission, distribution, and power consumption, forming a complex heterogeneous data environment. In this case, traditional data management methods are difficult to meet the requirements.

[0004] Existing power data management systems often have the following problems: First, there is a lack of a unified management strategy for different types of data, resulting in scattered and redundant data, which is difficult to effectively utilize; second, the data security protection measures are not perfect, especially the permission management for internal personnel is not fine enough, increasing the risk of data leakage; third, the data update and maintenance mechanism is not flexible enough, and it is difficult to respond in a timely manner to the dynamic changes of the power system; finally, the monitoring of data access is not comprehensive enough, and potential security threats cannot be discovered and processed in real time. Summary of the Invention

[0005] The problem solved by the present invention: How to effectively manage the data of complex heterogeneous power terminal devices and ensure the security and controllability of the data.

[0006] To solve the above problems, an embodiment of the present invention provides a data management method for complex heterogeneous power terminal devices. The data management method includes: data files are stored in a data management platform, and the data files are stored in a visual management unit and a monitoring management unit within the data management platform; the data files in the visual management unit are denoted as general files, and the data files in the monitoring management unit are denoted as control files, and access permissions are set for the control files according to the control level; when an update file needs to be input into the data management platform, the update code of the update file is obtained, and the update code is compared with the theoretical code of the update file to determine whether the update file meets the storage conditions; when a query request is received for a control file, the supervision module in the data management platform verifies the access permissions of the data query personnel and sets the display status of the control file according to the access permissions; when the control file is in the viewing state, the data query personnel are monitored in real time according to the control level corresponding to the control file.

[0007] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: The data management platform realizes the classified management of data by storing data files in the visual management unit and the monitoring management unit and setting access permissions according to the control level; by setting access permissions for the control files, the security of the data is ensured; in the management process of the update file, by obtaining the update code of the update file and comparing it with the theoretical code, it is ensured that only the update files that meet the storage conditions can be stored; in the data query process, by the supervision module verifying the access permissions of the data query personnel and monitoring in real time, the security of the data during the viewing process is ensured. Thus, the security and controllability of the data management of complex heterogeneous power terminal devices are realized as a whole.

[0008] In an embodiment of the present invention, when an update file needs to be input into the data management platform, the update code of the update file is obtained, and the update code is compared with the theoretical code of the update file to determine whether the update file meets the storage conditions, which specifically includes: The update file includes a new file and an iterative file. The new file has a new code, and the iterative file has a current iteration code; when only the iterative file exists in the update file, the actual iteration times of the iterative file and the historical iteration code of the iterated file are obtained; it is determined whether the update file meets the storage conditions according to the historical iteration code, the actual iteration times, and the current iteration code; when only the new file exists in the update file, the new instruction corresponding to the new file is obtained in the data management platform, and it is determined whether the update file meets the storage conditions according to the new instruction and the new code; when both the new file and the iterative file exist in the update file, it is determined whether the update file meets the storage conditions according to the actual iteration times and the new instruction.

[0009] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: By obtaining the update code of the update file and comparing it with the theoretical code, it is possible to accurately determine whether the update file meets the storage conditions, ensuring the accuracy and consistency of the data file; The present invention can more precisely process the judgment of the storage conditions for newly added files and iterative files, improving the efficiency and reliability of data management.

[0010] In an embodiment of the present invention, when determining whether the update file meets the storage conditions based on the historical iteration code, the actual iteration times, and the current iteration code, it further includes: Retrieving the first conversion key of the historical iteration code according to the actual iteration times, and converting the historical iteration code according to the first conversion key to obtain the standard iteration code; Determining whether the update file meets the storage conditions based on the standard iteration code and the current iteration code.

[0011] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: By introducing the first conversion key and the standard iteration code, the technical problems in the judgment of the storage conditions for update files are solved, improving the accuracy and reliability of the judgment; The present invention can not only ensure that the update file meets the specified storage conditions before storage, but also prevent storage errors caused by inaccurate iteration history, further enhancing the security and stability of the data management platform.

[0012] In an embodiment of the present invention, when the update file contains both newly added files and iterative files, when determining whether the update file meets the storage conditions based on the actual iteration times and the new addition instruction, it specifically includes: Obtaining the new addition number corresponding to the newly added file, and converting the value of the new addition number into the corresponding theoretical iteration times according to the iteration period; Obtaining the first conversion key of the iterative file according to the actual iteration times, and obtaining the second conversion key of the iterative file according to the theoretical iteration times; Determining whether the newly added file meets the storage conditions based on the first conversion key and the new addition instruction; Determining whether the iterative file meets the storage conditions based on the first conversion key and the second conversion key.

[0013] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: By converting and judging the numbers and instructions of the newly added files and iterative files, it is possible to effectively ensure the accuracy and effectiveness of the files during storage, avoiding data management problems caused by the files not meeting the storage conditions; The present invention improves the accuracy and reliability of data management by introducing the conversion key and the judgment mechanism of the new addition instruction, and can better meet the data management requirements of complex heterogeneous power terminal devices.

[0014] In an embodiment of the present invention, when a controlled file receives a query request, the supervision module in the data management platform verifies the access rights of the data query personnel and sets the display status of the controlled file according to the access rights, which specifically includes: performing corresponding environment settings on the access environment of the controlled file according to the control level of the controlled file, denoted as environment rights; when the data query personnel pass the identity verification of the supervision module, the supervision system monitors the access environment in real time and manages the display status of the controlled file according to the access environment and the corresponding environment rights; when the data query personnel do not pass the identity verification of the supervision module, the data management platform grants the data query personnel corresponding access rights according to the query request of the data query personnel.

[0015] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: by verifying the access rights of the data query personnel through the supervision module and setting the display status of the controlled file according to the access rights, the effective management of the access rights and display status of the controlled file is realized during the data query process. The present invention improves the security and reliability of the data and ensures the secure display of the controlled file in different access environments.

[0016] In an embodiment of the present invention, when the data query personnel pass the identity verification of the supervision module, the supervision system monitors the access environment in real time and manages the display status of the controlled file according to the access environment and the corresponding environment rights, which specifically includes: when the access environment meets the corresponding environment rights, the supervision module retrieves the corresponding controlled file in the data management unit and establishes a query log; when the access environment does not meet the corresponding environment rights, the supervision module locks the controlled file.

[0017] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: through the application of the supervision module and the supervision system, an effective technical solution is proposed, which can strictly monitor the access environment and perform rights management during the data query process. The advantages of the present invention are that it can monitor the access environment in real time, ensure the legality and traceability of data queries, and prevent unauthorized access, thereby effectively protecting the security of the data. Therefore, the present invention has made significant technical progress in solving the technical problem of managing the display status of the controlled file according to the query environment rights during the data query process.

[0018] In an embodiment of the present invention, when a data query person fails to pass the authentication of the supervision module, the data management platform grants the corresponding access rights to the data query person according to the query request of the data query person, specifically including: the data management platform identifies the identity of the data query person; when the data query person is an internal person, the data query person can obtain a general file and send a decryption application to the data management platform through the supervision module; when the data query person is not an internal person, a decryption application is sent to the data management platform through the supervision module.

[0019] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: by introducing an identity recognition and permission management mechanism, the problem of access rights for data query persons who have not passed the authentication of the supervision module is effectively solved. The technical solution of the present invention not only improves the security of data, but also simplifies the access process and enhances the user experience. Especially for internal persons, they can conveniently and quickly obtain the required information on the premise of ensuring data security. For external persons, through the decryption application mechanism of the supervision module, their access needs can also be met to a certain extent. Thus, the present invention achieves a good balance between security and convenience.

[0020] In an embodiment of the present invention, when a controlled file is in a viewing state, real-time monitoring is performed on the data query person according to the control level corresponding to the controlled file, specifically including: setting corresponding operation permissions, viewing times threshold, and viewing time threshold according to the control level of the controlled file; when the operation behavior of the data query person exceeds the operation permissions of the controlled file, an alarm message is sent to the data management platform; when the operation behavior of the data query person exceeds the operation permissions of the controlled file, an alarm message is sent to the data management platform; when the viewing times of the data query person are greater than the viewing times threshold, an alarm message is sent to the data management platform; when the viewing time of the data query person is greater than the viewing time threshold, an alarm message is sent to the data management platform.

[0021] Compared with the prior art, the technical effects achieved by adopting this technical solution are as follows: by setting the viewing times threshold and the viewing time threshold, real-time monitoring is performed on the viewing behavior of the data query person, and potential data leakage risks can be discovered and prevented in a timely manner. Different monitoring thresholds are set according to different levels of the controlled file, which has higher flexibility and security. Therefore, the present invention provides a more flexible and secure data management method, which can effectively protect the security of power data.

[0022] In one embodiment of the present invention, the present invention further provides a management system for complex heterogeneous power terminal devices. The management method described in the above embodiment is applied to this management system. The management system includes: a data storage module for storing general files and control files; a data management module for setting access permissions for control files; a data analysis module for analyzing whether an update file meets the storage conditions; and a data monitoring module for real-time monitoring of data query personnel. This management system has all the technical features of the above management method and will not be elaborated here one by one. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 FIG. 1 is one of the flowcharts of the data management method for complex heterogeneous power terminal devices of the present invention; Figure 2 FIG. 2 is another flowchart of the data management method for complex heterogeneous power terminal devices of the present invention; Figure 3 FIG. 3 is yet another flowchart of the data management method for complex heterogeneous power terminal devices of the present invention; Figure 4 FIG. 4 is still another flowchart of the data management method for complex heterogeneous power terminal devices of the present invention; Figure 5 FIG. 5 is a schematic diagram of the management system of the present invention; DESCRIPTION OF REFERENCE NUMERALS: 100 - management system; 110 - data storage module; 120 - data management module; 130 - data analysis module; 140 - data monitoring module. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention is provided in conjunction with the accompanying drawings.

[0025]

First Embodiment

[0026] In steps S100 and S200, the data management platform is divided into a visual management unit and a monitoring management unit according to the control level of the data file. The general files and control files are stored in the visual management unit and the monitoring management unit respectively. General files are usually files with a relatively low level of importance, such as temporary files generated within the company. The company can view and modify the temporary files at any time. Control files are usually files with a relatively high level of importance, such as the personal information of internal customers in the company, the work plan for the next quarter within the company, etc. Different viewing permissions are set for the control files according to the control level corresponding to the control files. Only personnel with viewing permissions can view the control files.

[0027] In step S300, generally, the data files in the data platform need to be changed, added, or deleted. However, when inputting updated files into the data management platform, various problems are usually encountered, such as data integrity problems, data format compatibility problems, data security problems, permission control problems, and performance problems. Therefore, it is necessary to obtain the update code of the updated file and compare the update code of the updated file with the theoretical code of the updated file during the input process of the updated file to determine whether the updated file meets the storage conditions. In addition, the theoretical code and the update code refer to code segments or instructions used to update the content or version of a specific file. These codes usually contain information such as the specific content of the updated file, the update method, and the update conditions. Among them, the update conditions include the memory size occupied by the updated file.

[0028] For example, the update condition shows that the memory size occupied by the updated file is 18KB. When the size of the updated file is 18KB, the updated file is stored in the monitoring management unit; when the size of the updated file is not 18KB, the updated file is returned to the upload location.

[0029] In step S400, the supervision module is set in the data transmission platform, which is used to establish the connection relationship between the data query personnel and the data management platform, and verify the access rights of the data query personnel. A large number of control files are stored in the monitoring and management unit, and different data query personnel have different access rights to the control files. When a query request is received for a control file, the supervision module can verify the data query personnel through a combined verification method. For example, the supervision module verifies the data query personnel through a dual encryption method of facial recognition and password input.

[0030] For example, a certain data query personnel has access rights to control file 1, control file 2, and control file 3. Then, when the data query personnel passes the verification of the supervision module, the monitoring and management unit hides the control files other than control file 1, control file 2, and control file 3.

[0031] In step S500, the data management platform sets different access rights for the control files according to the importance of the control files. The access rights include operation rights, the number of access times, and access time. Among them, the operation rights include but are not limited to: copy, modify, delete, download. Usually, when the control file is in the access state, data leakage may occur due to improper query behaviors of the data query personnel. Therefore, when the data query personnel access the control file, the data management platform needs to monitor the data query personnel in real time to facilitate judging whether the query behaviors of the data query personnel meet the requirements.

[0032] The data management platform realizes the classified management of data by storing the data files in the visual management unit and the monitoring and management unit and setting access rights according to the control level; by setting access rights for the control files, the security of the data is ensured. In the management process of updating files, by obtaining the update code of the update file and comparing it with the theoretical code, it is ensured that only the update files that meet the storage conditions can be stored. In the data query process, through the supervision module to verify and monitor the access rights of the data query personnel in real time, the security of the data during the access process is ensured. Thus, the security and controllability of the data management of complex heterogeneous power terminal devices are realized as a whole.

[0033]

Second Embodiment

[0034] In step S310, according to the nature of the updated file, the updated file is divided into a newly added file and an iterative file. A newly added file refers to inputting a new file on the data management platform. An iterative file generally refers to processing the content or the file itself in the file according to specific rules or conditions during the file processing. The new code refers to the code related to the newly added file. For example, the new code of the newly added file is set according to the memory size occupied by the newly added file; the current iteration code refers to the code related to the iterative file. For example, usually, when modifying the original data file, there are specific modification ranges and modification contents, and the current iteration code of the iterative file can be set according to the modification range and modification content.

[0035] In steps S320 and S330, generally, the historical iteration code of the file being iterated refers to that the data management platform will input the iteration code of the file being iterated into the monitoring and management unit in advance according to the data change requirements of the file being iterated. In addition, the data management platform will record the iteration count of the file being iterated. When a new iterative file is input, the data management platform will calculate the true iteration count of the iterative file according to the iteration count of the file being iterated. For example, if the iteration count of the file being iterated is 5 times, then when a new iterative file is input, the true iteration count of the new iterative file is 6 times.

[0036] In step S340, the new instruction corresponding to the newly added file can determine whether the newly added file is the target file. Generally, the new instruction can be set by the file name, the file content, and the byte size occupied by the file. For example, a specific prefix or suffix is added to the name of the newly added file to set the new instruction corresponding to the newly added file.

[0037] By obtaining the update code of the updated file and comparing it with the theoretical code, it can accurately determine whether the updated file meets the storage conditions, ensuring the accuracy and consistency of the data file. The present invention can more precisely process the judgment of the storage conditions of newly added files and iterative files, improving the efficiency and reliability of data management.

[0038]

Third Embodiment

[0039] In steps S331 and S332, the first conversion key generally refers to a key piece of information or code used in processes such as data conversion, encryption / decryption, and format conversion. It can be in digital form, character form, byte array form, or biometric form. Usually, for data security, a different conversion key is set for each iteration of the file being iterated. When the actual iteration count of the iterated file is obtained, the first conversion key of the historical iteration code is retrieved according to the actual iteration count, and then the historical iteration code is converted using the first conversion key to obtain the standard iteration code. For example, by converting the historical iteration code using the first conversion key, the standard iteration code of the iterated file is a specific file name.

[0040] It should be noted that different data files have different conversion key tables, and the conversion key tables record the number of conversion keys corresponding to the data files. When the iteration count exceeds the number of conversion keys, the actual iteration count is calculated based on the current iteration count and the number of conversion keys, and the correct first conversion key is determined in the key conversion table according to the actual iteration count.

[0041] Denote the current iteration count as D1, the number of conversion keys as D2, and the actual iteration count as D3. The following relationships hold among the current iteration count, the number of conversion keys, and the actual iteration count: When D1 > D2, D3 = D1 mod D2; When D1 ≤ D2, D3 = D1.

[0042] In step S332, to determine whether the update file meets the storage conditions based on the standard iteration code and the current iteration code, when the standard iteration code and the current iteration code are the same, the update file meets the storage conditions; when the standard iteration code and the current iteration code are different, the update file does not meet the storage conditions.

[0043] By introducing the first conversion key and the standard iteration code, the technical problems in the judgment of the storage conditions for updated files are solved. The first conversion key is adjusted according to the number of iterations, further enhancing the security of data files during iteration and preventing virus files from entering the data management platform through iterative files. It can not only ensure that the updated files meet the specified storage conditions before storage, but also prevent storage errors caused by inaccurate iteration history, further enhancing the security and stability of the data management platform.

[0044]

Fourth Embodiment

[0045] In step S351, the new number of the newly added file is set according to the number of data files already stored in the data management platform. When the newly added file is uploaded to the data management platform, the data management platform will set the corresponding conversion key table and key conversion quantity according to the type of the newly added file. The iteration period is rounded according to the number of days, and then the value of the rounded iteration period is added to the value of the new number to obtain the basic key value of the newly added file. The basic key value is divided by the key conversion quantity, and the remainder is recorded as the theoretical iteration number.

[0046] In step S352, the first conversion key is obtained in the same way as in step S331, and the second conversion key is determined according to the theoretical iteration number and the conversion key table corresponding to the newly added file.

[0047] In steps S353 and S354, the storage of the newly added file needs to be verified by the first conversion key generated by the iterative file, and the storage of the iterative file needs to be verified by the second conversion key generated by the newly added file. Only when the keys generated by each other meet the preset conditions of the data management platform can the newly added file and the iterative file be stored in the data management platform at the same time.

[0048] It should be noted that for some important data files, the data management platform can set the upload method of the data files, and bind the upload of new files and iterative files to reduce the risk of viruses in the files received by the data management platform.

[0049] By converting and judging the numbers and instructions of new files and iterative files, the accuracy and effectiveness of the files during storage can be effectively ensured. The method of binding the upload of new files and iterative files sets different security modes for different types of data files, enhancing the security of the data management platform. Through comprehensive judgment using new instructions, the first conversion key, and the second conversion key, data error transmission is avoided, and the possibility of viruses being carried in data files is reduced, enabling better adaptation to the data management requirements of complex heterogeneous power terminal devices.

[0050]

Fifth Embodiment

[0051] In step S410, usually, the control level of the controlled file is set according to its importance. For example, the controlled files are divided into three control levels, namely the first level, the second level, and the third level. The higher the importance of the controlled file, the higher its control level. Set the first specific area and the second specific area. The environmental right of the controlled file at the first level is that when the controlled file at the first level needs to be consulted, other personnel can be present in both the first specific area and the second specific area; the environmental right of the controlled file at the second level is that when the controlled file at the second level needs to be consulted, no other personnel can be present in the second specific area; the environmental right of the controlled file at the third level is that when the controlled file at the first level needs to be consulted, no other personnel can be present in either the first specific area or the second specific area.

[0052] In step S420, when the data query personnel pass the authentication of the supervision module, the first specific area and the second specific area are monitored in real time through instruments such as cameras, and the display status of the control documents is managed according to the corresponding environmental permissions in the control documents. For example, when the data query personnel need to query the control documents of the second level and there are other people in the second specific area found through the camera, then this control document will not be displayed.

[0053] It should be noted that when the data management platform can perform identity authentication through face recognition, when a third-level control document receives a viewing request and the personnel in the first area and the second area are all personnel who can view, this control document can be displayed. Similarly, when a second-level control document receives a viewing request and the personnel in the second specific area are all personnel who can view, this control document can be displayed. In addition, when the control document is being viewed, the supervision system still needs to monitor the viewing environment in real time. When the viewing environment does not meet the environmental permissions, this control document is immediately locked and not displayed.

[0054] The supervision module verifies the access permissions of the data query personnel and sets the display status of the control documents according to the access permissions, thereby effectively managing the access permissions and display status of the control documents during the data query process, improving the security and reliability of the data, and ensuring the safe display of the control documents in different viewing environments.

[0055]

Sixth Embodiment

[0056] In step S421, in order to facilitate subsequent data management and tracking, the query log is created to record the query records of the data query personnel. The query records store the query time, query content of the data query personnel, and the operations performed by the query personnel on the control documents.

[0057] In step S422, for example, when there are people without access control permissions around the inquirer, it is determined that the current access environment does not meet the environmental permissions. At this time, the data management platform will lock the controlled files, and the unlocking cannot be completed by the inquirer himself. Unlocking requires approval from the inquirer's affiliated unit. After the approval is passed, the access permissions of the access environment are authenticated again, and the controlled files will be displayed again.

[0058] Through the application of the supervision module and the supervision system, it is possible to strictly monitor the access environment and manage permissions during the data query process, to monitor the access environment in real time, ensure the legality and traceability of data queries, and prevent unauthorized access at the same time, thereby effectively protecting the security of data. Therefore, the present invention has made significant technological progress in solving the technical problem of managing the display status of controlled files according to the access environment permissions during the data query process.

[0059]

Seventh Embodiment

[0060] In steps S431 and S432, in special cases, it may be necessary for people who originally did not have access permissions to access controlled files due to reasons such as internal personnel mobility. Therefore, it is necessary to identify the identity of the data query person through the data management platform. When the data query person is an internal person, when the data management platform receives the decryption application, it judges whether to send a decryption code to the data query person through the identity verification method. When the data query person passes the identity verification, the decryption code is sent. When the data query person fails the identity verification, the decryption code is not sent.

[0061] In step S433, in the era of data sharing, it may be encountered that multiple departments and companies share data. When the data query person is not an internal person, the data management platform can verify the identity of the data query person through various verification methods. When the data query person passes the identity verification, the decryption code is sent. When the data query person fails the identity verification, the decryption code is not sent.

[0062] By introducing an identity recognition and permission management mechanism, the problem of access rights for data query personnel who have not passed the authentication of the supervision module is effectively solved. This not only improves the security of data, but also simplifies the access process and enhances the user experience. Especially for internal personnel, they can conveniently and quickly obtain the required information on the premise of ensuring data security. For external personnel, through the decryption application mechanism of the supervision module, their access needs can also be met to a certain extent, achieving a good balance between security and convenience for the data management platform.

[0063]

Eighth Embodiment

[0064] In step S510, usually, for the convenience of data management and to prevent data leakage, it is necessary to set the operation permissions, viewing times threshold, and viewing time threshold of the controlled file. The operation permissions include, but are not limited to: taking pictures, copying, modifying, deleting, and downloading, etc. The viewing times threshold refers to the maximum number of times that each data query personnel can query, and the viewing time threshold refers to the longest time that each data query personnel can view each time.

[0065] In step S520, when the operation behavior of the data query personnel exceeds the operation permissions of the controlled file, an alarm message is sent to the data management platform. For example, when a controlled file is in the viewing state and copying is not allowed, when the data query personnel perform copying, an alarm message is sent to the data management platform. After receiving the alarm message, the data management platform warns this data query personnel or locks this controlled file and no longer displays it.

[0066] In step S530, when the access times of a data query person are greater than the access times threshold, an alarm message is sent to the data management platform. For example, it is stipulated that the access times threshold for each data query person is 5 times. When the access times of a certain data query person are 6 times, an alarm message is sent to the data management platform. After receiving the alarm message, the data management platform processes this behavior, such as increasing the access times threshold for this data query person, or locking this controlled file and no longer displaying it.

[0067] In step S540, when the access time of a data query person is greater than the access time threshold, an alarm message is sent to the data management platform. For example, it is stipulated that the access time threshold for each data query person is 30 minutes. When the access time of a certain data query person exceeds 30 minutes, an alarm message is sent to the data management platform. After receiving the alarm message, the data management platform processes this behavior, such as extending the access time for this data query person, or locking this controlled file and no longer displaying it.

[0068] By setting the access times threshold and the access time threshold, the access behavior of data query persons is monitored in real time, potential data leakage risks can be discovered and prevented in a timely manner. Different monitoring thresholds are set according to the different levels of controlled files, which has higher flexibility and security and can effectively protect the security of power data.

[0069]

Ninth Embodiment

[0070] Although the present invention is disclosed as above, the present invention is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention should be subject to the scope defined by the claims.

Claims

1. A data management method for complex heterogeneous power terminal equipment, characterized in that: The data management method comprises: The data management platform stores data files, and the data files are stored in the visual management unit and the monitoring management unit in the data management platform; Record the data file in the visual management unit as a general file, record the data file in the monitoring management unit as a control file, and set access permissions for the control file according to the control level; When an update file needs to be input into the data management platform, an update code of the update file is obtained, and the update code is compared with a theoretical code of the update file to determine whether the update file meets the storage condition; When the control file receives a query request, the supervision module in the data management platform verifies the access rights of the data query personnel and sets the display status of the control file according to the access rights; When the control document is in the review state, the data query personnel are monitored in real time according to the control level corresponding to the control document.

2. The data management method according to claim 1, characterized in that: When an update file needs to be input into the data management platform, obtaining an update code of the update file, comparing the update code with a theoretical code of the update file, and determining whether the update file meets the storage condition specifically includes: The update file includes a newly added file and an iterative file, the newly added file has a newly added code, and the iterative file has a current iterative code; When the update file only contains the iteration file, obtaining the real iteration number of the iteration file and the historical iteration code of the iterated file; Determining whether the update file meets the storage condition according to the historical iteration code, the actual iteration number and the current iteration code; When the update file only contains the newly added file, obtaining a new instruction corresponding to the newly added file in the data management platform, and judging whether the update file meets the storage condition according to the new instruction and the new code; When the update file contains both the newly added file and the iterative file, it is determined whether the update file meets the storage condition according to the actual number of iterations and the newly added instruction.

3. The data management method according to claim 2, characterized in that: The step of judging whether the update file meets the storage condition according to the historical iteration code, the actual iteration number and the current iteration code further includes: Retrieving a first conversion key of the historical iteration code according to the actual number of iterations, and converting the historical iteration code according to the first conversion key to obtain a standard iteration code; It is determined whether the update file meets a storage condition according to the standard iteration code and the current iteration code.

4. The data management method according to claim 3, characterized in that: When the update file contains both the newly added file and the iterated file, judging whether the update file meets the storage condition according to the actual number of iterations and the newly added instruction specifically includes: Obtaining a new number corresponding to the new file, and converting the value of the new number into a corresponding theoretical number of iterations according to the iteration cycle; Acquire the first conversion key of the iteration file according to the actual number of iterations, and acquire the second conversion key of the iteration file according to the theoretical number of iterations; Determining whether the newly added file meets the storage condition according to the first conversion key and the newly added instruction; It is determined whether the iterative file meets the storage condition according to the first conversion key and the second conversion key.

5. The data management method according to claim 4, characterized in that: When the control file receives a query request, the supervision module in the data management platform verifies the access rights of the data query personnel and sets the display status of the control file according to the access rights, specifically including: According to the control level of the control file, corresponding environment settings are performed on the reading environment of the control file, which are recorded as environment permissions; When the data query personnel passes the identity authentication of the supervision module, the supervision system monitors the query environment in real time, and manages the display status of the control file according to the query environment and the corresponding environment authority; When the data query personnel fails to pass the identity authentication of the supervision module, the data management platform grants the data query personnel the corresponding access rights according to the query request of the data query personnel.

6. The data management method according to claim 5, characterized in that: When the data query personnel passes the identity authentication of the supervision module, the supervision system monitors the query environment in real time, and manages the display status of the control file according to the query environment and the corresponding environment authority, specifically including: When the query environment meets the corresponding environment authority, the supervision module retrieves the corresponding control file in the data management unit and creates a query log; When the review environment does not comply with the corresponding environment authority, the supervision module locks the control file.

7. The data management method according to claim 6, characterized in that: When the data query personnel fails to pass the identity authentication of the supervision module, the data management platform grants the data query personnel the corresponding access rights according to the query request of the data query personnel, specifically including: The data management platform identifies the identity of the data query person; When the data query personnel are internal personnel, the data query personnel can obtain the general file and send a decryption application to the data management platform through the supervision module; When the data query person is not an internal person, a decryption request is sent to the data management platform through the supervision module.

8. The data management method according to claim 7, characterized in that: When the control file is in the review state, real-time monitoring of the data query personnel is performed according to the control level corresponding to the control file, specifically including: According to the control level of the control file, set corresponding operation permissions, review number thresholds and review time thresholds; When the operation behavior of the data query personnel exceeds the operation authority of the control file, an alarm message is sent to the data management platform; When the number of inquiries by the data query personnel exceeds the threshold number of inquiries, an alarm message is sent to the data management platform; When the data query personnel's query time is greater than the query time threshold, an alarm message is sent to the data management platform.

9. A management system for complex heterogeneous power terminal equipment, characterized in that: The management method according to any one of claims 1 to 8 is applied to the management system, and the management system comprises: A data storage module, the data storage module is used to store the common files and the control files; A data management module, the data management module is used to set the access permission for the control file; A data analysis module, the data analysis module is used to analyze whether the update file meets the storage condition; A data monitoring module is used to monitor the data query personnel in real time.

Citation Information

Patent Citations

  • File management system and method

    CN106407474A

  • App increment hot updating method and service system

    CN108733400A

  • Intelligent management system for remote lookup of digital archives of cadre personnel

    CN112749273A

  • Software updating method and device, electronic terminal and computer readable storage medium

    CN115686587A

  • File borrowing comprehensive application management system

    CN116775715A