A data management method and system for complex heterogeneous power terminal equipment

By sorting and storing data files in the data management platform and setting up reference permissions, combined with the use of supervision modules and conversion keys, the data management challenges of complex heterogeneous power terminal equipment are solved, data security and controllability are achieved, and management efficiency and user experience are improved.

CN120180478BActive Publication Date: 2025-09-02NINGBO TRANSMISSION & DISTRIBUTION CONSTR
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510638581.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-09-02
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

When facing complex heterogeneous power terminal equipment, existing power data management systems have problems such as data dispersion, redundancy, insufficient security, insufficient authority management, inflexible updates and maintenance, and incomplete access monitoring, making it difficult to effectively manage and protect power data.

Method used

The data management platform is used to store data files in the visual management unit and the monitoring management unit, set the reference permissions according to the control level, and verify the access permissions through the supervision module, monitor the data query process in real time, and use the update code to compare the theoretical code to ensure storage conditions, introduce conversion keys and new instructions to judge file storage, and set the number of references and time thresholds for real-time monitoring.

Benefits of technology

It realizes the security and controllability of data of complex heterogeneous power terminal equipment, ensures the accuracy and consistency of data files, improves the efficiency and reliability of data management, prevents data leakage, simplifies the access process, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180478B_ABST
    Figure CN120180478B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data management technology, and specifically, to a data management method and system for complex heterogeneous power terminal equipment. The problem solved by the present invention is: how to effectively manage the data of complex heterogeneous power terminal equipment and ensure the security and controllability of the data. To solve the above problem, an embodiment of the present invention provides a data management method for complex heterogeneous power terminal equipment, and the data management method includes: data files are stored in a data management platform, and the data files are stored in a visual management unit and a monitoring management unit in the data management platform; the data files in the visual management unit are recorded as general files, and the data files in the monitoring management unit are recorded as control files, and the access permissions of the control files are set according to the control level; when the control file receives a query request, the supervision module in the data management platform verifies the access permissions of the data query personnel and sets the display status of the control file according to the access permissions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data management technology, and in particular to a data management method and system for complex heterogeneous power terminal equipment. Background Art

[0002] As an advanced productive force and a fundamental industry, the power industry plays a vital role in promoting national economic development and social progress, and is closely linked to socioeconomic and social development. Therefore, it is necessary to store and monitor power data to effectively safeguard the normal operation of the power system. Power data leaks are primarily caused by external attacks or insider information leaks. Therefore, strengthening defenses against external attacks and categorizing and managing internal personnel permissions are key to effectively protecting this data.

[0003] However, the data management challenges facing the power industry are becoming increasingly complex. As power systems continue to expand and become more intelligent, the amount of data generated is growing exponentially, and the types of data are becoming increasingly diverse. This data originates from diverse end-users, encompassing power generation, transmission, distribution, and consumption, creating a complex, heterogeneous data environment. Traditional data management methods are no longer sufficient in this context.

[0004] Existing power data management systems often have the following problems: First, there is a lack of unified management strategies for different types of data, resulting in data dispersion and redundancy, making it difficult to effectively utilize them; second, data security protection measures are not perfect, especially the lack of detailed permission management for internal personnel, which increases the risk of data leakage; third, data update and maintenance mechanisms are not flexible enough, making it difficult to respond to dynamic changes in the power system in a timely manner; finally, data access monitoring is not comprehensive enough, making it impossible to detect and deal with potential security threats in real time. Summary of the Invention

[0005] The problem solved by the present invention is how to effectively manage the data of complex and heterogeneous power terminal equipment to ensure the security and controllability of the data.

[0006] To solve the above problems, an embodiment of the present invention provides a data management method for complex heterogeneous power terminal equipment, the data management method comprising: data files are stored in a data management platform, and the data files are stored in a visual management unit and a monitoring management unit in the data management platform; the data files in the visual management unit are recorded as general files, and the data files in the monitoring management unit are recorded as control files, and review permissions are set for the control files according to the control level; when an update file needs to be input in the data management platform, an update code of the update file is obtained, and the update code is compared with the theoretical code of the update file to determine whether the update file meets the storage conditions; when the control file receives a query request, the supervision module in the data management platform verifies the access rights of the data query personnel and sets the display status of the control file according to the access rights; when the control file is in the review state, the data query personnel are monitored in real time according to the control level corresponding to the control file.

[0007] Compared with the existing technology, the technical effects achieved by adopting this technical solution are as follows: the data management platform realizes classified management of data by storing data files in the visual management unit and the monitoring management unit, and setting access permissions according to the management level; the security of data is ensured by setting access permissions for the management files; in the management process of update files, by obtaining the update code of the update file and comparing it with the theoretical code, it is ensured that only the update files that meet the storage conditions can be stored; in the data query process, the access rights of the data query personnel are verified and monitored in real time through the supervision module to ensure the security of the data during the query process. As a result, the security and controllability of data management of complex heterogeneous power terminal equipment are achieved as a whole.

[0008] In one embodiment of the present invention, when an update file needs to be input into the data management platform, the update code of the update file is obtained, the update code is compared with the theoretical code of the update file, and it is determined whether the update file meets the storage conditions, specifically including: the update file includes a newly added file and an iterative file, the newly added file has a newly added code, and the iterative file has a current iteration code; when only an iterative file exists in the update file, the actual number of iterations of the iterative file and the historical iteration code of the iterated file are obtained; whether the update file meets the storage conditions is determined based on the historical iteration code, the actual number of iterations and the current iteration code; when only a newly added file exists in the update file, the new instructions corresponding to the newly added file are obtained in the data management platform, and whether the update file meets the storage conditions is determined based on the new instructions and the new code; when both the newly added file and the iterative file exist in the update file, whether the update file meets the storage conditions is determined based on the actual number of iterations and the new instructions.

[0009] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: by obtaining the update code of the updated file and comparing it with the theoretical code, it is possible to accurately judge whether the updated file meets the storage conditions, thereby ensuring the accuracy and consistency of the data file; the present invention can more accurately handle the storage condition judgment of new files and iterative files, thereby improving the efficiency and reliability of data management.

[0010] In one embodiment of the present invention, judging whether the update file meets the storage conditions based on the historical iteration code, the actual number of iterations and the current iteration code also includes: retrieving a first conversion key of the historical iteration code based on the actual number of iterations, converting the historical iteration code based on the first conversion key to obtain a standard iteration code; judging whether the update file meets the storage conditions based on the standard iteration code and the current iteration code.

[0011] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: by introducing the first conversion key and the standard iteration code, the technical difficulties in judging the storage conditions of the updated file are solved, and the accuracy and reliability of the judgment are improved; the present invention can not only ensure that the updated file meets the specified storage conditions before storage, but also prevent storage errors caused by inaccurate iteration history, further improving the security and stability of the data management platform.

[0012] In one embodiment of the present invention, when an update file contains both a newly added file and an iterative file, whether the updated file meets the storage conditions is determined based on the actual number of iterations and the newly added instructions, specifically including: obtaining a newly added number corresponding to the newly added file, and converting the value of the newly added number into a corresponding theoretical number of iterations based on the iteration cycle; obtaining a first conversion key for the iterative file based on the actual number of iterations, and obtaining a second conversion key for the iterative file based on the theoretical number of iterations; determining whether the newly added file meets the storage conditions based on the first conversion key and the newly added instructions; and determining whether the iterative file meets the storage conditions based on the first conversion key and the second conversion key.

[0013] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: by converting and judging the numbers and instructions of new files and iterated files, the accuracy and validity of the files during storage can be effectively ensured, avoiding data management problems caused by files not meeting storage conditions; the present invention improves the accuracy and reliability of data management by introducing a judgment mechanism for conversion keys and new instructions, and can better adapt to the data management needs of complex heterogeneous power terminal equipment.

[0014] In one embodiment of the present invention, when a control file receives a query request, the supervision module within the data management platform verifies the access rights of the data query personnel and sets the display status of the control file according to the access rights, specifically including: making corresponding environmental settings for the review environment of the control file according to the control level of the control file, recorded as environmental permissions; when the data query personnel passes the identity authentication of the supervision module, the supervision system monitors the review environment in real time, and manages the display status of the control file according to the review environment and the corresponding environmental permissions; when the data query personnel fails to pass the identity authentication of the supervision module, the data management platform grants the data query personnel corresponding access rights according to the query request of the data query personnel.

[0015] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: the access rights of data query personnel are verified through the supervision module, and the display status of the control files is set according to the access rights, thereby realizing effective management of the access rights and display status of the control files during the data query process. The present invention improves the security and reliability of data and ensures the safe display of control files in different viewing environments.

[0016] In one embodiment of the present invention, when the data query personnel passes the identity authentication of the supervision module, the supervision system monitors the query environment in real time, and manages the display status of the control file according to the query environment and the corresponding environmental permissions, specifically including: when the query environment meets the corresponding environmental permissions, the supervision module retrieves the corresponding control file in the data management platform and establishes a query log; when the query environment does not meet the corresponding environmental permissions, the supervision module locks the control file.

[0017] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: through the application of the supervision module and the supervision system, an effective technical solution is proposed, which can strictly monitor the reference environment and perform authority management during the data query process. The advantage of the present invention is that it can monitor the reference environment in real time, ensure the legality and traceability of data query, and prevent unauthorized access, thereby effectively protecting the security of data. Therefore, the present invention has significant technical progress in solving the technical problem of managing the display status of controlled files according to the query environment authority during the data query process.

[0018] In one embodiment of the present invention, when the data query personnel fails to pass the identity authentication of the supervision module, the data management platform grants the data query personnel corresponding access rights based on the query request of the data query personnel, specifically including: the data management platform identifies the identity of the data query personnel; when the data query personnel is an internal personnel, the data query personnel can obtain common files and send a decryption application to the data management platform through the supervision module; when the data query personnel is not an internal personnel, a decryption application is sent to the data management platform through the supervision module.

[0019] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: by introducing identity recognition and authority management mechanisms, it effectively solves the access permission problem of data query personnel when they fail to pass the identity authentication of the supervision module. The technical solution of the present invention not only improves the security of the data, but also simplifies the access process and improves the user experience. In particular, for internal personnel, they can obtain the required information conveniently and quickly while ensuring data security. For external personnel, the decryption application mechanism of the supervision module can also meet their access needs to a certain extent. Therefore, the present invention has achieved a good balance between security and convenience.

[0020] In one embodiment of the present invention, when a control file is in a review state, data query personnel are monitored in real time according to the control level corresponding to the control file, specifically including: setting corresponding operation permissions, review count thresholds and review time thresholds according to the control level of the control file; when the operation behavior of the data query personnel exceeds the operation permissions of the control file, sending an alarm message to the data management platform; when the operation behavior of the data query personnel exceeds the operation permissions of the control file, sending an alarm message to the data management platform; when the number of reviews of the data query personnel is greater than the review count threshold, sending an alarm message to the data management platform; when the review time of the data query personnel is greater than the review time threshold, sending an alarm message to the data management platform.

[0021] Compared with the existing technology, the technical effect achieved by adopting this technical solution is: by setting the number of reading thresholds and the reading time threshold, the reading behavior of data query personnel can be monitored in real time, which can timely discover and prevent potential data leakage risks. Different monitoring thresholds are set according to the different levels of the management and control files, which has higher flexibility and security. Therefore, the present invention provides a more flexible and secure data management method, which can effectively protect the security of power data.

[0022] In one embodiment of the present invention, the present invention also provides a management system for complex heterogeneous power terminal equipment, and the management method described in the above embodiment is applied to the management system. The management system includes: a data storage module, which is used to store general files and control files; a data management module, which is used to set access permissions for control files; a data analysis module, which is used to analyze whether the updated files meet the storage conditions; and a data monitoring module, which is used to monitor data query personnel in real time. The management system has all the technical features of the above management method, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is one of the flow charts of the data management method for complex heterogeneous power terminal equipment of the present invention;

[0024] Figure 2 This is the second flow chart of the data management method for complex heterogeneous power terminal equipment of the present invention;

[0025] Figure 3 This is the third flow chart of the data management method for complex heterogeneous power terminal equipment of the present invention;

[0026] Figure 4 This is the fourth flow chart of the data management method for complex heterogeneous power terminal equipment of the present invention;

[0027] Figure 5 A schematic diagram of the management system of the present invention;

[0028] Description of reference numerals:

[0029] 100 - management system; 110 - data storage module; 120 - data management module; 130 - data analysis module; 140 - data monitoring module. DETAILED DESCRIPTION

[0030] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0031] [First embodiment]

[0032] See also Figure 1 The embodiment of the present invention provides a method for managing abnormal power dispatch monitoring data, the management method comprising:

[0033] S100: A data management platform stores data files, which are stored in a visual management unit and a monitoring management unit within the data management platform.

[0034] S200: Record the data files in the visual management unit as general files, record the data files in the monitoring management unit as control files, and set access permissions for the control files according to the control level;

[0035] S300: When an update file needs to be input into the data management platform, an update code of the update file is obtained, and the update code is compared with a theoretical code of the update file to determine whether the update file meets the storage conditions;

[0036] S400: When a query request is received for a controlled file, the supervision module in the data management platform verifies the access rights of the data query personnel and sets the display status of the controlled file according to the access rights;

[0037] S500: When the control file is in the review state, the data query personnel are monitored in real time according to the control level corresponding to the control file.

[0038] In step S100 and step S200, the data management platform is divided into a visual management unit and a monitoring management unit according to the control level of the data files, and general files and control files are stored in the visual management unit and the monitoring management unit respectively. General files are usually some files of low importance, such as temporary files generated within the company, etc. The company can review and modify temporary files at any time. Control files are usually files of high importance, such as personal information of internal customers of the company, work plan for the next quarter within the company, etc. Different review permissions are set for the control files according to the control level corresponding to the control files, and only personnel with review permissions can review the control files.

[0039] In step S300, usually, data files in the data platform need to be changed, added or deleted. However, when inputting update files into the data management platform, various problems are usually encountered, such as data integrity problems, data format compatibility problems, data security problems, permission control problems and performance problems. Therefore, it is necessary to obtain the update code of the update file, and in the process of inputting the update file, compare the update code of the update file with the theoretical code of the update file to determine whether the update file meets the storage conditions. In addition, the theoretical code and the update code refer to code snippets or instructions used to update the content or version of a specific file. These codes usually include information such as the specific content of the update file, the update method and the update conditions, where the update conditions include the size of the memory occupied by the update file.

[0040] For example, the update condition shows that the memory size occupied by the update file is 18KB. When the size of the update file is 18KB, the update file is stored in the monitoring management unit; when the size of the update file is not 18KB, the update file is returned to the upload location.

[0041] In step S400, a supervision module is set in the data transmission platform to establish a connection relationship between the data query personnel and the data management platform, and to verify the access rights of the data query personnel. A large number of control files are stored in the monitoring management unit. Different data query personnel have different access rights to the control files. When the control file receives a query request, the supervision module can verify the data query personnel through a combined verification method. For example, the supervision module verifies the data query personnel through a double encryption method of facial recognition and password input.

[0042] For example, a data query personnel has access rights to control file 1, control file 2 and control file 3. Then, after the data query personnel passes the verification of the supervision module, the monitoring management unit will hide the control files other than control file 1, control file 2 and control file 3.

[0043] In step S500, the data management platform will set different review permissions for the controlled files according to the importance of the controlled files. The review permissions include operation permissions, number of reviews and review time. The operation permissions include but are not limited to: copying, modifying, deleting, and downloading. Under normal circumstances, when the controlled files are in the review state, data leakage may occur due to improper query behavior of the data query personnel. Therefore, when the data query personnel are reviewing the controlled files, the data management platform needs to monitor the data query personnel in real time to determine whether the query behavior of the data query personnel meets the requirements.

[0044] The data management platform implements classified management of data by storing data files in the visual management unit and the monitoring management unit, and setting access permissions according to the management level; by setting access permissions for the management files, the security of the data is ensured. In the management process of updated files, the update code of the updated file is obtained and compared with the theoretical code to ensure that only updated files that meet the storage conditions can be stored. In the data query process, the access rights of the data query personnel are verified and monitored in real time through the supervision module to ensure the security of the data during the query process. In this way, the security and controllability of the data management of complex heterogeneous power terminal equipment are achieved as a whole.

[0045] [Second embodiment]

[0046] See also Figure 2 In a specific embodiment, when an update file needs to be input into the data management platform, an update code of the update file is obtained, and the update code is compared with a theoretical code of the update file to determine whether the update file meets the storage conditions, specifically including:

[0047] S310, the updated file includes a newly added file and an iterative file, the newly added file has a newly added code, and the iterative file has a current iteration code;

[0048] S320: When only the iterative file exists in the update file, obtain the actual iteration number of the iterative file and the historical iteration code of the iterated file;

[0049] S330, judging whether the update file meets the storage condition based on the historical iteration code, the actual number of iterations, and the current iteration code;

[0050] S340: When only newly added files exist in the update file, obtain a new instruction corresponding to the newly added file in the data management platform, and determine whether the updated file meets the storage conditions based on the new instruction and the new code;

[0051] S350: When the update file contains both a newly added file and an iterative file, determine whether the update file meets the storage condition according to the actual number of iterations and the newly added instructions.

[0052] In step S310, the updated file is divided into a new file and an iterative file according to the nature of the updated file. A new file refers to a new file input on the data management platform. An iterative file usually refers to the content in the file or the file itself being processed according to specific rules or conditions during the file processing process. A new code refers to a code related to the new file. For example, the new code for the new file is set according to the size of the memory occupied by the new file; the current iteration code refers to a code related to the iterative file. For example, under normal circumstances, when modifying the original data file, there will be a specific modification range and modification content. The current iteration code of the iterative file can be set according to the modification range and modification content.

[0053] In step S320 and step S330, under normal circumstances, the historical iteration code of the iterated file means that the data management platform will input the iteration code of the iterated file into the monitoring management unit in advance according to the data change requirements of the iterated file. In addition, the data management platform will record the number of iterations of the iterated file. When a new iterative file is input, the data management platform will calculate the actual number of iterations of the iterative file based on the number of iterations of the iterative file. For example, if the number of iterations of the iterative file is 5, then when a new iterative file is input, the actual number of iterations of the new iterative file is 6.

[0054] In step S340, the new instructions corresponding to the newly added file can determine whether the newly added file is the target file. Usually, the new instructions can be set according to the file name, file content and the byte size occupied by the file. For example, a specific prefix or suffix is ​​added to the name of the new file to set the new instructions corresponding to the new file.

[0055] By obtaining the update code of the updated file and comparing it with the theoretical code, it is possible to accurately determine whether the updated file meets the storage conditions, thereby ensuring the accuracy and consistency of the data file. The present invention can more accurately handle the storage condition judgment of newly added files and iterative files, thereby improving the efficiency and reliability of data management.

[0056] [Third embodiment]

[0057] In a specific embodiment, judging whether the update file meets the storage condition based on the historical iteration code, the actual iteration number, and the current iteration code further includes:

[0058] S331. Retrieve a first conversion key of a historical iteration code according to the actual number of iterations, and convert the historical iteration code according to the first conversion key to obtain a standard iteration code.

[0059] S332: Determine whether the updated file meets the storage condition based on the standard iteration code and the current iteration code.

[0060] In step S331 and step S332, the first conversion key generally refers to a key information or code used in the process of data conversion, encryption and decryption, format conversion, etc., which can be in digital form, character form, byte array form or biometric form. Usually, for data security, a different conversion key is set for each iteration of the iterated file. When the actual number of iterations of the iterated file is obtained, the first conversion key of the historical iteration code is retrieved according to the actual number of iterations, and the historical iteration code is converted by the first conversion key to obtain a standard iteration code. For example, the standard iteration code of the iterated file obtained by converting the historical iteration code by the first conversion key is a specific file name.

[0061] It should be noted that different data files have different conversion key tables. The conversion key table records the number of conversion keys corresponding to the data file. When the number of iterations exceeds the number of conversion keys, the actual number of iterations is calculated based on the current number of iterations and the number of conversion keys, and the correct first conversion key is determined in the key conversion table based on the actual number of iterations.

[0062] Let the current number of iterations be D1, the number of conversion keys be D2, and the actual number of iterations be D3. The following relationship is satisfied among the current number of iterations, the number of conversion keys, and the actual number of iterations:

[0063] When D1>D2, D3=D1mod D2;

[0064] When D1≤D2, D3=D1.

[0065] In step S332, whether the update file meets the storage condition is determined based on the standard iteration code and the current iteration code. When the standard iteration code and the current iteration code are the same, the update file meets the storage condition. When the standard iteration code and the current iteration code are different, the update file does not meet the storage condition.

[0066] By introducing the first conversion key and standard iteration code, the technical difficulties in judging the storage conditions of updated files are solved. The first conversion key is adjusted according to the number of iterations, which further improves the security of data files during iteration and prevents virus files from entering the data management platform through iterative files. It not only ensures that the updated files meet the specified storage conditions before storage, but also prevents storage errors caused by inaccurate iteration history, further improving the security and stability of the data management platform.

[0067] [Fourth embodiment]

[0068] In a specific embodiment, when the update file contains both a newly added file and an iterated file, determining whether the update file meets the storage condition based on the actual number of iterations and the newly added instructions specifically includes:

[0069] S351. Obtain a new number corresponding to the new file, and convert the value of the new number into a corresponding theoretical number of iterations according to the iteration cycle;

[0070] S352: Obtain a first conversion key for the iterative file according to the actual number of iterations, and obtain a second conversion key for the iterative file according to the theoretical number of iterations;

[0071] S353: Determine whether the newly added file meets the storage condition based on the first conversion key and the newly added instruction;

[0072] S354: Determine whether the iterative file meets the storage condition according to the first conversion key and the second conversion key.

[0073] In step S351, the new number of the newly added file is set according to the number of data files already stored in the data management platform. When the new file is uploaded to the data management platform, the data management platform will set the corresponding conversion key table and key conversion quantity according to the type of the new file, round the iteration cycle according to the number of days, and then add the rounded iteration cycle value and the new number value to obtain the basic key value of the new file. The basic key value is divided by the key conversion quantity, and the remainder obtained is recorded as the theoretical number of iterations.

[0074] In step S352, the first conversion key is obtained in the same manner as in step S331, and the second conversion key is determined according to the theoretical number of iterations and the conversion key table corresponding to the newly added file.

[0075] In step S353 and step S354, the storage of the newly added file needs to be verified by the first conversion key generated by the iterative file, and the storage of the iterative file needs to be verified by the second conversion key generated by the newly added file. Only when the keys generated by each other meet the preset conditions of the data management platform, can the newly added file and the iterative file be stored in the data management platform at the same time.

[0076] It should be noted that for some important data files, the data management platform can set the data file upload method, and reduce the possibility of viruses in the files received by the data management platform by bundling new files with iterative files for upload.

[0077] By converting and judging the numbers and instructions of new files and iterative files, the accuracy and validity of the files during storage can be effectively ensured. The way of binding the new files and iterative files for uploading sets different security modes for different types of data files, thereby improving the security of the data management platform. By making a comprehensive judgment through the new instructions, the first conversion key and the second conversion key, the erroneous data transmission is avoided, the possibility of viruses being carried in the data files is reduced, and it can better adapt to the data management needs of complex heterogeneous power terminal equipment.

[0078] [Fifth embodiment]

[0079] See also Figure 3 In a specific embodiment, when a control file receives a query request, the supervision module in the data management platform verifies the access rights of the data query personnel and sets the display status of the control file based on the access rights, specifically including:

[0080] S410. According to the control level of the control file, the corresponding environment settings are performed for the control file's access environment, which is recorded as the environment permission;

[0081] S420. When the data query person passes the identity verification of the supervision module, the supervision system monitors the query environment in real time and manages the display status of the controlled files based on the query environment and the corresponding environment permissions.

[0082] S430. When the data query personnel fails to pass the identity authentication of the supervision module, the data management platform grants the data query personnel corresponding access rights according to the query request of the data query personnel.

[0083] In step S410, under normal circumstances, the control level of the controlled file is set according to its importance. For example, the controlled file is divided into three control levels, namely the first level, the second level and the third level. The higher the importance of the controlled file, the higher its control level. A first specific area and a second specific area are set. The environmental authority of the first-level controlled file is that when the first-level controlled file needs to be consulted, other people can be present in the first specific area and the second specific area; the environmental authority of the second-level controlled file is that when the second-level controlled file needs to be consulted, no other people can be present in the second specific area; the environmental authority of the third-level controlled file is that when the first-level controlled file needs to be consulted, no other people can be present in the first specific area and the second specific area.

[0084] In step S420, when the data query personnel passes the identity authentication of the supervision module, the first specific area and the second specific area are monitored in real time through instruments such as cameras, and the display status of the control file is managed according to the corresponding environmental permissions of the control file. For example, when the data query personnel needs to query the second-level control file, the camera finds that there are other people in the second specific area, then this control file will not be displayed.

[0085] It should be noted that when the data management platform can authenticate identity through facial recognition, when the third-level control file receives a request for review, if the personnel in the first area and the second area are all eligible to review it, this control file can be displayed. Similarly, when the second-level control file receives a request for review, if the personnel in the second specific area are all eligible to review it, this control file can be displayed. In addition, when the control file is being reviewed, the supervision system still needs to monitor the review environment in real time. When the review environment does not meet the environmental authority, the control file will be immediately locked and not displayed.

[0086] The supervision module verifies the access rights of data query personnel and sets the display status of controlled files according to the access rights, thereby achieving effective management of the access rights and display status of controlled files during the data query process, improving the security and reliability of data, and ensuring the safe display of controlled files in different viewing environments.

[0087] [Sixth embodiment]

[0088] In a specific embodiment, when a data query person passes the identity verification of the supervision module, the supervision system monitors the query environment in real time and manages the display status of the controlled files based on the query environment and the corresponding environment permissions, specifically including:

[0089] S421. When the query environment meets the corresponding environment authority, the supervision module retrieves the corresponding control file in the data management platform and creates a query log;

[0090] S422. When the access environment does not comply with the corresponding environment authority, the supervision module locks the control file.

[0091] In step S421, in order to facilitate subsequent data management and tracking, a query log is established to record the query records of the data query personnel. The query log stores the query time, query content and operations performed by the data query personnel on the control file.

[0092] In step S422, for example, when there are people around the inquirer who do not have the permission to view the control, it is determined that the current viewing environment does not meet the environmental permissions. At this time, the data management platform will lock the control file, and the inquirer himself cannot unlock it. The unlocking needs to be approved by the inquirer's unit. When the approval is passed, the permission to view the environment is authenticated again, and the control file will be displayed again.

[0093] Through the application of the supervision module and the supervision system, the query environment can be strictly monitored and permission management can be performed during the data query process. The query environment can be monitored in real time to ensure the legality and traceability of data queries, while preventing unauthorized access, thereby effectively protecting the security of data. Therefore, the present invention has made significant technical progress in solving the technical problem of managing the display status of controlled files according to the query environment permissions during the data query process.

[0094] [Seventh embodiment]

[0095] In a specific embodiment, when the data query person fails to pass the identity authentication of the supervision module, the data management platform grants the data query person corresponding access rights according to the query request of the data query person, specifically including:

[0096] S431. The data management platform identifies the identity of the data query personnel;

[0097] S432. When the data query personnel are internal personnel, they can obtain common files and send a decryption request to the data management platform through the supervision module;

[0098] S433. When the data query person is not an internal staff, a decryption request is sent to the data management platform through the supervision module.

[0099] In step S431 and step S432, under special circumstances, personnel who do not have the right to review may need to review the controlled files due to internal personnel turnover and other reasons. Therefore, the identity of the data query personnel needs to be identified through the data management platform. When the data query personnel is an internal personnel, the data management platform determines whether to send a decryption code to the data query personnel through identity verification upon receiving the decryption application. When the data query personnel passes the identity verification, the decryption code is sent. When the data query personnel fails the identity verification, the decryption code is not sent.

[0100] In step S433, in the era of data sharing, data sharing may occur among multiple departments and companies. When the data query personnel are not internal personnel, the data management platform can verify the identity of the data query personnel through multiple verification methods. When the data query personnel passes the identity authentication, the decryption code is sent. When the data query personnel fails to pass the identity authentication, the decryption code is not sent.

[0101] By introducing an identity recognition and permission management mechanism, the access rights problem of data query personnel who fail to pass the identity authentication of the supervision module is effectively solved. This not only improves the security of the data, but also simplifies the access process and enhances the user experience. In particular, for internal personnel, they can obtain the required information conveniently and quickly while ensuring data security. For external personnel, the decryption application mechanism of the supervision module can also meet their access needs to a certain extent, allowing the data management platform to achieve a good balance between security and convenience.

[0102] [Eighth embodiment]

[0103] See also Figure 4 In a specific embodiment, when a control file is in a review state, real-time monitoring of the data query personnel is performed according to the control level corresponding to the control file, specifically including:

[0104] S510. Set corresponding operation permissions, review count thresholds, and review time thresholds based on the control level of the control file;

[0105] S520: When the operation behavior of the data query personnel exceeds the operation authority of the control file, an alarm message is sent to the data management platform;

[0106] S530: When the number of times the data query personnel has checked the data exceeds the number of times threshold, an alarm message is sent to the data management platform;

[0107] S540: When the data query personnel's query time exceeds the query time threshold, an alarm message is sent to the data management platform.

[0108] In step S510, under normal circumstances, in order to facilitate data management and prevent data leakage, it is necessary to set the operation permissions, reference count threshold and reference time threshold of the control file. The operation permissions include but are not limited to: taking pictures, copying, modifying, deleting and downloading, etc. The reference count threshold refers to the maximum number of times each data query person can query, and the reference time threshold refers to the maximum time each data query person can search a word.

[0109] In step S520, when the operation behavior of the data query personnel exceeds the operation authority of the control file, an alarm message is sent to the data management platform. For example, when a control file is in the viewing state, copying is not allowed. When the data query personnel copies it, an alarm message is sent to the data management platform. After receiving the alarm message, the data management platform warns the data query personnel or locks the control file and no longer displays it.

[0110] In step S530, when the number of times a data query person has viewed a data file is greater than the viewing threshold, an alarm message is sent to the data management platform. For example, the viewing threshold for each data query person is set to 5 times. When a data query person has viewed a data file 6 times, an alarm message is sent to the data management platform. After receiving the alarm message, the data management platform processes the behavior, such as increasing the viewing threshold for the data query person, or locking the control file so that it is no longer displayed.

[0111] In step S540, when the data query personnel's browsing time is greater than the browsing time threshold, an alarm message is sent to the data management platform. For example, the browsing time threshold for each data query personnel is set at 30 minutes. When a data query personnel's browsing time exceeds 30 minutes, an alarm message is sent to the data management platform. After receiving the alarm message, the data management platform processes this behavior, such as extending the browsing time of this data query personnel, or locking this control file so that it no longer displays it.

[0112] By setting the number of reading thresholds and the reading time threshold, the reading behavior of data query personnel can be monitored in real time, which can timely discover and prevent potential data leakage risks. Different monitoring thresholds can be set according to the different levels of management and control files, which has higher flexibility and security and can effectively protect the security of power data.

[0113] Ninth embodiment

[0114] See also Figure 5The present invention also provides a management system 100, in which the data management method described in the above embodiment is applied. The management system 100 includes: a data storage module 110, which is used to store general files and control files; a data management module 120, which is used to set access permissions for control files; a data analysis module 130, which is used to analyze whether the updated file meets the storage conditions; and a data monitoring module 140, which is used to monitor data query personnel in real time. The management system 100 has all the technical features of the above management method, which will not be described here one by one.

[0115] Although the present invention is disclosed as above, the present invention is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, the scope of protection of the present invention should be based on the scope defined by the claims.

Claims

1. A data management method for complex heterogeneous power terminal equipment, characterized in that: The data management method comprises: The data management platform stores data files, which are stored in the visual management unit and the monitoring management unit within the data management platform; Recording the data file in the visual management unit as a general file, recording the data file in the monitoring management unit as a control file, and setting access permissions for the control file according to the control level; When an update file needs to be input into the data management platform, an update code of the update file is obtained, and the update code is compared with a theoretical code of the update file to determine whether the update file meets the storage conditions; When the control file receives a query request, the supervision module in the data management platform verifies the access rights of the data query person and sets the display status of the control file according to the access rights; When the control file is in the review state, the data query personnel are monitored in real time according to the control level corresponding to the control file; When an update file needs to be input into the data management platform, obtaining an update code of the update file, comparing the update code with a theoretical code of the update file, and determining whether the update file meets the storage conditions specifically includes: The update file includes a new file and an iterative file, the new file has a new code, and the iterative file has a current iterative code; When the update file only contains the iterative file, obtaining the actual iteration number of the iterative file and the historical iteration code of the iterated file; determining whether the update file meets a storage condition according to the historical iteration code, the actual number of iterations, and the current iteration code; When the update file only contains the newly added file, obtaining a new instruction corresponding to the newly added file in the data management platform, and determining whether the update file meets the storage condition according to the new instruction and the new code; The determining whether the update file meets the storage condition according to the historical iteration code, the actual iteration number and the current iteration code further includes: Retrieving a first conversion key of the historical iteration code according to the actual number of iterations, and converting the historical iteration code according to the first conversion key to obtain a standard iteration code; determining whether the update file meets a storage condition according to the standard iteration code and the current iteration code; When inputting an update file into the data management platform, various problems may be encountered. It is necessary to obtain the update code of the update file and compare the update code of the update file with the theoretical code of the update file during the update file input process to determine whether the update file meets the storage conditions. The theoretical code and the update code refer to code fragments or instructions used to update the content or version of a specific file. These codes include the specific content of the update file, the update method, and the update conditions. The update conditions include the size of the memory occupied by the update file. According to the nature of the update file, the update file is divided into the newly added file and the iterative file. The newly added file refers to a new file input into the data management platform. The iterative file refers to the content or the file itself processed according to specific rules or conditions during the file processing process. The newly added code refers to the code related to the newly added file, and the newly added code of the newly added file is set according to the size of the memory occupied by the newly added file. The current iteration code refers to the code related to the iterative file. When modifying the original data file, there will be a specific modification range and modification content. The current iteration code of the iterative file is set according to the modification range and the modification content; The historical iteration code of the iterated file means that the data management platform will input the iteration code of the iterated file into the monitoring management unit in advance according to the data change requirements of the iterated file. The new instruction corresponding to the newly added file can determine whether the newly added file is the target file, and set the new instruction according to the file name, file content and the byte size occupied by the file.

2. The data management method according to claim 1, wherein: When the control file receives a query request, the supervision module in the data management platform verifies the access rights of the data query person and sets the display status of the control file according to the access rights, specifically including: According to the control level of the control document, corresponding environment settings are made for the access environment of the control document, which are recorded as environment permissions; When the data query person passes the identity authentication of the supervision module, the supervision system monitors the query environment in real time and manages the display status of the control file according to the query environment and the corresponding environment authority; When the data query person fails to pass the identity authentication of the supervision module, the data management platform grants the data query person the corresponding access rights according to the query request of the data query person.

3. The data management method according to claim 2, characterized in that: When the data query person passes the identity authentication of the supervision module, the supervision system monitors the query environment in real time and manages the display status of the control file according to the query environment and the corresponding environment authority, specifically including: When the query environment meets the corresponding environment authority, the supervision module retrieves the corresponding control file in the data management platform and creates a query log; When the review environment does not comply with the corresponding environment authority, the supervision module locks the control file.

4. The data management method according to claim 3, wherein: When the data query personnel fails to pass the identity authentication of the supervision module, the data management platform grants the data query personnel the corresponding access rights according to the query request of the data query personnel, specifically including: The data management platform identifies the identity of the data query person; When the data query personnel are internal personnel, the data query personnel can obtain the general file and send a decryption request to the data management platform through the supervision module; When the data query person is not an internal person, a decryption request is sent to the data management platform through the supervision module.

5. The data management method according to claim 4, characterized in that: When the control file is in the review state, real-time monitoring of the data query personnel is performed according to the control level corresponding to the control file, specifically including: According to the control level of the control file, set the corresponding operation permissions, review number threshold and review time threshold; When the operation behavior of the data query personnel exceeds the operation authority of the control file, an alarm message is sent to the data management platform; When the number of times the data query person has checked the data exceeds the threshold, an alarm message is sent to the data management platform; When the data query person's query time is greater than the query time threshold, an alarm message is sent to the data management platform.

6. A management system for complex heterogeneous power terminal equipment, characterized in that: The management method according to any one of claims 1 to 5 is applied to the management system, the management system comprising: A data storage module, the data storage module is used to store the general files and the control files; A data management module, configured to set access permissions for the control file; A data analysis module, configured to analyze whether the update file meets a storage condition; A data monitoring module is used to monitor the data query personnel in real time.

Citation Information

Patent Citations

  • Ecological monitoring station data security consulting authorization method

    CN118940307A

  • Real estate data security storage management system

    CN119271687A