Data exit security management and control system and method for centralized monitoring system of transformer substation

By introducing data catalog modules, data set modules, target system modules and data sending modules into the centralized monitoring system of the substation, data leakage and misinformation problems caused by the simplicity of the data export mechanism in the existing technology are solved, and data security, accurate and efficient transmission is achieved.

CN120185189AActive Publication Date: 2025-06-20NARI NANJING CONTROL SYSTEM CO LTD
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510164227.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-06-20
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

The data export mechanism of the existing substation centralized monitoring system is simple, making it difficult to effectively manage the different data needs of multiple external systems, resulting in the risk of data leakage and misinformation, and the configuration file management is inefficient.

Method used

Through the coordinated work of the data directory module, data set module, target system module and data sending module, each centralized data is broadcast only to the data receiving system that needs it, avoid data leakage and misinformation, and simplify data scope management by batch adding data sets.

Benefits of technology

It realizes the secure, accurate and efficient transmission of centralized data, reduces the risk of data leakage and misinformation, simplifies the data management process, and improves operational flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185189A_ABST
    Figure CN120185189A_ABST
Patent Text Reader

Abstract

The invention discloses a data exit security management and control system and method for a transformer substation centralized monitoring system, a storage medium and computer equipment. The method comprises the steps that a data directory module reads data model information of various data types from the transformer substation centralized monitoring system; the data set module constructs a plurality of data sets based on data receiving requirements of each data receiving system, sets a data range, and adds data model information conforming to the data range into the data set for the data range of each data set; the target system module determines a target data set of each data receiving system, and binds each data receiving system with the target data set; and the data sending module obtains to-be-sent data based on the data sending task, determines a target data receiving system and target data corresponding to the target data receiving system based on the to-be-sent data and a target data set bound with each data receiving system, and sends the target data to the corresponding target data receiving system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of power system centralized monitoring systems, and in particular to a data export security control system and method, storage medium, and computer device for a substation centralized monitoring system. Background Art

[0002] With the development of the power industry, a large amount of production data has been generated in the daily operation of substation centralized monitoring systems, covering multiple dimensions such as telemetry, telemetry, and alarm events. These data are crucial for realizing data analysis, processing, model training, and status monitoring. However, in the process of exporting these centralized control data to different external systems, a series of challenges are faced.

[0003] Traditionally, the data export mechanism of centralized monitoring systems is relatively simple, usually by sending all changed data and periodic data to a single target system. This method can only send data to a single target system. If data needs to be sent to multiple target systems, multiple system instances need to be started, increasing the complexity of operations and resource consumption. In addition, different external systems often have different requirements for the dimensions of the required data. According to the principle of least privilege, users should have the smallest set of privileges necessary to complete the task, that is, the centralized monitoring system should minimize the amount and scope of data sent to the target system and only send the data required by the other system. However, currently, only complex configuration files can be used to manage the data scope of different target systems, and the modification efficiency is low and error-prone. Summary of the Invention

[0004] In view of this, this application provides a data export security control system and method, storage medium, and computer device for a substation centralized monitoring system. By managing the target system module and the data set module, each centralized control data is only broadcast to all data receiving systems that need it, thus avoiding the leakage and mistransmission of centralized control data, and the management is simple and flexible; all data model information that meets the data range is batch-added to a certain data set, and it is easy to use in setting the data range.

[0005] According to one aspect of this application, a data export security control system for a substation centralized monitoring system is provided, including a data directory module, a data set module, a target system module, and a data sending module;

[0006] The data directory module is used to read the data model information of each data type from the substation centralized monitoring system, where the data types include centralized control measurement data, centralized control alarm data, and main transformer heavy overload data;

[0007] The dataset module is used to construct multiple datasets based on the data reception requirements of each data reception system, and set the data range corresponding to each dataset. For each dataset, according to the data range corresponding to the dataset, add the data model information that meets the data range to the dataset;

[0008] The target system module is used to determine the target dataset corresponding to each data reception system, and bind each data reception system to the corresponding target dataset;

[0009] The data sending module is used to obtain the data to be sent corresponding to the data sending task from the substation centralized monitoring system based on the data sending task, and determine the target data reception system and the target data corresponding to the target data reception system based on the data to be sent and the target datasets bound to each data reception system, and send the target data to the corresponding target data reception system.

[0010] According to another aspect of the present application, a method for secure control of the data export of a substation centralized monitoring system is provided, including:

[0011] The data catalog module reads the data model information of each data type from the substation centralized monitoring system, where the data types include centralized control measurement data, centralized control alarm data, and main transformer heavy overload data;

[0012] The dataset module constructs multiple datasets based on the data reception requirements of each data reception system, and sets the data range corresponding to each dataset. For each dataset, according to the data range corresponding to the dataset, add the data model information that meets the data range to the dataset;

[0013] The target system module determines the target dataset corresponding to each data reception system, and binds each data reception system to the corresponding target dataset;

[0014] The data sending module obtains the data to be sent corresponding to the data sending task from the substation centralized monitoring system based on the data sending task, and determines the target data reception system and the target data corresponding to the target data reception system based on the data to be sent and the target datasets bound to each data reception system, and sends the target data to the corresponding target data reception system.

[0015] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned method for secure control of the data export of a substation centralized monitoring system is implemented.

[0016] According to another aspect of the present application, there is provided a computer device, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor. When the processor executes the program, it implements the data export security control method of the above substation centralized monitoring system.

[0017] With the above technical solution, a data export security control system and method, a storage medium, and a computer device for a substation centralized monitoring system provided by the present application. The data directory module reads the data model information of various data types of centralized control data exported outward from the substation centralized monitoring system. After the data directory module obtains all the data model information, the data set module can construct multiple data sets based on the data reception requirements of each data reception system. Each data set is set with a specific data range to meet the requirements of different data reception systems. For each data set, the data set module automatically adds the data model information that meets the range to the data set according to the data range corresponding to the data set. Further, the target system module determines the target data set corresponding to each data reception system. Then, each data reception system is bound to the corresponding target data set. Subsequently, the data sending module obtains the data to be sent from the substation centralized monitoring system based on the data sending task. According to the data to be sent and the target data sets bound to each data reception system, the target data reception system and the corresponding target data can be determined. Finally, the data sending module sends the target data to the corresponding target data reception system. In the embodiment of the present application, by managing the target system module and the data set module, each piece of centralized control data is only broadcast to all data reception systems that need it, thus avoiding the leakage and mistransmission of centralized control data, and the management is simple and flexible; all data model information that meets the data range is batch-added to a certain data set, which has ease of use in setting the data range.

[0018] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of the present application more obvious and understandable, the following specifically illustrates the specific embodiments of the present application. Brief Description of the Drawings

[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0020] Figure 1 It shows a schematic structural diagram of a data export security control system for a substation centralized monitoring system provided by an embodiment of the present application;

[0021] Figure 2Shows a schematic structural diagram of another data export security control system for a substation centralized monitoring system provided by an embodiment of the present application;

[0022] Figure 3 Shows a schematic diagram of the data model information obtained by a data catalog module provided by an embodiment of the present application;

[0023] Figure 4 Shows a schematic diagram of the data set construction result of a data set module provided by an embodiment of the present application;

[0024] Figure 5 Shows a schematic diagram of the binding result of a target system module provided by an embodiment of the present application;

[0025] Figure 6 Shows a schematic diagram of the mapping relationship between the data model information and the target system provided by an embodiment of the present application;

[0026] Figure 7 Shows a schematic flowchart of a data export security control method for a substation centralized monitoring system provided by an embodiment of the present application;

[0027] Figure 8 Shows a schematic diagram of the device structure of a computer device provided by an embodiment of the present application. Detailed implementation manners

[0028] The present application will be described in detail below with reference to the drawings and in conjunction with embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0029] In this embodiment, a data export security control system for a substation centralized monitoring system is provided. As Figure 1 shown, the system includes a data catalog module, a data set module, a target system module, and a data sending module;

[0030] The data catalog module is used to read the data model information of each data type from the substation centralized monitoring system, where the data types include centralized control measurement data, centralized control alarm data, and main transformer heavy overload data;

[0031] The data set module is used to construct multiple data sets based on the data reception requirements of each data reception system, and set the data range corresponding to each data set. For each data set, according to the data range corresponding to the data set, add the data model information that meets the data range to the data set;

[0032] The target system module is used to determine the target data set corresponding to each data reception system, and bind each data reception system to the corresponding target data set;

[0033] The data sending module is used to obtain the data to be sent corresponding to the data sending task from the substation centralized monitoring system based on the data sending task, and determine the target data receiving system and the target data corresponding to the target data receiving system based on the data to be sent and the target data sets bound to each data receiving system, and send the target data to the corresponding target data receiving system.

[0034] A data export security control system for a substation centralized monitoring system provided by an embodiment of the present application mainly consists of four core modules: a data directory module, a data set module, a target system module, and a data sending module. These modules work together to ensure the safe, accurate, and efficient transmission of centralized control data to each data receiving system.

[0035] Among them, the data directory module reads the data model information of various types of centralized control data exported outward from the substation centralized monitoring system. These data types include, but are not limited to, centralized control measurement data, centralized control alarm data, and main transformer heavy overload data. The data model information is the metadata of export data such as centralized control measurement data (real-time measurement), centralized control alarm data, and main transformer heavy overload data, such as the substation to which the export data belongs, the corresponding equipment, the interval to which it belongs, and the voltage level to which it belongs. The data directory module is the cornerstone of the entire data export security control system. It provides the basic framework and index of the centralized control data, enabling other modules to efficiently access and process the data.

[0036] After the data directory module obtains all the data model information, the data set module can construct multiple data sets based on the data receiving requirements of each data receiving system. Each data set sets a specific data range to meet the requirements of different data receiving systems. Here, the data set can be constructed manually or automatically by the system. For each data set, the data set module automatically adds the data model information that meets the range to the data set according to the data range corresponding to the data set. The data range can be used to filter the data model information. It should be noted that a data receiving system can correspond to different data sets, and at the same time, each data set can be used for different data receiving systems. The data set module provides a high degree of flexibility, allowing system administrators to dynamically create, modify, and delete data sets according to actual needs.

[0037] Furthermore, the target system module determines the target data set corresponding to each data receiving system. Among them, one data receiving system can correspond to one or more target data sets. For example, there are a total of five data sets, namely Data Set 1 to Data Set 5. In addition, there are two data receiving systems, namely Data Receiving System 1 to Data Receiving System 2. The target data sets corresponding to Data Receiving System 1 are Data Set 1, Data Set 3, and Data Set 4, and the target data sets corresponding to Data Receiving System 2 are Data Set 1, Data Set 2, and Data Set 5. After that, the target system module binds each data receiving system to the corresponding target data set. In this way, when data is sent, the data egress security control system can accurately know which data should be sent to which data receiving system. Thus, it can be seen that the target system module is the key to ensuring the correct transmission of data to the target data receiving system. It realizes the precise distribution of data by establishing the mapping relationship between the data receiving system and the data set.

[0038] Furthermore, based on the data sending task, the data sending module obtains the data to be sent from the substation centralized monitoring system. According to the data to be sent and the target data sets bound to each data receiving system, the target data receiving system and the corresponding target data can be determined. Finally, the data sending module sends the target data to the corresponding target data receiving system. The data sending module is the executor of the entire system, and it is responsible for efficiently and securely transmitting the processed data to the target data receiving system.

[0039] By applying the technical solution of this embodiment, the data catalog module reads the data model information of various types of data exported outward from the substation centralized monitoring system. After the data catalog module obtains all the data model information, the data set module can construct multiple data sets based on the data reception requirements of each data reception system. Each data set is set with a specific data range to meet the requirements of different data reception systems. For each data set, the data set module automatically adds the data model information that meets the range to the data set according to the data range corresponding to the data set. Further, the target system module determines the target data set corresponding to each data reception system. Then, each data reception system is bound to the corresponding target data set. Subsequently, the data sending module obtains the data to be sent from the substation centralized monitoring system based on the data sending task, and can determine the target data reception system and the corresponding target data according to the data to be sent and the target data sets bound to each data reception system. Finally, the data sending module sends the target data to the corresponding target data reception system. By managing the target system module and the data set module, the embodiment of the present application realizes broadcasting each centralized control data only to all data reception systems that need it, thereby avoiding the leakage and mistransmission of centralized control data, and the management is simple and flexible; all data model information that meets the data range is batch-added to a certain data set, and it is easy to use in setting the data range.

[0040] In the embodiment of the present application, optionally, when the data sending task is a periodic sending task, the data sending module is configured to: in response to a trigger instruction of the periodic sending task, obtain multiple centralized control measurement data to be sent from the substation centralized monitoring system, and identify the data model information corresponding to each centralized control measurement data, and respectively represent each centralized control measurement data and the corresponding data model information in the form of key-value pairs to obtain multiple key-value pairs; determine the data model information list corresponding to each data reception system according to the data model information in the target data set bound to each data reception system; based on the data model information list corresponding to each data reception system and the multiple key-value pairs, determine the first target data reception system from each data reception system; for each first target data reception system, based on the data model information list corresponding to the first target data reception system, obtain the target key-value pair corresponding to the first target data reception system from the multiple key-value pairs, use the target key-value pair as the target data, and send the target data to the corresponding first target data reception system.

[0041] In this embodiment, the data sending module can automatically obtain the centralized control measurement data from the substation centralized monitoring system according to a preset period, and accurately send this data to the corresponding first target data receiving system according to the requirements of each data receiving system. Specifically, the data sending module can listen for or wait for a periodic trigger instruction in real time. This instruction is usually issued by the timer or scheduler of the data export security control system, indicating that the preset sending period has arrived. Once the data sending module receives the trigger instruction for the periodic sending task, it can obtain all the centralized control measurement data to be pushed from the real-time database of the substation centralized monitoring system. These centralized control measurement data can include various data such as voltage, current, and power.

[0042] For each piece of centralized control measurement data obtained, the data sending module can identify and extract its corresponding data model information. For the convenience of subsequent processing, the data sending module combines each piece of centralized control measurement data with its corresponding data model information into a key-value pair. In this way, all the centralized control measurement data is represented as a set of key-value pairs. In addition, the data sending module can also generate a data model information list for each data receiving system according to the data model information bound to each data receiving system. The list contains the data model information corresponding to the data that the system needs to receive.

[0043] For each first target data receiving system, the data sending module can also screen out the keys that match it from multiple key-value pairs according to its data model information list, and then determine the centralized control measurement data according to the values corresponding to these matching keys, and use these centralized control measurement data as the target data of the first target data receiving system. Subsequently, the screened target data is sent to the corresponding first target data receiving system. In one embodiment, the data sending module can also obtain the quality code of each piece of centralized control measurement data from the real-time database and send the quality code to the corresponding first target data receiving system together. The quality code is a code or mark used to describe the data quality status. In a data system, each data item can be associated with a quality code to represent the quality characteristics of the data in terms of accuracy, integrity, consistency, timeliness, etc.

[0044] The embodiment of the present application represents the centralized control measurement data to be sent in the form of key-value pairs, realizing the flexible management and efficient transmission of data. At the same time, by maintaining the corresponding relationship between the data receiving system and the data model information, it can ensure that the data is accurately sent to the data receiving systems that need them.

[0045] In an embodiment of the present application, optionally, when the data sending task is a trigger-based sending task, the data sending module is configured to: when receiving the emergency data sent by the substation centralized monitoring system, trigger the generation of an emergency data sending task, and obtain the data model information corresponding to the emergency data, where the emergency data includes centralized control alarm data and / or main transformer heavy overload data; determine a data model information list corresponding to each data receiving system according to the data model information in the target data set bound to each data receiving system; based on the data model information lists corresponding to each data receiving system and the data model information corresponding to the emergency data, determine a second target data receiving system from each data receiving system, and send the emergency data to all the second target data receiving systems.

[0046] In this embodiment, the substation centralized monitoring system can also generate emergency data such as centralized control alarm data and main transformer heavy overload data. After these emergency data are generated, the data sending module can obtain these emergency data through real-time messages or other channels. When the data sending module obtains emergency data such as a mutation of a certain centralized control telecontrol signal data or centralized control alarm data through real-time messages or other channels, it can automatically trigger the generation of an emergency data sending task. That is to say, the emergency data sending task is a trigger-based sending task, which is triggered based on a specific event, specifically triggered when receiving the emergency data sent by the substation centralized monitoring system. Here, the emergency data can include centralized control alarm data and / or main transformer heavy overload data. When the data sending module receives abnormal or important data of these data types, it can automatically trigger the emergency data sending task.

[0047] After triggering the emergency data sending task, the data sending module first obtains the data model information associated with the emergency data. In addition, each data receiving system is bound to one or more target data sets, and these target data sets define the data that the data receiving system expects to receive. Then, the data sending module can generate a list containing the data model information corresponding to the data that the data receiving system expects to receive according to the target data set bound to each data receiving system. After that, the data sending module can determine which data receiving systems should receive this emergency data by comparing the data model information corresponding to the emergency data with the data model information lists corresponding to each data receiving system.

[0048] Based on the above matching logic, the data sending module filters out the second target data receiving systems that meet the conditions from all possible data receiving systems. These second target data receiving systems are determined according to the data model information of the emergency data and the data expected to be received by each data receiving system. Finally, the data sending module sends the emergency data to these filtered second target data receiving systems. In one embodiment, the data sending module can also obtain the quality code of each piece of emergency data from the real-time database and send the quality code to the corresponding second target data receiving system together.

[0049] The embodiments of the present application allow the determination of the target for sending emergency data according to the data model information of the emergency data and the requirements of each data receiving system, improving the accuracy of sending emergency data; by matching the data model information, the data sending module can quickly and accurately determine which data receiving systems should receive the emergency data, reducing unnecessary data transmission and processing overhead.

[0050] It should be noted that in the present application for these two task methods of periodic sending tasks and triggered sending tasks, no matter how many target data receiving systems the target data is sent to, the process of obtaining the target data only needs to be done once, which can effectively avoid duplicate acquisition of data and reduce unnecessary data transmission and processing overhead.

[0051] In the embodiments of the present application, optionally, the target system module is further configured to: determine the importance level of the data received by each data receiving system, and set an encryption key for the data receiving systems whose importance level is greater than a preset level; correspondingly, the data sending module is further configured to: after determining the target data receiving system and the target data corresponding to the target data receiving system, read the encryption key corresponding to the target data receiving system from the target system module, and when the encryption key is successfully read, based on the encryption key, encrypt the target data, and send the encrypted target data to the corresponding target data receiving system.

[0052] In this embodiment, the target system module can also determine the importance level of the data received by the data receiving system and set an encryption key for the data receiving system with a higher importance level. Specifically, the target system module can evaluate the importance level of the data received by each data receiving system. This level can be determined based on factors such as the type of data, sensitivity, and impact on the business. For the data receiving systems whose importance level is greater than the preset level, the target system module can set an encryption key for it, and this encryption key is used to ensure the confidentiality and integrity of the data during data transmission.

[0053] Subsequently, after the data sending module determines the target data receiving system and its corresponding target data, further, the encryption key corresponding to the target data receiving system can be read from the target system module. If the encryption key is successfully read, the data sending module can encrypt the target data based on the encryption key. Encryption processing can use various encryption algorithms and technologies, such as symmetric encryption, asymmetric encryption, hash functions, etc. Through encryption, it can be ensured that the data is not stolen or tampered with by unauthorized personnel during the transmission process. Finally, the data sending module sends the encrypted target data to the corresponding target data receiving system.

[0054] By setting an encryption key for a data receiving system with a higher importance level in the embodiments of the present application, the security of data transmission can be significantly improved.

[0055] In the embodiments of the present application, optionally, the target system module is further configured to: set corresponding message broker information for each data receiving system; correspondingly, the data sending module is further configured to: after determining the target data receiving system and the target data corresponding to the target data receiving system, read the message broker information corresponding to the target data receiving system from the target system module, generate a producer instance of the message broker corresponding to the target data receiving system based on the read message broker information, and send the target data to the message broker corresponding to the target data receiving system through the producer instance.

[0056] In this embodiment, the target system module can also set corresponding message broker information for each data receiving system. Here, the message broker information can include the address of the message broker (such as IP address and port number), queue or topic name, authentication information, etc. By setting the message broker information, it can help the data sending module send the data correctly to the message broker of the target data receiving system. The message broker is usually a middleware used to provide an asynchronous and decoupled communication method between the data sender and the data receiver.

[0057] Subsequently, after the data sending module determines the target data receiving system and its corresponding target data, the message broker information corresponding to the target data receiving system can be read from the target system module. Subsequently, based on the read message broker information, the data sending module can generate a producer instance of the message broker corresponding to the target data receiving system. The producer instance is a bridge for communication between the data sending module and the message broker, and it is responsible for sending the data to the message broker. Finally, the data sending module sends the target data to the message broker corresponding to the target data receiving system through the producer instance, and the message broker is responsible for storing the data in the queue or topic and waiting for the target data receiving system (i.e., the consumer) to consume the data.

[0058] In the embodiments of the present application, by introducing a message broker, an asynchronous and decoupled communication method is achieved between the data sender and the data receiver, which helps to reduce the complexity of the system, improve the scalability and fault tolerance of the system; the message broker provides multiple communication modes (such as point-to-point, publish / subscribe, etc.) and multiple data persistence options (such as in-memory storage, disk storage, etc.), which enables the data sending module to flexibly configure and use the message broker according to different business requirements; the message broker usually has functions such as data persistence, message confirmation, and retry mechanism to ensure the reliability and integrity of the data. Even if the data sender or the data receiver fails, the message broker can ensure that the data will not be lost or resent.

[0059] In the embodiments of the present application, optionally, the data set module is configured to: in response to an instruction to add a data set, construct a new data set, obtain the data range corresponding to the new data set, and add the data model information that meets the data range to the new data set; and / or, in response to an instruction to delete a data set, determine the data set to be deleted corresponding to the deletion instruction, and determine whether there is a data receiving system in the current data receiving systems that is bound to the data set to be deleted. When there is none, delete the data set to be deleted; and / or, in response to an instruction to modify a data set, determine the data set to be modified corresponding to the modification instruction, obtain the modification task corresponding to the data set to be modified, identify the data model information and the target operation corresponding to the modification task, and perform the target operation on the data model information corresponding to the modification task to obtain the modified data set.

[0060] In this embodiment, in order to improve the flexibility of data set operations, the data set module can also perform addition, deletion, and modification operations on the data set under the operation of the user. When receiving an instruction to add a data set, the data set module can construct a new data set according to the requirements of the addition instruction. Subsequently, determine the data range corresponding to this new data set. Specifically, the user can manually set the data range corresponding to the new data set. After determining the data range, the data set module can traverse the data model information that meets this range. For each data model information that meets the data range, the data set module adds it to the new data set. Finally, a new data set containing all the data model information indicated by the data range is obtained.

[0061] When receiving a deletion instruction for a data set, the data set module can identify the data set to be deleted according to the deletion instruction. However, to ensure that the data receiving system can normally receive the required target data, before deletion, the data set module can check whether there is a data receiving system in each current data receiving system that binds to the data set to be deleted, so as to ensure that the deletion operation will not affect other data receiving systems that depend on this data set. If there is no data receiving system that binds to the data set to be deleted, the data set module performs the deletion operation to completely remove the data set and all the data it contains. If there is a data receiving system that binds to the data set to be deleted, the user can be reminded of the risk of deleting this data set, and it is up to the user to decide whether to continue the deletion.

[0062] When receiving a modification instruction for a data set, the data set module can identify the data set to be modified according to the modification instruction. Further, the data set module can parse the modification instruction to obtain specific modification tasks. The modification tasks can include operations such as adding, deleting, or updating data model information, etc. Subsequently, the data set module identifies the data model information to be operated on and the specific target operation (such as adding, deleting, updating, etc.), and performs the above target operation on the corresponding data model information in the data set to be modified. After the modification task is completed, the modified data set can be obtained.

[0063] In the embodiment of the present application, the data set module can respond to the add, delete, and modify operation instructions for the data set, so that the data set can be adjusted according to the user's needs, increasing the flexibility of data set management to adapt to different business requirements.

[0064] In the embodiment of the present application, optionally, the data set module is further configured to: when there is new data model information in the substation centralized monitoring system, based on the data range corresponding to each data set, determine the target data range to which the new data model information belongs, and add the new data model information to the data set corresponding to the target data range.

[0065] In this embodiment, in the substation centralized monitoring system, data model information is crucial for the operation and monitoring of the system. This data model information may be continuously updated as the system is upgraded, expanded, or new devices are added. Based on this, the data set module can also monitor in real time whether there is new data model information in the substation centralized monitoring system. This is usually achieved through system logs, event triggers, or regular scans. Once new data model information is detected, the data set module can determine the target data range to which the new data model information belongs according to the data range corresponding to each data set. After determining the target data range, the data set module can automatically add the new data model information to the corresponding data set. Since then, the new data model information has been officially integrated into the data set for subsequent processing and analysis.

[0066] By automatically integrating new data model information in the embodiments of this application, subsequent analysis can obtain the data corresponding to the new data model information more timely and accurately, thereby improving the monitoring ability of the data export security control system and providing more comprehensive and accurate guarantee for the safe operation of the substation.

[0067] In one embodiment, the data export security control system of the substation centralized monitoring system can be as Figure 2 shown. As Figure 2 shown, the data export security control system of the substation centralized control system can include a presentation layer, a business layer, a basic service layer, and a persistence layer. Among them, the presentation layer is used for front-end display through Web technology to achieve visualization of data management, such as displaying Figures 3 to 6 contents, etc. The business layer may include the data directory module, the data set module, the target system module, and the data sending module in this application, which are used to implement the data export security control method of this application. The basic service layer includes the centralized control system message bus and the MQ (Message Queue) component. The persistence layer includes a real-time database and a commercial database. Among them, the real-time database (RTDB-Real Time DataBase) is a branch of the development of the database system and is generated by combining database technology with real-time processing technology. It can collect and obtain various data during the operation of the substation centralized monitoring system in real time; the commercial database refers to a database system specifically used for commercial applications and business management. The data sending module in the business layer is used to send target data to an external system. Here, the target system is the aforementioned data receiving system.

[0068] In another embodiment, specific functions of the data directory module, the data set module, the target system module, and the data sending module in the data export security control system of the substation centralized monitoring system are provided. Among them, as Figure 3As shown in the figure, the data directory module can obtain the data model information corresponding to real-time measurement data (i.e., centralized control measurement data), alarm messages (i.e., centralized control alarm data), and main transformer heavy overload data. Here, the data directory module can include a real-time measurement data sub-directory, which contains measurement data one to measurement data six; an alarm information sub-directory, which contains alarm data seven to alarm data twelve; and a main transformer heavy overload data sub-directory, which contains main transformer heavy overload data thirteen to main transformer heavy overload data fourteen. Here, measurement data one to measurement data six, alarm data seven to alarm data twelve, and main transformer heavy overload data thirteen to main transformer heavy overload data fourteen can be denoted as data model information.

[0069] Next, as Figure 4 shown, the data set module can construct multiple data sets according to the data reception requirements of each data reception system. Specifically, the data set module constructs four data sets, namely data set one to data set four. Among them, data set one adds measurement data one to measurement data three; data set two adds measurement data four to measurement data six; data set three adds alarm data seven to alarm data nine; and data set four adds alarm data ten.

[0070] Subsequently, as Figure 5 shown, the target system module binds data sets to each target system (i.e., data reception system). Among them, the data sets bound to target system one are data set one, data set two, and data set four; the data sets bound to target system two are data set two, data set three, and data set four. In this way, the mapping relationship between each target system and the data model information as shown in Figure 6 the figure can be obtained.

[0071] Subsequently, assuming that an alarm occurs in the substation centralized monitoring system, when the data sending module receives emergency data from the message bus or the database alarm table of the data export security control system of the substation centralized monitoring system, it can trigger the generation of an emergency data sending task. Subsequently, it determines the second target data reception system corresponding to the emergency data and sends the emergency data to the second target data reception system.

[0072] Taking alarm data nine as an example, assuming that the data model information corresponding to the emergency data is alarm data nine, and it is determined that alarm data nine is included in the data sets bound to target system two, then this emergency data can be sent to target system two;

[0073] Taking alarm data ten as an example, assuming that the data model information corresponding to the emergency data is alarm data ten, and it is determined that alarm data ten is included in the data sets bound to both target system one and target system two, then this emergency data can be sent to target system one and target system two;

[0074] Taking the alarm data eleven as an example, assuming that the data model information corresponding to the emergency data is the alarm data eleven, and it is determined that there is no data set of the target system that contains the alarm data eleven, that is, the second target data receiving system of the emergency data is empty, then the emergency data will not be sent, and the sending process will be directly ended.

[0075] Further, as Figure 1 a specific implementation of the system, an embodiment of the present application provides a method for security control of data outlets in a substation centralized monitoring system, as Figure 7 shown, the method includes:

[0076] The data directory module reads the data model information of each data type from the substation centralized monitoring system, where the data types include centralized control measurement data, centralized control alarm data, and main transformer heavy overload data;

[0077] The data set module constructs multiple data sets based on the data receiving requirements of each data receiving system, and sets the data range corresponding to each data set. For each data set, according to the data range corresponding to the data set, the data model information that meets the data range is added to the data set;

[0078] The target system module determines the target data set corresponding to each data receiving system, and binds each data receiving system to the corresponding target data set;

[0079] The data sending module, based on the data sending task, obtains the data to be sent corresponding to the data sending task from the substation centralized monitoring system, and based on the data to be sent and the target data sets bound to each data receiving system, determines the target data receiving system and the target data corresponding to the target data receiving system, and sends the target data to the corresponding target data receiving system.

[0080] Optionally, when the data sending task is a periodic sending task, the method further includes:

[0081] The data sending module, in response to the trigger instruction of the periodic sending task, obtains multiple centralized control measurement data to be sent from the substation centralized monitoring system, and identifies the data model information corresponding to each centralized control measurement data, and respectively represents each centralized control measurement data and the corresponding data model information in the form of key-value pairs to obtain multiple key-value pairs;

[0082] The data sending module determines the data model information list corresponding to each data receiving system according to the data model information in the target data sets bound to each data receiving system;

[0083] The data sending module determines a first target data receiving system from each data receiving system based on the data model information list corresponding to each data receiving system and the multiple key-value pairs;

[0084] For each first target data receiving system, the data sending module obtains a target key-value pair corresponding to the first target data receiving system from the multiple key-value pairs based on the data model information list corresponding to the first target data receiving system, takes the target key-value pair as target data, and sends the target data to the corresponding first target data receiving system.

[0085] Optionally, when the data sending task is a trigger-based sending task, the method further includes:

[0086] When the data sending module receives the emergency data sent by the substation centralized monitoring system, it triggers and generates an emergency data sending task, and obtains the data model information corresponding to the emergency data, where the emergency data includes centralized control alarm data and / or main transformer heavy overload data;

[0087] The data sending module determines the data model information list corresponding to each data receiving system according to the data model information in the target data set bound to each data receiving system;

[0088] The data sending module determines a second target data receiving system from each data receiving system based on the data model information list corresponding to each data receiving system and the data model information corresponding to the emergency data, and sends the emergency data to all the second target data receiving systems.

[0089] Optionally, the method further includes:

[0090] The target system module determines the importance level of the data received by each data receiving system, and sets an encryption key for the data receiving systems whose importance level is greater than the preset level;

[0091] Correspondingly, the method further includes:

[0092] After the data sending module determines the target data receiving system and the target data corresponding to the target data receiving system, it reads the encryption key corresponding to the target data receiving system from the target system module, and when the encryption key is successfully read, based on the encryption key, encrypts the target data, and sends the encrypted target data to the corresponding target data receiving system.

[0093] Optionally, the method further includes:

[0094] The target system module sets corresponding message broker information for each data receiving system;

[0095] Correspondingly, the method further includes:

[0096] After the data sending module determines the target data receiving system and the target data corresponding to the target data receiving system, it reads the message broker information corresponding to the target data receiving system from the target system module, generates a producer instance of the message broker corresponding to the target data receiving system based on the read message broker information, and sends the target data to the message broker of the corresponding target data receiving system through the producer instance.

[0097] Optionally, the method further includes:

[0098] The data set module, in response to an instruction to add a data set, constructs a new data set, obtains the data range corresponding to the new data set, and adds the data model information that meets the data range to the new data set; and / or, in response to an instruction to delete a data set, determines the data set to be deleted corresponding to the deletion instruction, and determines whether there is a data receiving system in the current data receiving systems that is bound to the data set to be deleted. When there is none, deletes the data set to be deleted; and / or, in response to an instruction to modify a data set, determines the data set to be modified corresponding to the modification instruction, obtains the modification task corresponding to the data set to be modified, identifies the data model information and the target operation corresponding to the modification task, and performs the target operation on the data model information corresponding to the modification task to obtain the modified data set.

[0099] Optionally, the method further includes:

[0100] When there is new data model information in the substation centralized monitoring system, the data set module determines the target data range to which the new data model information belongs based on the data range corresponding to each data set, and adds the new data model information to the data set corresponding to the target data range.

[0101] It should be noted that for other corresponding descriptions of each functional unit involved in the data export security control method of the substation centralized monitoring system provided in the embodiments of the present application, reference can be made to Figures 1 to 6 the corresponding description in the system, which will not be elaborated here.

[0102] The embodiments of the present application further provide a computer device, which may specifically be a personal computer, a server, a network device, etc., such as Figure 8As shown, the computer device includes a bus, a processor, a memory, and a communication interface, and may further include an input / output interface and a display device. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in the method embodiments are implemented.

[0103] Those skilled in the art can understand that Figure 8 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0104] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0105] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0106] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0107] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include Read-Only Memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0108] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0109] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A data export security control system for a centralized monitoring system of a substation, characterized in that: It includes data directory module, data set module, target system module and data sending module; The data directory module is used to read data model information of various data types from the substation centralized monitoring system, wherein the data types include centralized control measurement data, centralized control alarm data and main transformer overload data; The data set module is used to construct multiple data sets based on the data receiving requirements of each data receiving system, and set the data range corresponding to each data set. For each data set, according to the data range corresponding to the data set, the data model information that meets the data range is added to the data set; The target system module is used to determine the target data set corresponding to each data receiving system and bind each data receiving system to the corresponding target data set; The data sending module is used to obtain the data to be sent corresponding to the data sending task from the substation centralized monitoring system based on the data sending task, and determine the target data receiving system and the target data corresponding to the target data receiving system based on the data to be sent and the target data set bound to each data receiving system, and send the target data to the corresponding target data receiving system.

2. The system according to claim 1, characterized in that When the data sending task is a periodic sending task, the data sending module is used to: In response to a trigger instruction of a periodic sending task, a plurality of centralized control measurement data to be sent are obtained from the centralized monitoring system of the substation, and data model information corresponding to each piece of centralized control measurement data is identified, and each piece of centralized control measurement data and the corresponding data model information are respectively represented in the form of a key-value pair to obtain a plurality of key-value pairs; Determine a data model information list corresponding to each data receiving system according to the data model information in the target data set bound to each data receiving system; Determine a first target data receiving system from each data receiving system based on the data model information list corresponding to each data receiving system and the multiple key-value pairs; For each first target data receiving system, based on the data model information list corresponding to the first target data receiving system, obtain the target key-value pair corresponding to the first target data receiving system from the multiple key-value pairs, use the target key-value pair as the target data, and send the target data to the corresponding first target data receiving system.

3. The system according to claim 1, characterized in that When the data sending task is a triggered sending task, the data sending module is used to: When receiving emergency data sent by the substation centralized monitoring system, triggering the generation of an emergency data sending task, and obtaining data model information corresponding to the emergency data, wherein the emergency data includes centralized control alarm data and / or main transformer overload data; Determine a data model information list corresponding to each data receiving system according to the data model information in the target data set bound to each data receiving system; Based on the data model information list corresponding to each data receiving system and the data model information corresponding to the urgent data, a second target data receiving system is determined from each data receiving system, and the urgent data is sent to all second target data receiving systems.

4. The system according to claim 1, characterized in that The target system module is also used for: Determine the importance level of data received by each data receiving system, and set an encryption key for the data receiving system with an importance level greater than a preset level; Accordingly, the data sending module is further used for: After determining the target data receiving system and the target data corresponding to the target data receiving system, read the encryption key corresponding to the target data receiving system from the target system module, and after successfully reading the encryption key, encrypt the target data based on the encryption key, and send the encrypted target data to the corresponding target data receiving system.

5. The system according to claim 1, characterized in that The target system module is also used for: Set corresponding message agent information for each data receiving system; Accordingly, the data sending module is further used for: After determining the target data receiving system and the target data corresponding to the target data receiving system, read the message agent information corresponding to the target data receiving system from the target system module, generate a producer instance of the message agent corresponding to the target data receiving system based on the read message agent information, and send the target data to the message agent of the corresponding target data receiving system through the producer instance.

6. The system according to any one of claims 1 to 5, characterized in that The data set module is used to: In response to the instruction for adding a new data set, a new data set is constructed, and a data range corresponding to the new data set is obtained, and data model information that conforms to the data range is added to the new data set; and / or, In response to a deletion instruction of a data set, determining a data set to be deleted corresponding to the deletion instruction, and judging whether there is a data receiving system bound to the data set to be deleted in each current data receiving system, and if no data receiving system exists, deleting the data set to be deleted; and / or, In response to a modification instruction of a data set, determine the data set to be modified corresponding to the modification instruction, obtain the modification task corresponding to the data set to be modified, identify the data model information and target operation corresponding to the modification task, perform the target operation on the data model information corresponding to the modification task, and obtain the modified data set.

7. The system according to any one of claims 1 to 5, characterized in that The data set module is also used for: When there is new data model information in the substation centralized monitoring system, the target data range to which the new data model information belongs is determined based on the data range corresponding to each data set, and the new data model information is added to the data set corresponding to the target data range.

8. A data export security control method for a centralized monitoring system of a substation, characterized in that: include: The data directory module reads data model information of each data type from the substation centralized monitoring system, wherein the data types include centralized control measurement data, centralized control alarm data and main transformer overload data; The data set module constructs multiple data sets based on the data receiving requirements of each data receiving system, and sets the data range corresponding to each data set. For each data set, according to the data range corresponding to the data set, the data model information that meets the data range is added to the data set; The target system module determines the target data set corresponding to each data receiving system, and binds each data receiving system to the corresponding target data set; Based on the data sending task, the data sending module obtains the data to be sent corresponding to the data sending task from the substation centralized monitoring system, and determines the target data receiving system and the target data corresponding to the target data receiving system based on the data to be sent and the target data set bound to each data receiving system, and sends the target data to the corresponding target data receiving system.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to claim 8 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to claim 8 is implemented.

Citation Information

Patent Citations

  • GOOSE data sending method and device, and configuration method and device

    CN109286515A

  • Substation online monitoring system based on Internet of things and terminal equipment

    CN110336379A

  • Power grid data sharing system

    CN113409021A

  • Data query system, method and device, electronic equipment and readable storage medium

    CN113609161A

  • Power distribution station network monitoring method and device, computer equipment and storage medium

    CN114301174A