Enterprise safety condition instant evaluation management method and system

By monitoring the data acquisition and processing of sensor networks and edge computing nodes, combined with digital twin models and reinforcement learning algorithms, the data incompleteness and intelligent management problems in enterprise security status assessment are solved, and comprehensive, real-time, accurate assessment and intelligent management of enterprise infrastructure are achieved.

CN120301912APending Publication Date: 2025-07-11SHENZHEN YUNKE IND TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510719989.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing technology has insufficient data collection in enterprise security status assessment and management, and cannot accurately reflect real-time status. The multi-source heterogeneous data processing capabilities are limited, it is difficult to extract effective feature information, lacks accurate identification and prediction capabilities for potential failures, and lacks intelligence and targeted management strategies.

Method used

Through the monitoring sensor network, multi-source heterogeneous facility data is collected, edge computing nodes are used to extract facility features and adopt a state evaluation combination algorithm to build a digital twin model and identify potential failures, and generate management strategies based on reinforcement learning algorithms.

Benefits of technology

It realizes a comprehensive, real-time and accurate assessment of enterprise infrastructure, can formulate intelligent management strategies, improve safety management level, timely discover potential hidden dangers and predict failures, and optimize operation and maintenance decisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301912A_ABST
    Figure CN120301912A_ABST
Patent Text Reader

Abstract

The invention provides a real-time evaluation management method and system for an enterprise safety condition, and relates to the technical field of enterprise safety management, and the method comprises the steps: collecting multi-source heterogeneous facility data through a monitoring sensor network of an enterprise infrastructure group, and carrying out the preprocessing of the multi-source heterogeneous facility data; multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data are extracted through edge computing nodes, and the facility safety state of the enterprise infrastructure group is evaluated by adopting a state evaluation combination algorithm; constructing a digital twinborn model of the enterprise infrastructure group based on the multi-source heterogeneous facility data, and identifying potential facility faults of the enterprise infrastructure group by adopting a fault identification integration algorithm based on the digital twinborn model; and on the basis of a reinforcement learning algorithm, an enterprise facility management strategy is generated according to the facility safety state and the potential facility fault and is sent to the operation and maintenance end, so that the safety condition of the enterprise infrastructure can be comprehensively and accurately evaluated in real time, the intelligent enterprise facility management strategy is formulated, and the enterprise safety management level is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of enterprise security management, and in particular, to a method and system for instantaneously evaluating and managing the security status of an enterprise. Background Art

[0002] During the operation of an enterprise, the security status of enterprise infrastructure is of crucial importance.

[0003] However, when the prior art evaluates and manages the security status of an enterprise, there are often many deficiencies: data collection is not comprehensive and timely enough to accurately reflect the real-time status of enterprise infrastructure; the processing ability for multi-source heterogeneous data is limited, making it difficult to extract effective feature information; there is a lack of accurate identification and prediction ability for potential faults, and it is impossible to take fault prevention measures in a timely manner; the generation of management strategies lacks intelligence and pertinence, and it is difficult to meet the actual security management needs of enterprises.

[0004] Therefore, it is necessary to provide a method and system for instantaneously evaluating and managing the security status of an enterprise to solve the above technical problems. Summary of the Invention

[0005] To solve the above technical problems, the present invention provides a method and system for instantaneously evaluating and managing the security status of an enterprise, which are used to solve the problems that the prior art cannot comprehensively, real-time, and accurately evaluate the security status of enterprise infrastructure and it is difficult to formulate an intelligent enterprise security management strategy.

[0006] A method for instantaneously evaluating and managing the security status of an enterprise provided by the present invention includes: Collecting multi-source heterogeneous facility data through a monitoring sensor network of an enterprise infrastructure group and performing preprocessing; Extracting multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes and evaluating the facility security status of the enterprise infrastructure group by using a state evaluation combination algorithm; Constructing a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data and identifying potential facility faults of the enterprise infrastructure group by using a fault identification integration algorithm based on the digital twin model; Generating an enterprise facility management strategy based on a reinforcement learning algorithm according to the facility security status and the potential facility faults and sending it to an operation and maintenance terminal.

[0007] Preferably, based on the actual monitoring requirements of the enterprise infrastructure group, a plurality of key monitoring nodes are set on the enterprise infrastructure group, and a monitoring sensor is installed on each key monitoring node, and all the monitoring sensors are aggregated to generate the monitoring sensor network; The acquisition process of the multi-source heterogeneous facility data adopts a batch acquisition strategy, that is, the acquisition frequency of the corresponding monitoring sensors is determined according to the change frequency of the multi-source heterogeneous facility data.

[0008] Preferably, the multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data are extracted by the edge computing node, and a state evaluation combination algorithm is used to evaluate the facility security state of the enterprise infrastructure group, specifically including: The edge computing node adopts a multi-core processor with an ARM architecture; Through the edge computing node, time-domain and frequency-domain features corresponding to the multi-source heterogeneous facility data are extracted based on the short-time Fourier transform technology, that is, the multi-source heterogeneous facility features; The state evaluation combination algorithm is a combination of the long short-term memory network algorithm and the convolutional neural network algorithm. The long short-term memory network algorithm is used to evaluate the facility time state of the multi-source heterogeneous facility features, and the convolutional neural network algorithm is used to evaluate the facility space state of the multi-source heterogeneous facility features. The facility time state and the facility space state are summarized to generate the facility security state.

[0009] Preferably, the digital twin model of the enterprise infrastructure group is constructed based on the multi-source heterogeneous facility data, specifically including: Based on the facility physical structure data in the multi-source heterogeneous facility data, a facility physical model of the enterprise infrastructure group is constructed; Based on the facility operation parameter data in the multi-source heterogeneous facility data, a data-driven model of the enterprise infrastructure group is constructed; The facility physical model and the data-driven model are fused to generate the digital twin model; An asynchronous communication mechanism based on a message queue is used to synchronize the multi-source heterogeneous facility data to the digital twin model.

[0010] Preferably, a fault identification integration algorithm is used to identify potential facility faults of the enterprise infrastructure group based on the digital twin model, specifically including: The fault identification integration algorithm integrates the support vector machine algorithm and the random forest algorithm. The support vector machine algorithm is used to identify potential linear faults corresponding to the enterprise infrastructure group, and the random forest algorithm is used to identify potential non-linear faults corresponding to the enterprise infrastructure group. The potential linear faults and the potential non-linear faults are summarized to generate the potential facility faults; Based on the digital twin model, the occurrence process of the potential facility faults is simulated to generate a fault propagation path and a fault chain reaction; Construct a fault propagation model, and analyze the fault impact area of the potential facility fault according to the fault propagation path and the fault chain reaction.

[0011] Preferably, based on the reinforcement learning algorithm, an enterprise facility management strategy is generated according to the facility safety state and the potential facility fault and sent to the operation and maintenance terminal, specifically including: Encode the facility safety state and the potential facility fault, and convert them into a facility state vector corresponding to the reinforcement learning algorithm; Set the action space and reward function corresponding to the reinforcement learning algorithm, and the action space is the candidate facility management strategy; Based on the reinforcement learning algorithm, according to the facility state vector and the reward function, select the enterprise facility management strategy from the candidate facility management strategies and send it to the operation and maintenance terminal.

[0012] An enterprise safety condition instant evaluation and management system, the system includes: A monitoring and acquisition module, which is used to collect multi-source heterogeneous facility data through the monitoring sensor network of the enterprise infrastructure group and perform preprocessing; An extraction and evaluation module, which is used to extract multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes, and use a state evaluation combination algorithm to evaluate the facility safety state of the enterprise infrastructure group; A construction and recognition module, which is used to build a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data, and use a fault recognition integration algorithm to identify potential facility faults of the enterprise infrastructure group based on the digital twin model; A solution determination module, which is used to generate an enterprise facility management strategy according to the facility safety state and the potential facility fault based on the reinforcement learning algorithm and send it to the operation and maintenance terminal.

[0013] An electronic device includes a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the steps of an enterprise safety condition instant evaluation and management method as described in any one of the above.

[0014] A readable storage medium stores a computer program, and the computer program is used to implement the steps of an enterprise safety condition instant evaluation and management method as described in any one of the above when executed by a processor.

[0015] Compared with the related technology, an enterprise safety condition instant evaluation and management method and system provided by the present invention have the following beneficial effects: Through the monitoring sensor network of the enterprise infrastructure group, this invention collects multi-source heterogeneous facility data and preprocesses it; through the edge computing nodes, it extracts the multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data, and uses the state evaluation combination algorithm to evaluate the facility security status of the enterprise infrastructure group; based on the multi-source heterogeneous facility data, it constructs a digital twin model of the enterprise infrastructure group, and based on the digital twin model, uses the fault identification integration algorithm to identify potential facility faults in the enterprise infrastructure group; based on the reinforcement learning algorithm, it generates enterprise facility management strategies according to the facility security status and potential facility faults and sends them to the operation and maintenance side, so as to comprehensively, real-time and accurately evaluate the security status of the enterprise infrastructure, and can formulate intelligent enterprise facility management strategies to improve the enterprise security management level.

[0016] Through the monitoring sensor network and the batch collection strategy, this invention can comprehensively and timely collect the multi-source heterogeneous data of the enterprise infrastructure, ensuring the accuracy and real-time nature of the data; this invention can use the edge computing nodes and feature extraction technology to efficiently process the multi-source heterogeneous data, extract effective time-domain and frequency-domain features, laying a foundation for accurately evaluating the facility security status; the digital twin model constructed by this invention can truly reflect the physical structure and operation status of the enterprise infrastructure group. Combining with the fault identification integration algorithm, it realizes the accurate identification and prediction of potential facility faults, and can simulate the occurrence process and influence area of the faults, providing a basis for taking preventive measures in advance; the enterprise facility management strategy generated by this invention based on the reinforcement learning algorithm is targeted and can timely adjust the enterprise management strategy according to the security status and potential faults of the facilities, improving the efficiency and effect of enterprise security management. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flowchart of a method for instantaneously evaluating and managing the security status of an enterprise provided by an embodiment of this invention; Figure 2 It is a system block diagram of a system for instantaneously evaluating and managing the security status of an enterprise provided by an embodiment of this invention; Figure 3 It is a schematic hardware structure diagram of an electronic device provided by an embodiment of this invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] To make the objectives, technical solutions and advantages of the embodiments of this invention clearer, the technical solutions in the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this invention. Obviously, the described embodiments are only a part of the embodiments of this invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of this invention without creative efforts shall fall within the scope of protection of this invention.

[0019] As shown Figure 1 in the figure, it is a flowchart of a method for instantaneously evaluating and managing the enterprise security status provided by an embodiment of the present invention. Figure 1 The execution subject of the method shown can be a software and / or hardware device. The execution subject of this application can include but is not limited to at least one of the following: user equipment, network equipment, etc. Among them, the user equipment can include but is not limited to a computer, a smart phone, a personal digital assistant (Personal Digital Assistant, abbreviated as: PDA), and the electronic devices mentioned above. The network equipment can include but is not limited to a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of computers or network servers based on cloud computing. Among them, cloud computing is a type of distributed computing, which is composed of a group of loosely coupled computers to form a super virtual computer. This embodiment does not make any restrictions on this. It includes steps S1 to S4, which are specifically as follows: S1, collect multi-source heterogeneous facility data through the monitoring sensor network of the enterprise infrastructure group and perform preprocessing; Among them, the enterprise infrastructure group refers to the infrastructure set composed of physical devices, information systems, and network resources required for enterprise operation, including but not limited to server clusters, industrial control systems (ICS), Internet of Things (IoT) devices, communication networks, etc. The monitoring sensor network refers to a network composed of distributed sensor nodes, which can obtain the operation parameters of the infrastructure in real time through data collection protocols such as MQTT, and support the collection of multi-modal data, including temperature, pressure, flow, voltage, etc. The multi-source heterogeneous facility data comes from different data sources and has different data structures and time granularities.

[0020] In order to comprehensively and accurately obtain the operation data of the infrastructure, a wide range of monitoring sensor networks can be deployed in the enterprise infrastructure group. These sensors are distributed at each key node and can collect various types of data such as temperature, pressure, vibration, current, voltage, etc. in real time.

[0021] Due to the complexity of the enterprise infrastructure, these data have the characteristics of multi-source heterogeneity, that is, they come from different sensors and have different data formats, sampling frequencies, and semantic meanings. In order to process these multi-source heterogeneous data, preprocessing operations can be performed. The preprocessing includes steps such as data cleaning, format conversion, time synchronization, and data fusion. Specifically, the data cleaning operation can remove noise data and outliers to improve the data quality; the format conversion operation can unify the data in different formats into a standard format for subsequent processing; the time synchronization processing can solve the problem of inconsistent sampling times of different sensors; the data fusion processing can integrate the data from multiple sources into an organic whole to provide more comprehensive information.

[0022] S2. Extract the multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes, and use the state evaluation combination algorithm to evaluate the facility security status of the enterprise infrastructure group; It can be understood that an edge computing node refers to a distributed computing node deployed near the data source, such as an industrial gateway, an intelligent terminal, etc. Through edge intelligent algorithms, such as wavelet transform, lightweight machine learning models, etc., it can realize data preprocessing and feature extraction, reducing the cloud computing load and transmission delay. The state evaluation combination algorithm refers to a hybrid algorithm that fuses the long short-term memory network (LSTM) and the convolutional neural network (CNN). It processes the long-term dependencies in time series data through LSTM, extracts spatial features through CNN, and then weights and fuses multi-modal features through the attention mechanism to output the facility security status vector.

[0023] To reduce the data transmission pressure and improve the data processing efficiency, through edge computing nodes, a variety of advanced signal processing and machine learning algorithms can be used to analyze the multi-source heterogeneous facility data from multiple perspectives such as time domain, frequency domain, and time-frequency domain, and convert it into a feature vector that can reflect the facility operation state, that is, the multi-source heterogeneous facility features.

[0024] After the multi-source heterogeneous facility features are extracted, the state evaluation combination algorithm can be used to evaluate the facility security status of the enterprise infrastructure group. Among them, the state evaluation combination algorithm combines the advantages of the long short-term memory network and the convolutional neural network. The long short-term memory network is good at processing time series data and can capture the long-term dependencies in the data, so as to accurately evaluate the time state of the facility. The convolutional neural network has unique advantages in processing spatial features and can effectively analyze the spatial state of the facility. By combining these two algorithms, the security status of the enterprise infrastructure can be comprehensively and accurately evaluated, and potential security hazards can be discovered in time.

[0025] S3. Build a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data, and use the fault identification integration algorithm to identify potential facility faults in the enterprise infrastructure group based on the digital twin model; It should be noted that the digital twin model refers to a virtual mapping model built based on the multi-dimensional data of the physical system, and the multi-dimensional data includes geometric models, physical properties, behavior rules, etc. Through data-driven and physical model coupling, it can perform real-time state simulation on physical facilities, supporting fault prediction and health management. The fault identification integration algorithm refers to a fault identification algorithm that integrates the support vector machine (SVM) and the random forest (RF). It identifies linearly separable fault patterns through SVM, processes non-linear fault features through RF, and then dynamically adjusts the classifier weights through the meta-learning algorithm to achieve fault type identification and severity assessment.

[0026] In order to deeply understand the operating status of enterprise infrastructure and predict potential failures, a digital twin model of the enterprise infrastructure group can be constructed based on multi-source heterogeneous facility data. The digital twin model is a digital mapping of physical entities, which not only includes the geometric structure and physical characteristics of the facilities, but also can simulate the operating process and behavior of the facilities.

[0027] When constructing the digital twin model, first, a facility physical model can be constructed based on the physical structure data of the facility, then a data-driven model can be constructed based on the operating parameter data of the facility, and finally, these two models are fused to form a complete digital twin model. Through the digital twin model, the operating status of the facility can be simulated in real time, and possible failures can be predicted.

[0028] Based on the digital twin model, a fault identification integration algorithm can be used to identify potential facility failures in the enterprise infrastructure group. The fault identification integration algorithm integrates multiple machine learning algorithms such as support vector machines and random forests. Support vector machines have high accuracy in dealing with linear classification problems and can identify potential linear failures in the enterprise infrastructure group. Random forests, on the other hand, perform well in dealing with non-linear problems and can identify potential non-linear failures in the enterprise infrastructure group. By combining these two algorithms, potential facility failures can be comprehensively and accurately identified, and the propagation path and impact area of the failures can be analyzed.

[0029] S4. Based on the reinforcement learning algorithm, generate an enterprise facility management strategy according to the facility safety status and the potential facility failures and send it to the operation and maintenance end.

[0030] Among them, the reinforcement learning algorithm is a machine learning algorithm that learns the optimal strategy through the interaction between the intelligent agent and the environment. The operation and maintenance end refers to an enterprise-level operation and maintenance management platform based on the microservice architecture, which displays the facility status through a digital twin visualization interface and supports closed-loop management functions such as automatic work order generation, intelligent dispatching, and maintenance process tracking.

[0031] In practical applications, an enterprise facility management strategy can be generated based on the reinforcement learning algorithm according to the facility safety status and potential facility failures. Among them, the facility safety status and potential facility failures constitute the environmental state, the preset management strategy set constitutes the action space, and the reward function is constructed based on factors such as fault repair timeliness and resource consumption. By continuously interacting with the environment, the reinforcement learning algorithm can learn the optimal management strategy, that is, in different facility states, select the management strategy that maximizes the reward and send it to the operation and maintenance end. The operation and maintenance end is the core platform for enterprise infrastructure management. It can receive the management strategy and convert it into specific operation and maintenance tasks. Operation and maintenance personnel can view the facility status, receive fault warnings, execute maintenance tasks, etc. through the operation and maintenance end. At the same time, the operation and maintenance end will also record the operation and maintenance process and results, providing feedback data for system optimization.

[0032] Through the above method, the enterprise infrastructure can be comprehensively and real-time monitored and intelligently managed, potential failures can be predicted in advance, the reliability and security of the enterprise infrastructure can be improved, the operation and maintenance costs can be reduced, and strong guarantee can be provided for the stable operation of the enterprise.

[0033] In the specific implementation process, based on the actual monitoring requirements of the enterprise infrastructure group, multiple key monitoring nodes are set on the enterprise infrastructure group, and a monitoring sensor is installed on each of the key monitoring nodes, and all the monitoring sensors are aggregated to generate the monitoring sensor network; The acquisition process of the multi-source heterogeneous facility data adopts a batch acquisition strategy, that is, the acquisition frequency of the corresponding monitoring sensors is determined according to the change frequency of the multi-source heterogeneous facility data.

[0034] Among them, the key monitoring nodes can be reasonably arranged according to the actual monitoring requirements of the enterprise infrastructure group. By comprehensively analyzing the structural characteristics, functional requirements and potential risk points of the enterprise infrastructure group, the positions that can effectively reflect the operation state of the infrastructure are determined as the key monitoring nodes. These nodes are usually located at the core devices of the system, key transmission lines and weak links prone to failures.

[0035] On each key monitoring node, corresponding monitoring sensors can be installed. These sensors have high-precision data acquisition capabilities and can real-time obtain various parameters during the operation of the enterprise infrastructure. According to different monitoring requirements, the types of sensors selected are also different, including but not limited to temperature sensors, pressure sensors, vibration sensors, current sensors, etc. By deploying targeted monitoring sensors at each key monitoring node, the operation state of the enterprise infrastructure can be perceived in multiple dimensions.

[0036] Then, all the monitoring sensors installed on the key monitoring nodes can be integrated to form a monitoring sensor network. This network adopts a distributed architecture design and has self-organization and self-healing capabilities, which can ensure the stability and reliability of data transmission. Through wireless communication technology or wired communication technology, each monitoring sensor transmits the collected data to the data processing center in real time, providing a basis for subsequent data analysis and decision-making.

[0037] During the acquisition process of multi-source heterogeneous facility data, a batch acquisition strategy is adopted. The core of this strategy lies in dynamically adjusting the acquisition frequency of the corresponding monitoring sensors according to the change frequency of the multi-source heterogeneous facility data. For data with a high change frequency, such as the real-time operation parameters of equipment, in order to capture its instantaneous changes and ensure the timeliness of the data, a higher acquisition frequency can be set; while for data with a low change frequency, such as the basic attribute information of equipment, in order to reduce the data storage pressure and transmission bandwidth consumption, a lower acquisition frequency can be set.

[0038] Through this batch acquisition strategy, the utilization efficiency of system resources can be optimized on the premise of ensuring data integrity and accuracy. At the same time, combined with data preprocessing technology, the collected multi-source heterogeneous data is cleaned, transformed and fused to further improve the data quality, providing reliable data support for the security assessment and fault prediction of enterprise infrastructure.

[0039] The extraction of multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data by the edge computing node and the evaluation of the facility security state of the enterprise infrastructure group by using the state evaluation combination algorithm specifically include: The edge computing node adopts a multi-core processor with an ARM architecture; Through the edge computing node, time-domain and frequency-domain features corresponding to the multi-source heterogeneous facility data are extracted based on the short-time Fourier transform technology, that is, the multi-source heterogeneous facility features; The state evaluation combination algorithm is a combination of the long short-term memory network algorithm and the convolutional neural network algorithm. The long short-term memory network algorithm is used to evaluate the facility time state of the multi-source heterogeneous facility features, and the convolutional neural network algorithm is used to evaluate the facility space state of the multi-source heterogeneous facility features. The facility time state and the facility space state are summarized to generate the facility security state.

[0040] It should be noted that the edge computing node undertakes the key tasks of data processing and feature extraction. This node adopts a multi-core processor with an ARM architecture, which has the characteristics of high performance and low power consumption, and can achieve efficient computing in the resource-constrained edge environment. By being distributed near the data source, the edge computing node can process the collected multi-source heterogeneous facility data nearby, reduce data transmission delay, and improve the system response speed.

[0041] Then, the feature extraction of multi-source heterogeneous facility data can be achieved based on the short-time Fourier transform technology. This technology divides the time-domain signal into multiple short time segments and performs Fourier transform on each segment to obtain the time-domain and frequency-domain features of the signal. In this way, key features reflecting the operating state of the facility, such as vibration frequency and temperature change trend, can be extracted from the original data. These features not only retain the time-domain characteristics of the data but also reveal its frequency-domain distribution law, providing a rich information basis for subsequent state assessment.

[0042] Furthermore, a combined state assessment algorithm that combines the long short-term memory network algorithm and the convolutional neural network algorithm can be used to evaluate the safety state of the facility. The long short-term memory network algorithm is a special recurrent neural network that can effectively handle long-term dependencies in sequence data. This algorithm can evaluate the time state of the facility with multi-source heterogeneous facility features. By analyzing the variation law of the data over time, it can capture the dynamic evolution process of the facility operating state. The convolutional neural network algorithm is good at processing data with grid structures, such as images or spatial data. In the assessment of the facility safety state, this algorithm is used to evaluate the spatial state of the facility with multi-source heterogeneous facility features. By automatically extracting local features and spatial relationships in the data through convolutional operations, it can identify the association and interaction patterns between different components of the facility.

[0043] By summarizing the facility time state and the facility spatial state, a comprehensive assessment result of the facility safety state can be generated. This combined assessment method gives full play to the advantages of the two algorithms, taking into account both the time evolution characteristics of the facility operating state and capturing its spatial structure information, so as to accurately evaluate the safety state of the enterprise infrastructure.

[0044] Through the efficient processing of the edge computing node and the synergistic effect of the combined state assessment algorithm, the operating state of the enterprise facilities can be grasped in real time and accurately, potential safety hazards can be discovered in a timely manner, and strong support can be provided for the enterprise's safe production and operation and maintenance decision-making.

[0045] Constructing the digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data specifically includes: Based on the facility physical structure data in the multi-source heterogeneous facility data, constructing the facility physical model of the enterprise infrastructure group; Based on the facility operation parameter data in the multi-source heterogeneous facility data, constructing the data-driven model of the enterprise infrastructure group; Fusing the facility physical model and the data-driven model to generate the digital twin model; Adopting an asynchronous communication mechanism based on message queues to synchronize the multi-source heterogeneous facility data to the digital twin model.

[0046] In practical applications, based on the facility physical structure data in the multi-source heterogeneous facility data, a facility physical model of the enterprise infrastructure group can be constructed. The facility physical structure data contains information reflecting the physical form and structural relationships of facilities in the enterprise infrastructure group, such as the geometric dimensions, spatial layout, component composition, and material properties of each facility. Through the processing and modeling of this data, the physical structure of the enterprise infrastructure group can be restored in the virtual space, forming a virtual model corresponding to the actual physical form of the facilities, providing a physical-level basic framework for the digital twin model.

[0047] Secondly, based on the facility operation parameter data in the multi-source heterogeneous facility data, a data-driven model of the enterprise infrastructure group can be constructed. The facility operation parameter data is various dynamic data generated during the operation of the facilities, such as temperature, pressure, flow rate, voltage, current, rotation speed, etc. Using data-driven methods, analyze and model these operation parameter data, mine the internal relationships and laws between the data, and establish a mathematical model that can describe the operation state and behavior of the facilities. This data-driven model can predict the operation state and output results of the facilities according to the input operation parameter data, realizing the dynamic simulation of the facility operation process.

[0048] Then, the facility physical model and the data-driven model can be integrated to generate a digital twin model. The facility physical model describes the physical structure and geometric features of the facilities, while the data-driven model depicts the operation behavior and dynamic characteristics of the facilities. By organically integrating the two, a digital twin model that is both physically realistic and can reflect the operation dynamics can be constructed in the virtual space, enabling the physical model and the data-driven model to be interrelated and interact with each other, forming a complete and unified virtual model, thus more accurately simulating the actual operation of the enterprise infrastructure group.

[0049] Finally, an asynchronous communication mechanism based on message queues can be adopted to synchronize the multi-source heterogeneous facility data to the digital twin model. A message queue is a middleware technology used to transfer messages between different systems. Under this mechanism, the multi-source heterogeneous facility data can be encapsulated into messages and sent to the message queue. Then, the digital twin model can obtain the messages from the message queue and process them to achieve data synchronization. The asynchronous communication method enables the sending and processing of data without real-time waiting, improving the throughput and response speed of the system. Moreover, this method can adapt to the large-scale and high-frequency acquisition and transmission requirements of multi-source heterogeneous facility data, ensuring that the digital twin model can obtain the latest facility operation data in a timely and accurate manner, thereby enabling real-time mapping of the actual operation state of the enterprise infrastructure group.

[0050] Identifying potential facility failures of the enterprise infrastructure group by using a fault identification integration algorithm based on the digital twin model specifically includes: The fault identification integrated algorithm integrates a support vector machine algorithm and a random forest algorithm. The support vector machine algorithm is used to identify potential linear faults corresponding to the enterprise infrastructure group, and the random forest algorithm is used to identify potential nonlinear faults corresponding to the enterprise infrastructure group. The potential linear faults and the potential nonlinear faults are summarized to generate the potential facility faults. Based on the digital twin model, simulate the occurrence process of the potential facility faults to generate a fault propagation path and a fault chain reaction. Construct a fault propagation model, and analyze the fault impact area of the potential facility faults according to the fault propagation path and the fault chain reaction.

[0051] Among them, the fault identification integrated algorithm integrates a support vector machine algorithm and a random forest algorithm, which are respectively used to identify potential linear faults and potential nonlinear faults, and summarize them to generate potential facility faults. Among them, the support vector machine algorithm is based on statistical learning theory and realizes the classification of linearly separable data by constructing an optimal hyperplane, and can effectively identify potential fault modes with linear characteristics in the enterprise infrastructure group. The random forest algorithm is an ensemble learning method composed of multiple decision trees. By synthesizing the prediction results of multiple decision trees, it can handle complex nonlinear relationships, so as to accurately identify potential faults presenting nonlinear characteristics in the enterprise infrastructure group. By integrating these two algorithms and giving full play to their advantages in dealing with linear and nonlinear faults, the operation data of the enterprise infrastructure group can be analyzed, various potential faults can be identified and summarized, and a comprehensive understanding of the potential facility faults can be formed.

[0052] Furthermore, the occurrence process of potential facility faults can be simulated based on the digital twin model to generate a fault propagation path and a fault chain reaction. The digital twin model is a real mapping of the enterprise infrastructure group in the virtual space, containing information such as the physical structure, operating parameters and mutual relationships of the facilities. Using the digital twin model, the identified potential facility faults are simulated. Starting from the initial occurrence point of the fault, according to the physical connection and logical relationship of the facilities, the development process of the fault is gradually deduced. During the simulation process, record the propagation trajectory of the fault in the enterprise infrastructure group to form a fault propagation path, and at the same time analyze the mutual influence between the facilities caused by the fault to generate a fault chain reaction, so as to clearly show the whole process of the potential facility faults from occurrence to development.

[0053] Finally, a fault propagation model can be constructed to analyze the fault impact area of potential facility faults based on the fault propagation path and fault chain reaction. The fault propagation model integrates relevant information on the fault propagation path and fault chain reaction to establish a mathematical model or logical model to describe the propagation characteristics of faults in the enterprise infrastructure group. Using this model, the impact range of potential facility faults can be analyzed to determine the range of facility locations that may be affected by the faults. By analyzing the fault impact area, the impact degree and range of potential facility faults on the operation of the enterprise infrastructure group can be understood, providing a basis for taking preventive measures in advance and formulating response strategies, so as to strengthen the monitoring and maintenance of the affected area targeted before the fault occurs and reduce the possibility and harm degree of the fault.

[0054] Through the above methods, based on the digital twin model and the fault identification integration algorithm, potential facility faults in the enterprise infrastructure group can be comprehensively and accurately identified, the fault occurrence process can be simulated, and the fault impact area can be analyzed, providing strong technical support for enterprise safety management and realizing early warning and effective prevention and control of potential faults in the enterprise infrastructure group.

[0055] Based on the reinforcement learning algorithm, an enterprise facility management strategy is generated according to the facility safety state and the potential facility fault and sent to the operation and maintenance terminal, specifically including: Encoding the facility safety state and the potential facility fault and converting them into a facility state vector corresponding to the reinforcement learning algorithm; Setting the action space and reward function corresponding to the reinforcement learning algorithm, where the action space is the candidate facility management strategy; Based on the reinforcement learning algorithm, according to the facility state vector and the reward function, select the enterprise facility management strategy from the candidate facility management strategies and send it to the operation and maintenance terminal.

[0056] It can be understood that the facility safety state and potential facility faults can be encoded and processed and converted into a facility state vector recognizable by the reinforcement learning algorithm. In this process, specific encoding rules need to be used for digital representation of various safety state parameters collected during the facility operation process and potential fault types determined by the fault prediction model. By quantifying the multi-dimensional parameters of the facility safety state and the characteristic attributes of potential faults, a state space that can comprehensively reflect the current situation of the facility is constructed, and then a facility state vector that meets the input requirements of the reinforcement learning algorithm is formed, providing a data basis for subsequent strategy generation.

[0057] Secondly, the action space and reward function corresponding to the reinforcement learning algorithm can be set. Among them, the action space is the set of candidate facility management strategies. In terms of constructing the action space, various possible operations of facility management need to be comprehensively considered, including but not limited to equipment maintenance, component replacement, operating parameter adjustment, etc., and these specific management operations are defined in a standardized manner to form a series of discrete action options, constituting the set of candidate facility management strategies. The design of the reward function needs to be closely centered around the goals of facility management. Usually, based on indicators such as the safety, reliability, and economy of facility operation, a mapping relationship between actions and rewards is established to measure the improvement effect of different management strategies on the facility state.

[0058] Finally, based on the reinforcement learning algorithm, according to the facility state vector and the reward function, the optimal enterprise facility management strategy can be selected from the candidate facility management strategies and sent to the operation and maintenance end. The reinforcement learning algorithm continuously interacts with the environment, uses the facility state vector as input, tries different candidate strategies in the action space, and learns according to the feedback signal obtained from the reward function. Through the iterative optimization process, this algorithm can screen out the enterprise facility management strategy that is most suitable for the current facility condition from the candidate facility management strategies to obtain the maximum cumulative reward, and send the selected strategy to the operation and maintenance end to guide the actual facility operation and maintenance work.

[0059] In the whole process, through the encoding process of the facility safety state and potential faults, the digital expression of the facility operation condition is realized; through the setting of the action space and the reward function, an evaluation system for facility management strategies is constructed; and the application of the reinforcement learning algorithm realizes the intelligent mapping from the facility state to the optimal management strategy, so that the management strategy can be dynamically adjusted according to the real-time state of the facility, improving the intelligent level and decision-making efficiency of facility management, and ensuring the safe, reliable, and economic operation of enterprise facilities.

[0060] As Figure 2 shown, it is a system block diagram of an enterprise safety condition instant evaluation management system provided by an embodiment of the present invention. The system includes: A monitoring and acquisition module, which is used to collect multi-source heterogeneous facility data through the monitoring sensor network of the enterprise infrastructure group and perform preprocessing; An extraction and evaluation module, which is used to extract multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes and evaluate the facility safety state of the enterprise infrastructure group by using a state evaluation combination algorithm; A construction and recognition module, which is used to construct a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data and identify potential facility faults of the enterprise infrastructure group by using a fault recognition integration algorithm based on the digital twin model; A solution determination module, configured to generate an enterprise facility management strategy based on a reinforcement learning algorithm according to the facility safety status and the potential facility failures, and send the strategy to an operation and maintenance terminal.

[0061] Figure 2 The device of the illustrated embodiment can correspondingly be used to execute Figure 1 the steps in the illustrated method embodiment, and the implementation principles and technical effects are similar, which will not be elaborated here.

[0062] An electronic device includes a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the steps of an enterprise security status instant evaluation and management method as described in any one of the above.

[0063] As Figure 3 shown, it is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present invention. The electronic device 30 includes: a processor 31, a memory 32, and a computer program; wherein The memory 32 is used to store the computer program, and the memory can also be a flash memory. The computer program is, for example, an application program or a functional module for implementing the above method.

[0064] The processor 31 is used to execute the computer program stored in the memory to implement each step executed by the device in the above method. Specifically, reference can be made to the relevant descriptions in the foregoing method embodiments.

[0065] Optionally, the memory 32 can be either independent or integrated with the processor 31.

[0066] When the memory 32 is a device independent of the processor 31, the device may further include: A bus 33, configured to connect the memory 32 and the processor 31.

[0067] A readable storage medium stores a computer program, and when the computer program is executed by a processor, it is used to implement the steps of an enterprise security status instant evaluation and management method as described in any one of the above.

[0068] Among them, the readable storage medium can be a computer storage medium or a communication medium. The communication medium includes any medium that facilitates the transfer of a computer program from one place to another. The computer storage medium can be any available medium accessible by a general or special purpose computer. For example, the readable storage medium is coupled to the processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Additionally, the ASIC can be located in a user device. Of course, the processor and the readable storage medium can also exist as discrete components in a communication device. The readable storage medium can be a read only memory (ROM), a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0069] The present invention also provides a program product, which includes execution instructions stored in a readable storage medium. At least one processor of the device can read the execution instructions from the readable storage medium, and the execution of the execution instructions by at least one processor enables the device to implement the methods provided by the above various embodiments.

[0070] In the embodiments of the above device, it should be understood that the processor can be a central processing unit (CPU for short), and can also be other general purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the present invention can be directly embodied as being completed by the execution of a hardware processor, or by a combination of hardware and software modules in the processor.

[0071] Through the introduction of the above embodiments, the present invention provides an enterprise security status real-time evaluation management method and system. Through the monitoring sensor network of the enterprise infrastructure group, multi-source heterogeneous facility data is collected and preprocessed; through the edge computing nodes, multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data are extracted, and a state evaluation combination algorithm is used to evaluate the facility security status of the enterprise infrastructure group; a digital twin model of the enterprise infrastructure group is constructed based on the multi-source heterogeneous facility data, and a fault identification integration algorithm is used based on the digital twin model to identify potential facility faults in the enterprise infrastructure group; based on the reinforcement learning algorithm, enterprise facility management strategies are generated according to the facility security status and potential facility faults and sent to the operation and maintenance end, so as to comprehensively, real-time and accurately evaluate the security status of the enterprise infrastructure, and intelligent enterprise facility management strategies can be formulated to improve the enterprise security management level.

[0072] Through the monitoring sensor network and the batch-by-batch collection strategy, the present invention can comprehensively and timely collect multi-source heterogeneous data of the enterprise infrastructure, ensuring the accuracy and real-time nature of the data; the present invention can efficiently process multi-source heterogeneous data by using edge computing nodes and feature extraction technologies, extract effective time-domain and frequency-domain features, laying a foundation for accurately evaluating the facility security status; the digital twin model constructed by the present invention can truly reflect the physical structure and operating state of the enterprise infrastructure group. Combined with the fault identification integration algorithm, it realizes the accurate identification and prediction of potential facility faults, and can simulate the occurrence process and impact area of the faults, providing a basis for taking preventive measures in advance; the enterprise facility management strategy generated by the present invention based on the reinforcement learning algorithm is intelligent and targeted, and can adjust the management strategy in a timely manner according to the security status and potential faults of the facilities, improving the efficiency and effectiveness of enterprise security management.

[0073] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. An instant evaluation management method for enterprise security status, characterized in that, The method includes: Collecting multi-source heterogeneous facility data through the monitoring sensor network of the enterprise infrastructure group and performing preprocessing; Extracting multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes, and evaluating the facility security status of the enterprise infrastructure group by using a state evaluation combination algorithm; Constructing a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data, and identifying potential facility faults of the enterprise infrastructure group by using a fault identification integration algorithm based on the digital twin model; Generating an enterprise facility management strategy according to the facility security status and the potential facility faults based on a reinforcement learning algorithm and sending it to the operation and maintenance end.

2. The instant evaluation management method for enterprise security status according to claim 1, characterized in that, Based on the actual monitoring requirements of the enterprise infrastructure group, setting multiple key monitoring nodes on the enterprise infrastructure group, and installing a monitoring sensor on each of the key monitoring nodes, and aggregating all the monitoring sensors to generate the monitoring sensor network; The acquisition process of the multi-source heterogeneous facility data adopts a batch acquisition strategy, that is, determining the acquisition frequency of the corresponding monitoring sensor according to the change frequency of the multi-source heterogeneous facility data.

3. The instant evaluation management method for enterprise security status according to claim 1, characterized in that, The extracting multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes, and evaluating the facility security status of the enterprise infrastructure group by using a state evaluation combination algorithm specifically includes: The edge computing node adopts a multi-core processor with an ARM architecture; Through the edge computing node, extracting time-domain and frequency-domain features corresponding to the multi-source heterogeneous facility data based on the short-time Fourier transform technology, that is, the multi-source heterogeneous facility features; The state evaluation combination algorithm is a combination of a long short-term memory network algorithm and a convolutional neural network algorithm. The long short-term memory network algorithm is used to evaluate the facility time state of the multi-source heterogeneous facility features, and the convolutional neural network algorithm is used to evaluate the facility space state of the multi-source heterogeneous facility features, and aggregating the facility time state and the facility space state to generate the facility security state.

4. The instant evaluation management method for enterprise security status according to claim 1, wherein, The constructing a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data specifically includes: Constructing a facility physical model of the enterprise infrastructure group based on the facility physical structure data in the multi-source heterogeneous facility data; Constructing a data-driven model of the enterprise infrastructure group based on the facility operation parameter data in the multi-source heterogeneous facility data; Fusing the facility physical model and the data-driven model to generate the digital twin model; Adopting an asynchronous communication mechanism based on a message queue to synchronize the multi-source heterogeneous facility data to the digital twin model.

5. The instant evaluation management method for enterprise security status according to claim 1, wherein The identifying potential facility faults of the enterprise infrastructure group by using a fault identification integration algorithm based on the digital twin model specifically includes: The fault identification integration algorithm integrates the support vector machine algorithm and the random forest algorithm. The support vector machine algorithm is used to identify potential linear faults corresponding to the enterprise infrastructure group, and the random forest algorithm is used to identify potential nonlinear faults corresponding to the enterprise infrastructure group. The potential linear faults and the potential nonlinear faults are summarized to generate the potential facility faults. Based on the digital twin model, simulate the occurrence process of the potential facility faults to generate fault propagation paths and fault chain reactions. Construct a fault propagation model, and analyze the fault impact area of the potential facility faults according to the fault propagation paths and the fault chain reactions.

6. The instant evaluation management method for enterprise security status according to claim 1, wherein Based on the reinforcement learning algorithm, generate an enterprise facility management strategy according to the facility safety state and the potential facility faults and send it to the operation and maintenance side. Specifically, it includes: Encode the facility safety state and the potential facility faults and convert them into a facility state vector corresponding to the reinforcement learning algorithm. Set the action space and the reward function corresponding to the reinforcement learning algorithm. The action space is the candidate facility management strategy. Based on the reinforcement learning algorithm, select the enterprise facility management strategy from the candidate facility management strategies according to the facility state vector and the reward function and send it to the operation and maintenance side.

7. An enterprise security status instant evaluation management system, which is applied to an enterprise security status instant evaluation management method as described in any one of claims 1-6, and is characterized in that, The system includes: A monitoring and acquisition module, which is used to collect multi-source heterogeneous facility data through the monitoring sensor network of the enterprise infrastructure group and perform preprocessing. An extraction and evaluation module, which is used to extract multi-source heterogeneous facility features corresponding to the multi-source heterogeneous facility data through edge computing nodes and evaluate the facility safety state of the enterprise infrastructure group by using a state evaluation combination algorithm. A construction and identification module, which is used to construct a digital twin model of the enterprise infrastructure group based on the multi-source heterogeneous facility data, and identify potential facility faults of the enterprise infrastructure group by using a fault identification integration algorithm based on the digital twin model. A solution determination module, which is used to generate an enterprise facility management strategy according to the facility safety state and the potential facility faults based on the reinforcement learning algorithm and send it to the operation and maintenance side.

8. An electronic device, comprising a memory and a processor, wherein a computer program is stored in the memory, characterized in that, When the processor runs the computer program stored in the memory, the processor executes the steps of an enterprise safety condition instant evaluation and management method according to any one of claims 1-6.

9. A readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it is used to implement the steps of an enterprise safety condition instant evaluation and management method according to any one of claims 1-6.