Equipment operation and maintenance management method and system based on multi-layer authority control
By combining the multi-layer permission control method of historical access database and prediction model, the problem of insufficient access control accuracy in device access management is solved, and higher accuracy and security are achieved, reducing the occurrence of equipment security accidents.
Patent Information
- Application Number
- CN202510600551.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-05-12
AI Technical Summary
The prior art lacks the ability to dynamic analysis of historical access data and predict task information in device access management, resulting in insufficient accuracy of access control and prone to misauthorization or security accidents.
By obtaining the access control request of the target user, determining the user's access rights in combination with the preset historical access database, and using the prediction model to predict task information based on the device data, and determining the access control request's permission based on the access rights and task information according to the preset judgment rules.
Accurate access control based on user permissions and task prediction is realized, which improves the accuracy and security of target device access management and reduces device security accidents.
Smart Images

Figure CN120474769A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a device operation and maintenance management method and system based on multi-layer authority control. Background Art
[0002] With the growing demand for device access management security, more and more industries are beginning to focus on precise control of target device access requests to ensure system security. Existing technologies usually obtain user access requests to devices, combine static permission databases or simple authentication methods to determine user access rights, and process access control requests based on fixed rules to maintain the security of device operations. Existing solutions lack the ability to dynamically analyze historical access data and predict task information, making it difficult to accurately judge the legitimacy and task relevance of user requests. Commonly used unified or overly simplified judgment rules cannot adapt to complex access scenarios, resulting in insufficient access control accuracy, easily leading to misauthorization or security incidents, and limiting the security and reliability of device access management. It can be seen that the existing technology has defects that need to be addressed urgently. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a device operation and maintenance management method and system based on multi-layer authority control, which can realize precise access control based on user authority and task prediction, improve the accuracy and security of target device access management, and reduce equipment safety accidents.
[0004] In order to solve the above technical problems, the first aspect of the present invention discloses a device operation and maintenance management method based on multi-layer authority control, the method comprising: Obtain the target user's access control request to the target device; Determining the user access rights corresponding to the target user based on a preset historical access database; Based on the prediction model, predicting task information corresponding to the access control request according to the device data of the target device and the access control request; According to the user access rights and the task information, based on preset access determination rules, the permission of the access control request is determined.
[0005] As an optional implementation manner, in the first aspect of the present invention, determining the user access rights corresponding to the target user based on a preset historical access database includes: Determining multiple historical access data identical or similar to the target user in a preset historical access database; Calculating a weighted average of the access levels corresponding to all the historical access data to obtain an access level parameter; The user access rights corresponding to the target user are determined according to the corresponding relationship between the preset access level and the access rights, and the access level parameter.
[0006] As an optional implementation manner, in the first aspect of the present invention, determining a plurality of historical access data identical or similar to the target user in a preset historical access database includes: For each access data record in a preset historical access database, obtaining relevant user information corresponding to the access data record; the relevant user information includes at least one of a sending user, a receiving user, an auditing user, and a supervising user; Calculating user similarity between the relevant user information and the user information of the target user; The access data records whose user similarity is greater than a preset similarity threshold are screened out to obtain a plurality of historical access data that are identical or similar to the target user.
[0007] As an optional embodiment, in the first aspect of the present invention, when calculating the weighted average of the access levels corresponding to all the historical access data, the calculation weight corresponding to each access level includes a first weight and a second weight; the first weight is proportional to the data completeness of the corresponding historical access data; the data completeness is obtained by inputting the historical access data into a trained completeness prediction model; the second weight is proportional to the user similarity corresponding to the corresponding historical access data.
[0008] As an optional embodiment, in the first aspect of the present invention, the target device is an energy production device; the energy production device is a solar panel, a wind turbine, a nuclear reactor, a water turbine, a geothermal pump, a coal-fired furnace, a gas turbine or a biomass furnace.
[0009] As an optional embodiment, in the first aspect of the present invention, predicting the task information corresponding to the access control request based on the device data of the target device and the access control request based on the prediction model includes: Obtaining device configuration parameters and historical energy production data corresponding to the target device; determining a plurality of historical operation data related to the access control request from the historical energy production operation data; All the historical work data, the device configuration parameters and the access control request are input into a trained task prediction neural network to obtain the task information corresponding to the access control request; the task prediction neural network is trained by a training data set including multiple training historical work data and corresponding device parameter annotations, access control request annotations and work task annotations.
[0010] As an optional embodiment, in the first aspect of the present invention, the time similarity between the working time point corresponding to the historical work data and the request time point corresponding to the access control request is greater than a preset second similarity threshold; the time similarity is the sum of the time difference and the time period type similarity; the time difference is the time difference between the working time point and the request time point; the time period type similarity is the similarity between the time type data corresponding to the working time point and the request time point respectively; the time type data includes one or more of the date type, holiday type, month type, season type and working time period type to which the time point belongs.
[0011] As an optional embodiment, in the first aspect of the present invention, determining whether to approve the access control request based on the user access rights and the task information and a preset access determination rule includes: Determine the user authority limit corresponding to the task information based on the correspondence between the preset tasks and authority thresholds; Determine whether the user access rights meet the user authority restrictions, and obtain a determination result; When the judgment result is yes, determining that the access control request is allowed to pass; When the judgment result is no, it is determined that the access control request is not allowed to pass.
[0012] A second aspect of an embodiment of the present invention discloses a device operation and maintenance management system based on multi-layer authority control, the system comprising: An acquisition module is used to obtain the access control request of the target user to the target device; A determination module, configured to determine the user access rights corresponding to the target user based on a preset historical access database; a prediction module, configured to predict task information corresponding to the access control request based on a prediction model and according to device data of the target device and the access control request; The judgment module is used to determine whether the access control request is allowed according to the user access rights and the task information based on preset access judgment rules.
[0013] As an optional implementation, in the second aspect of the present invention, the specific manner in which the determination module determines the user access rights corresponding to the target user based on a preset historical access database includes: Determining multiple historical access data identical or similar to the target user in a preset historical access database; Calculating a weighted average of the access levels corresponding to all the historical access data to obtain an access level parameter; The user access rights corresponding to the target user are determined according to the corresponding relationship between the preset access level and the access rights, and the access level parameter.
[0014] As an optional embodiment, in the second aspect of the present invention, the specific manner in which the determining module determines, in a preset historical access database, a plurality of historical access data identical or similar to the target user, includes: For each access data record in a preset historical access database, obtaining relevant user information corresponding to the access data record; the relevant user information includes at least one of a sending user, a receiving user, an auditing user, and a supervising user; Calculating user similarity between the relevant user information and the user information of the target user; The access data records whose user similarity is greater than a preset similarity threshold are screened out to obtain a plurality of historical access data that are identical or similar to the target user.
[0015] As an optional embodiment, in the second aspect of the present invention, when calculating the weighted average of the access levels corresponding to all the historical access data, the calculation weight corresponding to each access level includes a first weight and a second weight; the first weight is proportional to the data completeness of the corresponding historical access data; the data completeness is obtained by inputting the historical access data into a trained completeness prediction model; the second weight is proportional to the user similarity corresponding to the corresponding historical access data.
[0016] As an optional embodiment, in the second aspect of the present invention, the target device is an energy production device; the energy production equipment is a solar panel, a wind turbine, a nuclear reactor, a water turbine, a geothermal pump, a coal-fired furnace, a gas turbine or a biomass furnace.
[0017] As an optional embodiment, in the second aspect of the present invention, the prediction module predicts the task information corresponding to the access control request based on the prediction model and the device data of the target device and the access control request, including: Obtaining device configuration parameters and historical energy production data corresponding to the target device; determining a plurality of historical operation data related to the access control request from the historical energy production operation data; All the historical work data, the device configuration parameters and the access control request are input into a trained task prediction neural network to obtain the task information corresponding to the access control request; the task prediction neural network is trained by a training data set including multiple training historical work data and corresponding device parameter annotations, access control request annotations and work task annotations.
[0018] As an optional embodiment, in the second aspect of the present invention, the time similarity between the working time point corresponding to the historical work data and the request time point corresponding to the access control request is greater than a preset second similarity threshold; the time similarity is the sum of the time difference and the time period type similarity; the time difference is the time difference between the working time point and the request time point; the time period type similarity is the similarity between the time type data corresponding to the working time point and the request time point respectively; the time type data includes one or more of the date type, holiday type, month type, season type and working time period type to which the time point belongs.
[0019] As an optional embodiment, in the second aspect of the present invention, the determination module determines, based on the user access rights and the task information and a preset access determination rule, a specific manner of approving the access control request, including: Determine the user authority limit corresponding to the task information based on the correspondence between the preset tasks and authority thresholds; Determine whether the user access rights meet the user authority restrictions, and obtain a determination result; When the judgment result is yes, determining that the access control request is allowed to pass; When the judgment result is no, it is determined that the access control request is not allowed to pass.
[0020] A third aspect of the present invention discloses another device operation and maintenance management system based on multi-layer authority control, the system comprising: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute part or all of the steps in the device operation and maintenance management method based on multi-layer authority control disclosed in the first aspect of the present invention.
[0021] The fourth aspect of the present invention discloses a computer storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute some or all of the steps in the device operation and maintenance management method based on multi-layer authority control disclosed in the first aspect of the present invention.
[0022] Compared with the prior art, the embodiments of the present invention have the following beneficial effects: The present invention obtains the target user's access control request for the target device and determines the user's access rights in combination with a preset historical access database. At the same time, it uses a prediction model to predict task information based on device data and requests, and determines the approval of the access control request according to preset judgment rules based on the access rights and task information. This can achieve precise access control based on user rights and task predictions, improve the accuracy and security of target device access management, and reduce device safety accidents. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 This is a flow chart of a device operation and maintenance management method based on multi-layer authority control disclosed in an embodiment of the present invention.
[0025] Figure 2 This is a structural diagram of a device operation and maintenance management system based on multi-layer authority control disclosed in an embodiment of the present invention.
[0026] Figure 3 This is a structural diagram of another device operation and maintenance management system based on multi-layer authority control disclosed in an embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0028] The terms "first," "second," and so on, in the description and claims of the present invention and the accompanying drawings are used to distinguish between different objects, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or device.
[0029] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0030] The present invention discloses a device operation and maintenance management method and system based on multi-layer permission control. This method obtains the target user's access control request for the target device and determines the user's access rights in combination with a preset historical access database. Furthermore, a prediction model is used to predict task information based on device data and requests. Based on the access rights and task information, the approval of the access control request is determined according to preset judgment rules. This method achieves precise access control based on user permissions and task predictions, improves the accuracy and security of target device access management, and reduces device safety incidents. These are described in detail below.
[0031] Example 1 See also Figure 1 , Figure 1 This is a flow chart of a device operation and maintenance management method based on multi-layer authority control disclosed in an embodiment of the present invention. Figure 1 The device operation and maintenance management method based on multi-layer authority control described above can be applied to a data processing system / data processing device / data processing server (wherein the server includes a local processing server or a cloud processing server). Figure 1 As shown, the device operation and maintenance management method based on multi-layer authority control may include the following operations: 101. Obtain an access control request from a target user to a target device.
[0032] 102. Determine the user access rights corresponding to the target user based on a preset historical access database. 103. Based on the prediction model, predict task information corresponding to the access control request according to the device data of the target device and the access control request. 104. Determine whether the access control request is allowed based on the user access rights and task information and preset access determination rules.
[0033] It can be seen that the above-mentioned embodiment of the invention obtains the target user's access control request for the target device and determines the user's access rights in combination with the preset historical access database. At the same time, it uses the prediction model to predict task information based on device data and requests, and determines the approval of the access control request according to the preset judgment rules based on the access rights and task information. It can thus achieve precise access control based on user rights and task predictions, improve the accuracy and security of target device access management, and reduce equipment safety accidents.
[0034] As an optional embodiment, in the above step, determining the user access rights corresponding to the target user based on a preset historical access database includes: Determine multiple historical access data identical or similar to the target user in a preset historical access database; Calculate the weighted average of the access levels corresponding to all historical access data to obtain the access level parameter; The user access rights corresponding to the target user are determined based on the correspondence between the preset access level and the access rights, as well as the access level parameters.
[0035] It can be seen that through the above optional embodiments, the access level parameters are obtained by screening out historical access data that is identical or similar to the target user in the preset historical access database and calculating the weighted average of its access level. The access rights of the target user are determined based on the correspondence between the preset access level and the permission, thereby realizing accurate permission determination based on historical access behavior, assisting in realizing accurate access control based on user permissions and task predictions, improving the accuracy and security of target device access management, and reducing equipment safety accidents.
[0036] As an optional embodiment, in the above step, determining multiple historical access data identical or similar to the target user in a preset historical access database includes: For each access data record in a preset historical access database, obtain relevant user information corresponding to the access data record; optionally, the relevant user information includes at least one of a sending user, a receiving user, an auditing user, and a supervising user; Calculate the user similarity between the relevant user information and the target user's user information; The access data records with user similarity greater than a preset similarity threshold are screened out to obtain multiple historical access data that are the same or similar to the target user.
[0037] It can be seen that through the above optional embodiments, by analyzing the relevant user information of each access data record in the preset historical access database and calculating its similarity with the user information of the target user, records with a similarity exceeding the threshold are screened out as historical access data that are the same or similar to the target user, thereby realizing accurate historical data screening based on multi-dimensional user information comparison, improving the accuracy of target user access permission assessment, assisting in realizing accurate access control based on user authority and task prediction, improving the accuracy and security of target device access management, and reducing equipment safety accidents.
[0038] As an optional embodiment, in the above steps, when calculating the weighted average of the access levels corresponding to all historical access data, the calculation weight corresponding to each access level includes a first weight and a second weight; the first weight is proportional to the data completeness of the corresponding historical access data; the data completeness is obtained by inputting the historical access data into a trained completeness prediction model; the second weight is proportional to the user similarity corresponding to the corresponding historical access data.
[0039] It can be seen that through the above optional embodiments, by limiting the weight to be composed of a first weight proportional to the data integrity and a second weight proportional to the user similarity, the target user access rights are determined, thereby achieving accurate permission determination based on data integrity and user similarity, assisting in achieving accurate access control based on user permissions and task predictions, improving the accuracy and security of target device access management, and reducing device safety incidents.
[0040] As an optional embodiment, in the above steps, the target device is an energy production device; the energy production device is a solar panel, a wind turbine, a nuclear reactor, a water turbine, a geothermal pump, a coal-fired furnace, a gas turbine or a biomass furnace.
[0041] It can be seen that through the above optional embodiments, the device type of the target device is limited to effectively characterize the device characteristics, assist in achieving precise access control based on user permissions and task predictions, improve the accuracy and security of target device access management, and reduce device safety accidents.
[0042] As an optional embodiment, in the above step, predicting the task information corresponding to the access control request based on the prediction model and the device data of the target device and the access control request includes: Obtain device configuration parameters and historical energy production data corresponding to the target device; determining a plurality of historical work data related to the access control request in the historical energy production work data; All historical work data, device configuration parameters and access control requests are input into the trained task prediction neural network to obtain the task information corresponding to the access control request; the task prediction neural network is trained through a training data set including multiple training historical work data and corresponding device parameter annotations, access control request annotations and work task annotations.
[0043] It can be seen that through the above optional embodiments, by obtaining the device configuration parameters and historical energy production work data of the target device and filtering out the historical work data related to the access control request, it is input together with the device configuration parameters and the request into the trained task prediction neural network to determine the task information of the access control request, thereby achieving accurate task prediction based on device parameters and historical work data, and improving the accuracy of access control decisions and the security management efficiency of the target device energy production tasks.
[0044] As an optional embodiment, in the above steps, the time similarity between the working time point corresponding to the historical work data and the request time point corresponding to the access control request is greater than a preset second similarity threshold; the time similarity is the sum of the time difference and the time period type similarity; the time difference is the time difference between the working time point and the request time point; the time period type similarity is the similarity between the time type data corresponding to the working time point and the request time point respectively; the time type data includes one or more of the date type, holiday type, month type, season type and working time period type to which the time point belongs.
[0045] It can be seen that through the above optional embodiments, the details of screening relevant historical work data are limited so that more time-related work data can be used for task prediction, thereby achieving accurate task prediction based on multi-dimensional time similarity and equipment data, and improving the accuracy of access control decisions and the efficiency of energy production equipment safety management.
[0046] As an optional embodiment, in the above steps, determining whether to approve the access control request based on the user access rights and task information and preset access determination rules includes: Determine the user authority restrictions corresponding to the task information based on the preset correspondence between tasks and authority thresholds; Determine whether the user access rights meet the user permission restrictions and obtain the judgment result; When the judgment result is yes, determining that the access control request is allowed to pass; When the judgment result is no, it is determined that the access control request is not allowed to pass.
[0047] It can be seen that through the above optional embodiments, the user authority restriction corresponding to the task information is determined based on the correspondence between the preset task and the authority threshold and it is judged whether the user access rights meet the restriction. If it meets the restriction, the access control request is allowed to pass, otherwise it is rejected, thereby realizing precise access control based on task authority matching, improving the accuracy and security of target device access management, and reducing the energy production risks caused by unauthorized access.
[0048] Example 2 See also Figure 2 , Figure 2 This is a schematic diagram of the structure of a device operation and maintenance management system based on multi-layer authority control disclosed in an embodiment of the present invention. Figure 2 The device operation and maintenance management system based on multi-layer authority control described above can be applied to data processing systems / data processing devices / data processing servers (wherein the server includes a local processing server or a cloud processing server). Figure 2 As shown, the equipment operation and maintenance management system based on multi-layer authority control may include: The acquisition module 201 is configured to acquire an access control request from a target user to a target device.
[0049] The determination module 202 is configured to determine the user access rights corresponding to the target user based on a preset historical access database. The prediction module 203 is configured to predict task information corresponding to the access control request based on the prediction model and the device data of the target device and the access control request. The judgment module 204 is configured to determine whether the access control request is allowed based on the user access rights and task information and preset access judgment rules.
[0050] It can be seen that the above-mentioned embodiment of the invention obtains the target user's access control request for the target device and determines the user's access rights in combination with the preset historical access database. At the same time, it uses the prediction model to predict task information based on device data and requests, and determines the approval of the access control request according to the preset judgment rules based on the access rights and task information. It can thus achieve precise access control based on user rights and task predictions, improve the accuracy and security of target device access management, and reduce equipment safety accidents.
[0051] As an optional embodiment, the specific manner in which the determination module determines the user access rights corresponding to the target user based on a preset historical access database includes: Determine multiple historical access data identical or similar to the target user in a preset historical access database; Calculate the weighted average of the access levels corresponding to all historical access data to obtain the access level parameter; The user access rights corresponding to the target user are determined based on the correspondence between the preset access level and the access rights, as well as the access level parameters.
[0052] It can be seen that through the above optional embodiments, the access level parameters are obtained by screening out historical access data that is identical or similar to the target user in the preset historical access database and calculating the weighted average of its access level. The access rights of the target user are determined based on the correspondence between the preset access level and the permission, thereby realizing accurate permission determination based on historical access behavior, assisting in realizing accurate access control based on user permissions and task predictions, improving the accuracy and security of target device access management, and reducing equipment safety accidents.
[0053] As an optional embodiment, the specific manner in which the determination module determines multiple historical access data identical or similar to the target user in a preset historical access database includes: For each access data record in a preset historical access database, obtain relevant user information corresponding to the access data record; optionally, the relevant user information includes at least one of a sending user, a receiving user, an auditing user, and a supervising user; Calculate the user similarity between the relevant user information and the target user's user information; The access data records with user similarity greater than a preset similarity threshold are screened out to obtain multiple historical access data that are the same or similar to the target user.
[0054] It can be seen that through the above optional embodiments, by analyzing the relevant user information of each access data record in the preset historical access database and calculating its similarity with the user information of the target user, records with a similarity exceeding the threshold are screened out as historical access data that are the same or similar to the target user, thereby realizing accurate historical data screening based on multi-dimensional user information comparison, improving the accuracy of target user access permission assessment, assisting in realizing accurate access control based on user authority and task prediction, improving the accuracy and security of target device access management, and reducing equipment safety accidents.
[0055] As an optional embodiment, when calculating the weighted average of the access levels corresponding to all historical access data, the calculation weight corresponding to each access level includes a first weight and a second weight; the first weight is proportional to the data completeness of the corresponding historical access data; the data completeness is obtained by inputting the historical access data into a trained completeness prediction model; the second weight is proportional to the user similarity corresponding to the corresponding historical access data.
[0056] It can be seen that through the above optional embodiments, by limiting the weight to be composed of a first weight proportional to the data integrity and a second weight proportional to the user similarity, the target user access rights are determined, thereby achieving accurate permission determination based on data integrity and user similarity, assisting in achieving accurate access control based on user permissions and task predictions, improving the accuracy and security of target device access management, and reducing device safety incidents.
[0057] As an optional embodiment, the target device is an energy production device; the energy production device is a solar panel, a wind turbine, a nuclear reactor, a water turbine, a geothermal pump, a coal-fired furnace, a gas turbine or a biomass furnace.
[0058] It can be seen that through the above optional embodiments, the device type of the target device is limited to effectively characterize the device characteristics, assist in achieving precise access control based on user permissions and task predictions, improve the accuracy and security of target device access management, and reduce device safety accidents.
[0059] As an optional embodiment, the prediction module predicts the task information corresponding to the access control request based on the prediction model and the device data of the target device and the access control request, including: Obtain device configuration parameters and historical energy production data corresponding to the target device; determining a plurality of historical work data related to the access control request in the historical energy production work data; All historical work data, device configuration parameters and access control requests are input into the trained task prediction neural network to obtain the task information corresponding to the access control request; the task prediction neural network is trained through a training data set including multiple training historical work data and corresponding device parameter annotations, access control request annotations and work task annotations.
[0060] It can be seen that through the above optional embodiments, by obtaining the device configuration parameters and historical energy production work data of the target device and filtering out the historical work data related to the access control request, it is input together with the device configuration parameters and the request into the trained task prediction neural network to determine the task information of the access control request, thereby achieving accurate task prediction based on device parameters and historical work data, and improving the accuracy of access control decisions and the security management efficiency of the target device energy production tasks.
[0061] As an optional embodiment, the time similarity between the working time point corresponding to the historical work data and the request time point corresponding to the access control request is greater than a preset second similarity threshold; the time similarity is the sum of the time difference and the time period type similarity; the time difference is the time difference between the working time point and the request time point; the time period type similarity is the similarity between the time type data corresponding to the working time point and the request time point respectively; the time type data includes one or more of the date type, holiday type, month type, season type and working time period type to which the time point belongs.
[0062] It can be seen that through the above optional embodiments, the details of screening relevant historical work data are limited so that more time-related work data can be used for task prediction, thereby achieving accurate task prediction based on multi-dimensional time similarity and equipment data, and improving the accuracy of access control decisions and the efficiency of energy production equipment safety management.
[0063] As an optional embodiment, the judgment module determines the specific method of approving the access control request based on the user access rights and task information and preset access judgment rules, including: Determine the user authority restrictions corresponding to the task information based on the preset correspondence between tasks and authority thresholds; Determine whether the user access rights meet the user permission restrictions and obtain the judgment result; When the judgment result is yes, determining that the access control request is allowed to pass; When the judgment result is no, it is determined that the access control request is not allowed to pass.
[0064] It can be seen that through the above optional embodiments, the user authority restriction corresponding to the task information is determined based on the correspondence between the preset task and the authority threshold and it is judged whether the user access rights meet the restriction. If it meets the restriction, the access control request is allowed to pass, otherwise it is rejected, thereby realizing precise access control based on task authority matching, improving the accuracy and security of target device access management, and reducing the energy production risks caused by unauthorized access.
[0065] Example 3 See also Figure 3 , Figure 3 This is another device operation and maintenance management system based on multi-layer authority control disclosed in an embodiment of the present invention. Figure 3 The device operation and maintenance management system based on multi-layer authority control is applied to a data processing system / data processing device / data processing server (wherein the server includes a local processing server or a cloud processing server). Figure 3 As shown, the equipment operation and maintenance management system based on multi-layer authority control may include: A memory 301 storing executable program code; a processor 302 coupled to the memory 301; The processor 302 calls the executable program code stored in the memory 301 to execute the steps of the device operation and maintenance management method based on multi-layer authority control described in the first embodiment.
[0066] Example 4 An embodiment of the present invention discloses a computer-readable storage medium storing a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps of the device operation and maintenance management method based on multi-layer authority control described in the first embodiment.
[0067] Example 5 An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps of the device operation and maintenance management method based on multi-layer authority control described in Example 1.
[0068] The foregoing description of specific embodiments of the present disclosure is intended to illustrate a method for performing a multi-tasking process. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0069] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0070] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0071] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, the embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0072] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0073] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0074] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0075] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0076] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0077] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0078] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0079] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0080] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0081] Finally, it should be noted that the device operation and maintenance management method and system based on multi-layer authority control disclosed in the embodiment of the present invention is only a preferred embodiment of the present invention, which is only used to illustrate the technical solution of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the aforementioned embodiments, ordinary technicians in this field should understand that it is still possible to modify the technical solutions recorded in the aforementioned embodiments, or to replace some of the technical features therein with equivalents; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A device operation and maintenance management method based on multi-layer authority control, characterized in that: The method comprises: Obtain the target user's access control request to the target device; Determining the user access rights corresponding to the target user based on a preset historical access database; Based on the prediction model, predicting task information corresponding to the access control request according to the device data of the target device and the access control request; According to the user access rights and the task information, based on preset access determination rules, the permission of the access control request is determined.
2. The device operation and maintenance management method based on multi-layer authority control according to claim 1 is characterized in that: The determining the user access rights corresponding to the target user based on a preset historical access database includes: Determining multiple historical access data identical or similar to the target user in a preset historical access database; Calculating a weighted average of the access levels corresponding to all the historical access data to obtain an access level parameter; The user access rights corresponding to the target user are determined according to the corresponding relationship between the preset access level and the access rights, and the access level parameter.
3. The device operation and maintenance management method based on multi-layer authority control according to claim 2 is characterized in that: The determining of a plurality of historical access data identical or similar to the target user in a preset historical access database includes: For each access data record in a preset historical access database, obtaining relevant user information corresponding to the access data record; the relevant user information includes at least one of a sending user, a receiving user, an auditing user, and a supervising user; Calculating user similarity between the relevant user information and the user information of the target user; The access data records whose user similarity is greater than a preset similarity threshold are screened out to obtain a plurality of historical access data that are identical or similar to the target user.
4. The device operation and maintenance management method based on multi-layer authority control according to claim 3 is characterized in that: When calculating the weighted average of the access levels corresponding to all the historical access data, the calculated weight corresponding to each access level includes a first weight and a second weight; the first weight is proportional to the data completeness of the corresponding historical access data; the data completeness is obtained by inputting the historical access data into a trained completeness prediction model; the second weight is proportional to the user similarity corresponding to the corresponding historical access data.
5. The device operation and maintenance management method based on multi-layer authority control according to claim 1 is characterized in that: The target device is an energy production device; the energy production device is a solar panel, a wind turbine, a nuclear reactor, a water turbine, a geothermal pump, a coal-fired furnace, a gas turbine or a biomass furnace.
6. The device operation and maintenance management method based on multi-layer authority control according to claim 5 is characterized in that: The predicting, based on the prediction model and according to the device data of the target device and the access control request, task information corresponding to the access control request includes: Obtaining device configuration parameters and historical energy production data corresponding to the target device; determining a plurality of historical operation data related to the access control request from the historical energy production operation data; All the historical work data, the device configuration parameters and the access control request are input into a trained task prediction neural network to obtain the task information corresponding to the access control request; the task prediction neural network is trained by a training data set including multiple training historical work data and corresponding device parameter annotations, access control request annotations and work task annotations.
7. The device operation and maintenance management method based on multi-layer authority control according to claim 6 is characterized in that: The time similarity between the working time point corresponding to the historical working data and the request time point corresponding to the access control request is greater than a preset second similarity threshold; the time similarity is the sum of the time difference and the time period type similarity; the time difference is the time difference between the working time point and the request time point; the time period type similarity is the similarity between the time type data corresponding to the working time point and the request time point respectively; the time type data includes one or more of the date type, holiday type, month type, season type and working time period type to which the time point belongs.
8. The device operation and maintenance management method based on multi-layer authority control according to claim 1 is characterized in that: The determining, based on the user access rights and the task information and a preset access determination rule, whether the access control request is permitted includes: Determine the user authority limit corresponding to the task information based on the correspondence between the preset tasks and authority thresholds; Determine whether the user access rights meet the user authority restrictions, and obtain a determination result; When the judgment result is yes, determining that the access control request is allowed to pass; When the judgment result is no, it is determined that the access control request is not allowed to pass.
9. A device operation and maintenance management system based on multi-layer authority control, characterized in that: The system comprises: An acquisition module is used to obtain the access control request of the target user to the target device; A determination module, configured to determine the user access rights corresponding to the target user based on a preset historical access database; a prediction module, configured to predict task information corresponding to the access control request based on a prediction model and according to device data of the target device and the access control request; The judgment module is used to determine whether the access control request is allowed according to the user access rights and the task information based on preset access judgment rules.
10. A device operation and maintenance management system based on multi-layer authority control, characterized in that: The system comprises: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the device operation and maintenance management method based on multi-layer authority control as described in any one of claims 1-8.
Citation Information
Patent Citations
Service access method and device, equipment and storage medium
CN113114674A
Data access control method and device for resource guarantee investment and electronic equipment
CN113641868A
Database management method and system based on cloud use records
CN117632905A
Network data security protection method and system based on big data
CN118631577A
Access control method and device, equipment, medium and program product
CN119939620A