Power network data-driven optimization method and system based on dynamic permission modeling

By using dynamic permission modeling and data-driven optimization mechanisms, user and device permission feature sets are generated and dynamically mapped to power resource allocation strategies. This solves the problem of the separation between permission management and resource scheduling in power networks, realizes the adaptability and risk resistance of power networks in complex environments, and improves the flexibility and security response capabilities of resource management.

CN120611901BActive Publication Date: 2026-05-05STATE GRID SHANDONG ELECTRIC POWER CO +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
STATE GRID SHANDONG ELECTRIC POWER CO
Filing Date
2025-05-27
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

The existing power network's access control mechanism and resource scheduling logic are disconnected, making it impossible to dynamically adjust according to real-time network status. This leads to access control overload or resource allocation conflicts. Furthermore, the existing resource allocation strategy lacks the ability to collaboratively model user behavior patterns and equipment operating status, making it difficult to quickly generate the optimal scheduling path when the topology changes dynamically. This fails to meet the dual requirements of security protection and resource optimization in high real-time scenarios.

Method used

By acquiring power network operation data, dynamic permission modeling is performed to generate user permission feature sets and device permission feature sets. By combining user permission features and device permission features for collaborative mapping, a dynamic power resource allocation strategy is generated, load balancing paths and device control priorities are optimized in real time, and permission configuration update operations are performed to ensure that the system actively adapts to changes in the power grid operating environment.

Benefits of technology

It enables the power network to adapt to complex operating environments and enhances its resilience and risk resistance, thereby improving the flexibility and security response of resource management. It can quickly match the optimal resource scheduling scheme in high-concurrency operation or sudden failure scenarios, prevent the risk of unauthorized operation, maintain the continuity of core business, and proactively adapt to changes in the power grid environment, thereby improving operational efficiency and security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120611901B_ABST
    Figure CN120611901B_ABST
Patent Text Reader

Abstract

This application relates to the field of data analysis technology, providing a data-driven optimization method and system for power networks based on dynamic permission modeling, to enhance the adaptability and resilience of power networks in complex operating environments. The method includes: acquiring a power network operation data set; performing dynamic permission modeling on the power network operation data set to generate user permission feature sets and device permission feature sets; generating a dynamic power resource allocation strategy based on the user permission feature sets and device permission feature sets; and feeding back the dynamic power resource allocation strategy to the power network control system to activate permission configuration update operations. Thus, through the deep coupling of the permission model and resource scheduling, a technical path that balances flexibility and reliability is provided for the intelligent upgrading of power systems, thereby improving the adaptability and resilience of power networks in complex operating environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data analysis technology, specifically relating to a data-driven optimization method and system for power networks based on dynamic permission modeling. Background Technology

[0002] With the expansion of power grids and the widespread integration of distributed energy resources, real-time identification and precise control of power system operating status have become core requirements for ensuring the safe and stable operation of the power grid. Traditional power network status identification technologies mainly rely on equipment sensor data acquisition and static topology analysis, using threshold alarms and preset rules to achieve anomaly detection and resource scheduling. However, in the new power system environment, the complexity of user-side interactions has surged, and equipment dynamic access is frequent, making it difficult for existing technologies to effectively cope with the real-time correlation analysis and dynamic decision-making requirements of multi-dimensional heterogeneous data.

[0003] Current technologies have the following limitations: First, the permission management mechanism and resource scheduling logic are disconnected. User operation permissions are usually set based on fixed role templates and cannot be dynamically adjusted according to real-time network conditions (such as load fluctuations and equipment failures), leading to permission overload or frequent resource allocation conflicts. Second, existing resource allocation strategies mostly rely on offline simulation or historical experience configuration, lacking the ability to collaboratively model user behavior patterns and equipment operating states, making it difficult to quickly generate optimal scheduling paths when the topology changes dynamically. Third, permission configuration updates lag behind changes in the power grid's operating state. Traditional batch update mechanisms result in excessively long policy effectiveness cycles, failing to meet the dual requirements of security protection and resource optimization in high real-time scenarios.

[0004] Therefore, existing technologies struggle to dynamically adapt user permissions, device resources, and network operating status, especially when dealing with sudden load shifts or security threats, easily leading to policy rigidity and response delays. Thus, there is an urgent need for a technical solution that can enhance the adaptability and resilience of power networks in complex operating environments. Summary of the Invention

[0005] This application provides a data-driven optimization method and system for power networks based on dynamic permission modeling, which can improve the adaptability and risk resistance of power networks in complex operating environments.

[0006] In a first aspect, embodiments of this application provide a power network data-driven optimization method based on dynamic permission modeling, applied to a power network data-driven optimization system. The method includes: acquiring a power network operation data set, the power network operation data set including real-time device status data, user operation behavior logs, and network topology connection relationships; performing dynamic permission modeling processing on the power network operation data set to generate a user permission feature set and a device permission feature set; the user permission feature set represents access control parameters for different user roles to power resources, and the device permission feature set represents resource allocation permissions of different power devices in the operating environment; generating a dynamic power resource allocation strategy based on the user permission feature set and the device permission feature set; the dynamic power resource allocation strategy is used to adjust the load balancing path and device control priority in the power network; and feeding back the dynamic power resource allocation strategy to the power network control system to activate a permission configuration update operation, the permission configuration update operation including adjusting the user operation permission range and the resource response rules of power devices.

[0007] Secondly, embodiments of this application provide a power network data-driven optimization system, which includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the above-described method.

[0008] Thirdly, embodiments of this application provide a computer-readable storage medium including a computer program. When the computer program is run on a power network data-driven optimization system, the computer program is used to cause the power network data-driven optimization system to perform the steps of the above-described method.

[0009] In this application, dynamic permission modeling and data-driven optimization mechanisms significantly improve the flexibility and security response capabilities of power network resource management. First, based on multi-dimensional data fusion analysis of real-time device status, user operation behavior, and network topology, user permission feature sets and device permission feature sets are constructed. This accurately characterizes the minimum access requirements of users with different roles and the dynamic boundaries of device resource allocation, thus avoiding the drawbacks of over-authorization or insufficient permissions under traditional fixed permission rules. Second, through dynamic allocation strategy generation and processing, user permission features and device permission features are collaboratively mapped, optimizing load balancing paths and device control priorities in real time. This ensures that the power network can quickly match the optimal resource scheduling scheme under high-concurrency operation or sudden failure scenarios. For example, when user operation permissions are dynamically reduced, the system can simultaneously increase the resource response weight of critical equipment, preventing the risk of unauthorized operations while maintaining the continuity of core services. Furthermore, through a real-time feedback mechanism for permission configuration update operations, the system can proactively adapt to changes in the power grid operating environment (such as new equipment, topology reconfiguration, or escalating security threats), ensuring that permission rules and resource allocation strategies remain consistent. This improves power network operating efficiency while achieving a shift in security protection from passive response to proactive prediction. Therefore, by deeply coupling the permission model with resource scheduling, a technical path that balances flexibility and reliability is provided for the intelligent upgrading of the power system, which can improve the adaptability and risk resistance of the power network in complex operating environments. Attached Figure Description

[0010] Figure 1 This is a flowchart illustrating a power network data-driven optimization method based on dynamic permission modeling, provided in an embodiment of this application.

[0011] Figure 2 This is a schematic diagram of the structure of a power network data-driven optimization system provided in an embodiment of this application. Detailed Implementation

[0012] See Figure 1 This is a power network data-driven optimization method based on dynamic permission modeling provided in the embodiments of this application. This method can be applied to power network data-driven optimization systems, and the specific process is as follows: steps S110-S140.

[0013] Step S110: Obtain a power network operation data set, which includes real-time device status data, user operation behavior logs, and network topology connection relationships.

[0014] In the application scenario of the large-scale power network system involved in the embodiments of this application, the large-scale power network system includes numerous different types of widely distributed power equipment. Among them, real-time equipment status data records in detail the operating parameters of various types of equipment. Taking generator A as an example, its current output power is 600 megawatts, the voltage is maintained at 230 kV, the frequency is stable at 50 Hz, and the internal temperature of the equipment is 58 degrees Celsius; the transformation ratio of transformer B is set to 110 / 10 kV, the load rate reaches 75%, and the oil temperature is 48 degrees Celsius. These parameters change in real time as the equipment operates.

[0015] Optionally, the user operation behavior log records in detail the operations performed on the power equipment by different user roles. For example, maintenance personnel C performed a power adjustment operation on generator A at 10:00 AM, increasing the power from 550 MW to 600 MW; dispatcher D issued an instruction at 2:00 PM to adjust the taps of transformer B to optimize voltage distribution. The log accurately records information such as operation type, operation time, and operator role, comprehensively reflecting the interaction between users and power equipment.

[0016] Optionally, the network topology clearly illustrates the physical connections between various devices in the power network. For example, generator A is connected to transformer B via transmission line L1, and transformer B is connected to multiple distribution nodes via transmission line L2. This connection clearly defines the path and direction of power transmission, providing a basic framework for subsequent analysis and control. By comprehensively acquiring the above data, the operational status of the power network can be fully presented, providing rich and accurate data support for subsequent dynamic permission modeling and resource allocation strategy formulation.

[0017] Step S120: Perform dynamic permission modeling processing on the power network operation data set to generate a user permission feature set and a device permission feature set; the user permission feature set represents the access control parameters of different user roles to power resources, and the device permission feature set represents the resource allocation permissions of different power devices in the operating environment.

[0018] In one implementation, step S120 involves performing dynamic permission modeling on the power network operation data set to generate a user permission feature set and a device permission feature set, including:

[0019] Step S121: Extract the operation type sequence and operation timestamp sequence from the user operation behavior log. The operation type sequence includes the user role's control command type for the power equipment and the corresponding number of operations.

[0020] In this embodiment, operation type sequences and operation timestamp sequences are extracted based on information recorded in user operation behavior logs. For example, regarding the operation records of maintenance personnel C, in the past week's logs, generator A received 3 power increase commands, 2 power decrease commands, and 4 equipment status check commands; transformer B received 1 tap adjustment command and 3 equipment maintenance commands. These command types and their corresponding number of operations constitute the operation type sequence. Simultaneously, the specific time of each operation is recorded, such as the first power increase command for generator A being executed at 9:00 AM on Monday, and the second at 3:00 PM on Tuesday. These specific times form the operation timestamp sequence. Through the above extraction method, the user's operation on different power equipment at different times can be clearly understood, providing a detailed data foundation for subsequently generating a dynamic evolution map of user permissions.

[0021] Step S122: Based on the operation type sequence and the operation timestamp sequence, generate a dynamic evolution map of user permissions; the dynamic evolution map of user permissions includes the trajectory of changes in user role's operation permissions within a preset time window.

[0022] Optionally, generating a dynamic evolution map of user permissions based on the operation type sequence and the operation timestamp sequence in step S122 includes:

[0023] Step S1221: Evaluate the permission impact of the operation type sequence. Based on the probability calculation of different operation types triggering permission adjustments in historical permission change records, determine the impact weight of each operation type on user permission changes.

[0024] In this embodiment, the impact of each operation in the sequence of operation types can be evaluated by combining historical permission change records. For example, based on historical records, it is known that in the past 100 power boost operations, permission adjustments were triggered 30 times, so the probability of a power boost operation triggering a permission adjustment is 30%; while in the past 200 executions, the device status check operation only triggered permission adjustments 20 times, with a trigger probability of 10%. Based on these probabilities, a higher impact weight is assigned to the power boost operation, for example, set to 0.6; and a lower impact weight is assigned to the device status check operation, such as 0.1. Thus, the impact weight of each operation type on user permission changes can be determined, providing a quantitative basis for subsequent analysis of the dynamic changes in user permissions.

[0025] Step S1222: Generate a permission change time interval distribution based on the operation timestamp sequence. The time interval distribution is used to characterize the dynamic correlation between the time density of user operation behavior and the frequency of permission adjustment.

[0026] In this application scenario, the operation timestamp sequence is analyzed to generate a distribution of permission change time intervals. Taking the operation record of maintenance personnel C on generator A as an example, the time interval between two adjacent operations is statistically analyzed. For example, the first power increase operation is executed at 9:00 AM on Monday, and the second is executed at 3:00 PM on Tuesday, with a time interval of approximately 30 hours; the interval between the second power increase operation and the third is 22 hours. Through the statistical analysis of a series of operation time intervals, a distribution chart of permission change time intervals is drawn. Based on the distribution chart of permission change time intervals, it can be determined that when the time interval between maintenance personnel C's operations on generator A is short, that is, when the operation behavior is more intensive, the frequency of permission adjustment is relatively high; conversely, when the operation time interval is long, the frequency of permission adjustment is low. The distribution chart of permission change time intervals shows the dynamic correlation between the time intensity of user operation behavior and the frequency of permission adjustment.

[0027] Step S1223: Perform correlation analysis between the influence weight and the time interval distribution, calculate the correlation strength of the user role's permission status within a continuous time window, and generate node connection strength parameters in the dynamic evolution graph of user permissions; the node connection strength parameters quantify the probability and temporal dependency of permission status transitions between adjacent time windows.

[0028] In this embodiment, the previously determined influence weights are correlated with the generated time interval distribution. For example, within a weekly time window, maintenance personnel C performs three operations on generator A: two power boost operations (influence weight 0.6) and one equipment status check operation (influence weight 0.1). The time intervals between these three operations are 20 hours and 25 hours, respectively. Based on the corresponding calculation method (considering the number of operations, influence weights, and time intervals, an exemplary calculation method could be: (number of power boost operations × power boost influence weight + number of equipment status check operations × equipment status check influence weight) ÷ total operation time interval), the association strength of the user role's permission status with generator A within that week is calculated. This strength value is used as the connection strength parameter of the corresponding node in the user permission dynamic evolution graph. The connection strength parameter quantifies the probability and temporal dependency of permission status transitions between adjacent time windows. For example, a higher connection strength parameter indicates a higher probability of permission status transitions within adjacent time windows and a stronger temporal dependency, meaning that subsequent permission statuses are largely influenced by previous state operations.

[0029] Step S1224: Construct a dynamic permission state transition matrix based on the node connection strength parameters, wherein: the matrix row dimension represents the permission state set of the current time window, the column dimension represents the permission state set of the next time window, and the matrix element values ​​are obtained by normalizing the corresponding node connection strength parameters, which are used to reflect the transfer weight of permission states across time windows.

[0030] In this application scenario, a dynamic permission state transition matrix is ​​constructed using the example of user permission states being categorized into "high permission," "medium permission," and "low permission." For instance, through previous calculations, the node connection strength parameters within several consecutive time windows are obtained. For example, the node connection strength parameter from the current time window's "medium permission" state to the next time window's "high permission" state is 0.4, to the "medium permission" state is 0.3, and to the "low permission" state is 0.2. To construct the matrix, these parameters are first normalized. For example, the total strength parameter is 0.4 + 0.3 + 0.2 = 0.9. After normalization, the matrix element values ​​from "medium permission" to "high permission" are 0.4 ÷ 0.9 ≈ 0.44, to "medium permission" are 0.3 ÷ 0.9 ≈ 0.33, and to "low permission" are 0.2 ÷ 0.9 ≈ 0.22. According to the matrix construction rules, the row dimension represents the permission status of the current time window ("high permission", "medium permission", "low permission"), and the column dimension represents the permission status of the next time window (also "high permission", "medium permission", "low permission"). These normalized element values ​​are filled into the corresponding positions of the matrix. The dynamic permission status transition matrix constructed in this way can clearly reflect the transition weight of permission status across time windows, providing key data support for generating the spatiotemporal topology of the dynamic evolution map of user permissions.

[0031] Step S1225: Generate the spatiotemporal topology of the dynamic permission evolution graph based on the dynamic permission state transition matrix: map the permission state of each time window to a time-series node with timestamp attribute, connect adjacent time-series nodes in the order of time evolution to form directed edges, and each directed edge carries a normalized connection strength weight value.

[0032] In this embodiment, a spatiotemporal topology for the dynamic evolution graph of user permissions is constructed based on a dynamic permission state transition matrix. For example, the time windows of each day within the past week are used as the basis for node construction. Monday's permission state is "medium permission," which is mapped to a time-series node with a Monday timestamp attribute; Tuesday's permission state is "high permission," which is mapped to a time-series node with a Tuesday timestamp. According to the time evolution order, directed edges connect the nodes of Monday and Tuesday. The weight value of this directed edge is the transition weight value (set to 0.44) obtained through normalization processing from Monday's "medium permission" state to Tuesday's "high permission" state. In the same way, time-series nodes of other adjacent time windows are connected sequentially to form a complete spatiotemporal topology. Thus, through the above visualized structure, the evolution path of user permissions in the time dimension and the probabilistic relationship of permission state transitions between different time windows can be intuitively seen.

[0033] Step S1226: Embed a multi-dimensional permission feature vector in the time sequence node. The multi-dimensional permission feature vector is composed of the operation type distribution histogram, the cumulative value of permission influence, and the statistical features of the time interval distribution within the corresponding time window.

[0034] In this application scenario, a multi-dimensional permission feature vector is embedded for each time-series node. Taking Tuesday as an example, within this time window, maintenance personnel C performed one power boost operation and one equipment status check operation on generator A. The operation type distribution histogram can be represented as power boost operations accounting for 50% and equipment status check operations accounting for 50%. The cumulative value of permission influence is obtained by summing the influence weights of each operation within this time window. For example, if the influence weight of the power boost operation is 0.6 and the influence weight of the equipment status check operation is 0.1, then the cumulative value of permission influence is 0.6 + 0.1 = 0.7. The statistical characteristics of the time interval distribution, such as the average time interval of operations within this time window, are set to 24 hours. Then, the above information is combined into a multi-dimensional vector and embedded into the Tuesday time-series node. By embedding the above multi-dimensional permission feature vector at each time-series node, the dynamic attributes of user permissions within each time window can be described more comprehensively, enriching the information content of the dynamic evolution graph of user permissions.

[0035] Step S1227: By fusing the spatiotemporal topology and the multidimensional permission feature vector, the user permission dynamic evolution graph is generated, wherein: the topological edge weights of the user permission dynamic evolution graph represent the permission state transition probability, the node feature vectors characterize the dynamic attributes of the permission state, and the user permission dynamic evolution graph is a visual graph model containing time-dimensional evolution paths and spatial-dimensional permission association rules.

[0036] In this embodiment, the previously constructed spatiotemporal topology and multidimensional permission feature vectors are fused. The spatiotemporal topology, consisting of each time-stamped sequential node and the directed edges connecting them, is combined with the multidimensional permission feature vectors embedded in the nodes. This generates a dynamic evolution graph of user permissions. The weights of the topological edges intuitively represent the probability of permission state transitions between different time windows. For example, an edge weight of 0.4 from one node to another indicates a 40% probability of permission transitioning from one state to another. The node feature vectors, i.e., the embedded multidimensional permission feature vectors, characterize the dynamic attributes of the permission state in each time window, including operation type distribution, cumulative permission influence, and other information. In essence, this visualized graph model encompasses both the evolution path of user permissions in the time dimension, demonstrating how permissions change over time, and the association rules between different permission states in the spatial dimension, providing a comprehensive and intuitive tool for analyzing the dynamic changes of user permissions.

[0037] Step S123: Perform device association analysis on the network topology connection relationship to generate a device permission dependency graph; the device permission dependency graph reflects the resource call relationship and permission sharing constraints between power devices.

[0038] In one implementation, step S123, which involves resolving device associations in the network topology connections to generate a device permission dependency graph, includes:

[0039] Step S1231: Analyze the device hierarchy in the network topology connection relationship and determine the resource call path between the master control device and the controlled device.

[0040] In the power network of this application embodiment, the network topology connection relationship is analyzed in depth to determine the device hierarchy and resource access paths. For example, taking a subnet containing multiple transformers and distribution nodes as an example, by analyzing the network topology connection relationship diagram, it can be determined that transformer T3 is at a higher level and is the master control device, while multiple distribution nodes P1, P2, P3, etc. are controlled devices. Transformer T3 transmits power to each distribution node through different transmission lines, forming resource access paths. Specifically, transformer T3 transmits power to distribution node P1 through transmission line L31, to P2 through L32, and to P3 through L33.

[0041] Step S1232: Calculate the resource competition coefficient between the master control device and the controlled device based on the resource occupancy rate data in the real-time device status data; the resource competition coefficient reflects the probability of conflict when the master control device allocates resources to the controlled device.

[0042] In this embodiment, the resource competition coefficient is calculated by combining resource occupancy data from real-time device status data. Taking transformer T3 and distribution node P1 as an example, transformer T3 has a rated capacity of 800 MW, and the current real-time resource occupancy rate is 70%, meaning the actual output power is 560 MW; distribution node P1's required power is 150 MW, while the maximum carrying capacity of transmission line L31 connecting P1 and transformer T3 is 120 MW. According to a preset calculation method (e.g., resource competition coefficient = (required power - line carrying capacity) / rated capacity), the resource competition coefficient between transformer T3 and distribution node P1 is calculated to be (150-120) ÷ 800 = 0.0375. This coefficient reflects the probability of conflict when transformer T3 allocates resources to distribution node P1; the higher the coefficient, the greater the possibility of resource conflict. By performing the above calculations on all master control devices and controlled devices, a comprehensive understanding of the resource competition situation among power equipment is achieved.

[0043] Step S1233: Based on the resource call path and the resource competition coefficient, generate the device node weights and edge connection rules corresponding to the device permission dependency graph; the device node weights are used to identify the priority of power equipment in resource allocation, and the edge connection rules are used to constrain the maximum resource threshold for permission sharing between devices.

[0044] In this application scenario, device node weights and edge connection rules are generated based on resource allocation paths and resource contention coefficients. For device node weights, considering the core role of transformer T3 in resource allocation and its importance to multiple distribution nodes, it is assigned a high weight, for example, 0.8; while for distribution node P1, due to its relatively secondary role in resource allocation, a weight of 0.3 is assigned. Edge connection rules are determined based on the resource contention coefficient and system security constraints. For example, when the resource contention coefficient exceeds 0.05, the maximum resource threshold for shared permissions between devices is specified as 15% of the rated capacity. Thus, by clearly defining device node weights and edge connection rules, specific parameters and constraints are provided for constructing the device permission dependency graph.

[0045] Step S1234: Generate a device permission dependency graph based on the device node weights and the edge connection rules.

[0046] In this embodiment, a device permission dependency graph is generated based on the previously determined device node weights and edge connection rules. Graphically, transformer T3 and distribution nodes P1, P2, and P3 are plotted as nodes in the graph, with each node labeled with a corresponding weight value. Then, according to the resource access paths, edges are connected to each node, and edge connection rule information, such as the maximum resource threshold, is labeled on the edges. For example, the edge connecting transformer T3 and distribution node P1 is labeled with a maximum resource threshold of 15% of transformer T3's rated capacity. Thus, the generated device permission dependency graph illustrates the resource access relationships and permission sharing constraints between power devices, providing an important basis for subsequent development of power resource allocation strategies.

[0047] Step S130: Generate a dynamic power resource allocation strategy based on the user permission feature set and the device permission feature set; the dynamic power resource allocation strategy is used to adjust the load balancing path and device control priority in the power network.

[0048] In one implementation, step S130, generating a dynamic power resource allocation strategy based on the user permission feature set and the device permission feature set, includes:

[0049] Step S131: Calculate the matching degree between the access frequency feature in the user permission feature set and the resource occupancy rate feature in the device permission feature set to generate a user-device permission matching matrix.

[0050] In this embodiment, for ease of calculation, the access frequency feature can be simplified to the corresponding number of accesses, and the resource utilization feature can be simplified to the corresponding resource utilization rate. Taking maintenance personnel E and multiple power devices as an example, the matching degree is calculated. Maintenance personnel E accesses generator F 6 times per week, and generator F's resource utilization rate is 75%; the access frequency to transformer G is 4 times per week, and transformer G's resource utilization rate is 60%. Using a preset matching degree calculation method (e.g., matching degree = access frequency / resource utilization rate; in this embodiment, the access frequency feature is exemplarily mapped to 6 and 4), the matching degree between maintenance personnel E and generator F is calculated to be 6 ÷ 0.75 = 8, and the matching degree with transformer G is 4 ÷ 0.6 ≈ 6.67. Similar calculations are performed for all user roles and power devices. The above calculation results are organized into a two-dimensional matrix, namely the user-device permission matching matrix. The rows of the user-device permission matching matrix represent user roles, the columns represent power devices, and the matrix element values ​​are the corresponding matching degrees. This matrix provides a clear view of the permission matching between users and devices.

[0051] Step S132: Determine the set of target power devices with resource conflicts based on the user-device permission matching matrix; the resource conflicts include user access requests exceeding device resource capacity or permission sharing rules not meeting security constraints.

[0052] In this application scenario, the user-device permission matching matrix is ​​analyzed to identify the set of target power devices with resource conflicts. For example, based on the user-device permission matching matrix, it can be determined that dispatcher F accesses transformer H frequently, up to 10 times per week, while transformer H's resource occupancy rate is already as high as 90%, and its rated capacity is limited. Given the current access frequency and resource occupancy, user access requests exceed the device's resource capacity, potentially leading to equipment instability. Furthermore, regarding permission sharing, the permission sharing rules between some devices may not meet security constraints under the current load conditions. Through comprehensive analysis of the matrix, devices like transformer H with these resource conflict issues are identified as the target set of power devices, providing a basis for subsequently developing targeted power resource allocation strategies.

[0053] Step S133: Based on the resource conflict type of the target power equipment set, generate a dynamic load balancing path and a permission priority adjustment instruction, and combine the dynamic load balancing path and the permission priority adjustment instruction to determine a dynamic power resource allocation strategy; the dynamic load balancing path is used to reallocate resource call links between power equipment, and the permission priority adjustment instruction is used to restrict the access permissions of low-priority users to critical load equipment.

[0054] In this embodiment of the application, dynamic load balancing path and permission priority adjustment instructions are generated based on the resource conflict types presented by the target power equipment set.

[0055] To generate dynamic load balancing paths, the real-time load rate data and topology connection status of each device in the power network are first obtained. For example, in a local power network area covering multiple generators, transformers, and distribution lines, the real-time load rate of generator G1 is 85%, and the load rate of generator G2 is 60%; transformer T1 connects to a high-load distribution area with a load rate of 90%, while the load rate of transformer T2 is only 50%. Simultaneously, the topology connection relationships between each device are defined, such as generator G1 being connected to transformer T1 via transmission line L1, generator G2 being connected to transformer T2 via transmission line L2, and a tie line L3 also existing between transformers T1 and T2.

[0056] Then, a heatmap of equipment load distribution is constructed based on this real-time load rate data. The heatmap uses different colors to visually represent the load status of each device. For example, areas with high load (e.g., load rate exceeding 80%) are displayed in red, representing high load and potential overload risk; medium load areas (load rate between 60% and 80%) are displayed in yellow; and low load areas (load rate below 60%) are displayed in green. The heatmap clearly shows the remaining capacity and overload risk level of electrical equipment in different areas. For example, in the above example, the area where transformer T1 is located is red, indicating that it is under high load and has an overload risk; the area where transformer T2 is located is green, indicating that it has a relatively large remaining capacity.

[0057] Furthermore, based on the equipment load distribution heatmap and topology connection status, multiple candidate load balancing paths are generated. For example, considering the low load of generator G2 and the remaining capacity of transformer T2, a candidate path is generated: some of the power originally transmitted from generator G1 to transformer T1 is transferred to transformer T2 via tie line L3, and then distributed by transformer T2 to other demand areas. This candidate load balancing path includes the target equipment set for resource reallocation (such as generators G1 and G2, transformers T1 and T2, and related distribution nodes) and data transmission delay parameters. For example, after analyzing and estimating factors such as line length and transmission medium, the data transmission delay of this path is 40 milliseconds. Simultaneously, other candidate paths can be generated, such as using backup generator G3 to share part of the load, but the data transmission delay of this path may be 60 milliseconds, and it involves adjustments to more equipment.

[0058] Next, based on data transmission delay parameters and overload risk levels, the optimal path is selected from the candidate load balancing paths as the dynamic load balancing path. When comparing the candidate paths, two key factors are considered: data transmission delay and overload risk. For data transmission delay, lower delay means faster and more stable power transmission, reducing the impact on the real-time operation of the power system; while the overload risk level directly relates to the safe and stable operation of power equipment. For example, in the two candidate paths mentioned above, although the path utilizing backup generator G3 can share more load, its data transmission delay is longer and involves changes to more equipment, potentially leading to more risks. In contrast, the path transferring power via tie line L3 has a relatively low data transmission delay of 40 milliseconds and can effectively reduce the overload risk of transformer T1. Therefore, this path is selected as the dynamic load balancing path to achieve a reasonable redistribution of resources among power equipment.

[0059] Furthermore, regarding the generation of permission priority adjustment instructions, since access to critical load equipment by low-priority users may affect the normal operation of the equipment, corresponding instructions need to be formulated to restrict such access. For example, frequent routine maintenance operations by ordinary maintenance personnel on the critical transformer T1 under high load may interfere with the stable operation of the equipment and increase the risk of overload. Therefore, permission priority adjustment instructions are generated, stipulating that when the load rate of transformer T1 exceeds 85%, ordinary maintenance personnel are only allowed to perform emergency troubleshooting operations and are prohibited from performing routine maintenance operations. The above instructions clarify the access priority of different user roles under different equipment states, ensuring that critical load equipment can prioritize power supply and stable operation under high load.

[0060] Finally, the generated dynamic load balancing path and permission priority adjustment instructions are combined to form a complete dynamic power resource allocation strategy. This strategy optimizes the distribution of power resources and reduces the risk of equipment overload by redistributing resource access links between power devices through dynamic load balancing paths. On the other hand, it restricts the access permissions of low-priority users to critical load devices through permission priority adjustment instructions, ensuring the normal operation of equipment and the stability of the power network. The above comprehensive strategy can effectively adjust the load balancing path and equipment control priority in the power network, and achieve reasonable and efficient allocation of power resources.

[0061] Step S140: Feed back the dynamic power resource allocation strategy to the power network control system to activate the permission configuration update operation. The permission configuration update operation includes adjusting the user operation permission range and the resource response rules of power equipment.

[0062] In one implementation, step S140, which involves feeding back the dynamic power resource allocation strategy to the power network control system to activate the permission configuration update operation, includes:

[0063] Step S141: Receive dynamic load balancing path and permission priority adjustment instructions through the policy parsing interface of the power network control system.

[0064] In this embodiment, the policy parsing interface of the power network control system is a module with intelligent recognition and parsing functions, which can accurately receive and interpret these complex instruction information. For example, when dynamic load balancing path information is sent to the policy parsing interface in a preset data format (such as a data packet containing detailed information such as the target device set and path direction) and permission priority adjustment instructions (such as a text instruction that clearly specifies the permission restrictions for ordinary maintenance personnel in the target device state), the interface can quickly recognize and convert it into an internal instruction form that the system can understand for subsequent processing.

[0065] Step S142: Generate a path configuration confirmation signal based on the dynamic load balancing path, and transmit the path configuration confirmation signal to the target power equipment controller to activate the link switching operation.

[0066] Taking the previously determined dynamic load balancing path of transferring power via tie line L3 as an example, the system generates a path configuration confirmation signal based on this path information. This signal contains detailed path parameters, such as the starting device (generator G1), intermediate transfer device (transformer T2), target device (relevant distribution nodes), and key information such as the time requirements for path switching. The signal is accurately transmitted to the controllers of generator G1, transformers T1 and T2, and relevant distribution nodes. For example, after receiving the signal, the controller of generator G1 will gradually adjust the generator's output power distribution according to the signal requirements, switching part of the power output direction to tie line L3; the controller of transformer T2 will prepare to receive and redistribute power, adjusting its internal voltage conversion and power distribution parameters to ensure that power can pass smoothly and be distributed to the corresponding distribution nodes. Through these operations, the link switching operation is activated, realizing the adjustment of the power resource redistribution path.

[0067] Step S143: When the link switching operation is completed, capture the device response status code and synchronize and verify the device response status code with the permission priority adjustment instruction.

[0068] It is understandable that after generator G1, transformers T1 and T2, and related distribution nodes complete the link switching operation, the controllers of each device will return device response status codes. For example, the controller of generator G1 returns status code "200", indicating that the power output adjustment and link switching operation was successful; the controller of transformer T2 returns "200", indicating that power reception and distribution preparation is ready. These status codes are collected and synchronously verified along with the permission priority adjustment command. The verification process not only checks whether the device operation was successful, but also verifies whether the parameters and logic in the permission priority adjustment command conform to the system's preset rules. For example, it checks whether the permission restrictions for ordinary maintenance personnel on critical equipment specified in the permission priority adjustment command are within the scope of the system's security and management rules. If all devices respond with status codes of "200", and the logic and parameters of the permission priority adjustment command conform to the preset rules, the verification passes; if any device returns a status code other than "200", or if the permission priority adjustment command contains a logical error, such as the permission range setting not conforming to security standards, the verification will fail.

[0069] Step S144: Trigger the update process of the user role access control list based on the device response status code that has passed the verification, and generate a user permission configuration table containing the new permission scope.

[0070] Understandably, once the verification passes, the system will automatically initiate the update process for the user role access control list. Taking a regular maintenance worker as an example, based on the permission priority adjustment instruction, when the transformer T1 load rate exceeds 85%, their operation permissions are strictly limited to emergency troubleshooting operations. The system will accurately record the new permission scope of the regular maintenance worker in this situation in the user role access control list. Then, a detailed user permission configuration table will be generated, which clearly lists the specific operation permissions of each user role under different device states. For example, the table will clearly record that when the transformer T1 load rate is below 85%, the regular maintenance worker can perform routine maintenance and troubleshooting operations; when the load rate exceeds 85%, they can only perform emergency troubleshooting operations.

[0071] Step S145: Write the user permission configuration table into the access authorization database of the power network control system, and update the priority sorting parameters of the device resource response rules.

[0072] For example, the system accurately writes the generated user permission configuration table into the access authorization database. In the database, it locates the permission record field corresponding to ordinary maintenance personnel and updates it with the new permission scope information. The priority ranking parameters for device resource response rules are also adjusted according to the dynamic power resource allocation strategy. For example, for the high-load transformer T1, its resource response priority for emergency fault handling is increased, while the priority for routine maintenance operations is decreased. This means that during device resource allocation and response processing, the system prioritizes ensuring the resources and response speed required for emergency fault handling, ensuring the safe and stable operation of the equipment under special conditions such as high loads.

[0073] Step S146: Obtain the write completion identifier of the access authorization database in real time, and activate the network-wide permission policy effective instruction based on the write completion identifier.

[0074] Once the access authorization database successfully writes the user permission configuration table and updates the priority sorting parameters of the device resource response rules, the database system returns a write completion flag. The power network control system monitors this flag in real time. Once it obtains this flag, it immediately activates the network-wide permission policy activation command to notify the entire power network system to begin executing the new permission configuration policy.

[0075] Step S147: Drive the power network control system to perform permission configuration synchronization broadcast through the network-wide permission policy activation instruction, and generate a permission update broadcast confirmation queue.

[0076] Understandably, after the command to activate the network-wide permission policy is issued, the power network control system will send permission configuration update information to all devices and user terminals in the network. This information is sent in a broadcast manner to ensure that every relevant device and user in the network receives it. For example, through the communication protocols and signal transmission mechanisms in the power network, the new user permission scope and device resource response rules are sent to each generator, transformer, distribution node, and user operation terminal. After receiving the information, each device and user terminal will automatically parse and process it and return an acknowledgment response. These acknowledgment responses will form a permission update broadcast acknowledgment queue. The system monitors this queue to confirm that all relevant devices and users have received and acknowledged the new permission configuration information.

[0077] Step S148: After all power devices in the permission update broadcast confirmation queue return confirmation responses, a permission configuration update completion flag is generated and stored in the system log.

[0078] Optionally, once the last power device in the queue (such as a small power distribution device located in a remote area) returns a confirmation response, the system determines that the permission configuration update operation has been successfully completed and generates a permission configuration update completion flag. This flag is accurately recorded in the system log, which details the time of the permission configuration update, the devices and user roles involved, and the specific content of the update. For example, the system log might record "Permission configuration update completed at [specific time], involving adjustments to the permissions of ordinary maintenance personnel and updates to the priority of response rules for equipment resources such as transformer T1." These records provide detailed historical data for subsequent system auditing, troubleshooting, and operation management, allowing administrators to easily access and understand changes in system permission configurations.

[0079] Another implementation also includes the training process of the target dynamic permission model:

[0080] Step S210: Obtain historical power network operation dataset and corresponding optimization strategy execution effect data.

[0081] In the power network system involved in this application embodiment, the acquisition of historical power network operation datasets covers multiple data sources and a long time span. From the perspective of data sources, these mainly include real-time data records collected by various monitoring devices in the power network, detailed logs of user operation behavior, and records of network topology changes. For example, over the past three years, power monitoring devices in the system have continuously recorded the output power data of each generator. Taking generator M as an example, on January 1, 2020, its output power was 300 MW, 320 MW, etc., at different times. Voltage monitoring devices record the voltage data of each node, such as the voltage of a certain distribution node being 10.5 kV at a target time. User operation behavior logs record in detail the operations of different user roles on various power devices at different times. For example, maintenance personnel NP performed maintenance operations on transformer O on March 5, 2021, recording the specific content and time of the operation. Network topology change records document changes in the connection relationships of devices in the power network. For example, in July 2022, a new transmission line was added connecting two previously isolated areas.

[0082] The corresponding optimization strategy execution effect data is a detailed record of the optimization strategies adopted for different operating conditions and their effects after implementation. For example, during a certain period, voltage instability occurred in some areas of the power network. To solve this problem, optimization strategies were adopted, including adjusting transformer tap settings and optimizing generator reactive power output. After implementing this strategy, voltage data in the relevant areas was continuously monitored, and the recorded voltage fluctuation range decreased from ±5% to ±3%, and the power factor improved from 0.85 to 0.9. Simultaneously, by observing the operating status of equipment, it was determined that the number of overload warnings on some transmission lines that previously frequently triggered overload warnings due to voltage issues significantly decreased. These data record in detail the changes in operating parameters of the power network, the improvement in equipment status, and the degree of improvement in overall power supply quality before and after the implementation of the optimization strategy. This provides rich and realistic sample data for subsequent model training, helping to establish a more accurate and effective dynamic permission model.

[0083] Step S220: Extract permission features and label conflict events from the historical power network operation dataset to generate a model training sample set.

[0084] In this embodiment of the application, permission feature extraction and conflict event labeling are carried out on historical power network operation datasets.

[0085] For permission feature extraction, user permission features are analyzed from the perspective of user operation behavior. Taking dispatcher P as an example, their operation records in historical data are studied in depth. Over the past two years, dispatcher P has performed a series of operations on different generators and transformers. The number of power adjustment operations on generators is counted, for example, 15 power increase operations and 10 power decrease operations were performed on generator Q in different time periods. At the same time, the time of each operation and the operating status of the equipment at that time are recorded, such as a power increase operation when the load rate of generator Q reached 75%. By analyzing these operation data, the frequency characteristics of dispatcher P's operations on generator Q (such as the average number of operations per month), the operation time distribution characteristics (such as the time periods in which operations are concentrated), and the correlation characteristics between operations and equipment status (such as the operation tendency under different load rates of the equipment) are extracted as user permission features.

[0086] From a device perspective, device permission characteristics are extracted, combined with real-time device status data and network topology connections. For example, for transformer R, its resource utilization data at different times is analyzed to calculate its average resource utilization and the range of fluctuation. Simultaneously, considering transformer R's location in the network topology and its connections with other devices, its resource allocation is analyzed. For instance, transformer R is connected to multiple distribution nodes, and during certain time periods, changes in the demand of some distribution nodes cause fluctuations in transformer R's resource allocation. Through these analyses, characteristics such as transformer R's resource utilization, resource competition coefficient (e.g., the degree of resource competition with other adjacent transformers), and resource allocation path (e.g., the main resource output directions and paths) are extracted as device permission characteristics.

[0087] While extracting permission features, conflict events in the dataset are labeled. Historical operational data is carefully examined to identify events involving resource conflicts or permission issues. For example, at a certain moment, it is discovered that the output power of generator S suddenly increases significantly, causing overload on the transmission line connecting it to transformer T, resulting in a sharp rise in line temperature. This is a typical resource conflict event. Detailed labeling of this event is provided, recording the exact time of occurrence (e.g., 14:30 on September 15, 2021), the equipment involved (generator S, transformer T, and related transmission lines), the conflict type (power overload conflict), and the severity of the conflict (e.g., the specific value at which the line temperature exceeds the safety threshold). By comprehensively extracting permission features and accurately labeling conflict events from historical power network operational datasets, a rich, detailed, and targeted model training sample set is generated. This provides high-quality data support for subsequent model training, enabling the trained model to more accurately simulate and analyze permission management and resource allocation issues in power networks.

[0088] Step S230: Train the initial dynamic permission model using a reinforcement learning algorithm to obtain the target dynamic permission model; the target dynamic permission model outputs a set of user permission features and a set of device permission features that match the data on the execution effect of the optimization strategy based on the input power network operation data set.

[0089] In this embodiment of the application, reinforcement learning algorithms can be used to train the initial dynamic permission model in order to obtain the target dynamic permission model.

[0090] The core idea of ​​reinforcement learning algorithms is to learn the optimal policy through the interaction between the agent and the environment. In this scenario, the initial dynamic permission model can be understood as an agent that initially possesses the ability to analyze power network data, but its performance is not yet perfect and needs to be improved in accuracy and effectiveness through continuous learning.

[0091] At the start of training, a historical power network operation dataset is provided as input to the initial dynamic permission model. Based on this data, the model attempts to output sets of user permission features and device permission features. For example, given a set of historical data containing the operating status of power equipment and user operation behavior within a target time period, the model, based on its internal algorithms and parameters, outputs predictions of user permission features, such as the predicted frequency of operations by the target dispatcher on the target generator and operation legality labels; simultaneously, it outputs predictions of device permission features, such as the resource occupancy rate of a transformer and permission conflict detection parameters.

[0092] Next, the model output is compared with the data showing the effect of the optimization strategy. For example, the model predicts that the resource utilization rate of a transformer is 70%, while the actual resource utilization rate of the transformer after the optimization strategy is implemented, as shown by actual monitoring data, is 75%. This indicates that there is a certain deviation in the model's prediction. Through this comparison, the error between the model output and the actual data is calculated.

[0093] Based on the error, the reinforcement learning algorithm adjusts the parameters of the initial dynamic permission model. The algorithm updates the model's weights and parameters using pre-defined optimization methods, based on the magnitude and direction of the error. For example, if the model's predicted user permission features deviate significantly from the actual situation, the algorithm adjusts the parameters related to the calculation of these features to make the model's next prediction closer to the actual value. This adjustment process is repeated continuously, and with the continuous input of training data and adjustment of model parameters, the model's prediction accuracy gradually improves.

[0094] After extensive training and iterations, when the matching degree between the output of the initial dynamic permission model and the optimization strategy execution effect data reaches a satisfactory level, the target dynamic permission model is obtained. This target dynamic permission model can accurately output user permission feature sets and device permission feature sets that match the optimization strategy execution effect data based on the input power network operation data set. For example, when a new set of power network operation data is input, the target dynamic permission model can quickly and accurately analyze the data and output a set of user permission features that conforms to the actual situation, such as accurately predicting the access frequency of different user roles to various types of power equipment and operation legality tags; at the same time, it outputs an accurate set of device permission features, such as the resource occupancy rate characteristics of power equipment and permission conflict detection parameters. These output results highly match the optimization strategy execution effect data, meaning that the model can effectively simulate and reflect the real permission management and resource allocation situation in the power network.

[0095] For example, when faced with a new set of power network operation data, including recent changes in generator output power, transformer load status, and user operation records, the target dynamic permission model, after training, can accurately analyze the permission characteristics of different user roles (such as dispatchers and maintenance personnel) based on this data. For instance, for a dispatcher, the model might output that their operation frequency on a certain generator under the target operating state is 5 times per week, with the operation legality label being compliant. This aligns with the frequency and standards of dispatchers' reasonable generator operations based on power demand in reality. Regarding equipment permission characteristics, for a certain transformer, the model outputs its resource occupancy rate as 78%, and permission conflict detection parameters show no significant conflicts with surrounding equipment, which also matches the actual monitored transformer resource usage and inter-equipment relationships.

[0096] Through the above training process, the target dynamic permission model learns the inherent laws and correlations between power network operation data and user permission features and device permission features. It can accurately generate corresponding feature sets based on input data, providing a reliable basis for the formulation of subsequent dynamic power resource allocation strategies, and further ensuring the stable and efficient operation of the power network.

[0097] Step S240: Deploy the target dynamic permission model to the power network control system to realize real-time permission modeling and resource allocation strategy generation.

[0098] In this embodiment, the trained target dynamic permission model is integrated into the power network control system to achieve real-time permission modeling and resource allocation strategy generation, thereby improving the intelligence and optimization level of power network operation.

[0099] First, the deployment of the target dynamic permission model is required. This involves effectively integrating the model with various components of the power network control system. The power network control system comprises multiple subsystems and modules, such as data acquisition, monitoring, and decision-making modules. The target dynamic permission model needs to establish a tight connection with the data acquisition module to obtain the latest power network operation data in real time. For example, the data acquisition module continuously collects real-time equipment status data from various power devices, including generator output power, voltage, and frequency; transformer load rate and oil temperature; user operation logs; and any changes in network topology connections. The target dynamic permission model receives this data in real time through an interface, ensuring the timeliness and accuracy of its input data.

[0100] Simultaneously, the target dynamic permission model works in conjunction with the monitoring module: the monitoring module is responsible for monitoring the real-time operating status of the power network, while the target dynamic permission model analyzes and processes the received data. For example, if the monitoring module detects abnormal fluctuations in the load of power equipment in a certain area, the target dynamic permission model immediately analyzes the relevant data. Through its internal algorithms and learned patterns, it quickly generates user permission feature sets and device permission feature sets for that area. These feature sets provide the foundation for subsequent resource allocation strategies.

[0101] In achieving real-time permission modeling, the target dynamic permission model continuously and dynamically generates user permission feature sets and device permission feature sets based on constantly updated power network operation data. For example, when new user operation records are collected, or when the operating status of power equipment changes, the model quickly recalculates and updates the corresponding permission features. For instance, when a new maintenance worker joins the system and begins operating a generator, the target dynamic permission model adjusts the worker's user permission features in real time, such as operation frequency features and operation legality tags, based on the type and frequency of their operation and the device's response. Simultaneously, it updates the device permission features, such as resource occupancy rate features and permission conflict detection parameters, in response to changes in the generator's operating parameters. Through this real-time updating method, dynamic modeling of permissions in the power network is achieved, reflecting the constantly changing actual situation.

[0102] In terms of resource allocation strategy generation, the target dynamic permission model utilizes the generated user permission feature set and device permission feature set to quickly formulate a reasonable dynamic power resource allocation strategy. For example, when the model detects that a transformer is overloaded and finds other transformers with redundant resources nearby, it combines user permission features (such as the dispatcher's operating permissions on the equipment) and device permission features (such as resource call relationships and permission constraints between transformers) to generate a dynamic load balancing path. This path may involve transferring some power from the high-load transformer to the low-load transformer, while simultaneously generating permission priority adjustment instructions to restrict low-priority users from performing unnecessary operations on the high-load transformer at this time, in order to ensure the stable operation of the power network.

[0103] By deploying the target dynamic permission model to the power network control system, an integrated process from real-time data acquisition and permission modeling to resource allocation strategy generation is achieved. Based on real-time operational data, the power network control system can quickly and accurately perform permission modeling and resource allocation strategy formulation using the target dynamic permission model, thereby effectively optimizing power network operation, improving power resource utilization efficiency, and ensuring the stability and reliability of power supply.

[0104] In a non-limiting implementation, after feeding back the dynamic allocation strategy of power resources to the power network control system to activate the permission configuration update operation, the method further includes:

[0105] Step S310: Collect the current resource occupancy rate of power equipment and user operation logs after the permission configuration is updated in real time.

[0106] In this embodiment of the application, after the dynamic allocation strategy of power resources is fed back to the power network control system and the permission configuration update operation is successfully activated, the system begins to collect relevant data in real time to continuously monitor and evaluate the operating status of the power network.

[0107] The current resource utilization rate of power equipment is collected in real time through sensors and monitoring devices distributed across various power devices. For example, a power sensor is installed on each generator to monitor its output power in real time, thus reflecting the generator's resource utilization status. For instance, at a certain moment after the permission configuration of generator A is updated, the power sensor shows that its output power is 550 megawatts; this data reflects the current resource utilization rate of generator A at that moment. For transformers, resource utilization rate information is obtained by monitoring their load rate. For example, the load rate monitoring device of transformer B shows that its load rate is 72%, indicating the current resource utilization rate of transformer B. These sensors and monitoring devices transmit the real-time collected data to the data acquisition center of the power network control system, ensuring that the system can obtain the latest resource utilization rate data of power equipment in a timely manner.

[0108] Simultaneously, the system collects user operation logs in real time. These logs record all user actions related to power equipment. For example, if a dispatcher issues a new power generation plan adjustment instruction after updating permission configurations, this operation will be recorded in detail in the user operation log, including the operation time (e.g., [specific time]), operator role (dispatcher), operation target (generator C), and operation content (power generation plan adjustment, reducing output power from 600 MW to 620 MW). Through various user operation terminals and system recording mechanisms, it is ensured that all user actions are accurately and promptly recorded and transmitted to the power network control system's data storage module for subsequent analysis and processing.

[0109] By collecting real-time data on the current resource occupancy rate of power equipment and user operation logs, the power network control system can comprehensively and promptly grasp the operational dynamics of the power network after permission configuration updates. This data provides an important basis for subsequent analysis of the power network's operational effectiveness, detection of any anomalies, and further optimization of power resource allocation strategies.

[0110] Step S320: Calculate the difference between the current resource occupancy rate and the expected allocation value in the dynamic load balancing path to generate a resource deviation index for each power device.

[0111] In this embodiment of the application, in order to assess the degree of conformity between the actual resource occupancy of each power device in the power network and the expected allocation value of the dynamic load balancing path, a difference calculation is performed to generate a resource deviation index.

[0112] First, define the expected allocation values ​​in the dynamic load balancing path. For example, when formulating a dynamic load balancing path, for generator A, its output power is expected to be stable at 500 MW to achieve load balancing and stable operation of the power network; for transformer B, its load rate is expected to remain at around 65%. These expected allocation values ​​are set based on the overall demand of the power network, equipment performance, and the goal of optimizing resource allocation.

[0113] Then, the current resource occupancy rate collected in real time is compared with the expected allocation value for calculation. Taking generator A as an example, the currently collected output power is 550 MW, and the difference between this and the expected allocation value of 500 MW is calculated as 550 - 500 = 50 MW. To more intuitively reflect the degree of deviation, a resource deviation index is calculated. For example, using the relative deviation calculation method, the resource deviation index = (current resource occupancy rate - expected allocation value) / expected allocation value × 100%. Therefore, the resource deviation index of generator A is (550 - 500) / 500 × 100% = 10%.

[0114] For transformer B, the current load rate is 72%, and the expected load rate is 65%. Using the same calculation method, the difference is 72%-65%=7%, and the resource deviation index is (72%-65%) / 65%×100%≈10.77%.

[0115] By calculating the differences for each power device, corresponding resource deviation indices are generated. These indices clearly reflect the degree of deviation between the actual resource utilization of each power device and the expected allocation value of the dynamic load balancing path. The larger the resource deviation index, the greater the difference between the actual operation of the device and the expectation, which may indicate problems such as unreasonable power resource allocation or abnormal device operation, providing a quantitative basis for subsequent analysis and adjustment.

[0116] Step S330: When a resource deviation index exceeds a preset threshold, a secondary calculation instruction for dynamic permission modeling is triggered.

[0117] In this embodiment, to ensure the stable operation of the power network and the rational allocation of resources, a preset threshold is set to monitor the resource deviation of power equipment. Once a resource deviation indicator is found to exceed the preset threshold, the system will automatically trigger a secondary calculation instruction for dynamic permission modeling.

[0118] The preset threshold is determined based on a comprehensive consideration of factors such as the operating experience of the power network, equipment performance, and safety standards. For example, for critical equipment such as generators and transformers, the preset threshold for the resource deviation index is set at 8%. This means that when the resource deviation index of a certain power equipment exceeds 8%, the system determines that the operating status of the equipment deviates significantly from the expected dynamic load balancing path, which may affect the overall performance and stability of the power network.

[0119] For example, the resource deviation index of generator C reached 12%, exceeding the preset threshold of 8%. Upon detecting this, the system immediately triggers a secondary calculation instruction for dynamic permission modeling and notifies the power network control system to restart the dynamic permission modeling process to address potential resource allocation issues in the current power network.

[0120] The purpose of triggering the secondary calculation instruction is to re-examine and analyze the power network's operational data, redetermine the user permission feature set and device permission feature set based on the latest situation, and then generate a dynamic power resource allocation strategy that better meets actual needs. As a result, the system can adjust the power network's operating mode in a timely manner, optimize resource allocation, ensure that power equipment operates within a reasonable range, and improve the reliability and stability of the power network.

[0121] Step S340: Based on the secondary calculation instruction, re-execute the dynamic permission modeling process using the latest collected resource occupancy rate and user operation logs to generate a user permission update feature set and a device permission update feature set.

[0122] In this embodiment of the application, upon receiving the secondary calculation instruction for dynamic permission modeling, the system restarts the dynamic permission modeling process based on the latest collected resource occupancy rate and user operation logs.

[0123] First, a more in-depth analysis of user operation logs was conducted. For example, reviewing the latest recorded user operation behavior revealed changes in the frequency and method of operations performed by maintenance personnel on some devices after permission configuration updates. Taking the operations performed by maintenance personnel on transformer D as an example, the number of inspection operations on transformer D by maintenance personnel increased significantly in the past week, and the operation time also differed from the past in some cases. Through detailed analysis of these operation behaviors, operation type sequences and operation timestamp sequences were extracted. The operation type sequences clearly identified the specific operations performed by maintenance personnel, such as equipment inspections and parameter adjustments; the operation timestamp sequences recorded the specific time of each operation.

[0124] Then, the impact of these sequences is assessed. Combining historical permission change records, the weight of these operations on user permission changes is analyzed. For example, historical data shows that frequent equipment inspection operations may, under certain conditions, affect the scope of operation permissions for maintenance personnel on that equipment. After calculation and analysis, the weight of the impact of this equipment inspection operation on the maintenance personnel's permission change is determined to be 0.3. Simultaneously, based on the operation timestamp sequence, a distribution of permission change time intervals is generated, revealing that the time intervals between operations on transformer D by maintenance personnel are gradually shortening, indicating more frequent operations. Analyzing the dynamic correlation between this time interval distribution and the frequency of permission adjustments provides a basis for subsequently calculating the correlation strength of permission status.

[0125] The generation of the device permission feature set is based on the latest collected resource utilization data and network topology connections. For example, the latest resource utilization data for transformer D shows a load rate of 78%, which is higher than before. Simultaneously, considering transformer D's location in the network topology and its connections with other devices, its resource usage and potential permission sharing constraints are analyzed. It was found that changes in the load of surrounding devices have increased resource contention pressure on transformer D. Through these analyses, resource utilization characteristics, resource contention coefficient characteristics, and resource call path characteristics of transformer D are extracted as part of the device permission update feature set.

[0126] By re-executing the dynamic permission modeling process and comprehensively considering the latest collected data and actual operating conditions, user permission update feature sets and device permission update feature sets are generated. These updated feature sets can more accurately reflect the current operating status of the power network and the actual situation of user and device permissions, providing a more reliable basis for the subsequent regeneration of dynamic power resource allocation strategies.

[0127] Step S350: Regenerate the dynamic allocation strategy of power resources based on the user permission update feature set and the device permission update feature set, and trigger the permission configuration overwrite operation.

[0128] In this embodiment, based on the newly generated user permission update feature set and device permission update feature set, the dynamic allocation strategy for power resources is generated again, and the permission configuration overriding operation is triggered to adapt to the current operating status of the power network.

[0129] First, an in-depth analysis was conducted on the user permission update feature set and the device permission update feature set. For example, the user permission update feature set shows that due to changes in the operation behavior of maintenance personnel towards transformer D, their operation permissions for this device may need to be adjusted. Simultaneously, the device permission update feature set indicates that the resource occupancy rate of transformer D has increased, and the pressure of resource competition has intensified, necessitating a replanning of its resource allocation path.

[0130] Based on these feature sets, the user-device permission matching degree is recalculated. For example, a new matching degree is calculated between maintenance personnel and transformer D. For instance, if the frequency of maintenance personnel's operation on transformer D increases, and the resource utilization rate of transformer D rises, a new matching degree value is obtained using a preset calculation method (such as the previously mentioned matching degree = access frequency / resource utilization rate). Comparing this with the previous matching degree reveals a significant difference, indicating that the power resource allocation strategy needs to be adjusted.

[0131] Based on the new matching degree and factors such as the resource competition situation of the equipment, a new dynamic load balancing path is generated. For example, considering the high load and resource competition pressure of transformer D, it is found that the adjacent transformer E has a lower load and corresponding redundant resources. Therefore, a new dynamic load balancing path is formulated to transfer some power from the line where transformer D is located to transformer E, and then transformer E distributes it to other demand areas. This new path includes the target set of equipment for resource reallocation (such as transformers D, E and related distribution nodes) and data transmission delay parameters.

[0132] Simultaneously, instructions for adjusting permission priorities are generated. For example, given that operations performed by maintenance personnel on transformer D may affect its stable operation, it is stipulated that when the load rate of transformer D exceeds 80%, some non-emergency operation permissions of maintenance personnel will be further restricted to ensure the normal operation of the equipment.

[0133] The newly generated dynamic load balancing path and permission priority adjustment instructions are combined to form a new dynamic power resource allocation strategy. Then, a permission configuration overwrite operation is triggered. The system overwrites the original permission configuration with the permission configuration information from the new dynamic power resource allocation strategy, such as adjustments to user permission scopes and updates to device resource response rules. This ensures that the power network control system operates according to the new strategy, achieving a rational reallocation of power resources, improving the operational efficiency and stability of the power network, and addressing current resource allocation problems and changes in user permissions within the power network.

[0134] In a non-limiting implementation, after feeding back the dynamic allocation strategy of power resources to the power network control system to activate the permission configuration update operation, the method further includes:

[0135] Step S410: Intercept all user access requests to critical power equipment within a preset time period.

[0136] In this embodiment of the application, after the dynamic allocation strategy of power resources is fed back to the power network control system and the permission configuration update operation is activated, in order to ensure the stable operation of critical power equipment during the permission configuration update period, the system will intercept all user access requests to critical power equipment within a preset time period.

[0137] The preset time period is set based on experience and considerations for the stability of the power network system. For example, the preset time period is set to the next 30 minutes after the permission configuration update operation is completed. During this time period, the system uses access control mechanisms to block all access requests destined for critical power equipment. Critical power equipment refers to equipment that is essential to the operation of the power network, such as large generators and core transformers. For example, generator F, as the main power supply equipment in the power network, and transformer G, as a hub connecting multiple important areas, are both considered critical power equipment.

[0138] When a user initiates an access request to critical power equipment, the system automatically detects and intercepts these requests. For example, if a dispatcher attempts to issue a power adjustment command to generator F within a preset time period, this request will be identified and blocked by the system's access control module. The system will send a notification to the dispatcher, informing them that access to the critical power equipment is temporarily restricted for the preset time period. This ensures the stable operation of the equipment and the smooth updating of permission configurations. Thus, it avoids potential problems such as abnormal operation of power equipment or confusion in permission configurations caused by improper user access operations during permission configuration updates, providing a guarantee for a stable transition of the power network.

[0139] Step S420: Compare the user role identifier in the access request with the latest permission range in the user permission configuration table in real time.

[0140] In this embodiment of the application, after intercepting a user's access request to critical power equipment, the system will compare the user role identifier in the access request with the latest permission range in the user permission configuration table in real time to determine whether the access request is legitimate.

[0141] The system first extracts the user role identifier from the access request. For example, when a dispatcher initiates an access request for generator F, the request information includes the dispatcher's identity identifier. Then, the system quickly queries the user permission configuration table, which stores the latest user permission scope information. For example, the user permission configuration table explicitly defines the scope of operation permissions for generator F under specific circumstances (such as generator F being in a partially operational state or during permission configuration updates) for the dispatcher role. For instance, during the current permission configuration update, the dispatcher's operation permissions for generator F are limited to emergency fault handling operations.

[0142] The system compares the extracted user role identifier with the corresponding permission range in the user permission configuration table in real time. Using a precise matching algorithm, it checks whether the dispatcher's access request is within the permission range specified in the permission configuration table. For example, if the dispatcher initiates a request to adjust the power of generator F as a routine operation, and the user permission configuration table explicitly prohibits such operations within the current preset time period, the comparison result will show that the access request exceeds the permission range. Conversely, if the dispatcher initiates a request to handle a sudden emergency failure of generator F, and this meets the permission requirements in the user permission configuration table for emergency situations, the comparison result will show that the access request is within the permission range.

[0143] The aforementioned real-time comparison mechanism ensures that only access requests that conform to the latest permission scope can be further processed, effectively preventing users from making illegal access operations due to unclear permissions or permission changes, ensuring the security and stability of critical power equipment during special periods (such as during permission configuration updates), and maintaining the order and reliability of power network operation.

[0144] Step S430: When an unauthorized access request is detected, a permission interception log is generated and a temporary lock command of the device resource response rule is triggered.

[0145] In this embodiment of the application, once the system detects an unauthorized access request after comparing the user role identifier in the access request with the latest permission range in the user permission configuration table in real time, it will perform a series of corresponding operations to ensure the safe and stable operation of the power network.

[0146] First, the system generates an access control log. This log records detailed information about each unauthorized access request, including the time the request was initiated, the user's role, the critical power equipment attempted to be accessed, and the reason for the unauthorized access. For example, at [specific time], dispatcher [name] initiated an access request to adjust the non-emergency power of generator F. Because this operation is outside the scope of permissions defined in the current user permission configuration table, the system classifies the request as unauthorized access and records this information in the access control log. This logging not only helps in subsequent auditing and tracing of system security incidents but also provides data support for analyzing user permission usage and optimizing permission configurations.

[0147] Simultaneously, the system triggers a temporary lock command for the device resource response rules. This command aims to prevent unauthorized access from potentially causing adverse effects on critical power equipment. Taking generator F as an example, when an unauthorized access request is detected, the system sends a temporary lock command to generator F's controller. Upon receiving the command, the controller immediately activates the corresponding protection mechanism, temporarily locking some of the device's resource response functions. For example, it prohibits modification of generator F's power regulation parameters and closes interfaces for non-emergency maintenance operations. Through this temporary lock measure, it ensures that important parameters and operations of critical power equipment are not arbitrarily changed during unauthorized access, thereby guaranteeing the stable operation of the equipment and the security of the power network.

[0148] By generating permission interception logs and triggering temporary lock commands for device resource response rules, the system can promptly respond to unauthorized access requests, record relevant information for subsequent analysis and processing, and take effective measures to protect critical power equipment and prevent power network failures or security risks caused by illegal operations.

[0149] Step S440: Based on the permission interception log, trace back to the dynamic evolution graph of user permissions and correct the judgment threshold of the operation legality label.

[0150] In this embodiment of the application, the system corrects the operation legality label judgment threshold in the user permission dynamic evolution graph based on the generated permission interception log, so as to further optimize user permission management and improve the security of the power network.

[0151] The access control logs record detailed information about unauthorized access requests, providing crucial clues for tracing the dynamic evolution of user permissions. For example, the logs show that over a period of time, maintenance personnel repeatedly performed certain operations on a transformer that were deemed unauthorized. By analyzing these logs, the specific types of these unauthorized access operations, the times they occurred, and the relevant user roles and device information can be determined.

[0152] Based on this information, we traced back to the dynamic evolution graph of user permissions. This graph records the changes in user role permission status at different times and the relationship between operations and permissions. For example, the graph shows the operation trajectories of maintenance personnel on transformers at different times, along with the corresponding operation legality tags. Analysis revealed that the current operation legality tag judgment thresholds might not be set accurately enough, causing some operations that should have been restricted to not be identified as illegal operations in a timely manner.

[0153] Based on this, the threshold for determining the legitimacy of operations is revised. For example, if it is found that some unnecessary operations performed by maintenance personnel when the equipment load rate is high are frequently blocked, it indicates that the current threshold for determining the legitimacy of these operations may be too high. Therefore, the threshold for determining the legitimacy of such operations under high load conditions is lowered. Specifically, previously, when the equipment load rate reached 80%, a certain maintenance operation was still considered legitimate; now, the threshold is adjusted to 75%, meaning that when the equipment load rate reaches 75% or higher, the maintenance operation will be considered illegitimate.

[0154] Therefore, based on actual unauthorized access incidents, the threshold for determining the legality of operations in the user permission dynamic evolution graph is dynamically adjusted and optimized. This makes user permission determination more accurate and stringent, better adapts to the actual operational needs of the power network, further ensures the safe and stable operation of the power network, and prevents potential risks caused by improper permission management.

[0155] Step S450: Regenerate the device control priority update parameters using the corrected user permission dynamic evolution graph, and send the device control priority update parameters to the device controller in real time.

[0156] In this embodiment of the application, the modified user permission dynamic evolution graph is used to regenerate the device control priority update parameters to ensure that power equipment can be controlled and managed according to reasonable priorities under different circumstances, thereby ensuring the stable operation of the power network.

[0157] The revised user permission dynamic evolution graph more accurately reflects the relationship between user permissions and operations, as well as the legality determination of operations under different circumstances. Based on this graph, we analyze the changes in the operation permissions of different user roles for various types of power equipment and the changes in the operating status of the equipment itself. For example, the graph shows that with the adjustment of maintenance personnel permissions and changes in operating parameters such as equipment load rate, the control priority of some equipment may need to be reassessed.

[0158] For critical equipment such as generators, the equipment control priority update parameters are recalculated based on information from the power grid map, considering the impact of different user operations on their operational stability and the overall needs of the power network. For example, if it is found that the dispatcher's operating permissions for the generator have changed under the target conditions, and this change affects the generator's power supply priority in the power network, then a new equipment control priority is calculated based on the relevant data and rules in the power grid map. For instance, if the generator's control priority during normal operation was originally 3 (priority is divided into 5 levels, with 1 being the highest and 5 being the lowest), after analysis, it is found that under the current user permission adjustment and equipment operating status, in order to ensure the stability and reliability of power supply, its control priority is increased to 2.

[0159] Optionally, after generating these device control priority update parameters, the system sends them to the device controllers in real time. Through the communication mechanism of the power network control system, the updated parameters are accurately transmitted to the controllers of the relevant devices. For example, for the generator mentioned above, after receiving the instruction with an updated control priority parameter of 2, its controller will immediately adjust its internal control strategy. In subsequent operation, when faced with multiple operation requests or resource allocation decisions, the generator controller will process them according to the new priority parameters, prioritizing high-priority operation requests to ensure that the generator's operation better meets the overall needs of the power network, improving the efficiency and stability of power network operation. Thus, by utilizing the revised user permission dynamic evolution graph, dynamic adjustment and optimization of device control priorities are achieved, ensuring the safe, stable, and efficient operation of the power network under various conditions.

[0160] In a non-limiting embodiment, after feeding back the dynamic allocation strategy of power resources to the power network control system to activate the permission configuration update operation, the method further includes:

[0161] Step S510: Continuously monitor the actual response latency data of each link in the dynamic load balancing path.

[0162] The purpose of continuously monitoring actual response latency data is to promptly detect whether link response latency exceeds the expected range and whether there are any unstable or abnormal fluctuations. This is crucial for ensuring the normal operation of the power network, as excessively long or unstable response latency may lead to problems such as untimely power distribution and difficulties in equipment coordination, affecting the overall performance and reliability of the power network. By acquiring this data in real time, the system can take timely measures to address potential problems and ensure the stable operation of the dynamic load balancing path.

[0163] Step S520: When the delay data of the target link is detected to exceed the maximum constraint value in the device permission dependency graph, a path switching trigger signal is generated.

[0164] In this embodiment, to avoid adverse effects on the power network due to excessive delays, the system immediately generates a path switching trigger signal and notifies the power network control system that the current dynamic load balancing path needs to be adjusted, switched to a backup path, or a new path needs to be planned to ensure that power can be transmitted to where it is needed in a timely and stable manner. The path switching trigger signal includes the target link identifier, delay data, and related path switching requirements, so that the power network control system can accurately perform subsequent operations based on the signal, quickly respond to and resolve problems caused by excessive link delays, and maintain the stable and reliable operation of the power network.

[0165] Step S530: Extract the redundant resource parameters of the backup device from the network topology connection relationship according to the path switching trigger signal.

[0166] In this embodiment, upon receiving a path switching trigger signal, the system extracts redundant resource parameters of the backup equipment from the network topology connection relationship based on the signal, providing necessary information for subsequent replanning of power transmission paths. For example, by extracting redundant resource parameters of the backup equipment from the network topology connection relationship, the system obtains key information required for replanning power transmission paths. These parameters help the system assess whether the backup equipment can meet the current power transmission needs, as well as the transmission capacity and stability of the backup path, laying the foundation for generating new load migration paths based on this information and ensuring the normal operation of the power network.

[0167] Step S540: Recalculate the load migration path based on the redundant resource parameters and generate a local load balancing optimization instruction.

[0168] In this embodiment, after obtaining the redundant resource parameters of the backup equipment, the system recalculates the load migration path based on these parameters to generate local load balancing optimization instructions, thereby achieving reasonable adjustment and optimization of the load in the power network. It can be understood that by generating local load balancing optimization instructions, the system provides clear operational guidance to the power network control system, enabling it to quickly and accurately execute load migration operations, achieve load balancing in local areas, improve the operating efficiency and stability of the power network, resolve load imbalances caused by link delays and other issues, and ensure the reliability of power supply.

[0169] Step S550: Insert the optimization instruction into the current execution queue of the power network control system, interrupt the resource allocation of the original path and activate the real-time response of the new path.

[0170] In this embodiment, after generating a local load balancing optimization instruction, the system inserts the instruction into the current execution queue of the power network control system. This interrupts the resource allocation of the original path and activates the real-time response of the new path, ensuring that the power network can quickly adjust to a new load balancing state. It can be understood that by inserting the optimization instruction into the execution queue, interrupting the resource allocation of the original path, and activating the real-time response of the new path, the power network control system can quickly react to problems such as link latency, adjust the power transmission path in a timely manner, ensure the stable operation of the power network, avoid problems such as insufficient power supply or equipment overload caused by abnormalities in the original path, and ensure that the power network can continuously and reliably provide power services to users.

[0171] Based on the same inventive concept, embodiments of this application also provide a power network data-driven optimization system. See also... Figure 2 As shown, this is a schematic diagram of a possible power network data-driven optimization system provided in an embodiment of this application. Figure 2 In the power network data-driven optimization system 200, a processor 210 and a memory 220 are included. The memory 220 stores computer programs that can be executed by the processor 210. By executing the instructions stored in the memory 220, the processor 210 can perform the steps of the power network data-driven optimization method based on dynamic permission modeling described above.

[0172] Based on the same inventive concept, embodiments of this application provide a computer-readable storage medium including a computer program. When the computer program runs on a power network data-driven optimization system, it causes the power network data-driven optimization system to perform the steps of the aforementioned power network data-driven optimization method based on dynamic permission modeling. In some possible implementations, various aspects of the power network data-driven optimization method based on dynamic permission modeling provided in this application can also be implemented as a program product including a computer program. When the program product runs on a power network data-driven optimization system, the computer program causes the power network data-driven optimization system to perform the steps of the aforementioned power network data-driven optimization method based on dynamic permission modeling. For example, the power network data-driven optimization system can perform actions such as... Figure 1 The steps are shown in the figure.

[0173] In the technical solutions involved in the above embodiments of the present invention, whether performing comparison calculations of multi-dimensional features or constructing composite parameters, if there are problems caused by significant differences in the number of dimensions, units of measurement, and semantic meanings of different features, those skilled in the art, based on their professional knowledge and past practical experience, can fully understand that these differences need to be properly handled so that the calculation results are accurate and comparable, and to avoid situations such as logical confusion and unclear mathematical meaning.

[0174] The formulas and calculation processes involved in the embodiments of this application, whether used for multidimensional feature comparison or composite loss function construction, strictly adhere to the principle of dimensional correspondence. Each variable in the formula has a clear and explicit physical meaning, and its operational logic fully conforms to basic mathematical and physical logic. The calculation results are necessarily the reasonable results expected by this application. Those skilled in the art are capable of effectively solving various problems arising from the number of dimensions, dimensional differences, etc., in the multidimensional feature comparison calculation and composite loss function construction in the embodiments, based on specific data conditions and business needs, by comprehensively utilizing the above-mentioned general technical means, thus ensuring the accuracy, reliability, and implementability of the technical solution of this invention.

Claims

1. A data-driven optimization method for power networks based on dynamic permission modeling, characterized in that, The method includes: Acquire a set of power network operation data, which includes real-time equipment status data, user operation behavior logs, and network topology connection relationships; Dynamic permission modeling is performed on the power network operation data set to generate a user permission feature set and a device permission feature set. The user permission feature set represents the access control parameters of different user roles to power resources, and the device permission feature set represents the resource allocation permissions of different power devices in the operating environment. Based on the user permission feature set and the device permission feature set, a dynamic power resource allocation strategy is generated; the dynamic power resource allocation strategy is used to adjust the load balancing path and device control priority in the power network. The dynamic allocation strategy of power resources is fed back to the power network control system to activate the permission configuration update operation, which includes adjusting the scope of user operation permissions and the resource response rules of power equipment. The dynamic permission modeling process performed on the power network operation data set to generate user permission feature sets and device permission feature sets includes: Extract the operation type sequence and operation timestamp sequence from the user operation behavior log. The operation type sequence includes the type of control command for the power equipment by the user role and the corresponding number of operations. Based on the operation type sequence and the operation timestamp sequence, a dynamic evolution map of user permissions is generated; the dynamic evolution map of user permissions includes the trajectory of changes in the operation permissions of a user role within a preset time window; The network topology connections are analyzed to generate a device permission dependency graph; the device permission dependency graph reflects the resource access relationships and permission sharing constraints between power devices. Based on the dynamic evolution graph of user permissions and the dependency graph of device permissions, a user permission feature set and a device permission feature set are constructed; wherein, the user permission feature set includes the access frequency characteristics of user roles to target power equipment and operation legality tags, and the device permission feature set includes the resource occupancy rate characteristics of power equipment and permission conflict detection parameters; The step of generating a dynamic evolution graph of user permissions based on the operation type sequence and the operation timestamp sequence includes: The impact of the operation type sequence on user permissions is evaluated. Based on the probability calculation of different operation types triggering permission adjustments in historical permission change records, the impact weight of each operation type on user permission changes is determined. Based on the operation timestamp sequence, a permission change time interval distribution is generated. The time interval distribution is used to characterize the dynamic correlation between the time density of user operation behavior and the frequency of permission adjustment. The influence weights are correlated with the time interval distribution to calculate the correlation strength of the user role's permission status within a continuous time window, generating node connection strength parameters in the dynamic evolution graph of user permissions; the node connection strength parameters quantify the probability and temporal dependency of permission status transitions between adjacent time windows. A dynamic permission state transition matrix is ​​constructed based on the node connection strength parameters, wherein: the row dimension of the matrix represents the permission state set of the current time window, the column dimension represents the permission state set of the next time window, and the matrix element values ​​are obtained by normalizing the corresponding node connection strength parameters, which are used to reflect the transition weight of permission states across time windows. The spatiotemporal topology of the dynamic permission state transition matrix is ​​generated as follows: the permission state of each time window is mapped to a time-series node with a timestamp attribute, and adjacent time-series nodes are connected in the order of time evolution to form directed edges. Each directed edge carries a normalized connection strength weight value. A multi-dimensional permission feature vector is embedded in the time sequence node. The multi-dimensional permission feature vector is composed of the operation type distribution histogram, the cumulative value of permission influence, and the statistical features of the time interval distribution within the corresponding time window. By fusing the spatiotemporal topology and the multidimensional permission feature vector, the user permission dynamic evolution graph is generated, wherein: the topological edge weights of the user permission dynamic evolution graph represent the permission state transition probability, the node feature vectors characterize the dynamic attributes of the permission state, and the user permission dynamic evolution graph is a visual graph model containing time-dimensional evolution paths and spatial-dimensional permission association rules. The step of generating a dynamic power resource allocation strategy based on the user permission feature set and the device permission feature set includes: The access frequency feature in the user permission feature set and the resource occupancy rate feature in the device permission feature set are matched to calculate the degree of matching, and a user-device permission matching matrix is ​​generated. The set of target power devices with resource conflicts is determined based on the user-device permission matching matrix; the resource conflicts include user access requests exceeding the device resource capacity or permission sharing rules not meeting security constraints. Based on the resource conflict types of the target power equipment set, a dynamic load balancing path and a permission priority adjustment instruction are generated, and a dynamic power resource allocation strategy is determined by combining the dynamic load balancing path and the permission priority adjustment instruction; the dynamic load balancing path is used to reallocate resource call links between power equipment, and the permission priority adjustment instruction is used to restrict the access permissions of low-priority users to critical load equipment. The step of generating a dynamic load balancing path includes: Obtain real-time load rate data and topology connection status of each device in the power network; A heat map of equipment load distribution is constructed based on the real-time load rate data. The heat map of equipment load distribution reflects the remaining resource capacity and overload risk level of power equipment in different areas. Based on the device load distribution heatmap and the topology connection status, multiple candidate load balancing paths are generated; each candidate load balancing path includes a set of target devices for resource reallocation and data transmission latency parameters. Based on the data transmission delay parameters and overload risk level, the optimal path is selected from the candidate load balancing paths as the dynamic load balancing path. Based on the device load distribution heatmap and the topology connection status, multiple candidate load balancing paths are generated, including: Identify standby device nodes with redundant resource capacity in the network topology connection relationship; Based on the remaining resource capacity of the backup device node and its physical distance from the critical load device, a backup resource call link is generated; The backup resource call link is combined with the current resource call path to form a candidate load balancing path with N levels of resource allocation; wherein, the N levels of resource allocation correspond to load migration schemes with different response speeds. The step of feeding back the dynamic allocation strategy of power resources to the power network control system to activate the permission configuration update operation includes: Receive dynamic load balancing path and permission priority adjustment instructions through the policy parsing interface of the power network control system; A path configuration confirmation signal is generated based on the dynamic load balancing path, and the path configuration confirmation signal is transmitted to the target power equipment controller to activate the link switching operation; When the link switching operation is completed, capture the device response status code and synchronize and verify the device response status code with the permission priority adjustment instruction. Based on the device response status code that has passed verification, the update process of the user role access control list is triggered to generate a user permission configuration table containing the new permission scope; Write the user permission configuration table into the access authorization database of the power network control system, and update the priority sorting parameters of the device resource response rules at the same time. Obtain the write completion identifier of the access authorization database in real time, and activate the network-wide permission policy effective instruction based on the write completion identifier; The power network control system is driven to perform synchronous broadcast of permission configuration by the instruction to activate the network-wide permission policy, thereby generating a permission update broadcast confirmation queue. After all power devices in the permission update broadcast confirmation queue return confirmation responses, a permission configuration update completion flag is generated and stored in the system log.

2. The method as described in claim 1, characterized in that, The step of performing device association resolution on the network topology connections to generate a device permission dependency graph includes: Analyze the device hierarchy in the network topology connection relationship to determine the resource call path between the master control device and the controlled device; Based on the resource occupancy rate data in the real-time device status data, the resource competition coefficient between the master control device and the controlled device is calculated; the resource competition coefficient reflects the probability of conflict when the master control device allocates resources to the controlled device. Based on the resource call path and the resource competition coefficient, a device node weight and edge connection rule are generated corresponding to the device permission dependency graph. The device node weight is used to identify the priority of power equipment in resource allocation, and the edge connection rule is used to constrain the maximum resource threshold for permission sharing between devices. Based on the device node weights and the edge connection rules, a device permission dependency graph is generated.

3. The method as described in claim 1, characterized in that, The method also includes real-time monitoring of the power network operation status after permission configuration updates: The system periodically polls the equipment resource utilization rate acquisition interface of the power network control system to extract the updated real-time resource utilization rate dataset. Synchronously scan the storage partition of user operation behavior logs to obtain user operation response log records after permission configuration updates; The real-time resource utilization dataset is compared item by item with the baseline resource allocation template of the expected load balancing path to generate a set of device-level resource deviation indicators. The user operation response logs are simultaneously compared with the user permission configuration table to verify their legality, and a list of user operation violation events is generated. Aggregate the set of device-level resource deviation indicators and the list of user operation violation events to generate a global resource allocation anomaly detection report; When the global resource allocation anomaly detection report contains a device-level resource deviation index exceeding a preset threshold or a non-empty user operation violation event, a permission conflict alarm trigger signal is generated. Based on the permission conflict alarm trigger signal, the restart interface of dynamic permission modeling is invoked to inject the latest equipment status snapshot and user operation record into the power network operation data set; After injection is completed, the process of regenerating the user permission dynamic evolution graph and the device permission dependency graph is activated to trigger the calculation of the new allocation strategy.

4. The method as described in claim 1, characterized in that, The method also includes a training process for the target dynamic permission model: Obtain historical power network operation datasets and corresponding optimization strategy execution effect data; Permission features and conflict events are extracted from the historical power network operation dataset to generate a model training sample set; An initial dynamic permission model is trained using a reinforcement learning algorithm to obtain a target dynamic permission model; the target dynamic permission model outputs a set of user permission features and a set of device permission features that match the data on the execution effect of the optimization strategy based on the input power network operation data set. The target dynamic permission model is deployed to the power network control system to achieve real-time permission modeling and resource allocation strategy generation.

5. A data-driven optimization system for power networks, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the steps of any of claims 1 to 4.

Citation Information

Patent Citations

  • Real-time hierarchical distribution method for power cloud resources of digital power grid

    CN119603304A

  • Cloud-native-based power grid real-time data parallel processing system and method

    CN119917254A