Authentication method, device and equipment of power secondary system, medium and product

By conducting security assessments and credibility analyses on the verification browsing information of the power secondary system, the network security threats to the power secondary system were resolved, identity authentication and access control were implemented, and the security and traceability of remote access were ensured.

CN120850264APending Publication Date: 2025-10-28CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510881463.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

The power secondary system faces cybersecurity threats. Traditional firewalls are unable to defend against professional-level attacks, system vulnerabilities are easy targets, and patch-based protection is passive and unable to cope with rapidly changing security threats.

Method used

By acquiring the target user's verification browsing information, and utilizing pre-set verification security assessment models, permission security analysis models, and operation credibility analysis models, identity authentication and access control are performed to ensure secure remote access.

Benefits of technology

It enables identity authentication and access control for the power secondary system, effectively resisting external attacks, ensuring system information security, improving operation and maintenance efficiency, and reducing the risk of human error.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120850264A_ABST
    Figure CN120850264A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication method, device and equipment for an electric power secondary system, a medium and a product. The method comprises the following steps: acquiring verification browsing information of accessing the electric power secondary system by a target user; performing verification security evaluation on the verification information to obtain a verification security evaluation result of the target user; performing permission security analysis on the verification security evaluation result and the permission allocation level of the target user to obtain a permission security analysis result of the target user; performing operation credibility analysis on the permission security analysis result and the browsing path information to obtain an operation credibility analysis result of the target user; and carrying out operation early warning according to an operation credibility analysis result. According to the method, operation credibility analysis can be performed on the verification browsing information based on the verification browsing information of the target user accessing the power secondary system, identity authentication and authority control can be performed on each node of the power secondary system, remote access security of the power secondary system is ensured, external attacks are effectively resisted, and system information security is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system technology, and in particular to a method, apparatus, equipment, medium and product for the authentication of a power secondary system. Background Art

[0002] As a critical national infrastructure, the security of the power system is directly related to the national economy, people's livelihood, and national security. In recent years, with the rapid development of network technology and the continuous upgrading of network attack methods, the power system faces increasingly severe cybersecurity threats. As a core component of the power system, the power secondary system faces numerous security threats: on the one hand, the operating environment of the power secondary system is vulnerable to external attacks; traditional firewalls are insufficient to defend against professional-level security threats, protection measures for the power system's special communication protocols are inadequate, and malicious code attacks are difficult to defend against; on the other hand, the computer network of the power secondary system itself has security vulnerabilities, such as operating system and software vulnerabilities, open network ports that are easy targets for attacks, and staff do not update system patches in a timely manner. The traditional "patching" protection method is passive and cannot cope with rapidly changing security threats. Therefore, the power secondary system has significant security vulnerabilities. Summary of the Invention

[0003] This invention provides an authentication method, apparatus, device, medium, and product for a power secondary system. Based on the verification browsing information of a target user accessing the power secondary system, the invention performs operational credibility analysis on the verification browsing information to achieve identity authentication and access control for each node of the power secondary system, ensuring the security of remote access to the power secondary system, effectively resisting external attacks, and protecting system information security.

[0004] To achieve the above objectives, embodiments of the present invention provide a method for authenticating a power secondary system, comprising:

[0005] Obtain the verification browsing information of the target user accessing the power secondary system; wherein, the verification browsing information includes verification information and browsing path information;

[0006] A preset verification security assessment model is used to assess the verification information to obtain the verification security assessment result of the target user.

[0007] Using a preset permission security analysis model, permission security analysis is performed on the verification security assessment results and the permission allocation level of the target user to obtain the permission security analysis results of the target user;

[0008] Using a preset operation credibility analysis model, the operation credibility analysis is performed on the permission security analysis results and the browsing path information to obtain the operation credibility analysis results of the target user;

[0009] Operational warnings will be issued based on the results of the operation credibility analysis.

[0010] As an improvement to the above scheme, if the verification information includes login password input information and login username;

[0011] The step of using a preset verification security assessment model to perform a verification security assessment on the verification information to obtain the verification security assessment result for the target user includes:

[0012] A preset verification security assessment model is used to perform a verification security assessment on the login password input information and login username to obtain the verification security assessment result of the target user.

[0013] As an improvement to the above solution, a preset permission security analysis model is used to perform permission security analysis on the verification security assessment results and the permission allocation level of the target user, to obtain the permission security analysis results of the target user, including:

[0014] Acquire data on the number of user interfaces accessed by the target user to the power secondary system and data on the total number of interfaces that can be accessed by the power secondary system.

[0015] Based on the number of user interfaces and the total number of interfaces, determine the permission allocation level for the target user;

[0016] Using a preset permission security analysis model, permission security analysis is performed on the verification security assessment results and the permission allocation level to obtain the permission security analysis results of the target user.

[0017] As an improvement to the above solution, the step of employing a preset operation credibility analysis model to perform operation credibility analysis on the permission security analysis results and the browsing path information, and obtaining the operation credibility analysis results of the target user, includes:

[0018] Determine the browsing access anomaly coefficient of the target user based on the browsing path information;

[0019] Using a preset operation credibility analysis model, the operation credibility analysis results of the permission security analysis results and the browsing access anomaly coefficient are analyzed to obtain the operation credibility analysis results of the target user.

[0020] As an improvement to the above solution, the step of issuing an operation warning based on the operation credibility analysis result includes:

[0021] If the operation credibility analysis result is greater than or equal to the preset operation credibility threshold, then the user access of the target user is displayed as normal.

[0022] If the operation credibility analysis result is less than the preset operation credibility threshold, then the user access of the target user is displayed as abnormal, so as to provide an operation warning.

[0023] To achieve the above objectives, embodiments of the present invention provide an authentication device for a power secondary system, comprising:

[0024] The information acquisition module is used to acquire the verification browsing information of the target user accessing the power secondary system; wherein, the verification browsing information includes verification information and browsing path information;

[0025] The security assessment module is used to perform a security assessment on the verification information using a preset security assessment model, and obtain the security assessment result of the target user.

[0026] The permission analysis module is used to perform permission security analysis on the verification security assessment results and the permission allocation level of the target user using a preset permission security analysis model, so as to obtain the permission security analysis results of the target user.

[0027] The trust analysis module is used to perform operation trust analysis on the permission security analysis results and the browsing path information using a preset operation trust analysis model, so as to obtain the operation trust analysis results of the target user.

[0028] The operation warning module is used to issue operation warnings based on the operation credibility analysis results.

[0029] To achieve the above objectives, embodiments of the present invention provide an authentication device for a power secondary system, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the above-described authentication method for the power secondary system.

[0030] To achieve the above objectives, embodiments of the present invention also provide a computer-readable storage medium, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the above-described authentication method for the power secondary system.

[0031] To achieve the above objectives, embodiments of the present invention also provide a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the above-described power secondary system authentication method.

[0032] Compared with existing technologies, the present invention discloses an authentication method, apparatus, device, medium, and product for a power secondary system. This method acquires verification browsing information of a target user accessing the power secondary system. The verification browsing information includes verification information and browsing path information. A preset verification security assessment model is used to perform a verification security assessment on the verification information, yielding a verification security assessment result for the target user. A preset permission security analysis model is used to perform permission security analysis on the verification security assessment result and the permission allocation level of the target user, yielding a permission security analysis result for the target user. A preset operation credibility analysis model is used to perform operation credibility analysis on the permission security analysis result and the browsing path information, yielding an operation credibility analysis result for the target user. An operation warning is then issued based on the operation credibility analysis result. This method enables operation credibility analysis of the verification browsing information of a target user accessing the power secondary system, achieving identity authentication and permission control for each node of the power secondary system, ensuring the security of remote access to the power secondary system, effectively resisting external attacks, and protecting system information security. Attached Figure Description

[0033] Figure 1 This is a flowchart illustrating a certification method for a power secondary system provided in an embodiment of the present invention;

[0034] Figure 2 This is a schematic diagram of a trusted computing platform structure provided in an embodiment of the present invention;

[0035] Figure 3 This is a schematic diagram of the structure of an authentication device for a power secondary system provided in an embodiment of the present invention;

[0036] Figure 4 This is a structural block diagram of a power secondary system certification device provided in an embodiment of the present invention. Detailed Implementation

[0037] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0038] It should be noted that the terms "comprising" and "specific" in this invention, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or device.

[0039] Please see Figure 1 , Figure 1 This is a flowchart illustrating an authentication method for a power secondary system provided in an embodiment of the present invention. The authentication method for the power secondary system includes:

[0040] S1, Obtain the verification browsing information of the target user accessing the power secondary system; wherein, the verification browsing information includes verification information and browsing path information;

[0041] S2, using a preset verification security assessment model, perform a verification security assessment on the verification information to obtain the verification security assessment result of the target user;

[0042] S3, using a preset permission security analysis model, perform permission security analysis on the verification security assessment results and the permission allocation level of the target user to obtain the permission security analysis results of the target user;

[0043] S4, using a preset operation credibility analysis model, perform operation credibility analysis on the permission security analysis results and the browsing path information to obtain the operation credibility analysis results of the target user;

[0044] S5, issue an operation warning based on the operation credibility analysis results.

[0045] For example, the authentication method for a power secondary system described in this embodiment of the invention is implemented by a trusted computing platform, which is capable of interacting with the target user and with the power secondary system. See also Figure 2 , Figure 2This is a schematic diagram of a trusted computing platform structure provided by an embodiment of the present invention. The trusted computing platform includes a verification information acquisition module, a verification security assessment module, a permission management and analysis module, an operation credibility analysis module, an early warning module, and a control module. The verification information acquisition module is used to acquire verification information during user login and browsing path information during browsing, including a verification information acquisition unit and a browsing operation path acquisition unit. The verification security assessment module is used to perform a verification security assessment on the verification information. The permission management and analysis module is used to perform permission security analysis on the verification security assessment results and permission allocation levels. The operation credibility analysis module is used to perform operation... The system performs credibility analysis; the early warning module is used to issue operation warnings based on the operation credibility analysis results, and includes a data comparison unit and an access warning unit; the control module is used to control the operation of the verification information acquisition module, the verification security assessment module, the permission management analysis module, the operation credibility analysis module, and the early warning module; wherein, the verification information acquisition unit is used to acquire the password input and login name output data of the target user's login verification, and the browsing operation path acquisition unit is used to acquire the visitor's (target user's) browsing path and operation path data; the data comparison unit is used to compare the operation credibility with a preset operation credibility threshold to obtain the comparison result; the access warning unit is used to issue operation warnings based on the comparison result.

[0046] For example, a trusted computing platform obtains the verification browsing information of a target user accessing a power secondary system (e.g., verification information during the login process and browsing path information during the access process). Using a preset verification security assessment model, it performs a verification security assessment on the verification information to obtain the verification security assessment result for the target user. Using a preset permission security analysis model, it performs permission security analysis on the verification security assessment result and the permission allocation level of the target user to obtain the permission security analysis result for the target user. Using a preset operation credibility analysis model, it performs operation credibility analysis on the permission security analysis result and the browsing path information to obtain the operation credibility analysis result for the target user. Operation warnings are then issued based on the operation credibility analysis result. This embodiment of the invention can perform operation credibility analysis on the verification browsing information of a target user accessing a power secondary system, thereby achieving identity authentication and permission control for each node of the power secondary system, ensuring the security of remote access to the power secondary system, effectively resisting external attacks, and protecting system information security.

[0047] Specifically, if the verification information includes login password input information and login username, then step S2 includes:

[0048] S21, using a preset verification security assessment model, perform verification security assessment on the login password input information and login username to obtain the verification security assessment result of the target user.

[0049] In one optional embodiment, the login username of the visitor (target user), the historical login password input information of the visitor's historical login process (e.g., average historical password input interval time and average number of historical password input errors), and the login password input information of the current access process (e.g., password input interval time and number of password input errors) are obtained. The obtained historical login password input information and login password input information are input into a preset verification security assessment model to calculate the verification security assessment value (verification security assessment result) of the target user. The preset verification security assessment model can be calculated from the average historical password input interval time and / or the average number of historical password input errors and / or the password input interval time and / or the number of password input errors of the target user's current login process. The expression of the preset verification security assessment model is:

[0050]

[0051] In the formula, Mq is the security assessment value of the target user, m is the number of password verifications, a is the interval time ratio coefficient, and x i Let s be the password input interval during the i-th access process, x be the average password input interval during the historical login processes of the user with the login username, and s be the password input interval. i Let be the number of incorrect password entries during the i-th access process, and s be the average number of incorrect password entries in the historical login processes of the user with the login username.

[0052] It's worth noting that obtaining a visitor's login username, password input interval, and number of incorrect password attempts typically requires logging on the backend server or tracking using frontend JavaScript code. It's essential to ensure that the target user's username (login username), password input interval, and number of incorrect password attempts are captured in the HTML form.

[0053] Specifically, step S3 includes:

[0054] S31, obtain data on the number of user interfaces accessed by the target user to the power secondary system and data on the total number of interfaces that can be accessed by the power secondary system.

[0055] S32, determine the permission allocation level of the target user based on the user interface quantity data and the total number of interfaces;

[0056] S33, using a preset permission security analysis model, perform permission security analysis on the verification security assessment results and the permission allocation level to obtain the permission security analysis results of the target user.

[0057] For example, data on the number of user interfaces that the logged-in user can access and manage, and data on the total number of interfaces that the power secondary system can access, are obtained; based on the user interface data and the total number of interfaces, the permission allocation level of the target user is determined.

[0058] The permission allocation level and the calculated verification security assessment value are input into a preset permission security analysis model to calculate the permission security analysis value (permission security analysis result) of the target user. The preset permission security analysis model can be calculated from the target user's permission security analysis result and / or permission allocation level, and the expression of the preset permission security analysis model is:

[0059] Sq = β × Mq,

[0060] In the formula, Sq is the security analysis value of the target user, and β is the permission allocation level of the target user. Wherein, sw represents the number of user interfaces that the logged-in user can access and manage, sx represents the number of user interfaces that the target user can access in the power secondary system, and sx represents the total number of interfaces that the power secondary system can access.

[0061] Specifically, step S4 includes:

[0062] S41, determine the browsing access anomaly coefficient of the target user based on the browsing path information;

[0063] S42, using a preset operation credibility analysis model, perform operation credibility analysis on the permission security analysis results and the browsing access anomaly coefficient to obtain the operation credibility analysis results of the target user.

[0064] For example, the browsing path information (number of user interfaces, number of browsing visits, etc.) during the target user's browsing process is obtained to determine the number of abnormal interfaces accessed by the target user outside of their browsing permissions. The number of user interfaces includes the number of accessible interfaces and the number of abnormal interfaces. The obtained browsing path information and the number of mistakenly accessed interfaces are input into a formula for calculating the browsing access anomaly coefficient to calculate the target user's browsing access anomaly coefficient. The calculated permission security analysis value and the browsing access anomaly coefficient are input into a preset operation credibility analysis model to calculate the target user's operation credibility analysis result (operation credibility). The preset operation credibility analysis model can be calculated from the target user's permission security analysis result and / or the browsing access anomaly coefficient.

[0065] The formula for calculating the browsing access anomaly coefficient k is as follows:

[0066]

[0067] In the formula, n represents the number of times the target user accesses browsing access outside of their browsing permissions in the browsing path information, and X tz For the browsing path information, this refers to the browsing level that the target user accesses outside of the t-th browsing permission. T represents the browsing level of the target user's account. tz M represents the browsing time of the target user accessing the site outside of the t-th browsing permission in the browsing path information, and M represents the total number of browsing attempts in the browsing path information. fz The browsing time is the f-th browsing time in the browsing path information. The browsing level is calculated as follows: the number of accessible interfaces in the user interface quantity data divided by the total number of interfaces (the browsing level of the target user's account), or the number of abnormal interfaces divided by the total number of interfaces (the browsing level outside of browsing permissions).

[0068] The expression for the preset operation reliability analysis model is:

[0069] Kx = Sq × (1-k),

[0070] In the formula, Kx represents the credibility of the target user's operation.

[0071] Specifically, step S5 includes:

[0072] S51, if the operation credibility analysis result is greater than or equal to the preset operation credibility threshold, then the user access of the target user is displayed as normal;

[0073] S52, if the operation credibility analysis result is less than the preset operation credibility threshold, then display the user access anomaly of the target user to provide an operation warning.

[0074] For example, the operation credibility analysis result is compared with a preset operation credibility threshold (which can be set as needed). If the operation credibility analysis result is greater than or equal to the preset operation credibility threshold, the administrator terminal will display that the target user's access is normal. If the operation credibility analysis result is less than the preset operation credibility threshold, the administrator terminal will display that the target user's access is abnormal and issue an access warning.

[0075] This invention utilizes a trusted computing platform, combined with remote authentication and auditing mechanisms, to perform identity authentication and access control on each node of the power secondary system, ensuring the security and traceability of remote access. Through encrypted communication, digital signatures, and other technologies, it enables real-time monitoring and auditing of remote access behavior, thereby achieving secure remote access and management of the power secondary system, improving system operation and maintenance efficiency and security, and reducing the risk of human error.

[0076] This invention discloses an authentication method for a power secondary system. The method involves acquiring verification browsing information of a target user accessing the power secondary system. This verification browsing information includes verification information and browsing path information. A preset verification security assessment model is used to assess the verification information, yielding a verification security assessment result for the target user. A preset permission security analysis model is used to analyze the verification security assessment result and the target user's permission allocation level, yielding a permission security analysis result for the target user. A preset operation credibility analysis model is used to analyze the permission security analysis result and the browsing path information, yielding an operation credibility analysis result for the target user. An operation warning is then issued based on the operation credibility analysis result. This method enables operation credibility analysis of the verification browsing information of a target user accessing the power secondary system, achieving identity authentication and permission control for each node in the power secondary system. This ensures secure remote access to the power secondary system, effectively resists external attacks, and protects system information security.

[0077] See Figure 3 , Figure 3 This is a schematic diagram of the structure of an authentication device 10 for a power secondary system provided in an embodiment of the present invention. The authentication device 10 for the power secondary system includes:

[0078] The information acquisition module 11 is used to acquire the verification browsing information of the target user accessing the power secondary system; wherein, the verification browsing information includes verification information and browsing path information;

[0079] The security assessment module 12 is used to perform a verification security assessment on the verification information using a preset verification security assessment model, and obtain the verification security assessment result of the target user.

[0080] The permission analysis module 13 is used to perform permission security analysis on the verification security assessment results and the permission allocation level of the target user using a preset permission security analysis model, so as to obtain the permission security analysis results of the target user.

[0081] Trust analysis module 14 is used to perform operation trust analysis on the permission security analysis results and the browsing path information using a preset operation trust analysis model, so as to obtain the operation trust analysis results of the target user;

[0082] The operation warning module 15 is used to issue operation warnings based on the operation credibility analysis results.

[0083] The authentication device 10 for a power secondary system provided in this embodiment of the invention can realize all the processes of the authentication method for the power secondary system in the above embodiments. The functions and technical effects of each module in the device are the same as those of the authentication method for the power secondary system in the above embodiments, and will not be repeated here.

[0084] See Figure 4 , Figure 4 This is a schematic diagram of the structure of an authentication device 20 for a secondary power system provided in an embodiment of the present invention. The authentication device 20 for the secondary power system in this embodiment includes: a processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, it implements the steps in the above-described authentication method embodiment for the secondary power system. Alternatively, when the processor 21 executes the computer program, it implements the functions of each module in the above-described authentication device embodiment for the secondary power system.

[0085] For example, the computer program may be divided into one or more modules, which are stored in the memory 22 and executed by the processor 21 to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the authentication device 20 of the power secondary system.

[0086] The authentication device 20 of the power secondary system can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. The authentication device 20 of the power secondary system may include, but is not limited to, a processor 21 and a memory 22. Those skilled in the art will understand that the schematic diagram is merely an example of the authentication device 20 of the power secondary system and does not constitute a limitation on the authentication device 20 of the power secondary system. It may include more or fewer components than shown, or combine certain components, or different components. For example, the authentication device 20 of the power secondary system may also include input / output devices, network access devices, buses, etc.

[0087] The processor 21 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor. The processor 21 is the control center of the authentication equipment 20 of the power secondary system, connecting various parts of the authentication equipment 20 of the entire power secondary system via various interfaces and lines.

[0088] The memory 22 can be used to store the computer programs and / or modules. The processor 21 implements various functions of the power secondary system authentication device 20 by running or executing the computer programs and / or modules stored in the memory 22 and calling the data stored in the memory 22. The memory 22 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 22 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0089] If the module integrated into the authentication device 20 of the power secondary system is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 21, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the content as required by the legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium may not include electrical carrier signals and telecommunication signals.

[0090] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0091] This invention also provides a computer-readable storage medium, which includes a stored computer program, wherein the computer program, when running, controls the device where the computer-readable storage medium is located to execute the authentication method of the power secondary system as described in the above embodiments.

[0092] Furthermore, embodiments of the present invention also provide a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the power secondary system authentication method described above.

[0093] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A certification method for a power secondary system, characterized in that, include: Obtain the verification browsing information of the target user accessing the power secondary system; wherein, the verification browsing information includes verification information and browsing path information; A preset verification security assessment model is used to assess the verification information to obtain the verification security assessment result of the target user. Using a preset permission security analysis model, permission security analysis is performed on the verification security assessment results and the permission allocation level of the target user to obtain the permission security analysis results of the target user; Using a preset operation credibility analysis model, the operation credibility analysis is performed on the permission security analysis results and the browsing path information to obtain the operation credibility analysis results of the target user; Operational warnings will be issued based on the results of the operation credibility analysis.

2. The authentication method for a power secondary system as described in claim 1, characterized in that, If the verification information includes login password input information and login username; The step of using a preset verification security assessment model to perform a verification security assessment on the verification information to obtain the verification security assessment result for the target user includes: A preset verification security assessment model is used to perform a verification security assessment on the login password input information and login username to obtain the verification security assessment result of the target user.

3. The authentication method for a power secondary system as described in claim 1, characterized in that, The method employs a preset permission security analysis model to perform permission security analysis on the verification security assessment results and the permission allocation level of the target user, thereby obtaining the permission security analysis results of the target user, including: Acquire data on the number of user interfaces accessed by the target user to the power secondary system and data on the total number of interfaces that can be accessed by the power secondary system. Based on the number of user interfaces and the total number of interfaces, determine the permission allocation level for the target user; Using a preset permission security analysis model, permission security analysis is performed on the verification security assessment results and the permission allocation level to obtain the permission security analysis results of the target user.

4. The authentication method for a power secondary system as described in claim 1, characterized in that, The method employs a preset operation credibility analysis model to perform operation credibility analysis on the permission security analysis results and the browsing path information, thereby obtaining the operation credibility analysis results of the target user, including: Determine the browsing access anomaly coefficient of the target user based on the browsing path information; Using a preset operation credibility analysis model, the operation credibility analysis results of the permission security analysis results and the browsing access anomaly coefficient are analyzed to obtain the operation credibility analysis results of the target user.

5. The authentication method for a power secondary system as described in claim 1, characterized in that, The operation warning based on the operation credibility analysis results includes: If the operation credibility analysis result is greater than or equal to the preset operation credibility threshold, then the user access of the target user is displayed as normal. If the operation credibility analysis result is less than the preset operation credibility threshold, then the user access of the target user is displayed as abnormal, so as to provide an operation warning.

6. A certification device for a power secondary system, characterized in that, include: The information acquisition module is used to acquire the verification browsing information of the target user accessing the power secondary system; wherein, the verification browsing information includes verification information and browsing path information; The security assessment module is used to perform a security assessment on the verification information using a preset security assessment model, and obtain the security assessment result of the target user. The permission analysis module is used to perform permission security analysis on the verification security assessment results and the permission allocation level of the target user using a preset permission security analysis model, so as to obtain the permission security analysis results of the target user. The trust analysis module is used to perform operation trust analysis on the permission security analysis results and the browsing path information using a preset operation trust analysis model, so as to obtain the operation trust analysis results of the target user. The operation warning module is used to issue operation warnings based on the operation credibility analysis results.

7. A certification device for a power secondary system, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the authentication method for a power secondary system as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the authentication method for a power secondary system as described in any one of claims 1-5.

9. A computer program product, characterized in that, The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the authentication method for a power secondary system as described in any one of claims 1-5.