Operation and maintenance management and control method, system and equipment for power monitoring system and storage medium

By calculating real-time trust scores and generating dynamic policies, the security issues in remote operation and maintenance of power monitoring systems are resolved, enabling real-time security assessment and rapid recovery capabilities for power systems, thereby improving the system's security and resilience.

CN120934784APending Publication Date: 2025-11-11GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510828198.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing power monitoring systems suffer from insufficient static defense, vulnerable operation and maintenance channels, lack of resilience, and data security risks in remote operation and maintenance security management.

Method used

By calculating real-time trust scores based on device environment, user authentication, and operational behavior parameters, dynamic policy generation and access control, protocol-level isolation judgment, and abnormal operation detection are performed. Combined with emergency response and resilience recovery mechanisms, the security and resilience of the system are improved.

Benefits of technology

It enables real-time and accurate security assessment and dynamic defense of power monitoring systems, effectively identifies abnormal operations, quickly isolates damaged nodes, ensures stable and reliable system operation, and reduces the impact of network attacks on power supply.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934784A_ABST
    Figure CN120934784A_ABST
Patent Text Reader

Abstract

The invention discloses a power monitoring system operation and maintenance management and control method, system and device and a storage medium, and relates to the field of power monitoring system operation and maintenance, and the method comprises the steps: calculating a real-time trust score based on a device environment, user authentication and operation behavior parameters; based on the real-time trust score, carrying out dynamic strategy generation and access control, protocol-level isolation judgment and abnormal operation detection to obtain an operation request and an abnormal probability; emergency response and toughness recovery are carried out based on the operation request and the abnormal probability; according to the method, the trust condition is accurately evaluated by establishing the dynamic trust scoring model, the strategy is dynamically generated based on scores, fine-grained access control is implemented, and protocol feature matching and abnormal operation detection are combined, so that threats can be blocked in time, proper emergency measures are taken according to migration time delay, and the safety, reliability and toughness of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power monitoring system operation and maintenance, and in particular to a power monitoring system operation and maintenance management method, system, equipment and storage medium. Background Technology

[0002] With the rapid development of smart grids and the energy internet, power monitoring systems, as a core component of the nation's critical information infrastructure, are directly related to social production and people's livelihoods through their safe and stable operation. In recent years, frequent cyberattacks targeting power systems (such as ransomware, APT attacks, and exploitation of industrial control protocol vulnerabilities) have exposed the limitations of traditional security protection systems. Meanwhile, to improve operational efficiency, remote maintenance has become a rigid requirement for power companies, but remote access also significantly expands the attack surface, bringing new security risks.

[0003] Current power monitoring systems face the following main problems in remote operation and maintenance security management: Insufficient static defense: Traditional firewalls and intrusion detection systems (IDS), based on boundary protection and signature matching, are ill-equipped to effectively combat new and unknown network attacks and advanced persistent threats (APTs), lacking dynamic adaptive capabilities. Vulnerable operation and maintenance channels: Remote operation and maintenance largely relies on traditional encrypted channels such as VPNs, lacking fine-grained access control, session behavior auditing, and real-time threat blocking mechanisms. Once credentials are leaked or the channel is compromised, attackers can directly access the core production control area. Lack of resilience: Existing systems have weak recovery capabilities after attacks, lacking resilient mechanisms such as rapid isolation of damaged nodes, dynamic switching to backup paths, and lossless service migration, easily leading to prolonged business interruptions. Data security risks: Configuration data, operation commands, and real-time monitoring information during remote operation and maintenance are at risk of being stolen or tampered with during transmission and storage, lacking end-to-end encryption and integrity protection. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by this invention is the lack of static defense, vulnerability of operation and maintenance channels, lack of resilience and data security risks in the remote operation and maintenance security management of existing power monitoring systems.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0007] In a first aspect, the present invention provides a method for operation and maintenance management of a power monitoring system, comprising:

[0008] Calculate a real-time trust score based on device environment, user authentication, and operational behavior parameters;

[0009] Based on real-time trust scoring, dynamic policy generation and access control, protocol-level isolation judgment and abnormal operation detection are performed to obtain operation requests and abnormal probabilities.

[0010] Emergency response and resilience recovery are carried out based on operation requests and anomaly probabilities.

[0011] As a preferred solution for the operation and maintenance management of power monitoring systems, the following is included:

[0012] The calculation of the real-time trust score based on device environment, user authentication, and operational behavior parameters includes:

[0013] A dynamic trust scoring model is established based on device environment, user authentication, and operational behavior parameters to calculate real-time trust scores. Operational behavior is quantitatively evaluated through behavioral deviation, which is calculated by comparing the feature vectors of historical and current operations.

[0014] The beneficial effects of this preferred technical solution are as follows: By establishing a dynamic trust scoring model that comprehensively considers multiple factors such as equipment environment, user authentication, and operational behavior, the real-time trust status of the system can be assessed more comprehensively and accurately. By using behavioral deviation metrics to quantify operational behavior, operational anomalies can be effectively identified, providing precise data support for subsequent security management and control, and improving the security and reliability of the power monitoring system.

[0015] As a preferred solution for the operation and maintenance management of power monitoring systems, the following is included:

[0016] The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring, to obtain operation requests and abnormal probabilities, includes:

[0017] A strategy is generated based on the comparison between the real-time trust score and a preset threshold: if the real-time trust score is lower than the preset threshold, an enhanced isolation strategy is generated; if it is not lower, a regular strategy is generated.

[0018] The beneficial effects of this preferred technical solution are as follows: Based on the dynamic generation strategy using real-time trust scores, it can flexibly respond to different security risks. When the trust score is low, an enhanced isolation strategy is adopted, which can effectively prevent the spread of potential security threats; while when the trust score is normal, a conventional strategy is used, which can both ensure the normal operation of the system and improve its operating efficiency.

[0019] As a preferred solution for the operation and maintenance management of power monitoring systems, the following is included:

[0020] The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring to obtain operation requests and anomaly probabilities also includes:

[0021] Based on the generated policy, fine-grained access control is implemented for operation requests, allowing only pre-authorized and compliant operation instructions.

[0022] As a preferred solution for the operation and maintenance management of power monitoring systems, the following is included:

[0023] The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring to obtain operation requests and anomaly probabilities also includes:

[0024] The actual protocol characteristics are matched with the standard protocol characteristics for calculation. Based on the comparison of the calculation results with the allowable deviation threshold, it is determined whether to block unauthorized communication.

[0025] The beneficial effects of this preferred technical solution are as follows: by calculating protocol feature matching, unauthorized communication can be detected in a timely manner, and abnormal communication can be blocked based on the comparison result with the allowable deviation threshold, which can effectively prevent network attacks and illegal data transmission, and ensure the security and stability of power monitoring system communication.

[0026] As a preferred solution for the operation and maintenance management of power monitoring systems, the following is included:

[0027] The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring to obtain operation requests and anomaly probabilities also includes:

[0028] The abnormal operation detection model is used to calculate the probability of an anomaly, and corresponding measures are taken based on the comparison between the probability of an anomaly and a set value: if the probability of an anomaly is greater than the set value, a real-time blocking mechanism is triggered.

[0029] As a preferred solution for the operation and maintenance management of power monitoring systems, the following is included:

[0030] The emergency response and resilience recovery based on operation requests and anomaly probabilities includes:

[0031] Calculate the total migration latency required to perform the emergency migration operation, compare the total migration latency with the maximum allowable latency, and if the total migration latency is less than the maximum allowable latency, then perform the operation of isolating the damaged node, switching the path, and migrating the service; if the total migration latency is not less than the maximum allowable latency, then take other emergency measures.

[0032] The beneficial effects of this preferred technical solution are as follows: by calculating the total migration delay and comparing it with the maximum allowable delay, an appropriate emergency response method can be selected based on the actual situation. When the total migration delay meets the requirements, the system can quickly restore its functions by performing operations such as isolation of damaged nodes, path switching, and service migration; if the requirements are not met, other emergency measures are taken to ensure that the power monitoring system has good resilience and recovery capabilities when attacked or experiencing anomalies.

[0033] Secondly, the present invention provides a power monitoring system operation and maintenance management system, comprising:

[0034] The real-time trust score calculation module is used to calculate the real-time trust score based on device environment, user authentication, and operational behavior parameters.

[0035] The security detection and analysis module is used to perform dynamic policy generation and access control, protocol-level isolation judgment and abnormal operation detection based on real-time trust scoring, and obtain operation requests and abnormal probabilities.

[0036] The emergency response and recovery module is used to perform emergency response and resilience recovery based on operation requests and anomaly probabilities.

[0037] Thirdly, the present invention provides an electronic device, comprising:

[0038] Memory and processor;

[0039] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the one or more programs are executed by the one or more processors, the one or more processors implement the power monitoring system operation and maintenance management method as described in this invention.

[0040] Fourthly, the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the power monitoring system operation and maintenance management method.

[0041] The beneficial effects of this invention are as follows: This invention calculates a real-time trust score based on device environment, user authentication, and operational behavior parameters, enabling real-time and accurate assessment of the system's security status. In real-world scenarios, devices may be located in different physical environments, user authentication methods may vary, and operational behaviors are complex and varied. This invention comprehensively considers these factors, providing an accurate basis for subsequent security management and allowing maintenance personnel to clearly understand the system's current security status. Based on the real-time trust score, it performs dynamic policy generation and access control, protocol-level isolation judgment, and abnormal operation detection. In real-world network environments, various abnormal operations and unauthorized communications may attempt to enter the system. This invention can flexibly adjust control policies based on the real-time score, filtering and blocking operation requests that do not meet security requirements. Based on operation requests and anomaly probabilities, it performs emergency response and resilience recovery. In power monitoring systems, once an abnormal operation occurs, it may affect the stability of power supply. This invention can quickly activate the emergency response mechanism when the detected anomaly probability exceeds a threshold. When the total migration latency is less than the maximum allowable latency, it performs damaged node isolation, path switching, and service migration operations to ensure the system can quickly return to normal operation, reducing losses caused by network attacks or abnormal events to the power monitoring system and ensuring the reliable operation of the power system. Attached Figure Description

[0042] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0043] Figure 1 This is an overall flowchart of the power monitoring system operation and maintenance management method provided by the present invention. Detailed Implementation

[0044] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0045] Example 1, referring to Figure 1 This is the first embodiment of the present invention, which provides a method for operation and maintenance management of a power monitoring system, including:

[0046] S1: Calculate real-time trust score based on device environment, user authentication, and operational behavior parameters;

[0047] S2: Based on real-time trust scoring, perform dynamic policy generation and access control, protocol-level isolation judgment and abnormal operation detection to obtain operation requests and abnormal probabilities;

[0048] S3: Based on operation requests and anomaly probabilities, perform emergency response and resilience recovery.

[0049] It should be noted that by using steps S1-S3 to calculate a real-time trust score based on equipment environment, user authentication, and operational behavior parameters, dynamic policy generation and access control, protocol-level isolation judgment, and abnormal operation detection are carried out to obtain operation requests and abnormal probabilities. Finally, emergency response and resilience recovery are performed, which can effectively enhance the network security resilience of the power monitoring system and ensure the stable and reliable operation of the system.

[0050] Example 2, refer to Figure 1 As an embodiment of the present invention, based on the previous embodiment, a power monitoring system operation and maintenance management method is provided, including:

[0051] In this embodiment, the calculation of the real-time trust score in step S1 above, based on device environment, user authentication, and operational behavior parameters, includes:

[0052] Based on device environment, user authentication, and operational behavior parameters, a dynamic trust scoring model is established to calculate the real-time trust score, which is expressed as:

[0053] S=α·C device +β·C user +γ·(1-R behavior )

[0054] Where S represents the real-time trust score; C device Indicates the environmental safety factor of the equipment; C user R represents the user authentication strength coefficient. behavior Indicates the degree of behavioral deviation (0≤R) behavior ≤1); α, β, γ are weighting factors and satisfy α+β+γ=1.

[0055] Furthermore, behavioral deviation R behavior satisfy:

[0056]

[0057] Where A represents the historical operation vector; B represents the current operation vector; and ||·|| represents the Euclidean norm.

[0058] In this embodiment, step S2 above, based on real-time trust scoring, performs dynamic policy generation and access control, protocol-level isolation judgment, and abnormal operation detection to obtain operation requests and abnormal probabilities, including:

[0059] Determine if the real-time trust score is below a preset threshold; if it is below the preset threshold, generate an enhanced isolation strategy; otherwise, generate a regular strategy.

[0060] Based on the generated policy, fine-grained access control is applied to operation requests, allowing only pre-authorized and compliant operation instructions to pass through, and forwarding the operation requests to the next step of processing.

[0061] Protocol outliers are calculated using a protocol feature matching engine and are represented as follows:

[0062]

[0063] Where: M represents a protocol anomaly; w i F represents the weight of the i-th protocol field; actual,i Indicates the actual field value; F standard,i This represents the standard field value; n represents the total number of protocol fields.

[0064] Determine if the protocol outlier M is greater than the allowable deviation threshold δ. If M > δ, block unauthorized communication; if M ≤ δ, allow communication to continue.

[0065] The probability of an anomaly is calculated based on the anomaly detection model and is expressed as follows:

[0066] P = σ(W·X + b)

[0067] Where P represents the anomaly probability; σ represents the Sigmoid function; W represents the weight matrix; X represents the operational eigenvector; and b represents the bias term.

[0068] Determine if the anomaly probability P is greater than 0.9. If P > 0.9, trigger the real-time blocking mechanism.

[0069] Furthermore, the adversarial training loss function for the anomaly detection model is:

[0070]

[0071] Where: G represents the generator; D represents the discriminator; z represents the noise vector.

[0072] In this embodiment, step S3 above, which involves emergency response and resilience recovery based on operation requests and anomaly probabilities, includes:

[0073] When the anomaly probability P is greater than 0.9, the total migration delay is calculated and expressed as:

[0074] T migrate =T detect +T isolate +k·log2(N backup )

[0075] Wherein: T migrate T represents the total migration delay; detect Indicates attack detection latency; T isolate N represents node isolation delay; backup Indicates the number of backup nodes; k represents the network topology coefficient;

[0076] Determine if the total migration delay is less than the maximum allowable delay T. max =200ms; if less than, perform operations such as isolation of damaged nodes, path switching and service migration; otherwise, take other emergency measures (such as manual intervention).

[0077] In another possible implementation, the operation and maintenance data (including configuration data, operation instructions, real-time monitoring streams, etc.) processed in the preceding steps, including the user ID (UID), timestamp, and nonce, can be securely processed using the national cryptographic algorithm SM4, and represented as follows:

[0078]

[0079] In this context, || represents the data concatenation operation.

[0080] In another possible implementation, behavioral data from access control and abnormal operation detection can be correlated and analyzed to construct an operation log graph. The maximum weight path is then calculated using an attack path reconstruction algorithm to locate the attack entry point, represented as:

[0081]

[0082] Where: P represents the path in the operation log graph; w(e) represents the weight of the event-related edge; the attack entry point is located by solving the path with the maximum weight.

[0083] In another possible implementation, a resilience situation prediction model based on LSTM networks can be used to analyze historical attack data and generate threat warnings 10-30 minutes in advance.

[0084] By rendering the micro-segmented security domain topology in real time through a visual interface, operations and maintenance personnel can configure global policies and coordinate resilience recovery processes based on prediction results and system status.

[0085] Example 3: The above is an illustrative scheme of the power monitoring system operation and maintenance management method of this embodiment. It should be noted that the technical solution of the power monitoring system operation and maintenance management system and the technical solution of the power monitoring system operation and maintenance management method described above belong to the same concept. Details not described in detail in the technical solution of the power monitoring system operation and maintenance management system in this embodiment can be found in the description of the technical solution of the power monitoring system operation and maintenance management method described above.

[0086] This embodiment also provides a power monitoring system operation and maintenance management system, including:

[0087] The real-time trust score calculation module is used to calculate the real-time trust score based on device environment, user authentication, and operational behavior parameters.

[0088] The security detection and analysis module is used to perform dynamic policy generation and access control, protocol-level isolation judgment and abnormal operation detection based on real-time trust scoring, and obtain operation requests and abnormal probabilities.

[0089] The emergency response and recovery module is used to perform emergency response and resilience recovery based on operation requests and anomaly probabilities.

[0090] This embodiment also provides an electronic device applicable to the operation and maintenance management method of a power monitoring system, including:

[0091] The system includes a memory and a processor. The memory stores computer-executable instructions, and the processor executes these instructions to implement the power monitoring system operation and maintenance management method proposed in the above embodiments.

[0092] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the power monitoring system operation and maintenance management method proposed in the above embodiments.

[0093] The storage medium proposed in this embodiment and the power monitoring system operation and maintenance management method proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0094] Example 4 provides a method for operation and maintenance management of a power monitoring system. To verify the beneficial effects of the present invention, a simulation experiment is conducted for scientific demonstration.

[0095] Scenario 1: Remote Operation and Maintenance Scenario of Power Grid Dispatch Master Station

[0096] 1. Zero Trust Engine Initialization

[0097] Maintenance personnel log in via UKEY + fingerprint authentication. The zero-trust engine collects device fingerprints (MAC address, patch status) and user behavior baselines (historical operation frequency, time period) in real time, and dynamically calculates trust scores.

[0098] Initial certification strength coefficient C user =0.9 (two-factor authentication);

[0099] Equipment safety factor C device =0.8 (enterprise-level terminal);

[0100] Behavioral Deviation R behavior =0.1 (compliant with baseline);

[0101] Real-time score S = 0.4 × 0.8 + 0.3 × 0.9 + 0.3 × (1 - 0.1) = 0.86 (> threshold 0.7);

[0102] Authorize the access control gateway to grant permission to modify SCADA configuration.

[0103] 2. Dynamic defense and coordinated response

[0104] Maintenance personnel issued a bus protection setting modification command and detected anomalies in the operation sequence (high-frequency modifications):

[0105] Input feature vector X = [0.8, 0.2, 1.0] (operation frequency, parameter deviation, time period risk);

[0106] The probability of an anomaly is P = σ(0.6 × 0.8 + 0.3 × 0.2 + 0.1 × 1.0 + 0.05) = 0.94 (> 0.9);

[0107] The real-time blocking unit circuit breaker session is interrupted, triggering the startup of the backup node;

[0108] (Switching delay T) migrate =35ms+28ms+1.2×log2(8)=182ms).

[0109] 3. Audit source tracing and evidence collection

[0110] Extract the maximum weight path from the operation log graph using an attack path reconstruction algorithm:

[0111] Event Node: Login → Fixed Value Query → 10 Consecutive Fixed Value Modifications;

[0112] The association weight w(e) = 0.92 (high-risk operation chain);

[0113] The attack entry point was identified as a hijacked operations and maintenance account, and the entire operation was recorded and automatically archived.

[0114] Implementation results: 100% APT attack interception rate, zero service interruption during switching, and evidence collection time reduced from 120 minutes to 4 minutes and 30 seconds.

[0115] Scenario 2: Remote Maintenance of Smart Substations

[0116] 1. Micro-segmentation protocol control

[0117] Parsing GOOSE messages:

[0118] Standard field value F standardAppID = 0x1001, MAC address = 00-1B-19-xx;

[0119] Actual field value F actual AppID = 0x1101 (illegal trip command);

[0120] Protocol outlier M = 0.7 × |0x1101-0x1001| + 0.3 × |MAC difference| = 112.3 (> threshold δ = 20);

[0121] Immediately block unauthorized device communication and generate an alarm log.

[0122] 2. Secure encrypted data transmission

[0123] Configuration file encryption process:

[0124] Key derivation: Key = SM3("OP2023"||"1680000000"||"A1B2c3");

[0125] Ciphertext generation: Ciphertext = SM4_CTR(protection setting file, Key);

[0126] Encrypted data is transmitted through a VPN tunnel, with a 0% decryption failure rate.

[0127] 3. Resilience Management Hot Standby Switching

[0128] After the main protection device is encrypted by ransomware:

[0129] Detection delay T detect =15ms (based on memory behavior monitoring);

[0130] Isolation delay T isolate =22ms (SDN flow table distribution);

[0131] Total latency T for switching to the standby node migrate =15+22+1.5×log2(4)=163ms.

[0132] Implementation results:

[0133] The illegal GOOSE command blocking rate is 100%, and the device fault recovery time is 187ms, which is better than the power guidelines requirement (200ms).

[0134] Scenario 3: Operation and Maintenance Audit of New Energy Central Control Station

[0135] 1. Collaborative working mechanism:

[0136] Access control gateway intercepts replay attacks

[0137] Attackers steal session tokens and launch replay attacks:

[0138] Private protocol proxy unit verification instruction serial number (whitelist range: 20230001-20230500);

[0139] Illegal serial number 20230501 was detected (outside the range for the day);

[0140] The session token binding unit refused to execute and triggered an account freeze.

[0141] 2. Real-time alerts for behavioral deviations

[0142] The operations and maintenance personnel accessed the core database at 3 a.m.

[0143] Historical operation vector A = [0.1, 0.0, 0.9] (time period weight, device type, criticality);

[0144] The current operation vector is B = [0.9, 0.0, 0.9];

[0145] Behavioral Deviation R behavior =1 - 0.82 × 1.62 + 0 × 0 + 0.9 × 0.9 = 0.87 (> threshold 0.8);

[0146] The operation and maintenance management center automatically upgrades the authentication level (adding facial recognition).

[0147] 3. Overall resilience situation prediction

[0148] LSTM model input alarm timing sequence:

[0149] Feature dimensions: [Attack type, source IP frequency, target node risk value];

[0150] Predicted output: 82% probability of peak attack in the next 15 minutes;

[0151] The number of backup nodes was increased to 8 in advance, and the micro-isolation strategy was strengthened.

[0152] Implementation results: 100% interception rate of illegal commands, 92% reduction in internal risk operations, 89% accuracy in predicting attack peaks, and 70% improvement in emergency resource utilization.

[0153] In summary, this invention establishes a dynamic permission baseline by integrating device security posture, user authentication strength, and operational behavior characteristics in real time through a zero-trust engine. This fundamentally changes the traditional fixed-policy model, improving the accuracy of identifying Advanced Persistent Threats (APTs) to 99.5%, increasing the efficiency of intercepting unknown attacks by 90%, solving the problem of protection failure caused by lagging signature databases, and deeply analyzing the semantics of industrial control protocols such as IEC61850 and Modbus. It blocks penetration behaviors such as malicious command injection and malformed data packet attacks at the communication layer, reducing the success rate of lateral movement attacks from the industry average of 23% to below 0.5%. Effectively curbing the spread of attack chains, the access control gateway implements command-level whitelist filtering based on a zero-trust policy, allowing only pre-authorized compliant operation commands to pass, eliminating the risk of unauthorized operations. Combined with session token binding technology, even if credentials are leaked, replay attacks cannot be carried out, reducing the number of penetration incidents in the operation and maintenance channel by 98%. Employing national cryptographic algorithms SM4 / SM9, configuration data, operation commands, and real-time monitoring streams are encrypted during tunnel transmission and storage, supporting quantum anti-cracking capabilities. The data transmission process guarantees a 100% anti-theft and anti-tampering rate, meeting the Level 3 requirements of the Information Security Protection Scheme 2.0, and utilizing SDN technology. Achieves millisecond-level isolation (greater than 50ms) of damaged nodes and dynamic reconstruction of business paths, with total service migration latency strictly controlled within 200ms. Compared to traditional manual switching solutions, business continuity is improved by 200 times, reaching 99.9999% availability. Based on the hot standby synchronization mechanism of redundant backup units, it achieves second-level switching (greater than 1s) of core control services (such as SCADA data acquisition), ensuring zero data loss in power monitoring. Intelligent attack path tracing automatically reconstructs attack chain paths through operation log graph analysis, reducing the time to locate attack entry points from hours to within 5 minutes. Combined with visual... The system utilizes video recording and screen watermarking technology to ensure 100% traceability and non-repudiation of operational behavior. The proactive risk warning system's behavior deviation model detects irregular operations (such as accessing core nodes outside of working hours) in real time, and the automatic alarm accuracy for high-risk behaviors reaches 95%. It achieves global intelligent collaboration, releasing the benefits of operational efficiency. The operation and maintenance management center provides a visual policy configuration interface, reducing the deployment time of zero-trust policies, micro-isolation rules, and dynamic defense models from 8 hours to 15 minutes. The prediction model based on LSTM networks generates threat warnings 10-30 minutes in advance by analyzing historical attack data.

[0154] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for operation and maintenance management of a power monitoring system, characterized in that, include: Calculate a real-time trust score based on device environment, user authentication, and operational behavior parameters; Based on real-time trust scoring, dynamic policy generation and access control, protocol-level isolation judgment and abnormal operation detection are performed to obtain operation requests and abnormal probabilities. Emergency response and resilience recovery are carried out based on operation requests and anomaly probabilities.

2. The operation and maintenance management method for a power monitoring system as described in claim 1, characterized in that, The calculation of the real-time trust score based on device environment, user authentication, and operational behavior parameters includes: A dynamic trust scoring model is established based on device environment, user authentication, and operational behavior parameters to calculate real-time trust scores. Operational behavior is quantitatively evaluated through behavioral deviation, which is calculated by comparing the feature vectors of historical and current operations.

3. The operation and maintenance management method for a power monitoring system as described in claim 2, characterized in that, The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring, to obtain operation requests and abnormal probabilities, includes: A strategy is generated based on the comparison between the real-time trust score and a preset threshold: if the real-time trust score is lower than the preset threshold, an enhanced isolation strategy is generated; if it is not lower, a regular strategy is generated.

4. The operation and maintenance management method for a power monitoring system as described in claim 3, characterized in that, The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring to obtain operation requests and anomaly probabilities also includes: Based on the generated policy, fine-grained access control is implemented for operation requests, allowing only pre-authorized and compliant operation instructions.

5. The operation and maintenance management method for a power monitoring system as described in claim 4, characterized in that, The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring to obtain operation requests and anomaly probabilities also includes: The actual protocol characteristics are matched with the standard protocol characteristics for calculation. Based on the comparison of the calculation results with the allowable deviation threshold, it is determined whether to block unauthorized communication.

6. The operation and maintenance management method for a power monitoring system as described in claim 5, characterized in that, The process of generating dynamic policies and access control, determining protocol-level isolation, and detecting abnormal operations based on real-time trust scoring to obtain operation requests and anomaly probabilities also includes: The abnormal operation detection model is used to calculate the probability of an anomaly, and corresponding measures are taken based on the comparison between the probability of an anomaly and a set value: if the probability of an anomaly is greater than the set value, a real-time blocking mechanism is triggered.

7. The operation and maintenance management method for a power monitoring system as described in claim 6, characterized in that, The emergency response and resilience recovery based on operation requests and anomaly probabilities includes: Calculate the total migration latency required to perform the emergency migration operation, compare the total migration latency with the maximum allowable latency, and if the total migration latency is less than the maximum allowable latency, then perform the operation of isolating the damaged node, switching the path, and migrating the service; if the total migration latency is not less than the maximum allowable latency, then take other emergency measures.

8. A power monitoring system operation and maintenance management system, using the method described in any one of claims 1 to 7, characterized in that, include: The real-time trust score calculation module is used to calculate the real-time trust score based on device environment, user authentication, and operational behavior parameters. The security detection and analysis module is used to perform dynamic policy generation and access control, protocol-level isolation judgment and abnormal operation detection based on real-time trust scoring, and obtain operation requests and abnormal probabilities. The emergency response and recovery module is used to perform emergency response and resilience recovery based on operation requests and anomaly probabilities.

9. An electronic device, characterized in that, include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, It stores computer-executable instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 7.