Multi-source safety data fusion analysis method and system for explosion-proof design of intelligent monitoring equipment

By using a multi-source safety data fusion and analysis method from intelligent monitoring equipment, the problems of data silos and response delays in the safety monitoring system of the oil and gas industry have been solved, enabling accurate perception and rapid response to explosion-proof environments, and improving the efficiency of anomaly handling and system stability.

CN121261925APending Publication Date: 2026-01-02FULIHENG AUTOMATION ENG TECH BEIJING
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511316889.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Existing safety monitoring systems in the oil and gas industry suffer from problems such as data silos, response delays, and limited analytical capabilities. They are unable to meet the rapid response needs in high-temperature, high-pressure, flammable, and explosive environments, lack the ability to collaboratively analyze multi-source heterogeneous data, and lack full lifecycle management of explosion-proof equipment and system compatibility.

Method used

A multi-source safety data fusion analysis method based on the explosion-proof design of intelligent monitoring equipment is adopted. This method collects multi-source heterogeneous safety data, preprocesses and unifies the format, uses a deep reinforcement learning model to generate disposal strategies, and optimizes safety control commands through a closed-loop processing flow to achieve real-time monitoring and anomaly response of explosion-proof assets.

Benefits of technology

It achieves accurate perception and rapid response to explosion-proof environments, significantly reduces false alarm rates, improves anomaly handling efficiency, dynamically adjusts handling strategies to reduce production interruptions, and ensures stable system operation in hazardous environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121261925A_ABST
    Figure CN121261925A_ABST
Patent Text Reader

Abstract

The invention provides a multi-source safety data fusion analysis method and system for explosion-proof design of intelligent monitoring equipment, relates to the technical field of safety monitoring, and solves the problems of response lag and high false alarm rate in traditional explosion-proof monitoring. The analysis method comprises the following steps: collecting multi-source heterogeneous safety data according to real-time monitoring requirements, and preprocessing to generate a standardized log; constructing an asset state portrait through asset identification, and inputting a CNN-BiLSTM model to identify equipment physical abnormity or communication service abnormity; generating a disposal strategy based on the anomaly type by using deep reinforcement learning, and performing dynamic optimization after digital twinborn simulation verification; and converting the strategy into a safety control instruction and issuing the safety control instruction to the target security and protection equipment to form a closed-loop processing flow. The method is characterized in that: for equipment physical abnormity, whether to deal with delay is determined through dynamic matching of an emergency capability feature vector on a time axis; for communication service abnormity, whether communication is guaranteed preferentially is determined according to dynamic comparison of the task important value and the risk threshold value, and the effects include reduction of the false alarm rate, shortening of the response time and improvement of the resource scheduling efficiency in the dangerous environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of safety monitoring technology, and in particular to a multi-source safety data fusion analysis method and system for explosion-proof design of intelligent monitoring equipment. Background Technology

[0002] As a core sector of national energy security, the oil and gas industry is characterized by its production environment, which is characterized by high temperature and pressure, flammability, explosiveness, and widespread distribution of toxic and hazardous media. The reliability of the safety monitoring system directly impacts personnel safety and environmental security. In recent years, with the continuous expansion of oil and gas field development and the increasing complexity of refining processes, traditional safety monitoring methods have become insufficient to meet the needs of comprehensive risk perception and accurate early warning. Industry statistics show that over 70% of safety accidents in the petroleum industry stem from untimely risk warnings or incomplete hazard identification, with explosion-proof equipment failure and data silos being key factors contributing to the escalation of accidents.

[0003] Currently, safety monitoring systems in the petroleum industry face two major technical bottlenecks: explosion-proof design and multi-source data fusion. Regarding explosion-proof design, existing equipment commonly suffers from non-standard selection and inadequate installation and maintenance. Existing systems typically employ a single-sensor monitoring mode, failing to achieve deep integration of equipment operating parameters, ambient gas concentrations, personnel location information, and process flow data. Although some platforms attempt to integrate video surveillance and environmental data, incompatible data formats and heterogeneous communication protocols across different subsystems have resulted in severe data silos. For example, pressure sensor data at gas wellheads and data from surrounding combustible gas detectors belong to different management systems, making correlation analysis impossible and hindering early identification of potential leak risks. Existing technologies also have limitations in algorithm application and real-time performance, currently focusing primarily on single-dimensional video image recognition and lacking the ability to collaboratively analyze multi-source heterogeneous data. In explosion-proof environments, data transmission faces even stricter limitations. Wireless communication is susceptible to electromagnetic interference, while wired transmission incurs high cabling costs due to explosion-proof sealing requirements. Traditional systems employ a "full data upload + cloud analysis" model, which not only consumes significant bandwidth resources but also results in substantial delays in early warning responses, making it difficult to meet the rapid response needs in flammable and explosive environments. From the perspective of industry standard evolution and regulatory requirements, technical specifications for safe production are developing towards greater refinement and intelligence. However, existing monitoring systems generally lack real-time monitoring capabilities for the explosion-proof status of equipment, lack full lifecycle management and system compatibility for explosion-proof equipment, and cannot promptly detect hidden defects such as aging seals and excessive explosion-proof gaps. Simultaneously, emergency management departments require the establishment of a "historically traceable and on-site accessible" regulatory model, which places higher demands on the temporal correlation and source tracing analysis of multi-source data.

[0004] In view of this, there is an urgent need for a multi-source safety data fusion analysis method and system for the explosion-proof design of intelligent monitoring equipment, in order to at least address the above-mentioned shortcomings. Summary of the Invention

[0005] The purpose of this invention is to provide a multi-source safety data fusion and analysis method and system for the explosion-proof design of intelligent monitoring equipment, so as to solve the problems of data silos, response delays and limited analysis capabilities in the prior art. The specific technical solution is as follows:

[0006] This invention provides a multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment, including:

[0007] Step 1: Based on the real-time monitoring requirements of the explosion-proof monitoring network of intelligent monitoring equipment, collect multi-source heterogeneous safety data from the explosion-proof environment, preprocess the multi-source heterogeneous safety data to unify the format and map the content, and generate standardized safety log data;

[0008] Step 2: Based on the standardized security log data, perform asset identification to determine the monitored explosion-proof assets and their status. Input the standardized security log data into the network security threat identification model for risk identification and output security threat identification results containing anomaly types, including physical equipment anomalies and communication service anomalies.

[0009] Step 3: Based on the security threat identification results and their anomaly types, use a deep reinforcement learning model to generate a preliminary handling strategy for the identified risks, and feed the processing results of the strategy back to the deep reinforcement learning model for continuous training and optimization, dynamically adjusting the judgment conditions of the handling strategy.

[0010] Step 4: Convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security device in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security device and its associated explosion-proof environment, and return to Step 1 to form a closed-loop processing flow.

[0011] Furthermore, the multi-source heterogeneous security data includes equipment operating status data, environmental security data, video surveillance data, and personnel behavior data; the preprocessing includes: converting raw data of different protocol formats into a unified time-series data format, and mapping the raw equipment values ​​to engineering values ​​with physical meaning.

[0012] Furthermore, asset identification in step 2 includes:

[0013] Generate unique identifiers and status monitoring projects for explosion-proof assets based on asset feature database and network topology;

[0014] Based on the monitoring projects, a digital twin model representing the real-time security status of assets is constructed as an asset status profile;

[0015] By establishing a correlation between asset status profiles and real-time monitoring data through feature alignment, a security status view is formed.

[0016] Furthermore, the asset feature library is set according to the technical parameters of the explosion-proof equipment. The monitoring items for pressure vessel equipment include pressure fluctuation safety threshold and explosion-proof enclosure integrity, while the monitoring items for gas detection equipment include calibration status and detection accuracy.

[0017] Furthermore, in step 4, when the anomaly type is a physical equipment anomaly, the following must be executed before the safety control command conversion:

[0018] a) Obtain information on the emergency response capabilities of the target security equipment, including the processing capabilities of the equipment itself, associated equipment, and environmental control systems;

[0019] b) Extract response time, processing duration, processing effect, and processing capacity features using the emergency response capability feature extraction template;

[0020] c) Determine whether the emergency response capability is available based on the emergency response capability characteristics. If so, implement the emergency response first and then implement safety control.

[0021] Furthermore, the assessment of anomaly handling capabilities specifically includes:

[0022] Match emergency response strategies for physical anomalies in the equipment;

[0023] The emergency response strategy is laid out along a timeline according to the response time.

[0024] Construct an emergency response capability description vector and mark the possible intervention time range on the time axis;

[0025] Traverse the timeline points to match the combined vector of emergency response capability descriptions. If there is a mismatch, it is determined that there is no response capability.

[0026] Furthermore, in step 4, when the exception type is a communication service exception, the following must be executed before the security control instruction conversion:

[0027] If the importance value of the communication task is greater than or equal to the importance threshold, then network connectivity will be guaranteed until the task is completed before security control is implemented.

[0028] If the importance value is less than the importance value threshold, then security control is executed directly;

[0029] The importance threshold is determined based on the risk value of communication service anomaly quantification.

[0030] Furthermore, the risk value is obtained by weighted fusion after normalizing the evaluation indicators of the security threat dimension, service quality dimension, and protocol compliance dimension, with the weights set according to the historical minimum loss experiment.

[0031] The present invention also relates to a system for multi-source safety data fusion analysis method for explosion-proof design of the aforementioned intelligent monitoring equipment, comprising:

[0032] The data acquisition module is used to collect multi-source heterogeneous safety data from the explosion-proof environment according to the real-time monitoring needs of the explosion-proof monitoring network of the intelligent monitoring equipment, preprocess the multi-source heterogeneous safety data, and generate standardized safety log data.

[0033] The risk identification module is used to identify assets based on the standardized security log data to determine the monitored explosion-proof assets and their status, and input the standardized security log data into the network security threat identification model for risk identification, and output security threat identification results including abnormal types;

[0034] The handling strategy module is used to generate preliminary handling strategies for identified risks using a deep reinforcement learning model based on the security threat identification results and their anomaly types. The processing results of the strategy are fed back to the deep reinforcement learning model for continuous training and optimization, and the judgment conditions of the handling strategy are dynamically adjusted.

[0035] The safety control module is used to convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security device in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security device and its associated explosion-proof environment, and return it to the data acquisition module to form a closed-loop processing flow.

[0036] The present invention also relates to an electronic device, including a processor and a memory, wherein the memory stores a computer program that, when executed by the processor, implements the method as described.

[0037] The beneficial effects of this invention are as follows: Through multi-source data fusion and intelligent analysis, this invention achieves accurate perception and rapid response to the safety status of explosion-proof environments, significantly reducing false alarm rates and improving anomaly handling efficiency. The system adopts a differentiated handling mechanism, prioritizing the activation of the system's own emergency capabilities to reduce production interruptions in the event of equipment anomalies, and dynamically ensuring the integrity of critical tasks in the event of communication anomalies, thereby minimizing losses. Policy optimization based on deep reinforcement learning and digital twin verification greatly improves resource utilization efficiency. The entire process complies with explosion-proof standards and is compatible with industrial protocols, ensuring stable operation in hazardous environments. A closed-loop self-iterative mechanism continuously optimizes safety protection capabilities, forming an ever-evolving proactive defense system.

[0038] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0039] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0040] Figure 1 This is a schematic diagram of a multi-source safety data fusion and analysis method for explosion-proof design of intelligent monitoring equipment in an embodiment of the present invention;

[0041] Figure 2 This is a schematic diagram of a multi-source safety data fusion analysis system for the explosion-proof design of intelligent monitoring equipment in an embodiment of the present invention. Detailed Implementation

[0042] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0043] This embodiment provides a multi-source safety data fusion analysis method for the explosion-proof design of intelligent monitoring equipment, such as... Figure 1 As shown, it includes:

[0044] Step 1: Based on the real-time monitoring requirements of the explosion-proof monitoring network of intelligent monitoring equipment, collect multi-source heterogeneous safety data from the explosion-proof environment, preprocess the multi-source heterogeneous safety data, and generate standardized safety log data;

[0045] The real-time monitoring requirement refers to the real-time control strategy employed by the intelligent monitoring equipment platform to collect data from distributed monitoring nodes in order to achieve explosion-proof safety monitoring objectives. Specifically, the real-time monitoring requirement is a set of technical instructions automatically generated by the strategy configuration module within the intelligent monitoring equipment platform based on pre-set explosion-proof safety rules (such as GB 3836.1-2021 General Requirements for Explosive Atmosphere Equipment) and real-time dynamic environmental risk assessment results. For example, when the system learns through a meteorological interface that the monitored area (such as a chemical plant tank area) is about to experience thunderstorms, this module will dynamically generate a monitoring requirement instruction. Its technical parameters include: increasing the sampling frequency of lightning-induced voltage to 100Hz, activating the video analysis function of all explosion-proof cameras to monitor for abnormal open flames, and dynamically lowering the alarm threshold of the oxygen concentration sensor to 19.5% VOL. This requirement is a technical signal containing specific control parameters that can be directly executed by the system hardware and software.

[0046] Among them, multi-source heterogeneous security data includes: equipment operation status data, environmental security data, video surveillance data, and personnel behavior data;

[0047] Preprocessing includes format unification and content mapping, which converts raw data of different protocols and formats into a unified time-series data format and maps the raw device values ​​into engineering values ​​with clear physical meaning.

[0048] Step 2: Based on the standardized security log data, perform asset identification to determine the monitored explosion-proof assets and their status, input the standardized security log data into the network security threat identification model for risk identification, and output security threat identification results including anomaly types;

[0049] Step 2: Based on the standardized security log data, asset identification is performed to determine the monitored explosion-proof assets and their status. The standardized security log data is then input into the network security threat identification model for risk identification. This includes generating a unique identifier and status monitoring item for each explosion-proof asset based on the asset feature library and network topology.

[0050] Among them, the asset feature database is the basic database for generating various asset monitoring features for asset identification and comparison. It is set according to the technical parameters and safety requirements of explosion-proof equipment. For example, based on the explosion-proof requirements, it is determined that pressure vessel equipment A needs to monitor whether the pressure fluctuation range is within the safety threshold and whether the integrity of the explosion-proof shell is damaged. It is determined that gas detection equipment B needs to monitor whether the calibration status is normal and whether the detection accuracy meets the standard. It is determined that network equipment C needs to monitor whether the communication protocol complies with the MODBUS / TCP specification and whether the access control policy has been tampered with.

[0051] Based on asset identification and monitoring projects, construct asset status profiles;

[0052] Among them, the asset status profile is a digital twin model built based on the asset feature library and real-time monitoring data. It is used to represent the real-time security status of assets and serve as a benchmark for risk identification. The asset status profile is also connected to the risk analysis engine, which adopts a CNN-BiLSTM hybrid neural network architecture.

[0053] Based on the monitoring items of each asset, obtain monitoring data from standardized security log data through the security data interface;

[0054] Among them, the security data interface is a data acquisition and preprocessing module deployed in the intelligent monitoring equipment platform, which undertakes the tasks of multi-source data fusion and standardization;

[0055] Align asset status profiles and real-time monitoring data by feature matching, establish the correlation between asset status profiles and monitoring data in the same time series, and obtain a complete security status view;

[0056] Among them, the security status view is: the asset status profile is an analysis network that compares expected status data and real-time monitoring data with the risk analysis engine that is connected to the profile and performs anomaly identification.

[0057] The risk analysis engine adopts a CNN-BiLSTM hybrid neural network architecture, where the CNN part is responsible for extracting spatial features from the monitoring data and the BiLSTM part is responsible for capturing abnormal patterns in the time series.

[0058] The anomalies include physical equipment anomalies and communication service anomalies. Physical equipment anomalies are specifically manifested as: sensor readings exceeding physical safety limits, abnormal fluctuations in equipment operating parameters, and abnormal explosion-proof structural integrity indicators. Communication service anomalies are specifically manifested as: abnormal tampering with industrial communication protocol fields, unauthorized access attempts, and abnormal communication interruption frequency.

[0059] Step 3: Based on the security threat identification results and their anomaly types, use a deep reinforcement learning model to generate a preliminary handling strategy for the identified risks, and feed the processing results of the strategy back to the deep reinforcement learning model for continuous training and optimization, dynamically adjusting the judgment conditions of the handling strategy.

[0060] Step 3: Based on the security threat identification results and their anomaly types, a preliminary handling strategy for the identified risks is generated using a deep reinforcement learning model, including: generating a sequence of handling actions for each handling stage based on the anomaly type and the handling strategy generation rules;

[0061] The handling strategy generation rules are a rule base for generating handling actions at each stage of the handling process, based on the type of anomaly. These rules are set according to explosion-proof safety handling experience. For example, based on handling experience, for physical anomalies in pressure vessel equipment, the initial handling stage requires executing pressure regulation commands and activating the backup cooling system; the upgraded handling stage requires executing equipment isolation commands and safe pressure relief operations; and the termination handling stage requires executing equipment shutdown commands and maintenance plans. Similarly, for network communication service anomalies, the initial handling stage requires communication link switching and access control policy reset; the upgraded handling stage requires network isolation and key update operations; and the termination handling stage requires security auditing and system hardening.

[0062] Construct a response verification network based on the response stages and actions;

[0063] Among them, the disposal verification network is a digital twin simulation environment built based on disposal strategy generation rules and disposal actions, used to simulate disposal effects and serve as a benchmark for strategy optimization. The disposal verification network is also connected to the effect evaluation engine.

[0064] Based on the actions taken at each stage of the response, the system executes response commands and collects response effect data through the safety control interface.

[0065] Among them, the security control interface is the instruction issuance and execution monitoring module deployed in the intelligent monitoring equipment platform, which is responsible for the task of converting disposal instructions and collecting execution status;

[0066] Align the treatment verification network with the actual treatment effect data, establish a comparison mechanism between expected and actual effects using the same evaluation standard, and obtain a strategy optimization network;

[0067] Among them, the strategy optimization network is: the disposal verification network inputs the expected disposal effect and the actual disposal effect into the effect evaluation engine connected to the verification network, compares them, and generates a reward signal.

[0068] Among them, the effect evaluation engine adopts the Actor-Critic architecture in deep reinforcement learning, where the Actor network is responsible for generating the disposal policy and the Critic network is responsible for evaluating the value of the policy.

[0069] The continuous training and optimization includes: updating network parameters based on reward signals, adjusting the generation weights of disposal strategies, and optimizing the probability distribution of disposal actions.

[0070] Step 4: Convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security device in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security device and its associated explosion-proof environment, and return to Step 1 to form a closed-loop processing flow;

[0071] Step 4 involves converting the optimized preliminary handling strategy into specific security control instructions, including generating device control instructions for each execution stage based on instruction conversion rules and device control templates.

[0072] Among them, target security equipment includes circuit breakers, isolators, alarms, or communication relays;

[0073] Among them, the instruction conversion rules are a rule base for generating equipment control instructions for each execution stage by referring to the handling strategy, and are set according to the explosion-proof equipment control protocol; for example, according to the control protocol, for pressure regulation instructions, the strategy parameters need to be converted into Modbus function codes and register addresses that can be recognized by the PLC during the instruction conversion stage; for equipment isolation instructions, the strategy parameters need to be converted into tripping signals and control timing that can be recognized by the intelligent circuit breaker; and for alarm instructions, the strategy parameters need to be converted into the frequency mode and flashing mode of the audible and visual alarm.

[0074] Construct an instruction verification network based on the execution phase and control instructions;

[0075] Among them, the instruction verification network is a digital twin test environment built on instruction conversion rules and control instructions, used to simulate the instruction execution process and serve as a benchmark for instruction verification. The instruction verification network also interfaces with the execution monitoring engine.

[0076] Based on the control instructions for each execution stage, instructions are issued and execution status data is collected through the device control interface;

[0077] Among them, the device control interface is a protocol conversion and command issuance module deployed in the intelligent monitoring device platform, which undertakes the tasks of control command encapsulation and device protocol adaptation;

[0078] Align the instruction verification network with the actual execution status data to establish a comparison mechanism between the expected execution effect and the actual execution effect under the same evaluation standard, and obtain the execution monitoring network.

[0079] Among them, the execution monitoring network is: the command verification network inputs the expected execution effect and the actual execution effect into the execution monitoring engine connected to the verification network for comparison and generates the execution evaluation result;

[0080] A new round of multi-source heterogeneous security data will be collected from the target security equipment and its associated explosion-proof environment, including: real-time collection of equipment status data, environmental parameter data and network communication data through intrinsically safe sensors and explosion-proof acquisition devices deployed in the explosion-proof environment;

[0081] The closed-loop processing flow is as follows: newly collected multi-source heterogeneous security data is sent to the data preprocessing flow in step 1 to start a new round of security monitoring cycle and form a continuously optimized security protection closed loop.

[0082] The beneficial effects of the above technical solution are as follows: by fusion analysis of multi-source data, the false alarm rate is reduced, and accurate perception of the safety status of explosion-proof environment is achieved; by adopting dynamic threshold adjustment and edge computing technology, the abnormal response time is shortened, meeting the rapid disposal needs of flammable and explosive environments; through the strategy optimization mechanism, the disposal strategy is dynamically adjusted and continuously improved, avoiding over-disposal or under-disposal, and improving the efficiency of emergency resource utilization; all data acquisition and processing links are based on explosion-proof design, support multiple industrial protocol conversions, and ensure the safe and stable operation of the system in hazardous environments.

[0083] In one embodiment, step 4: convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security device in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security device and its associated explosion-proof environment, return to step 1, and form a closed-loop processing flow, including: if the anomaly type is a physical anomaly of the equipment, obtain the first safety control condition satisfied by the target security device; wherein, obtaining the first safety control condition satisfied by the target security device includes: determining the emergency handling capability information of the target security device, the emergency handling capability information including: the first emergency handling capability of the device itself, the second emergency handling capability of the associated equipment, and the environmental control capability. The third emergency response capability of the system; based on the emergency response capability feature extraction template and emergency response capability information, emergency response capability features are extracted; among them, the emergency response capability feature extraction template is: a template for extracting features of different emergency response capability feature types by comparing with emergency response capability information. For example, emergency response capability feature types include: response time, processing duration, processing effect, and processing capacity. Then, the emergency response capability feature extraction template is a template for extracting response time by comparing with emergency response capability information, a template for extracting processing duration by comparing with emergency response capability information, a template for extracting processing effect by comparing with emergency response capability information, and a template for extracting processing capacity by comparing with emergency response capability information; based on the emergency response capability features, the system judges... The system must be capable of handling abnormal situations. This capability refers to the ability to invoke primary, secondary, and tertiary emergency response capabilities to address physical anomalies in equipment. Examples include: the equipment's automatic adjustment capabilities (such as automatic pressure relief from pressure vessel safety valves), the coordinated handling capabilities of related equipment (such as activating backup cooling systems), and the emergency response capabilities of environmental control systems (such as activating leak gas extraction systems). If the anomaly can be handled, then the corresponding target security equipment will be subject to safety control. Specifically, the ability to handle anomalies refers to the ability to dispatch the emergency response capabilities of the target security equipment and its related systems to address physical anomalies. If the anomaly cannot be handled, the corresponding target security equipment will be directly controlled. Safety control of the equipment; after implementing safety control under the first safety control scenario, a first control strategy is determined based on the physical anomaly of the equipment; wherein, the physical anomaly of the equipment is: the anomaly type is the specific anomaly content of the physical anomaly of the equipment, such as: pressure vessel pressure exceeding the standard by 20%, abnormal fluctuation of temperature sensor readings, and equipment vibration amplitude exceeding the limit; wherein, the first control strategy is a control strategy for the physical anomaly of the equipment matched with the equipment physical anomaly and the preset control strategy library for the physical anomaly of the equipment; after processing based on the first control strategy, the corresponding target security equipment is re-acquired; if the anomaly type is communication service anomaly, the second safety control scenario satisfied by the target security equipment is obtained; wherein, obtaining the second safety control scenario satisfied by the target security equipment includes:

[0084] If the importance value of a communication task is greater than or equal to the importance value threshold, network connectivity is guaranteed during the execution of the communication task. After the communication task is completed, security control of the corresponding target security equipment is then implemented. The importance value of the communication task is quantified according to manually preset quantification rules.

[0085] If the importance value is less than the importance value threshold, the security control of the corresponding target security equipment is directly implemented. After implementing the security control for the second security control scenario, a second control strategy is determined based on the communication service anomaly. The communication service anomaly refers to the specific anomaly content of the anomaly type, such as: critical control command transmission delay timeout, unauthorized device access to the network, or tampering with industrial protocol fields. The second control strategy is a control strategy for the communication service anomaly matched with a preset control strategy library based on the communication service anomaly. After processing based on the second control strategy, the corresponding target security equipment undergoes re-data acquisition. The working principle and beneficial effects of the above technical solution are as follows:

[0086] Different anomaly types require different security control measures for target security equipment before the anomaly is resolved and data is re-collected. Blindly implementing security controls, interrupting equipment operation, and handling the anomaly can lead to significant real losses, such as production disruptions and delays in critical control tasks. Therefore, this invention provides targeted security controls and subsequent anomaly handling based on the anomaly type to minimize losses. Specifically, when the anomaly is a physical equipment anomaly, security controls are not immediately implemented; instead, the emergency handling capabilities of the equipment itself and related systems are considered. An emergency capability feature extraction template is introduced to extract emergency capability features from emergency handling capability information. Based on these features, it is determined whether the abnormal equipment has the capability to handle the anomaly. If the anomaly can be handled, security control of the target security equipment is implemented after the anomaly is resolved, avoiding production disruptions and reducing economic losses. When the anomaly is a communication service anomaly, the physical connection layer is intact, therefore the target security equipment has the capability to handle communication tasks, but an anomaly exists at the communication protocol level. Therefore, by quantifying the importance value of communication tasks, if the importance value is greater than or equal to the importance value threshold, in order to avoid delays in important control tasks and ensure network connectivity during the execution of communication tasks, the security control of the corresponding target security equipment can be carried out after the communication task is completed, thereby improving the completion rate of important control tasks.

[0087] After security control is completed, the corresponding anomaly type is adapted to the control strategy library for anomaly handling. Once the anomaly handling is complete, the corresponding target security equipment will be re-collected for data.

[0088] This invention does not immediately implement security controls when identifying anomalies in target security equipment. Instead, it conducts targeted assessments based on the type of anomaly and the specific security control situation. Specifically, when a device experiences a physical anomaly, the invention assesses the anomaly handling capability based on emergency response information to determine whether emergency intervention is necessary, minimizing production disruptions. When communication services are abnormal, the invention introduces a priority value for communication tasks, prioritizing high-priority communication tasks and then addressing the corresponding target security equipment afterward—a more rational approach.

[0089] In one embodiment, determining the ability to handle emergencies based on emergency response characteristics includes:

[0090] Based on the physical anomalies of the equipment, an emergency response strategy is matched;

[0091] The emergency response strategy is a strategy for handling physical anomalies of equipment using the equipment itself and related systems. It uses an anomaly-emergency strategy mapping table for matching. The anomaly-emergency strategy mapping table is configured in advance by the staff. For example, if the anomaly is: the pressure vessel pressure exceeds the limit, the emergency response strategy is to call the safety valve to automatically release pressure and start the backup cooling system; or if the anomaly is: the temperature sensor abnormally jumps, the emergency response strategy is to call the redundant temperature sensor and start the equipment to operate under reduced load.

[0092] The emergency response strategy is laid out on a timeline;

[0093] When the emergency response strategy is unfolded on the timeline, the corresponding emergency response sub-strategies are unfolded according to the emergency response time.

[0094] Construct an emergency response capability description vector based on the characteristics of emergency response capabilities;

[0095] In constructing the emergency response capability description vector, the positions of feature values ​​for different emergency response capability characteristic types within the vector are pre-set manually, such as: [response time, processing duration, processing effect, processing capacity]. Specifically, the emergency response capability vector for a safety valve pressure relief is, for example: [2 seconds, 5 minutes, pressure reduction of 0.5 MPa, 10 m]. 3 / min]; The emergency capability vector of the backup cooling system is, for example: [30 seconds, 2 hours, temperature drop of 10℃, 500kW];

[0096] Based on the first time range of the emergency response capability description vector, the emergency response capability description vector is marked on the time axis accordingly;

[0097] The first time range is the intervention time corresponding to the emergency capability description vector and the duration after the intervention time; the intervention time is determined based on the response time, and the initial response time is all time axis points after the response time duration after the starting axis point; the duration after the intervention time is determined based on the processing duration of the emergency capability description vector.

[0098] Starting from the beginning of the timeline, traverse each timeline point sequentially. Based on the emergency response capability description vector of the emergency response sub-strategy at the i-th timeline point, match the emergency response capability description combination vector at the i-th timeline point.

[0099] Among them, the support emergency capability description vector is the feature representation description vector of the emergency handling capability corresponding to the emergency handling sub-strategy, and the construction method is the same as the emergency capability description vector; when matching the emergency capability description combination vector at the i-th time axis point, if one or more emergency capability description vectors at the i-th time axis point match the support emergency capability description vector, then the corresponding one or more emergency capability description vectors are the emergency capability description combination vector.

[0100] After updating the emergency capability description vector marked on the time axis after the second time range of the decomposed emergency capability description vector based on the combined emergency capability description vector, continue to traverse the (i+1)th time axis point.

[0101] Among them, the decomposed emergency response capability description vector is: one or more emergency response capability description vectors marked on the time axis that match the vectors corresponding to the supporting emergency response capability description vectors.

[0102] The second time range is the time range within which emergency handling is not allowed to intervene in the corresponding decomposed emergency capability description vector, specifically the time range of the processing duration in the corresponding decomposed emergency capability description vector after the i-th time axis point.

[0103] If, during the traversal, there is a situation where no emergency response capability description combination vector can be matched, it is determined that there is no abnormal handling capability; otherwise, there is an abnormal handling capability.

[0104] Where i is an integer greater than or equal to 1.

[0105] The working principle and beneficial effects of the above technical solution are as follows:

[0106] This invention utilizes an anomaly-emergency strategy mapping table to match emergency handling strategies corresponding to physical anomalies of equipment. A timeline is introduced to expand the emergency handling strategies, determining the supporting emergency capability description vector for each timeline point. Simultaneously, based on the initial intervention time and subsequent duration of the emergency capability description vector, the vector is marked on the timeline. Starting from the initial timeline point, each timeline point is traversed sequentially. Based on the supporting emergency capability description vector and the marked emergency capability description vector for each timeline point, a combined emergency capability description vector is matched. According to the second time range of the decomposed emergency capability description vector, the subsequent intervention time corresponding to the decomposed emergency capability description vector is limited, and the matching emergency capability description vector for subsequent times is updated in real time, greatly improving the efficiency of determining subsequent combined emergency capability description vectors. This invention vectorizes heterogeneous emergency resources, enabling precise coordination between second-level response and minute-level processing, achieving synergistic optimization of time and resources, and avoiding waste of emergency resources.

[0107] In one embodiment, the importance threshold is determined based on the risk value of communication service anomaly quantification.

[0108] Specifically, when quantifying risk values ​​based on communication service anomalies, the risk assessment indicators for the abnormal content dimension are normalized and weighted to obtain the risk value. For example, the assessment indicator for the security threat dimension is the number of unauthorized accesses / total number of accesses; the assessment indicator for the service quality dimension is the transmission delay timeout ratio; and the assessment indicator for the protocol compliance dimension is the protocol field anomaly ratio. The assessment indicator values ​​for the abnormal content dimension are normalized, multiplied by a preset weight, and then summed to obtain the risk value. The importance threshold and the risk value are numerically equal.

[0109] The preset weight is the historical importance value threshold that minimizes the consequences of the experiment, which sets the weight of the abnormal content dimension used in the record.

[0110] The working principle and beneficial effects of the above technical solution are as follows: When determining the importance threshold, this invention uses the risk value of communication service anomaly quantification as the importance threshold, achieving the effect that the higher the risk value, the higher the importance threshold. In this way, the post-processing threshold for communication tasks with high risk levels is higher, forming a dynamic post-processing threshold setting mechanism. That is, the higher the risk level of the communication task, the higher the priority for in-process protection, which is more appropriate.

[0111] A multi-source safety data fusion analysis system for explosion-proof design of intelligent monitoring equipment, such as Figure 2 As shown, it includes:

[0112] The data acquisition module is used to collect multi-source heterogeneous safety data from the explosion-proof environment according to the real-time monitoring needs of the explosion-proof monitoring network of the intelligent monitoring equipment, preprocess the multi-source heterogeneous safety data, and generate standardized safety log data.

[0113] The risk identification module is used to identify assets based on the standardized security log data to determine the monitored explosion-proof assets and their status, and input the standardized security log data into the network security threat identification model for risk identification, and output security threat identification results including abnormal types;

[0114] The handling strategy module is used to generate preliminary handling strategies for identified risks using a deep reinforcement learning model based on the security threat identification results and their anomaly types, and to feed the processing results of the strategy back to the deep reinforcement learning model for continuous training and optimization, and dynamically adjust the judgment conditions of the handling strategy.

[0115] The safety control module is used to convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security device in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security device and its associated explosion-proof environment, and return it to the data acquisition module to form a closed-loop processing flow;

[0116] The safety control module processes the different types of anomalies according to the safety control measures, and then re-collects data.

[0117] After the security control module processes the security control situation according to the different anomaly types, it re-collects data, including:

[0118] If the anomaly type is a physical anomaly of the equipment, obtain the first security control condition that the target security equipment meets;

[0119] After implementing safety control measures for the first safety control scenario, determine the first control strategy based on the physical anomaly of the equipment.

[0120] After processing based on the first control strategy, re-collect data from the corresponding target security equipment;

[0121] If the anomaly type is communication service anomaly, obtain the second security control condition satisfied by the target security device;

[0122] After implementing security controls for the second security control scenario, a second control strategy is determined based on the communication service anomaly.

[0123] After processing based on the second control strategy, the corresponding target security equipment will be re-acquired.

[0124] The first security control condition satisfied by the target security equipment includes:

[0125] Determine the emergency response capabilities of the target security equipment;

[0126] Based on the template for extracting emergency response capability characteristics and emergency handling capability information, emergency response capability characteristics are extracted.

[0127] Assess emergency response capabilities based on their characteristics;

[0128] If the anomaly can be handled, then the corresponding target security equipment should be put under security control after the anomaly is handled.

[0129] If the abnormal situation cannot be handled, directly implement security control of the corresponding target security equipment;

[0130] Among them, the second security control condition satisfied by the target security equipment includes:

[0131] If the importance value of a communication task is greater than or equal to the importance value threshold, network connectivity is guaranteed during the execution of the communication task. After the communication task is completed, security control of the corresponding target security equipment is then performed.

[0132] If the importance value is less than the importance value threshold, then the security control of the corresponding target security equipment will be directly implemented;

[0133] The importance threshold is determined based on the risk value of communication service anomaly quantification.

[0134] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment, characterized in that, include: Step 1: Based on the real-time monitoring requirements of the explosion-proof monitoring network of intelligent monitoring equipment, collect multi-source heterogeneous safety data from the explosion-proof environment, preprocess the multi-source heterogeneous safety data to unify the format and map the content, and generate standardized safety log data; Step 2: Based on standardized security log data, identify assets to determine the monitored explosion-proof assets and their status. Input the standardized security log data into the network security threat identification model for risk identification and output security threat identification results including anomaly types. Step 3: Based on the security threat identification results and their anomaly types, use a deep reinforcement learning model to generate preliminary handling strategies for the identified risks. Feed the processing results of the strategies back to the deep reinforcement learning model for continuous training and optimization, and dynamically adjust the judgment conditions of the handling strategies. Step 4: Convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security equipment in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security equipment and its associated explosion-proof environment, and return to Step 1 to form a closed-loop processing flow.

2. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 1, characterized in that, The anomaly types include physical device anomalies and communication service anomalies; The multi-source heterogeneous security data includes equipment operating status data, environmental security data, video surveillance data, and personnel behavior data; The preprocessing includes: converting raw data of different protocol formats into a unified time-series data format, and mapping the original device values ​​to engineering values ​​with physical meaning.

3. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 1, characterized in that, The asset identification in step 2 includes: Generate unique identifiers and status monitoring projects for explosion-proof assets based on asset feature database and network topology; Based on the monitoring projects, a digital twin model representing the real-time security status of assets is constructed as an asset status profile; By establishing a correlation between asset status profiles and real-time monitoring data through feature alignment, a security status view is formed.

4. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 3, characterized in that, The asset feature database is set according to the technical parameters of explosion-proof equipment. The monitoring items for pressure vessel equipment include pressure fluctuation safety threshold and explosion-proof enclosure integrity, while the monitoring items for gas detection equipment include calibration status and detection accuracy.

5. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 1, characterized in that, In step 4, when the anomaly type is a physical equipment anomaly, the following must be executed before the safety control command conversion: a) Obtain information on the emergency response capabilities of the target security equipment, including the processing capabilities of the equipment itself, associated equipment, and environmental control systems; b) Extract response time, processing duration, processing effect, and processing capacity features using the emergency response capability feature extraction template; c) Determine whether the emergency response capability is available based on the emergency response capability characteristics. If so, implement the emergency response first and then implement safety control.

6. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 5, characterized in that, The assessment of anomaly handling capabilities specifically includes: Match emergency response strategies for physical anomalies in the equipment; The emergency response strategy is laid out along a timeline according to the response time. Construct an emergency response capability description vector and mark the possible intervention time range on the time axis; Traverse the timeline points to match the combined vector of emergency response capability descriptions. If there is a mismatch, it is determined that there is no response capability.

7. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 1, characterized in that, In step 4, when the exception type is a communication service exception, the following must be executed before the security control instruction conversion: If the importance value of the communication task is greater than or equal to the importance threshold, then network connectivity will be guaranteed until the task is completed before security control is implemented. If the importance value is less than the importance value threshold, then security control is executed directly; The importance threshold is determined based on the risk value of communication service anomaly quantification.

8. The multi-source safety data fusion analysis method for explosion-proof design of intelligent monitoring equipment as described in claim 7, characterized in that, The risk value is obtained by weighted fusion after normalizing the evaluation indicators of security threat dimension, service quality dimension and protocol compliance dimension, with the weights set according to the historical minimum loss experiment.

9. A system for multi-source safety data fusion analysis of explosion-proof design of intelligent monitoring equipment according to any one of claims 1-8, characterized in that: The data acquisition module is used to collect multi-source heterogeneous safety data from the explosion-proof environment according to the real-time monitoring needs of the explosion-proof monitoring network of the intelligent monitoring equipment, preprocess the multi-source heterogeneous safety data, and generate standardized safety log data. The risk identification module is used to identify assets based on the standardized security log data to determine the monitored explosion-proof assets and their status, and input the standardized security log data into the network security threat identification model for risk identification, and output security threat identification results including abnormal types; The handling strategy module is used to generate preliminary handling strategies for identified risks using a deep reinforcement learning model based on the security threat identification results and their anomaly types. The processing results of the strategy are fed back to the deep reinforcement learning model for continuous training and optimization, and the judgment conditions of the handling strategy are dynamically adjusted. The safety control module is used to convert the optimized preliminary handling strategy into specific safety control instructions; send the safety control instructions to the corresponding target security device in the explosion-proof monitoring network of the intelligent monitoring equipment, re-collect a new round of multi-source heterogeneous safety data of the target security device and its associated explosion-proof environment, and return it to the data acquisition module to form a closed-loop processing flow.

10. An electronic device, comprising a processor and a memory, characterized in that, The memory stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1-6.