A security risk management and control system based on a double prevention mechanism

CN121390894BActive Publication Date: 2026-09-29ZHONGCHENG ANHUAN (TIANJIN) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511549643.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-28
Publication Date
2026-09-29
Estimated Expiration
2045-10-28

AI Technical Summary

Technical Problem

[0003]本申请提供了一种基于双重预防机制的安全风险管控系统,其能够通过多单元协同与动态优化逻辑,解决现有系统数据冲突处理差、耦合计算不准、响应效率低的问题,提升安全风险管控的精准性与实时性

Benefits of technology

1.提供了一种基于双重预防机制的安全风险管控系统,提升风险管控精准性与实时性;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121390894B_ABST
    Figure CN121390894B_ABST
Patent Text Reader

Abstract

The application provides a security risk management and control system based on a double prevention mechanism, belongs to the field of security risk management and control, and is used for solving the problems of inaccurate coupling of risks and hidden dangers, non-closed-loop management and control link and low multi-module cooperation efficiency in the related art. The system comprises a multi-source data acquisition unit, a risk-hidden danger dynamic coupling calculation unit, a double prevention execution unit and the like. Through multi-source data fusion, dynamic coupling calculation, closed-loop feedback and edge-cloud cooperation, accurate risk assessment and efficient management and control are realized, and the system operation stability and anti-risk capability are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security risk management, and in particular to a security risk management system based on a dual prevention mechanism. Background Technology

[0002] In industrial production, chemical manufacturing, and machinery processing, safety risk management is a core element in ensuring stable production and operations and preventing casualties and property damage. The dual prevention mechanism of "risk-level classification and control" and "hazard investigation and management" has become the mainstream management model in the industry. With the development of industrial intelligence, enterprises are widely introducing multi-source data acquisition equipment, hoping to achieve dynamic correlation analysis of risks and hazards through real-time data monitoring. This is the current state of development in the field. While existing security risk management systems attempt to integrate multi-source data, they still rely on traditional data processing and computation models in practical applications. For example, when dealing with conflicts between multi-source data, simple methods such as "taking the average," "taking the maximum value," or "selecting with fixed weights" are often used; risk-hazard coupling calculations use fixed models and constraint thresholds that remain unchanged for a long time; and the architecture design is mostly based on centralized cloud computing, with each module running according to fixed processes and resource allocations. This is the main situation of existing technologies. However, existing technologies have significant shortcomings: multi-source data conflict handling does not consider the reliability of data sources and the adaptability of scenarios, resulting in a high rate of risk misjudgment; coupled computing lacks dynamic adaptability, and the results are out of sync with the actual state of the equipment; the architecture lacks real-time performance and stability, and critical computing is prone to timeouts or paralysis due to network failures. These shortcomings directly lead to poor implementation of the dual prevention mechanism and fail to meet the needs of accurate, real-time, and stable security risk management, which has become an urgent problem to be solved in the industry. Summary of the Invention

[0003] This application provides a security risk management system based on a dual prevention mechanism, which can solve the problems of poor data conflict handling, inaccurate coupled calculation, and low response efficiency in existing systems through multi-unit collaboration and dynamic optimization logic, thereby improving the accuracy and real-time performance of security risk management. Firstly, this application provides a safety risk management system based on a dual prevention mechanism. It includes a multi-source data acquisition unit, a risk-hazard dynamic coupling calculation unit, and a dual prevention execution unit. The multi-source data acquisition unit collects equipment operation data, environmental data, and manual inspection data within the enterprise. The risk-hazard dynamic coupling calculation unit receives the output data from the multi-source data acquisition unit, constructs a correlation model between risk factors and hazard characteristics, and combines it with multi-source data conflict handling rules based on data source credibility to perform weighted fusion processing on conflicting data to achieve dynamic coupling calculation of risks and hazards. Based on the calculation results of the risk-hazard dynamic coupling calculation unit, the dual prevention execution unit executes risk classification management and hazard investigation and treatment operations respectively. The multi-source data acquisition unit, the risk-hazard dynamic coupling calculation unit, and the dual prevention execution unit are sequentially connected, and the risk-hazard dynamic coupling calculation unit also forms a deviation feedback link with the multi-source data acquisition unit to constitute a closed-loop safety risk management link. By adopting the above technical solutions, the multi-source data acquisition unit achieves full-dimensional data coverage, and the conflict handling rules based on the credibility of the data source avoid the deviation of simple mean or fixed weight; the dynamic coupling calculation unit constructs an association model and forms a closed-loop feedback to ensure that the calculation fits the real-time changes; the dual prevention execution unit operates based on accurate results, effectively reducing the risk misjudgment rate and solving the problem of insufficient accuracy in the existing system's control. Furthermore, the risk-hazard dynamic coupling calculation unit includes a scenario complexity assessment subunit. The scenario complexity assessment subunit constructs scenario complexity quantification rules by acquiring the conflict characteristics of multi-source data and the proportion of high-risk data to determine the complexity level of the current security scenario, and can update the complexity level according to real-time data changes. By adopting the above technical solutions, the complexity of the scene can be identified in real time, providing a basis for subsequent resource scheduling and computing logic adjustment, avoiding the "one-size-fits-all" computing mode, and improving the system's adaptability to different scenarios. Furthermore, the scenario complexity assessment subunit also includes a complexity mutation response subunit; when the difference between two adjacent complexity levels exceeds a set threshold, the complexity mutation response subunit triggers a complexity level rearrangement and synchronizes the rearranged complexity level to the risk-hazard dynamic coupling calculation unit. By adopting the above technical solutions, we can quickly respond to sudden changes in scenario complexity, update the level in a timely manner and synchronize it to the core computing unit, ensuring that computing and resource allocation are dynamically adjusted according to the scenario and avoiding computing lag caused by sudden changes in the scenario. Furthermore, it also includes a multi-module collaborative scheduling unit; the multi-module collaborative scheduling unit pre-stores the mapping relationship between the scene complexity level output by the scene complexity assessment sub-unit and the priority of each computing unit, allocates the proportion of computing resources of each computing unit according to the scene complexity level, and can obtain the remaining computing volume by monitoring the thread occupancy rate of each computing unit in real time to dynamically adjust the resource allocation scheme. By adopting the above technical solution, resources are allocated based on both scenario complexity and remaining computing power, avoiding insufficient resources in key modules, improving overall computing efficiency and response speed, and solving the problem of unreasonable resource allocation in existing systems. Furthermore, the multi-module collaborative scheduling unit is equipped with a computation timeout processing subunit. The computation timeout processing subunit sets a preset timeout threshold based on the scene complexity level output by the scene complexity evaluation subunit. When the computation time of any computing unit approaches the timeout threshold of the corresponding scene complexity level, the computation timeout processing subunit retrieves a preset proportion of computing resources from the low-priority computing unit and allocates them to the high-priority computing unit. By adopting the above technical solutions, resources can be urgently allocated before critical calculations are about to time out, avoiding delays in risk assessment, ensuring that core computing tasks are completed in a timely manner in extremely complex scenarios, and guaranteeing the real-time performance of the system. Furthermore, the risk-hazard dynamic coupling calculation unit includes an evidence chain weight optimization subunit. The evidence chain weight optimization subunit constructs multi-feature weight calculation rules based on the historical data accuracy, data attribute quality, data deviation trend, and scenario matching degree of the data source to determine the basic weight of each data source, and can dynamically adjust the basic weight according to the real-time data deviation value. By adopting the above technical solutions, the reliability of the data source is evaluated from multiple dimensions and the weights are dynamically adjusted to avoid misjudgment of single feature weights, improve the accuracy of conflict data fusion, and provide high-quality input for coupled computing. Furthermore, the evidence chain weight optimization subunit also includes an abnormal data processing subunit; when the deviation value of the data output from the data source is detected to exceed the set range, the abnormal data processing subunit reduces the weight correction magnitude of the corresponding data source and marks the abnormal data information, and the proportion of the marked abnormal data in the subsequent risk-hazard coupling calculation is reduced by a preset ratio. By adopting the above technical solutions, the impact of abnormal data can be identified and mitigated, coupling deviations caused by faulty data sources can be avoided, and a basis for operation and maintenance can be provided to improve the system's anti-interference capability. Furthermore, the risk-hazard dynamic coupling calculation unit includes a physical constraint correction subunit; the physical constraint correction subunit constructs dynamic constraint threshold calculation rules based on the equipment's service life and real-time load rate to constrain and verify the risk-hazard coupling coefficient, and can adjust the correction magnitude of the coupling coefficient according to the risk diffusion speed. By adopting the above technical solutions and dynamically setting constraint thresholds based on equipment status, fixed thresholds are avoided from deviating from physical reality; the correction range is adjusted according to the risk diffusion speed to ensure that the coupling coefficient matches the equipment's tolerance capacity and the urgency of the risk, thereby improving the rationality of the calculation. Furthermore, it also includes an adaptive feedback unit; the adaptive feedback unit triggers the parameter adjustment command of the risk-hazard dynamic coupling calculation unit by monitoring the risk assessment deviation rate output by the risk-hazard dynamic coupling calculation unit and the constraint correction deviation rate output by the physical constraint correction subunit, and can verify the adjustment effect and optimize the adjustment rules based on the deviation improvement after parameter adjustment. By adopting the above technical solution, a closed-loop optimization mechanism of "monitoring-adjustment-verification" is constructed, which automatically optimizes calculation parameters without manual intervention, thus solving the problems of lagging parameter adjustment and high operation and maintenance costs in the existing system. Furthermore, an edge-cloud collaborative architecture is adopted; key computing modules of multi-source data acquisition units and risk-hazard dynamic coupling computing units are deployed at the edge, and data storage units and global parameter management units are deployed in the cloud; the edge and the cloud are connected through dual-link communication, and automatically switch to the backup link when the latency of the main link exceeds the preset latency threshold or the link is interrupted, and the edge has the ability to operate independently in offline state. By adopting the above technical solutions, core computing localization reduces transmission latency, and dual-link and edge offline capabilities prevent system paralysis caused by network failures, thereby improving the real-time performance and stability of the architecture. In summary, this application has at least the following beneficial effects: 1. A security risk management system based on a dual prevention mechanism is provided to improve the accuracy and real-time nature of risk management; 2. By optimizing multi-feature weights and handling anomalies, the evaluation bias caused by data conflicts is reduced; 3. By leveraging edge-cloud collaboration and adaptive feedback, the system can ensure stable operation and achieve parameter self-optimization.

[0004] It should be understood that the description in the Summary Section is not intended to limit the key or essential features of the embodiments of this application, nor is it intended to restrict the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0005] The above and other features, advantages, and aspects of the embodiments of this application will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein: Figure 1 A schematic diagram of an exemplary operating environment in which embodiments of this application can be implemented is shown.

[0006] Figure 2 A schematic diagram of a security risk management system based on a dual prevention mechanism is shown in an embodiment of this application. Detailed Implementation

[0007] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0008] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0009] This application provides a security risk management system based on a dual prevention mechanism, which can accurately handle multi-source data conflicts, dynamically optimize risk-hazard coupling calculation, and rely on edge-cloud collaboration to ensure real-time stability. It can also adaptively optimize parameters, greatly improve the accuracy and efficiency of management and control, and reduce operation and maintenance costs.

[0010] Figure 1 A schematic diagram of an exemplary operating environment in which embodiments of this application can be implemented is shown.

[0011] Reference Figure 1 The operating environment includes five hardware support systems that support the realization of "a security risk management system based on a dual prevention mechanism". Each system works together to provide the foundation for data acquisition, real-time calculation, stable transmission, global management and software operation, ensuring that the system can realize the dynamic coupling calculation of risk and hidden danger and the execution of dual prevention functions. The five major hardware support systems of the operating environment specifically include the hardware and software carriers corresponding to the hardware acquisition layer, edge computing layer, cloud support layer, network transmission layer, and software infrastructure layer. The hardware acquisition layer, as the data entry point, consists of a high-precision sensor cluster, a mobile inspection terminal network, and log data acquisition equipment. The high-precision sensor cluster collects equipment operating status and environmental parameters, the mobile inspection terminal network uploads manual inspection data, and the log data acquisition equipment captures logs from the equipment control system. These three components work together to achieve the fusion and access of three data sources: sensors, manual inspection, and logs. The edge computing layer, as the real-time computing carrier, consists of an industrial-grade edge server cluster, edge cache, and local storage devices. The edge server cluster undertakes localized computing tasks such as scenario complexity assessment and weight optimization. The edge cache and local storage devices are used to temporarily store real-time data and temporary parameters, ensuring independent operation during network outages. The cloud support layer, as the global hub, consists of… The system consists of a highly available cloud server cluster and a time-series + relational database cluster. The cloud server cluster enables global collaborative scheduling and algorithm management, while the database cluster stores real-time computation data and static parameters, providing support for global parameter synchronization and historical data querying. The network transmission layer serves as a communication guarantee, consisting of an industrial Ethernet local network and a 5G + wired dual-backup wide area network. The industrial Ethernet enables low-latency connections between local hardware, while the dual-backup wide area network enables highly reliable communication between the edge and the cloud, and supports automatic fault switching. The software infrastructure layer serves as the underlying support, consisting of an industrial-grade operating system, a virtualization environment, and algorithm and visualization support software. The operating system and virtualization environment ensure stable allocation of hardware resources, while the support software ensures the operation of core algorithms and visualized operation and maintenance. The various hardware support systems work together through pre-defined connections: all devices in the hardware acquisition layer are connected to the edge server cluster in the edge computing layer through the industrial Ethernet local network. The edge computing layer interacts with the cloud support layer through a 5G+ wired dual-backup wide area network to achieve data and command interaction. The operating system and supporting software of the software foundation layer are deployed in the hardware devices of the edge computing layer and the cloud support layer, respectively, forming a complete operation link of "data acquisition-local computing-cloud collaboration-operation and maintenance interaction", which together support the stable and efficient operation of "a security risk management system based on a dual prevention mechanism".

[0012] This application discloses a security risk management system based on a dual prevention mechanism. Figure 2 A schematic diagram of a security risk management system based on a dual prevention mechanism is shown in an embodiment of this application. Reference Figure 2The system includes a multi-source data acquisition unit, a risk-hazard dynamic coupling calculation unit, a dual prevention execution unit, a scenario complexity assessment subunit, a complexity mutation response subunit, a multi-module collaborative scheduling unit, a calculation timeout processing subunit, an evidence chain weight optimization subunit, an abnormal data processing subunit, a physical constraint correction subunit, and an adaptive feedback unit. The multi-source data acquisition unit is used to collect equipment operation data, environmental data, and manual inspection data within the enterprise. This unit adopts a "distributed acquisition + centralized preprocessing" architecture, which is divided into several acquisition sub-nodes (such as workshop-level sub-nodes and factory-level sub-nodes) according to the control area. Each sub-node is equipped with one acquisition controller to realize unified access and preliminary processing of various types of data within the jurisdiction. The data is then aggregated to the edge data storage module through industrial Ethernet to ensure that the acquisition coverage is comprehensive and the data transmission is efficient.

[0013] Regarding equipment operation data acquisition, the acquisition sub-nodes connect to the enterprise's existing equipment control system (such as PLC, DCS, SCADA system) via an industrial protocol converter (supporting mainstream industrial protocols such as Modbus-RTU, OPCUA, and Profinet). Acquired parameters include equipment operating current. ,Voltage ,temperature Vibration frequency Rotation speed Key operating indicators are monitored, and the data acquisition frequency is dynamically set according to the importance of the parameters. Core safety parameters (such as reactor temperature and high-pressure equipment current) are acquired at a frequency of 1 time per second, while general status parameters (such as ordinary motor speed) are acquired at a frequency of 1 time per 10 seconds. The data acquisition controller uses a formula... Analog signal output by the sensor Perform linear calibration (where This is the sensitivity coefficient. The zero-point offset (set according to the sensor's factory calibration report) converts the analog signal into a physical quantity value, ensuring the original data... Precision error .

[0014] Environmental data acquisition relies on an array of environmental sensors deployed at key locations within the controlled area, including temperature and humidity sensors (which collect ambient temperature data). relative humidity ), gas concentration sensor (collects combustible gas concentration) toxic gas concentration Dust concentration sensor (collects PM2.5 concentration) ) and open flame detection sensor (output switch signal) (1 indicates open flame detected, 0 indicates no open flame). All sensors employ industrial-grade protection design (protection level...). IP65 rating, suitable for high-temperature, high-humidity, and dusty workshop environments; the data acquisition controller performs real-time validity checks on environmental data, and will detect data exceeding the sensor's range (such as the range of a gas concentration sensor). LEL, detection value or When LEL is used, it is automatically marked as invalid data. This triggers a sensor fault warning, preventing abnormal data from entering subsequent calculation processes.

[0015] Manual inspection data collection is achieved through mobile inspection terminals equipped with 5G communication modules (such as industrial-grade tablets and handheld PDAs). Inspectors can use the terminals on-site to input descriptions of potential equipment defects (such as "leakage at valve seals" or "corrosion of equipment casing") and take photos of the defects (resolution...). (pixels), and manually input parameters that cannot be automatically collected (such as equipment lubricating oil level, fastening bolt torque value). The terminal has a built-in standardized data entry template to ensure a uniform inspection data format; the inspection data is stored in a dual mode of "real-time upload + local caching". The terminal is used in areas with 5G signal coverage (signal strength) Data is uploaded to the acquisition sub-node in real time during signal outages, and temporarily stored in the terminal's local storage (storage capacity). The data will be automatically retransmitted after the network is reconnected, and a verification code will be used during the retransmission. (in For data bytes, Verify data integrity (total number of bytes) to ensure no data loss.

[0016] To improve the data source quality for subsequent risk-hazard coupling calculations, the data acquisition controller performs centralized preprocessing on three types of raw data: first, data standardization processing, using the min-max standardization formula. (in These are the historical extreme values ​​of the parameters (determined based on statistical analysis of historical data from the past year), and the original data... Mapped to First, the data is processed by averaging the data across different parameters to eliminate dimensional differences. Second, data smoothing is performed, using a moving average algorithm for parameters with large fluctuations, such as vibration frequency and gas concentration. (in The sliding window size is set to 5-10 acquisition cycles (based on parameter fluctuation frequency) to reduce random interference noise; thirdly, data association and labeling are performed for each preprocessed data. Add timestamp (Accurate to milliseconds), data collection sub-node number Equipment number The data is then identified by a data type identifier (Type 1 for equipment operation data, Type 2 for environmental data, and Type 3 for manual inspection data) to form structured data records. The data is then transmitted to the edge-end risk-hazard dynamic coupling calculation unit, providing a standardized and high-quality data source foundation for subsequent conflict handling and correlation analysis. The risk-hazard dynamic coupling calculation unit receives the output data from the multi-source data acquisition unit and first records the input structured data. Type A second validity check is performed to remove outliers that still exist after preprocessing of the multi-source data acquisition unit (such as those after standardization). or (data), and through timestamps Align multi-dimensional data from the same device at the same time (e.g., device A at the same time) (Temperature, current, and ambient humidity data) are used to form a device-time two-dimensional data matrix. (in (This refers to the number of collected parameters associated with the device) to ensure the consistency and timeliness of the data source for subsequent calculations.

[0017] By constructing a correlation model between risk factors and hazard characteristics, this model, using equipment as a unit, first starts from the data matrix. Extract risk factor set With hazard characteristic set — Risk Factor Set Includes equipment operating status factors (such as current deviation rate) ,in The rated current of the equipment; the duration of temperature exceeding the limit. , For indicator functions, (Temperature safety threshold) and environmental impact factors (such as the multiple of combustible gas concentration exceeding the standard). (For gas safety concentration limits), a total of The core risk factors consist of ; Hazard Characteristics Set Includes explicit equipment hazard characteristics (such as the binary characteristic corresponding to "valve leakage" in manual inspection records). If there is no leakage The sensor detected "excessive vibration" corresponding to ) and hidden danger characteristics (such as the aging coefficient corresponding to the service life of the equipment) A total of 100 selected The characteristics of each hidden danger constitute

[0018] The correlation model employs a hybrid algorithm combining multiple linear regression and grey relational analysis. First, it uses the grey relational degree formula... (in (The discrimination coefficient is set to 0.5 to mitigate the impact of extreme values) Calculate each risk factor. Characteristics of hidden dangers correlation Then construct the correlation weight matrix Subsequently, the parameters of the correlation model were optimized using gradient descent. Establish a risk-hazard correlation function (in For the intercept term, The characteristic coefficients, (for the error term), through This represents the actual risk factor value. These are the model's predicted values. To verify the model fit (using the mean of the actual values), the following requirements are made: This ensures that the correlation model can effectively reflect the inherent relationship between risks and hidden dangers.

[0019] In conjunction with multi-source data conflict handling rules based on data source credibility, the data conflict scenario is first defined as follows: when the same parameter of the same device exists in multiple sources within the same time window (e.g., within 10 seconds) (e.g., temperature collected by a sensor). Temperature recorded during manual inspection Temperature exported from system logs Furthermore, the data difference exceeds the set conflict threshold. (like When this occurs, it is determined to be a data conflict. Data source credibility is comprehensively evaluated across four dimensions: historical data accuracy, data attribute quality, data deviation trend, and scenario matching. Each dimension is scored from 0 to 10, and the credibility is calculated by weighting the scores. The formula is (in Weight According to industry safety standards, such as (Historical accuracy has the highest weight). (Data attribute quality) (deviation trend) (Scene matching accuracy); historical accuracy Data attribute quality Based on data accuracy (e.g., 0.1 level sensor) class ) Settings, data deviation trend (The smaller the mean deviation, the better) (Higher), scene matching degree Based on the data source and scenario adaptability (e.g., high-temperature resistant sensors in high-temperature scenarios) Ordinary sensors )set up.

[0020] When performing weighted fusion processing on conflicting data, a credibility-based weighted average algorithm is used. Let the conflicting data set be... ( (Number of conflicting data sources), corresponding to the set of credibility. The merged data If the credibility of a certain data source is... (Out of 10 points) then its weight is reduced. Then participate in the fusion, that is, the corrected weights. To avoid interference from low-reliability data in the fusion results; after fusion, a variance test is performed. To verify stability, the requirements are as follows: ( The preset variance threshold is set based on the parameter fluctuation characteristics, such as temperature parameters. If the conditions are not met, the credibility of the data source will be reassessed and the weights adjusted until the merged data is stable.

[0021] To achieve dynamic coupling calculation of risks and hidden dangers, the dynamic coupling calculation is carried out in three steps: First, update the risk factor set based on the fused data. With hazard characteristic set Calculate the real-time correlation matrix using the correlation model. And introduce a time decay coefficient ( (The time interval between the current moment and the last calculation, in minutes), and the historical correlation. After applying attenuation correction, the dynamic correlation degree is obtained. The first step is to ensure that the correlation is dynamically updated over time; the second step is to construct a risk-hazard coupling coefficient calculation model. ,in For elements of the dynamic correlation matrix, Standardized risk factors Standardized hazard characteristics ( Coupling coefficient The closer the value is to 1, the higher the coupling degree between risk and hidden danger, and the greater the safety risk; the third step is to introduce physical constraint corrections (such as the coupling upper limit corresponding to the service life of the equipment). (As the aging coefficient), the coupling coefficient is constrained and verified to obtain the corrected coupling coefficient. Simultaneously, set a warning threshold for the coupling coefficient. (like ),when At that time, a risk warning will be triggered and The associated risk factors and hazard characteristics are simultaneously transmitted to the dual prevention implementation unit, providing a quantitative basis for risk classification and control and hazard investigation and management.

[0022] The dual-prevention execution unit, based on the calculation results of the risk-hazard dynamic coupling calculation unit, first receives the corrected coupling coefficient synchronized by that unit. Related risk factor set Hazard Characteristics Set and equipment identification The unit's built-in result parsing module performs structured processing on the data, generating an execution instruction data package containing "Equipment ID - Coupling Coefficient - Risk Factor Details - Hidden Danger Characteristic Details". and through the verification code Verify the integrity of data packets to ensure that received data has not been tampered with, providing a reliable basis for subsequent operations.

[0023] Risk classification and control and hazard investigation and management operations are performed separately; the risk classification and control operation uses the modified coupling coefficient. Based on this core principle, and combined with the influence weights of risk factors, a multi-level risk classification model is constructed. First, the classification weights of each risk factor are determined using the Analytic Hierarchy Process (AHP). ,satisfy The weight determination process undergoes a consistency check. To determine the largest eigenvalue of a matrix, As the average random consistency index, it is required that Ensure the weight allocation is reasonable; then construct a comprehensive risk level scoring formula. ,in According to the rating Risk is categorized into four levels: low risk Medium risk High risk Extremely high risk Different risk levels correspond to different management and control strategies.

[0024] For low-risk levels ( Implement basic control strategies: only activate routine equipment status monitoring, include the equipment in the daily routine inspection checklist, and maintain the default inspection cycle. During the hour, it simultaneously outputs a "normal operation" command through the unit-associated device control interface, without requiring adjustment of device operating parameters; medium risk level. Implement enhanced control strategies: on the one hand, shorten the inspection cycle to... (like hour, On the one hand, it fine-tunes the operating parameters corresponding to key risk factors (such as current deviation rate) (hours). When the limit is exceeded, use the formula Adjust the operating current of the equipment to reduce To a safe range); high-risk level ( Implement emergency control measures: Immediately trigger audible and visual alarms (alarm decibels). Light flashing frequency (times / second), while the remote control equipment reduces the load to the rated load. (like hour, ), and notify the operations and maintenance personnel in Within minutes (e.g.) hour, Arrive at the scene within minutes to conduct investigation; extremely high risk level. Implement shutdown control strategies: Immediately send equipment shutdown commands via industrial control protocols (such as Modbus-TCP), cut off the main power supply to the equipment, trigger a plant-level emergency alarm, activate the fire protection system to standby mode, and automatically upload alarm information of "Equipment Shutdown - Risk Level - Emergency Handling Suggestions" to the safety production management platform to ensure that extreme risks are quickly controlled.

[0025] Hazard identification and mitigation operations are based on hazard characteristic sets. Based on risk levels, a closed-loop process is constructed: "Hazard Priority Ranking - Investigation Path Planning - Remediation Solution Matching - Effect Verification". First, hazard characteristics are prioritized, and a hazard priority index is defined. ,in Characteristics of potential hazards The hazard weight (e.g., "valve leakage") "Equipment aging" A higher value indicates a more urgent potential hazard that requires priority investigation. Subsequently, based on the physical layout of the factory area where the equipment is located (e.g., workshop location, equipment spacing), Dijkstra's algorithm is used to plan the optimal investigation path. The objective function for path planning is... ( For the first The first screening point and the first The straight-line distance between the investigation points (To ensure the number of inspection points), so that maintenance personnel can complete the inspection of potential hazards of multiple devices in the shortest way.

[0026] For identified hazards, the implementation unit matches remediation solutions using a hazard-solution mapping library. The library pre-stores standard remediation measures corresponding to various hazard characteristics (such as "excessive vibration"). The corresponding responses are: "Check the tightness of the equipment's foundation bolts and replace the vibration damping pads if necessary"; "Gas concentration exceeds the standard". (Corresponding to "Check the operating status of the ventilation system and replace the gas sensor"), and also according to the age of the equipment. With operating load The solution is adapted and adjusted, with adjustment coefficients. To ensure the treatment plan aligns with the actual condition of the equipment, after treatment, the execution unit recalculates the corrected coupling coefficient by collecting subsequent data from the multi-source data acquisition unit (equipment operation data and environmental data within one hour after treatment). And through the governance effectiveness evaluation formula ( To improve the effectiveness of governance, (Indicating effective governance) Verification of results requires... If the treatment is deemed satisfactory, Then the remediation plan is rematched and implemented until the hazard is rectified, forming a complete closed loop of hazard investigation and remediation.

[0027] The multi-source data acquisition unit, risk-hazard dynamic coupling calculation unit, and dual prevention execution unit are sequentially connected, employing a layered communication architecture of "industrial Ethernet + edge gateway forwarding." Each unit connects to an industrial-grade gigabit switch (supporting the IEEE 802.3 standard) via an RJ45 interface and achieves data interaction based on the Modbus-TCP protocol. The multi-source data acquisition unit acts as the data sender, encapsulating structured data frames in the format of "device ID + data type + timestamp + value," with the data frame length controlled within 1024 bytes. The sending cycle is synchronized with the acquisition frequency (1 time / second for core parameters, 1 time / 10 seconds for general parameters), and the data is transmitted via formula. ( (For the sampling frequency) Ensure that data transmission matches the sampling rhythm to avoid data accumulation.

[0028] The risk-hazard dynamic coupling calculation unit, acting as an intermediate forwarding and calculation node, receives data frames from the multi-source data acquisition unit. It first verifies data integrity using the CRC32 checksum algorithm CRC32 = XOR(dataframe, polynomial) (where polynomial is the standard CRC32 polynomial 0xEDB88320). After successful verification, it parses the data and performs coupling calculations. Once the calculations are complete, it adjusts the coupling coefficients accordingly. Risk level rating The results are encapsulated into new data frames and forwarded to the dual prevention execution unit. The forwarding latency is controlled within 50ms (by configuring the QoS priority of the switch, the data frame priority of this unit is set to the highest to ensure that forwarding takes precedence over other non-critical data). After receiving the data frame, the dual prevention execution unit also performs CRC32 verification. If the verification passes, it parses and executes control and governance operations, and generates an "operation status feedback frame" (such as "control policy has been executed" or "hazard investigation in progress"), which is then sent back to the risk-hazard dynamic coupling calculation unit to form a one-way communication closed loop foundation of "collection-calculation-execution-status feedback".

[0029] Furthermore, the risk-hazard dynamic coupling calculation unit forms a deviation feedback link with the multi-source data acquisition unit to constitute a closed-loop safety risk management link; the triggering logic of this deviation feedback link is based on the risk assessment deviation rate determination, and the risk-hazard dynamic coupling calculation unit compares the risk factor values ​​predicted by the coupling calculation. "and" the actual risk factor values ​​subsequently collected by the multi-source data acquisition unit Calculate the risk assessment deviation rate ( (for the number of risk factors), when Exceeding the preset deviation threshold (like When a deviation feedback process is triggered, it ensures that feedback is only initiated when there is a significant deviation between the calculation result and the actual data, thus avoiding invalid feedback consuming communication resources.

[0030] The feedback content of the deviation feedback chain includes three parts: "deviation source identification - deviation value - correction suggestion". The deviation source identification clearly identifies the specific abnormal risk factors (such as...). (Current deviation rate) Deviation exceeds standard), deviation value passes The magnitude of the quantified deviation (positive deviation indicates the predicted value is higher than the actual value, negative deviation indicates the predicted value is lower than the actual value), and correction suggestions are generated based on the deviation trend, such as when... If there are three consecutive positive deviations that gradually increase, it is recommended to "reduce the risk factor". The weighting ratio in the coupled calculation; the feedback data is transmitted through a dedicated communication link (physically isolated from the forward data transmission link, using independent ports and VLANs), the transmission protocol adopts the MQTT lightweight protocol, and the message QoS level is set to 2 (ensuring that the message is received only once and is not lost), which meets the feedback requirements of low bandwidth and high reliability.

[0031] After receiving feedback data, the multi-source data acquisition unit performs parameter correction operations: First, it parses the correction suggestions in the feedback; if the suggestion is to adjust the acquisition parameters (such as "increase"), it will correct the parameter settings. The corresponding current parameter acquisition frequency is then obtained through the formula. Adjust the sampling frequency (e.g.) hour, Increase the sampling density of abnormal parameters; if it is recommended to adjust the data preprocessing algorithm (such as "optimizing the smoothing window size of current parameters"), then recalculate the moving average window. The original window size is used, and the window range is limited to between 3 and 10 to avoid data fluctuations due to an excessively small window or lag due to an excessively large window. The parameters of the preprocessing module are also updated.

[0032] After parameter correction, the multi-source data acquisition unit resends the corrected acquisition data to the risk-hazard dynamic coupling calculation unit. This unit then re-executes the coupling calculation based on the new data and recalculates the risk assessment deviation rate. Improvement rate through deviation To verify the effectiveness of the correction, if If the correction is deemed valid, the current parameter configuration will be retained; if This triggers secondary feedback, adjusting the correction strategy (such as further increasing the sampling frequency or changing the preprocessing algorithm) until... This forms a complete closed loop of "deviation detection - feedback - correction - verification". Ultimately, through the collaboration of "forward data links for sequential communication" and "reverse adjustment links for deviation feedback", a closed-loop safety risk management link covering the entire process of "data acquisition - calculation - execution - correction" is formed, ensuring that the system continuously adapts to changes in actual working conditions and improves the accuracy and stability of long-term operation.

[0033] The scenario complexity assessment subunit acquires conflict characteristics and the proportion of high-risk data from multi-source data to construct quantification rules for scenario complexity, thereby determining the complexity level of the current security scenario. It can also update the complexity level based on real-time data changes. The multi-source data conflict characteristics are quantified through three dimensions: conflict frequency, number of devices involved in the conflict, and data type of the conflict. (Considering the real-time data requirements in industrial scenarios, a time window of approximately 1 minute is manually set to balance data timeliness and computational efficiency), reflecting the density of data conflicts per unit time; the percentage of devices involved in the conflicts. The "number of devices with data conflicts" refers to the total number of devices with at least one parameter exhibiting multi-source data conflicts within the current time window, reflecting the scope of devices affected by the conflicts; the conflict data type weights... (Existence type) conflict) For the number of data types, such as temperature, current, vibration, etc. Type weight, core security parameter type Normal parameter type (As an indicator function), it distinguishes the degree of influence of different conflict types, and the final comprehensive value of conflict characteristics. , .

[0034] The proportion of high-risk data is calculated based on the distribution characteristics of risk factor data exceeding the threshold: First, the risk factors for each device are... (e.g., current deviation rate, duration of temperature exceeding limit) Set safety thresholds ,when Data was identified as high-risk at that time; subsequently, the percentage of high-risk data per device was calculated. Then, based on the importance weight of the equipment (Key production equipment) Auxiliary equipment Weighted calculation of the overall proportion of high-risk data in the region (N is the total number of devices within the controlled area). .

[0035] Based on the comprehensive value of conflict characteristics The proportion of high-risk data Construct a metric formula for scene complexity ,in This formula normalizes and merges features from two dimensions into a single complexity index; subsequently, a threshold is set for classifying complexity levels: low complexity... Medium complexity ( High complexity Extremely high complexity This forms a set of quantification rules for complex scenarios. When new data is input, the sub-unit recalculates every 5 seconds. If the new calculated value matches the threshold range corresponding to the current complexity level, the current level is maintained; otherwise, if it exceeds the threshold range of the current level (such as the original low complexity level), the current level is maintained. New value If the complexity level is not updated, it will be updated to the corresponding new level to ensure that the complexity level is dynamically adjusted according to real-time data.

[0036] The scene complexity assessment subunit also includes a complexity mutation response subunit; this subunit communicates with the scene complexity calculation module in real time, obtaining two consecutive scene complexity levels at a 1-second interval. (Current time level) and (Previous time level), and preset level difference threshold. (like That is, a response is triggered when the difference between adjacent levels is 1, and the levels are ranked as "low". ,middle 2. High Extremely high (Quantification) provides a criterion for mutation detection.

[0037] When the difference between two consecutive complexity levels exceeds a set threshold, the complexity mutation response subunit triggers a complexity level rearrangement and synchronizes the rearranged complexity level to the risk-hazard dynamic coupling calculation unit; firstly, the level difference quantification formula is used. Calculate the difference between adjacent grades, when Time (e.g.) (Medium complexity) (Extremely high complexity) If a conflict is detected, it is determined to be a sudden change in complexity, and a rearrangement process is immediately triggered. During the rearrangement, the sub-unit first backtracks the conflict characteristics within the last 3 minutes. The proportion of high-risk data The curve changes, calculated by slope. rate of change) and ( Rate of change), if the rate of change is positive and the absolute value minutes (e.g.) If the number of occurrences is less than or equal to 1 / minute, it is considered a "persistent mutation," and the rearranged level will maintain the current level. And extend the level stability monitoring cycle to 10 seconds; if the absolute value of the rate of change If the value is / minute, it is determined to be a "transient mutation" and rearranged as follows: and intermediate level (such as) The intermediate level is 3 (high complexity) to avoid misjudgment of the level due to instantaneous data fluctuations.

[0038] After the rearrangement is completed, the complexity mutation response subunit transmits the rearranged hierarchy via the Modbus-TCP protocol. Mutation type (persistent / transient), mutation triggering basis (e.g., " It rose from 20 to [amount] in 3 minutes. The data is encapsulated as a response data packet and sent to the global scheduling module of the risk-hazard dynamic coupling calculation unit. At the same time, it is synchronized to the multi-module collaborative scheduling unit to provide a decision-making basis for subsequent allocation of computing resources and adjustment of coupling calculation parameters under sudden change scenarios, ensuring that the system can still accurately perform risk-hazard coupling calculation when the complexity of the scenario changes drastically. The system also includes a multi-module collaborative scheduling unit; this unit is deployed on an edge industrial server and communicates with the control modules of the scenario complexity assessment subunit, the risk-hazard dynamic coupling calculation unit (including each subunit), and the multi-source data acquisition unit via an internal bus, with a communication rate of [missing information]. It ensures real-time reception of scene complexity level and running status data of each computing unit, and has global scheduling authority over computing resources such as edge CPU, memory, and disk I / O, with scheduling granularity accurate to the process level (supports resource allocation by individual computing thread).

[0039] The multi-module collaborative scheduling unit pre-stores the mapping relationship between the scene complexity level output by the scene complexity evaluation subunit and the priority of each computing unit. The mapping relationship is stored in the form of a two-dimensional table, where the scene complexity level is divided into low and high. ,middle( ,high Extremely high Level 4, with priority given to each computing unit according to "core computing". Auxiliary calculation The "data temporary storage" principle is set as follows: the risk-hazard dynamic coupling calculation unit (including sub-units such as scenario complexity assessment and evidence chain weight optimization) has the highest priority (denoted as...). The preprocessing module of the multi-source data acquisition unit is the next step. The minimum edge data storage module Priority adjustment coefficients corresponding to different complexity levels Low complexity Medium complexity High complexity Extremely high complexity Adjusted actual priority ( Based on the basic priority), ensure that the priority of core computing units is further improved in high-complexity scenarios.

[0040] The computing resources allocated to each computing unit are determined based on the level of scenario complexity. This allocation is based on the total computing resources at the edge (number of CPU cores). Memory capacity Based on this, a weighted proportional algorithm is used: first, the priority ratio of each unit is calculated. ( To calculate the number of units, ), then press Memor Allocate basic resources; for example, the edge terminal has a total of 8 CPU cores and 16GB of total memory, and dynamic coupling computing units for risks and hidden dangers in medium-complexity scenarios. Multi-source data acquisition and preprocessing module Data storage module ,but This corresponds to an allocation of approximately 3.48 CPU cores (rounded up to 3 cores) and approximately 6.96GB of memory (rounded up to 7GB), thereby ensuring that resources are tilted towards high-priority units.

[0041] Furthermore, it can dynamically adjust resource allocation by monitoring the thread utilization rate of each computing unit in real time to obtain the remaining computing power; this unit collects thread utilization rate every 500ms through resource monitoring agents deployed in each computing unit. (such as CPU thread utilization) Memory thread usage And through the formula for remaining calculation amount Calculate the remaining computational workload for each unit ( Allocate total resources to this unit. This represents the number of sampling periods in the last 10 times. For the first (Thread occupancy rate of the second sample); when a certain unit (Resource scarcity threshold) and the existence of other units When the resource redundancy threshold is reached, dynamic adjustment is triggered: Adjustment amount ( The adjustment factor is set to 0.3. For the remaining resources of redundant units, (representing the resource quantity corresponding to the redundancy threshold), and the redundant units. Resources were allocated to units with limited resources, and adjustments were made accordingly. Secondary monitoring ensures that resource allocation meets real-time requirements and thread utilization. This reflects the resource usage intensity of the computing unit at the t-th sampling time. By averaging the thread occupancy rates of the last T samplings, the average resource usage ratio per unit time can be obtained. Subtract this ratio from 1 and then multiply by the total allocated resources. The remaining allocatable computational cost can then be derived. This ensures that resource adjustments are based on actual usage.

[0042] The multi-module collaborative scheduling unit is equipped with a computation timeout handling subunit; this subunit corresponds one-to-one with the task scheduling module of each computing unit and receives the start time of the computing tasks in real time. Current running time ( (The current time is used), and preset timeout thresholds corresponding to different scene complexity levels are stored in advance. This forms a timeout threshold mapping table: low In complex scenarios, core computing units (such as risk-hazard coupled computing) Auxiliary computing units (such as data preprocessing) In medium complexity scenarios, , In highly complex scenarios, In extremely complex scenarios, The threshold setting is based on the principle that "the higher the complexity, the higher the requirement for computational timeliness" to ensure that core tasks can be completed quickly in high-risk scenarios.

[0043] The computation timeout handling subunit sets a preset timeout threshold based on the scene complexity level output by the scene complexity evaluation subunit. When the computation time of any computation unit approaches the timeout threshold for the corresponding scene complexity level, a timeout warning formula is used. Calculate the early warning coefficient when (Right now When a timeout is detected, the resource retrieval process is immediately triggered. The timeout processing subunit retrieves a preset proportion of computing resources from low-priority computing units and allocates them to high-priority computing units. according to Dynamic settings: hour, hour, hour, The type of resource retrieved is consistent with the type of missing resource in the stressed unit (e.g., if CPU is scarce, CPU resources are retrieved; if memory is scarce, memory resources are retrieved); for example, in extremely complex scenarios, risk-hazard coupled computing units... ), Then it will retrieve its data from the data storage module (low priority). CPU resources are allocated to this unit to ensure that tasks are performed within the specified timeframe. Complete within the time frame to avoid delays in risk assessment due to calculation timeouts.

[0044] After resource retrieval is completed, the computation timeout handling subunit continuously monitors the target unit's... and ,like If the task completes normally, then the resources retrieved by the low-priority unit are restored; if Still approaching Then the call will be triggered again (maximum number of calls). (Timeout warning) is sent to the operation and maintenance terminal at the same time, prompting manual intervention for inspection, forming a closed-loop processing mechanism of "timeout warning - resource retrieval - result feedback" to ensure that each computing unit can run efficiently under different complexity scenarios.

[0045] The risk-hazard dynamic coupling calculation unit includes an evidence chain weight optimization subunit. This subunit communicates bidirectionally with the data source management module of the multi-source data acquisition unit and the coupling coefficient calculation module of the risk-hazard dynamic coupling calculation unit. On the one hand, it receives historical operating data and real-time output data from various data sources (such as temperature sensors, vibration sensors, and manual inspection terminals). On the other hand, it synchronizes the optimized data source weights to the coupling calculation module, providing a weight basis for the weighted fusion of conflicting data. The communication adopts JSON data format, and the data transmission delay is ≤20ms to ensure that the weight update and calculation rhythm are synchronized.

[0046] The evidence chain weight optimization subunit constructs multi-feature weight calculation rules based on the historical data accuracy, data attribute quality, data deviation trend, and scenario matching degree of the data sources to determine the basic weights of each data source. First, it quantifies the four types of features: historical data accuracy... Based on data verification results from the past three months, the formula is: If a temperature sensor collects 10,000 data points in the past three months, and 9,850 of them pass the verification, then... Data attribute quality Values ​​are assigned based on the data source hardware parameters and data type, including sensor accuracy (0.1 level accuracy). Score, Level 0.5 (minutes), data sampling frequency (1 time / second) 1 point, 1 time / 10 seconds (points), through We get the weighted average. Data deviation trend The formula is calculated based on the mean change in data deviation over the past week. The average deviation over the past week is ,but 10 points Scene matching degree Assign values ​​based on the degree to which the data source adapts to the current scenario, such as high-temperature resistant sensors in high-temperature scenarios. Classification, ordinary sensors Partial waterproof sensor for humid environments Part, non-waterproof sensor point, .

[0047] When constructing the multi-feature weight calculation rules, the Analytic Hierarchy Process (AHP) is used to determine the weight coefficients of the four types of features: historical data accuracy weight. (Highest weighting, reflecting the core importance of data reliability), Data attribute quality weighting Data deviation trend weight Scene matching weight ,satisfy Passed the consistency test Verify the rationality of the weights To determine the largest eigenvalue of a matrix, ,Require ); Basic weights The calculation formula is After normalizing each feature value, a weighted fusion is performed to ensure... such as a data source ,but A higher base weight indicates a stronger reliability of the data source.

[0048] Furthermore, it can dynamically adjust the base weights based on real-time data deviation values; real-time data deviation values Defined as "real-time output value of data source" Standard values ​​after fusion with multi-source data "absolute difference", that is Set deviation threshold (Set according to the data source type, such as temperature sensor) Current sensor ),when When, correction factor (The smaller the deviation, the larger the correction coefficient, with a maximum of 1.1), the corrected weights ;when When, correction factor ( Maximum permissible deviation of the data source, such as a temperature sensor. ),make sure To prevent data source failure due to excessively low weight, the weight was corrected. For example, a temperature sensor ( ,but By dynamically adjusting the weights, the current reliability of the data source can be reflected in real time.

[0049] The evidence chain weight optimization subunit also includes an anomaly data processing subunit; this subunit works in conjunction with the real-time data source monitoring module to collect output data from each data source at a 100ms interval, while simultaneously receiving the standard value after multi-source data fusion. Abnormal data is identified through a deviation detection algorithm, ensuring that abnormal data is processed in a timely manner before entering the coupled calculation, thus avoiding interference with the risk-hazard coupling results.

[0050] When a deviation value in the data source output is detected to exceed the set range, the anomaly is first defined using a dual judgment standard: one is the absolute deviation judgment. (Maximum permissible deviation); secondly, continuous deviation determination, based on three consecutive data acquisitions. All exceeded (e.g., temperature sensor 3 consecutive times) If any one of the criteria is met, it is determined to be abnormal data; the abnormal data processing subunit reduces the weight correction magnitude of the corresponding data source, and the correction magnitude adjustment coefficient is... (Under normal conditions) That is, the corrected weights If a data source has a weight of 0.93 after normal correction, but an anomaly occurs... This reduces the impact of abnormal data sources on the overall weight.

[0051] At the same time, abnormal data information is marked, including the unique identifier of the abnormal data source. (e.g., "Temp_Sensor_001"), time of exception occurrence (Accurate to milliseconds), deviation value Anomaly type (absolute deviation / continuous deviation), and marking information are stored in the edge-end anomaly data log database, with a retention period of [not specified]. This allows maintenance personnel to trace the cause of anomalies within hours, facilitating subsequent investigations (such as sensor failures or line interference); and the proportion of marked anomaly data in subsequent risk-hazard coupling calculations is reduced by a preset percentage. Dynamically set based on the severity of the anomaly: Absolute deviation anomaly (The proportion decreased) Only retain (involved in calculation), continuous deviation anomaly (The proportion decreased) ,reserve (Involved in the calculation), the percentage adjustment formula is as follows: Such as abnormal data Abnormal absolute deviation Significantly reduces the impact of abnormal data on the coupling coefficient To prevent interference and ensure the accuracy of the calculation results.

[0052] After an anomaly is handled, the sub-unit continues to monitor the data source. Changes, when collected 5 times consecutively When the anomaly is resolved, the weight adjustment range is restored. The proportion of data involved in calculation And update the exception log status to "recovered"; if the exception lasts for more than 1 hour ( If the data source is continuously abnormal, an alarm message "data source is continuously abnormal" will be sent to the operation and maintenance terminal, prompting the replacement of the sensor or the inspection of the communication line. This forms a closed-loop processing mechanism of "abnormal detection - weight adjustment - data deweighting - recovery verification - alarm prompt", ensuring that the weight of the evidence chain always matches the actual state of the data source. The risk-hazard dynamic coupling calculation unit includes a physical constraint correction subunit. This subunit communicates bidirectionally with the coupling coefficient calculation module of the risk-hazard dynamic coupling calculation unit, the equipment information management module of the multi-source data acquisition unit, and the edge device status monitoring module. On the one hand, it receives the initial coupling coefficient output by the coupling coefficient calculation module. Basic equipment information synchronized by multi-source data acquisition units (such as equipment design life) Rated load On the other hand, the device's current service life is collected in real time by the edge device status monitoring module. Real-time load Risk data is transmitted to adjacent devices. The communication uses the industrial Ethernet protocol, and the data update cycle is synchronized with the coupling calculation cycle (1 time / 5 seconds) to ensure that the constraint correction and coupling calculation rhythm match and avoid correction lag.

[0053] The physical constraint correction subunit constructs dynamic constraint threshold calculation rules based on equipment service life and real-time load rate to perform constraint verification on the risk-hazard coupling coefficient. First, the equipment service life and real-time load rate are quantified: Equipment Service Life Coefficient. The formula is calculated by comparing the current service life with the design life. For example, the design life of a certain device Years, current service life Year, then ;like ,but (This indicates that the equipment has exceeded its service life and its physical performance has completely deteriorated.) A higher value indicates a lower safety redundancy due to equipment aging.

[0054] Real-time load rate Defined as the ratio of the current real-time load to the rated load, the formula is: Such as the rated load of the equipment Real-time load ,but Considering the reasonableness of short-term equipment overload, a maximum load rate threshold is set. ,when Time to take (To avoid threshold distortion caused by extreme overload data). The larger the value, the higher the current operating load of the equipment and the greater the physical pressure it bears.

[0055] When constructing dynamic constraint threshold calculation rules, a weighted fusion algorithm is used to determine the upper limit of coupling coefficient constraints. (i.e., dynamic constraint threshold), firstly, the weights of the service life coefficient and the real-time load rate are determined using the Analytic Hierarchy Process (AHP): Equipment service life weight. (Reflecting the long-term impact of equipment aging on safety redundancy), real-time load factor weighting (Reflecting the immediate impact of the current load on the safety status), meeting the requirements. Passed the consistency test Verify the reasonableness of the weights ( To determine the largest eigenvalue of a matrix, ,Require (Ensure that the weight allocation is absolutely reasonable); dynamically constrain the threshold. The calculation formula is ,in Used to normalize the load rate to The range is consistent with the service life coefficient dimension; for example, a certain device ,but This indicates that the reasonable upper limit of the risk-hazard coupling coefficient for the current physical state of the equipment is 0.255; if it exceeds this value, it needs to be corrected.

[0056] When performing constraint verification on the risk-hazard coupling coefficient, the initial coupling coefficient is... With dynamic constraint threshold Comparison: If If the initial coupling coefficients meet the physical constraints of the device, no correction is needed, and the output can be directly performed. ;like If the initial coupling coefficient exceeds the actual physical carrying capacity of the equipment (possibly due to data fluctuations or model deviations), constraint correction is required. The correction formula is as follows: (The exponential term is used to implement the non-linear correction that "the more the threshold is exceeded, the greater the correction magnitude," and the coefficient 5 is an empirical parameter to ensure that the correction is effective.) Approaching ),like ,but This is to avoid the corrected coefficients becoming completely disconnected from the actual risks.

[0057] Furthermore, it can adjust the correction magnitude of the coupling coefficient according to the risk diffusion rate; firstly, regarding the risk diffusion rate... To quantify this, the risk diffusion rate is defined as the efficiency of risk transmission between adjacent devices, calculated by multiplying the "risk transmission time" by the "risk change rate": Risk Transmission Time The time interval between the transmission of a risk signal (such as excessive temperature or abnormal vibration) from one device to an adjacent device is obtained by the time difference in sensor data acquisition between the adjacent devices. The formula is: ( The time it takes for a risk to be detected by adjacent devices. (Time when the risk is detected by the local device), such as the local device Adjacent devices ,but Risk change rate The formula is: The change range of local equipment risk factors within a preset time window (the default preset time window is 10 seconds, which can be manually adjusted according to the industry's risk diffusion characteristics; for example, the time window can be set to 5 seconds for the chemical industry where risk diffusion is faster, and 15 seconds for the machinery industry). ( The risk factor value after 10 seconds. (current risk factor value), such as ,but

[0058] Risk diffusion speed The calculation formula is The unit is A higher value indicates that the risk spreads faster between devices, requiring stricter coupling coefficient correction for early warning; a risk spread rate classification threshold is set: low-speed spread ( ), medium-speed diffusion ( ), high-speed diffusion ( Different diffusion velocities correspond to different correction adjustment coefficients. Slow diffusion (Maintaining the original correction range), medium-speed diffusion (The correction range has been increased) ,make Closer ), high-speed diffusion (The correction range has been increased) Further compression (To avoid underestimation of the coupling coefficient due to risk diffusion).

[0059] When adjusting the correction magnitude of the coupling coefficient, if the initial coupling coefficient The corrected final coupling coefficient By introducing an adjustment coefficient Increase the exponent term, thereby reducing the adjusted coefficient. The difference increases the correction margin; for example... High-speed diffusion ,but Compared to before the adjustment Further reductions better meet the physical constraints of equipment under conditions of rapid risk diffusion; if Then only At that time, through (Slight decrease) Preventive corrections are made to avoid risk spread that could lead to excessive coupling coefficients, ensuring that constraint corrections are both consistent with the physical state of the equipment and can dynamically adapt to the risk spread trend.

[0060] After constraint verification is completed, the physical constraint correction subunit will use the final corrected coupling coefficients. (or Dynamic constraint threshold Speed ​​of risk spread The results output module of the dynamic coupling calculation unit for risk and hidden danger is synchronized, and the correction basis (such as...) is also included. The data is stored in the edge correction log library, which makes it easy for maintenance personnel to trace the correction logic and form a complete constraint correction process of "data collection - threshold calculation - constraint verification - amplitude adjustment - result output". This ensures that the risk-hidden danger coupling coefficient always matches the actual physical load-bearing capacity of the equipment and avoids misjudgment of risks due to model calculation deviations.

[0061] The system also includes an adaptive feedback unit; this unit is deployed on both edge and cloud nodes. The edge feedback submodule communicates in real time with the risk-hazard dynamic coupling calculation unit and the physical constraint correction subunit via an internal bus, with a sampling period of once. The second interval is used for rapid response to local deviations; the cloud feedback submodule receives deviation data and adjustment records synchronized from the edge terminal through the wide area network, once every 30 seconds, for global parameter optimization. The dual-node collaboration ensures that the feedback is both real-time and globally adaptable. At the same time, the unit has a built-in feedback rule database, which pre-stores parameter adjustment strategy templates corresponding to different deviation scenarios, providing a basis for triggering adjustment commands.

[0062] The adaptive feedback unit monitors the risk assessment deviation rate output by the risk-hazard dynamic coupling calculation unit and the constraint correction deviation rate output by the physical constraint correction subunit. First, it quantifies both types of deviation rates: risk assessment deviation rate. To couple the calculation of the deviation between the predicted and actual values, the formula is as follows: For the number of risk factors, To predict risk factor values, (This refers to the actual risk factor values ​​subsequently collected by the multi-source data acquisition unit). For example, the deviations between the predicted and actual values ​​of three risk factors for a certain device are as follows: ,but Constraint Correction Deviation Rate To correct the deviation between the corrected coupling coefficient and the actual safety status of the equipment, the "corrected coupling coefficient" is used. Compared with the actual failure rate of equipment The correlation is calculated using the following formula: ( The correlation coefficient is set based on industry failure statistics, such as those for the chemical industry. ,like ,but .

[0063] When the parameter adjustment command of the risk-hazard dynamic coupling calculation unit is triggered, a deviation rate threshold is set. ,when or At that time, adjust the parameters according to the deviation type: if If the standard is exceeded, adjust the characteristic coefficients of the risk-hazard correlation model. (as in the original) Adjusted to (Ensure that the adjustment range is positively correlated with the degree of deviation); if If the limit is exceeded, adjust the dynamic threshold weight of the physical constraint correction subunit. (as in the original) Adjusted to The adjustment command is encapsulated in JSON format, containing "adjustment parameter name - original value - new value - adjustment basis". or (Numerical values) ensure that the dynamic coupling calculation unit for risk and hidden danger can accurately perform parameter updates.

[0064] Furthermore, it can verify the adjustment effect and optimize the adjustment rules based on the improvement in deviation after parameter adjustment; the adjustment effect verification passes the deviation improvement rate. The calculation formula is as follows: ( To adjust the previous deviation rate, For adjustment The mean of the deviation rates of three consecutive samples after adjustment), if If the adjustment is deemed valid, the current adjustment rules will be retained; if The adjustment was deemed valid and passed. Fine-tune the adjustment range coefficient (e.g., adjust the original adjustment range coefficient of 0.8 to...). );like If the adjustment is deemed invalid, rule optimization is triggered, and a backup adjustment strategy (such as the original adjustment) is retrieved from the feedback rule database. Change to adjustment ), re-execute the adjustments and verify until Simultaneously, the "deviation type - adjustment parameters - adjustment range - improvement rate" are recorded in the cloud rule optimization library. By statistically analyzing data from the past month, the improvement rate of each adjustment rule under the same deviation scenario is calculated. The average improvement rate of each rule is calculated using a weighted average method (the weight is the number of rule executions). The rule with the highest average improvement rate is marked as the "preferred rule" to ensure the objectivity of the preferred rule. The adjustment rule with the highest improvement rate under the same deviation scenario is marked as the "preferred rule" and updated to the edge feedback rule database to achieve self-optimization of the adjustment rule.

[0065] The system adopts an edge-cloud collaborative architecture; this architecture follows the principle of "real-time computing localized, non-real-time tasks cloudified," with industrial-grade edge servers (such as Advantech UNO-2484G, with an Intel Core i7-1165G7 CPU, 16GB of memory, and 512GB of SSD storage) at the edge, providing wide temperature range (…). ), vibration resistance ( With its acceleration capabilities, it is well-suited for harsh industrial environments. The cloud-based distributed server cluster (3 Huawei FusionServerPro2288HV5 servers, each with an Intel Xeon Gold 6338 CPU, 64GB of memory, and 2TB HDD + 1TB SSD storage) utilizes KVM virtualization technology to partition the cloud into independent virtual machines, deploying data storage and parameter management services separately to ensure high availability (cluster availability) of cloud services. ).

[0066] The key computing modules for deploying multi-source data acquisition units and risk-hazard dynamic coupling calculation units at the edge are as follows: the multi-source data acquisition unit includes a sensor access module and a data preprocessing module (such as moving average and standardization), and communicates directly with field sensors and inspection terminals, with low latency in data acquisition and preprocessing. The key computational modules of the risk-hazard dynamic coupling computation unit include a scenario complexity assessment subunit, an evidence chain weight optimization subunit, and a physical constraint correction subunit, all deployed locally at the edge to ensure the latency of core coupling computations. This system meets the needs of real-time risk assessment. A cloud-based data storage unit and a global parameter management unit are deployed. The data storage unit uses a combination of a time-series database (InfluxDB) and a relational database (MySQL). The time-series database stores nearly one year's worth of real-time coupling coefficients, deviation rates, and other time-series data (sampling interval 1 time / 5 seconds, annual storage capacity per device approximately 6.3GB). The relational database stores static data such as device basic information, feedback rules, and adjustment records. The global parameter management unit pre-stores default parameter templates for various industries (chemical, machinery, electronics) (e.g., chemical industry). Machinery industry It can be manually modified through the Web management interface, or automatically updated by receiving optimization requests from edge devices, thus achieving unified global parameter management.

[0067] The edge device and the cloud are connected via dual-link communication. The main link uses industrial Ethernet (gigabit bandwidth, supporting IEEE 802.3ad link aggregation), with low transmission latency. It is mainly used for real-time data synchronization (such as synchronizing the coupling coefficient once every 5 seconds) and parameter command issuance; the backup link adopts a 5G industrial router (supporting SA standalone networking, downlink speed) Delay This feature is only enabled when the primary link fails, and is used for critical data backup (such as synchronizing deviation records every 30 seconds). It automatically switches to the backup link when the primary link latency exceeds a preset latency threshold or the link is interrupted. The primary link latency is calculated as the average of three consecutive samples, using the following formula: (The main link delay is the delay of three consecutive samples), with a preset delay threshold. ,when When a link interruption signal is triggered (such as five consecutive ICMP ping requests timeouts), the handover logic is completed within 100ms. During the handover process, the edge device temporarily stores the data to be synchronized in its local cache (cache capacity). Once the link is restored, data will be retransmitted in the order of "old first, then new" to avoid data loss.

[0068] Furthermore, the edge device possesses the ability to operate independently in offline mode. The offline determination condition is "both links are interrupted and the duration is..." "Seconds" refers to the automatic activation of core parameters (such as dynamic constraint thresholds and weighting coefficients within the past hour) and feedback rules at the edge when offline, maintaining the normal operation of core functions such as multi-source data collection, risk-hazard coupling calculation, and dual prevention execution. The offline runtime is [not specified]. The duration is 24 hours (depending on edge storage capacity and device power consumption; 72 hours is supported by default). Operational data generated during offline periods (such as coupling coefficients and operation logs) is stored on the edge's local SSD, named according to "timestamp + data type," with a single file size of [missing information]. To avoid file fragmentation; when dual links are restored, the edge device automatically detects and triggers data retransmission, and uses an MD5 checksum before retransmission. data data After verifying data integrity and completing the retransmission, the system receives the latest parameters and rules from the cloud, updates local configurations, and ensures that the collaborative state with the cloud can be quickly restored after going offline, forming a complete closed loop of "real-time collaboration - anomaly switching - offline autonomy - recovery synchronization".

[0069] The adaptive feedback unit achieves synergy between rapid response to local deviations and optimization of global parameters through a technical approach of "dual-node deployment at the edge and the cloud + one edge sampling every 2 seconds + one cloud synchronization every 30 seconds"—high-frequency sampling at the edge can capture the risk assessment deviation rate in real time. Deviation rate from constraint correction Subtle changes prevent the accumulation and expansion of local deviations; low-frequency synchronization in the cloud can integrate deviation data and adjustment records from multiple edge nodes, providing cross-scenario data support for global parameter template optimization. The combination of the two enables the feedback mechanism to have both millisecond-level local response capabilities and to form universal optimization rules that are adaptable to multiple industries, thereby reducing the problem of parameter adjustment failure caused by "local response lag" or "single global rules".

[0070] Through quantitative calculation and and set The trigger threshold, combined with the precise matching logic of "deviation type - parameter adjustment" (such as...) Adjusting the correlation model coefficients beyond the standard Adjusting the constraint threshold weight when the limit is exceeded This ensures that parameter adjustments are initiated only when the deviation exceeds a reasonable range, and that the adjustment target directly corresponds to the root cause of the deviation—avoiding invalid adjustments that consume computational resources when there is no deviation. It also prevents a decrease in coupling calculation accuracy caused by mismatch between deviation and adjustment parameters, thereby reducing the risk-hazard coupling coefficient. The calculation deviation is always kept within an acceptable range, thus improving the stability of the risk assessment results.

[0071] Based on deviation improvement rate Effect verification and rule optimization mechanism ( Retention rules (Triggering backup strategies) allows for continuous iterative adjustment of the logic through a closed loop of "adjustment-verification-optimization"—effectively filtering the optimal adjustment strategies to suit different deviation scenarios, eliminating inefficient strategies, and avoiding the decline in adaptability caused by long-term reliance on fixed adjustment rules; at the same time, the "preferred rules" are synchronized to the edge database, so that efficient strategies can be directly called in subsequent scenarios with the same deviation, shortening the adjustment response cycle, and thus improving the efficiency and reliability of the entire system's parameter self-optimization.

[0072] The system adopts an edge-cloud collaborative architecture of "real-time computing localized + non-real-time tasks cloudified". The wide temperature range and vibration resistance of the industrial-grade edge servers are suitable for industrial environments, ensuring multi-source data acquisition (latency) ) and core coupled computing (delay) Stable operation under harsh working conditions; cloud-based distributed clusters achieve high availability of data storage and global parameter management through virtualization technology. It can securely store massive amounts of time-series data and static configuration information. The two work together to meet the low latency requirements of real-time risk management on site, and can also achieve unified parameter management of cross-regional devices through the cloud, avoiding the problems of "insufficient computing power when running entirely locally" or "excessive latency when running entirely in the cloud".

[0073] The edge and cloud are designed with dual links (industrial Ethernet main link + 5G backup link), combined with the average latency of the main link. The calculation and 100ms link switching logic can be implemented when the main link latency exceeds the threshold. In the event of an interruption, the system quickly switches to a backup link while temporarily storing data to be synchronized in a local cache; this works in conjunction with the "dual-link interruption" mechanism at the edge. The "trigger offline execution in seconds" mechanism ensures that even in the event of network anomalies, the edge device can still maintain core functions (multi-source data acquisition, coupled computing, and dual-prevention execution) by relying on local backup parameters. This prevents the entire security management system from being paralyzed due to network failures, thereby improving the continuity of system operation and risk resistance. The MD5 checksum retransmission and parameter update after the link is restored can ensure the consistency of data between the edge and the cloud, and maintain the long-term stability of the collaborative architecture.

[0074] In summary, this application has at least the following beneficial effects: 1. Improve the response efficiency and adaptability of parameter adjustment. Through edge-cloud dual-node collaborative feedback, it can achieve millisecond-level rapid response to local deviations and rely on the cloud to integrate multi-scenario data to form general optimization rules, effectively reducing the problem of parameter adjustment failure caused by local response lag or single global rules. 2. To ensure the stability and accuracy of risk assessment results, by quantifying the deviation rate and setting trigger thresholds, and by combining the precise matching of deviation types and adjustment parameters, we can avoid calculation deviations caused by ineffective adjustments that consume resources and parameter mismatches, so that the calculation deviation of the risk-hazard coupling coefficient is always within an acceptable range. 3. Enhance the continuity and resilience of system operation. Relying on the edge-cloud dual-link switching and edge offline operation mechanism, when network latency exceeds the standard or is interrupted, it can quickly switch links to ensure data transmission, and maintain the core functions for ≥24 hours through local backup parameters, so as to avoid system paralysis caused by network failure. 4. Optimize system resource allocation and global management capabilities. Through the architectural division of labor of "real-time computing localized + non-real-time tasks cloudified", it can not only meet the on-site low-latency management and control requirements, but also achieve secure storage of massive data and unified management of cross-regional device parameters with the help of cloud distributed clusters, avoiding the problems of insufficient local computing power or excessive latency in the cloud.

[0075] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A security risk management system based on a dual prevention mechanism, characterized in that, It includes a multi-source data acquisition unit, a risk-hazard dynamic coupling calculation unit, and a dual prevention execution unit; The multi-source data acquisition unit is used to collect equipment operation data, environmental data, and manual inspection data within the enterprise; The risk-hazard dynamic coupling calculation unit receives the output data from the multi-source data acquisition unit, constructs a correlation model between risk factors and hazard characteristics, and combines it with multi-source data conflict handling rules based on data source credibility to perform weighted fusion processing on conflicting data in order to achieve dynamic coupling calculation of risk and hazard. The dual prevention execution unit performs risk classification and control and hidden danger investigation and management operations based on the calculation results of the risk-hazard dynamic coupling calculation unit. The multi-source data acquisition unit, the risk-hazard dynamic coupling calculation unit, and the dual prevention execution unit are sequentially connected in communication. The risk-hazard dynamic coupling calculation unit also forms a deviation feedback link with the multi-source data acquisition unit to form a closed-loop safety risk management and control link. The risk-hazard dynamic coupling calculation unit includes a scenario complexity assessment subunit; The scenario complexity assessment subunit constructs scenario complexity quantification rules by acquiring the conflict characteristics of multi-source data and the proportion of high-risk data to determine the complexity level of the current security scenario, and can update the complexity level according to real-time data changes. It also includes a multi-module collaborative scheduling unit; The multi-module collaborative scheduling unit pre-stores the mapping relationship between the scene complexity level output by the scene complexity evaluation sub-unit and the priority of each computing unit. It allocates the proportion of computing resources of each computing unit according to the scene complexity level, and can obtain the remaining computing volume by monitoring the thread occupancy rate of each computing unit in real time to dynamically adjust the resource allocation scheme.

2. The security risk management system based on a dual prevention mechanism according to claim 1, characterized in that, The scenario complexity assessment subunit also includes a complexity mutation response subunit; When the difference between the complexity levels of two consecutive outputs exceeds a set threshold, the complexity mutation response subunit triggers a complexity level rearrangement and synchronizes the rearranged complexity level to the risk-hazard dynamic coupling calculation unit.

3. The security risk management system based on a dual prevention mechanism according to claim 1, characterized in that, The multi-module collaborative scheduling unit is equipped with a computation timeout processing subunit; The computation timeout processing subunit sets a preset timeout threshold based on the scene complexity level output by the scene complexity evaluation subunit. When the computation time of any computation unit approaches the timeout threshold of the corresponding scene complexity level, the computation timeout processing subunit retrieves a preset proportion of computation resources from the low-priority computation unit and allocates them to the high-priority computation unit.

4. The security risk management system based on a dual prevention mechanism according to claim 1, characterized in that, The risk-hazard dynamic coupling calculation unit includes an evidence chain weight optimization subunit; The evidence chain weight optimization subunit constructs multi-feature weight calculation rules based on the historical data accuracy, data attribute quality, data deviation trend, and scenario matching degree of the data source to determine the basic weight of each data source, and can dynamically adjust the basic weight according to the real-time data deviation value.

5. The security risk management system based on a dual prevention mechanism according to claim 4, characterized in that, The evidence chain weight optimization subunit also includes an anomaly data processing subunit; When the deviation value of the data output from the data source is detected to exceed the set range, the abnormal data processing subunit reduces the weight correction magnitude of the corresponding data source and marks the abnormal data information. The proportion of the marked abnormal data in the subsequent risk-hazard coupling calculation is reduced by a preset ratio.

6. The security risk management system based on a dual prevention mechanism according to claim 1, characterized in that, The risk-hazard dynamic coupling calculation unit includes a physical constraint correction subunit; The physical constraint correction subunit constructs dynamic constraint threshold calculation rules based on the equipment's service life and real-time load rate to constrain and verify the risk-hazard coupling coefficient, and can adjust the correction magnitude of the coupling coefficient according to the risk diffusion speed.

7. The security risk management system based on a dual prevention mechanism according to claim 6, characterized in that, It also includes an adaptive feedback unit; The adaptive feedback unit monitors the risk assessment deviation rate output by the risk-hazard dynamic coupling calculation unit and the constraint correction deviation rate output by the physical constraint correction subunit, triggers parameter adjustment commands for the risk-hazard dynamic coupling calculation unit, and can verify the adjustment effect and optimize the adjustment rules based on the deviation improvement after parameter adjustment.

8. The security risk management system based on a dual prevention mechanism according to claim 1, characterized in that, Adopting an edge-cloud collaborative architecture; The key computing modules of the multi-source data acquisition unit and the risk-hazard dynamic coupling computing unit are deployed at the edge, while the data storage unit and the global parameter management unit are deployed in the cloud. The edge device is connected to the cloud via dual-link communication. When the latency of the primary link exceeds the preset latency threshold or the link is interrupted, it automatically switches to the backup link. The edge device also has the ability to operate independently in offline mode.

Citation Information

Patent Citations

  • SCL field safety accident analysis and early warning method and system, medium and program product

    CN119625954A

  • Risk and hidden danger management system and method based on big data

    CN120471444A