Data security management system and method of relay protection screen cabinet based on NFC
The NFC-based data security management system solves the problems of information disconnect and security in relay protection cabinet data management, and achieves efficient and secure data synchronization and tracking, ensuring the stable operation of the power grid.
Patent Information
- Application Number
- CN202511587641.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2026-02-17
AI Technical Summary
In the existing data management of relay protection cabinets, paper labels or static electronic tags cannot support real-time updates of field data, resulting in a disconnect between back-end data and field status, a lack of safety audit and tracking mechanisms, and impact on the safe operation of the power grid and accountability.
An NFC-based data security management system is adopted, which stores encrypted device information and cabinet identification codes through NFC tags. It uses mobile terminals and remote operation and maintenance back-end systems for operation permission authentication and data synchronization, realizing two-way data synchronization and audit tracking.
It improves the efficiency of device information acquisition, ensures data security and privacy, prevents unauthorized access, supports real-time updates and effective tracking, and reduces potential safety hazards to the power grid.
Smart Images

Figure CN121543612A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of relay protection, and particularly relates to a data security management system and method for a relay protection screen cabinet based on NFC. BACKGROUND
[0002] In the operation and maintenance of a substation of a power system, a cabinet for installing a relay protection device can be referred to as a relay protection screen cabinet, and a plurality of relay protection devices are installed on the relay protection screen cabinet. The relay protection screen cabinet is a unit for carrying key protection and control equipment, and the accuracy and real-time performance of the related information of the relay protection screen cabinet are directly related to the safe and stable operation of the power grid.
[0003] In the existing data management of the relay protection screen cabinet, paper labels or static electronic labels (such as two-dimensional codes) are generally used. However, these labels or electronic labels cannot support the instant update of on-site data, and the on-site updated data cannot be automatically synchronized to the remote operation and maintenance background system, thereby forming an "information island", which causes the background data to be seriously out of touch with the actual state on site, and the data consistency cannot be guaranteed. At the same time, the existing mode lacks an effective security audit tracking mechanism, and cannot provide traceable evidence for the operation behavior, which brings major hidden dangers to the safe operation of the power grid and the responsibility tracing. SUMMARY
[0004] The data security management system and method for the relay protection screen cabinet based on NFC provided in the embodiments of the application can efficiently obtain as much as possible the related information of the screen cabinet and the relay protection device, thereby saving the time length for obtaining the information, and realizing the data bidirectional synchronization and audit tracking between the on-site of the substation and the background system.
[0005] In a first aspect, the embodiments of the application provide a data security management system for a relay protection screen cabinet based on NFC, comprising: an NFC tag fixedly arranged on the relay protection screen cabinet, the NFC tag storing encrypted device information and a screen cabinet identification code, the encrypted device information and the screen cabinet identification code being used for uniquely identifying the relay protection screen cabinet; a mobile terminal, which internally has an NFC reading and writing module and an encryption and decryption module; a remote operation and maintenance background system, which is in communication connection with the mobile terminal; the mobile terminal is configured to read the encrypted device information and the screen cabinet identification code in the NFC tag by using a near field communication mode through the NFC reading and writing module, and send an operation permission authentication request including the screen cabinet identification code and / or user identity information to the remote operation and maintenance background system, so that the remote operation and maintenance background system performs operation permission authentication; the remote operation and maintenance background system is configured to perform operation permission authentication in response to the operation permission authentication request of the mobile terminal, and send an authentication result to the mobile terminal; wherein, When the operation permission authentication is passed, the mobile terminal decrypts and displays the encrypted device information through the encryption and decryption module, and can also generate new device information in response to the user's operation and maintenance operation, and write the new device information into the NFC tag after encryption by the encryption and decryption module; When the operation permission authentication is not passed, the mobile terminal is prohibited from decrypting and displaying the encrypted device information.
[0006] In a possible implementation manner of the first aspect, the user's operation and maintenance operation includes: a patrol information input operation and / or a device state update operation. The device information includes at least one of a screen cabinet name, a screen cabinet number, a screen cabinet size, a screen cabinet door shaft direction, a screen cabinet color, a screen cabinet modification history record, screen cabinet drawing information, a relay protection device model, a relay protection device technical parameter, a corresponding protection interval, a relay protection device ID information, a fixed value list, a commissioning date, a patrol record, a fault information, a screen cabinet modification record, and a device state update information.
[0007] In a possible implementation manner of the first aspect, the mobile terminal further has a verification module built-in, configured to perform power system compliance verification on the new device information after the new device information is generated and before the new device information is encrypted.
[0008] In a possible implementation manner of the first aspect, the remote operation and maintenance background system is further configured to receive and permanently store the operation log sent by the mobile terminal, and the operation log is associated with the new device information.
[0009] In a possible implementation manner of the first aspect, further comprising: an NFC communication device fixedly arranged on the relay protection screen cabinet, the NFC communication device being electrically connected with the NFC tag; wherein, The NFC communication device is configured to periodically read the encrypted device information stored in the NFC tag and send the encrypted device information to the station control layer network; wherein, the station control layer network is configured to associate the received encrypted device information with real-time operation data of the substation and upload to the remote operation and maintenance background system for centralized display and / or alarm.
[0010] In a possible implementation manner of the first aspect, the NFC communication device and the NFC tag are electrically connected through a serial bus.
[0011] In a second aspect, the embodiments of the present application provide a data security management method for a relay protection screen cabinet based on NFC, comprising: When the mobile terminal detects a signal of the NFC tag arranged on the relay protection screen cabinet, the mobile terminal establishes a near field communication connection with the NFC tag and reads encrypted device information and a screen cabinet identification code stored in the NFC tag; The mobile terminal sends the screen cabinet identification code and / or user identity information to the remote operation and maintenance background system to enable the remote operation and maintenance background system to perform operation permission authentication; after receiving an instruction that the operation permission authentication is passed, the mobile terminal decrypts the encrypted device information and displays the same; The mobile terminal also generates new device information in response to the operation and maintenance operation of the user; The mobile terminal encrypts the new device information and writes the same into the NFC tag.
[0012] In a possible implementation manner of the second aspect, the mobile terminal is configured to perform power system compliance verification on the new device information by invoking a compliance verification rule library in the mobile terminal, and if the verification is passed, encrypt the new device information and write the same into the NFC tag.
[0013] In a possible implementation manner of the second aspect, the mobile terminal is further configured to associate the new device information with user identity information and timestamp information, generate an operation log, and upload the operation log to the remote operation and maintenance background system.
[0014] In a third aspect, an embodiment of the present application provides a data security management device for a relay protection screen cabinet based on NFC, comprising: The NFC read-write module is configured to, when detecting a signal of an NFC tag arranged on the relay protection screen cabinet, establish a near field communication connection with the NFC tag, and read encrypted device information and a screen cabinet identification code stored in the NFC tag. The NFC read-write module is also configured to send the screen cabinet identification code and / or user identity information to a remote operation and maintenance background system to enable the remote operation and maintenance background system to perform operation permission authentication.
[0015] The encryption and decryption module is configured to, after receiving an instruction that the operation permission authentication is passed, decrypt the encrypted device information and display the same. The encryption and decryption module is also configured to generate new device information in response to an operation and maintenance operation of the user. The encryption and decryption module is also configured to encrypt the new device information.
[0016] The NFC read-write module is also configured to write the new device information into the NFC tag.
[0017] The device further comprises a verification module configured to invoke an embedded compliance verification rule library to perform power system compliance verification on the new device information. The encryption and decryption module is configured to, if the verification is passed, encrypt the new device information. The NFC read-write module is also configured to write the new device information into the NFC tag. The NFC read-write module is also configured to, if the verification is passed, associate the new device information with user identity information and timestamp information, generate an operation log, and upload the operation log to the remote operation and maintenance background system.
[0018] In a fourth aspect, an embodiment of the present application provides a mobile terminal, comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and characterized in that the processor implements the method of any one of the above second aspect when executing the computer program.
[0019] In a fifth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program, when executed by a processor, implements the method of any one of the above second aspect.
[0020] In a sixth aspect, an embodiment of the present application provides a computer program product, which, when running on a mobile terminal, causes the mobile terminal to execute the method of any one of the above second aspect.
[0021] It can be understood that the beneficial effects of the above second aspect to sixth aspect can refer to the related description in the above first aspect, which will not be repeated here.
[0022] Compared with the prior art, the beneficial effects of the embodiments of the present application are: In the embodiments of the present application, the device information is stored in the NFC tag, the mobile terminal can be connected with the NFC tag through the near field communication mode, and the device information in the NFC tag is read and displayed on the interface of the mobile terminal. In this way, all information related to the relay protection screen cabinet and the relay protection device, i.e., the device information, can be obtained centrally, and the device information acquisition efficiency is high and the operation is simple.
[0023] Moreover, the device information is stored in an encrypted manner, which can ensure the privacy of the device information, prevent the device information from being leaked or tampered, and ensure the security of information storage.
[0024] Moreover, when reading the device information, the mobile terminal needs to send the screen cabinet identification code and / or user identity information to the remote operation and maintenance equipment, so that the remote operation and maintenance equipment performs operation permission authentication through the screen cabinet identification code and / or user identity information. When the authentication is passed, the mobile terminal decrypts and displays the encrypted device information. In this way, only authorized users or equipment can access the encrypted device information, effectively preventing unauthorized operation or data leakage, avoiding the device information being obtained by other irrelevant equipment or users, ensuring the privacy and security of the device information, and realizing effective tracking of the device information to facilitate timely attention to the device information, reducing the possibility of occurrence of power grid safe operation and responsibility tracing accidents. BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative effort.
[0026] Figure 1 is a schematic diagram of an NFC tag provided by an embodiment of the present application; Figure 2 is a schematic diagram of a data security management system of an NFC-based relay protection screen cabinet provided by an embodiment of the present application; Figure 3 is a schematic diagram of a data security management system of an NFC-based relay protection screen cabinet provided by an embodiment of the present application; Figure 4 is a flowchart of a data security management method of an NFC-based relay protection screen cabinet provided by an embodiment of the present application; Figure 5 is a flowchart of a data security management method of an NFC-based relay protection screen cabinet provided by another embodiment of the present application; Figure 6 is a structural schematic diagram of a data security management device of an NFC-based relay protection screen cabinet provided by an embodiment of the present application; Figure 7 is a structural schematic diagram of a mobile terminal provided by an embodiment of the present application. DETAILED DESCRIPTION
[0027] In the following description, specific details are set forth in order to provide a thorough understanding of the embodiments of the present application. However, persons skilled in the art will understand that the present application can be practiced without these specific details. In other instances, well-known structures, devices, circuits, and methods have not been described in detail in order to avoid obscuring the present application.
[0028] It should be understood that, when used in the specification and the appended claims of the present application, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0029] It should also be understood that, when used in the specification and the appended claims of the present application, the term "and / or" refers to any combination of one or more of the associated listed items and all possible combinations thereof, and includes these combinations.
[0030] As used in the specification and the appended claims herein, the term "if' can be interpreted as meaning "when" or "upon" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrase "if it is determined" or "if [the described condition or event] is detected" can be interpreted as meaning "upon determining" or "in response to determining" or "upon detecting [the described condition or event]" or "in response to detecting [the described condition or event]" depending on the context.
[0031] In addition, in the description of the present application and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0032] In the present application, the reference "one embodiment" or "some embodiments" and the like means that the specific features, structures or characteristics described in connection with the embodiment are included in one or more embodiments of the present application. Therefore, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in further some embodiments" and the like appearing in different places in the specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "include", "contain", "have" and their variants mean "include but not limited to", unless otherwise specifically emphasized.
[0033] For ease of understanding, some examples are given in the description of the present application related to the concept of the embodiments for reference.
[0034] 1, NFC tag: a "chip" that stores and responds. After being activated by the magnetic field of the NFC read-write module, it will send out the data stored in its internal memory.
[0035] 2, NFC read-write module: a "probe" that initiates induction and reading. It can generate a magnetic field to activate the NFC tag and exchange data.
[0036] The present application provides a data security management system, method and computer readable storage medium based on NFC for relay protection screen cabinet, which can be applied to various scenes of data storage and acquisition related to relay protection screen cabinet.
[0037] As shown in Figure 1 The relay protection screen cabinet (the relay protection screen cabinet can be referred to as: relay protection cabinet or screen cabinet) can be provided with an NFC tag 100, and the data related to the relay protection screen cabinet can be saved in the NFC tag 100. Thus, if a user wants to obtain the data related to the relay protection screen cabinet, the user can use a mobile terminal to approach the NFC tag and scan the NFC tag to obtain the data related to the relay protection screen cabinet.
[0038] The data security management system of the relay protection screen cabinet of the NFC can include an NFC tag, a mobile terminal, and a remote operation background system.
[0039] The NFC tag is used to store data related to the relay protection screen cabinet, including device information and screen cabinet identification codes. The NFC tag can include a data storage module for storing device information and screen cabinet identification codes. The NFC tag can also include an NFC near-field communication module for near-field communication with the mobile terminal, sending device information and screen cabinet identification codes to the mobile terminal.
[0040] As shown in Figure 2 The mobile terminal includes an NFC read-write module 301, an encryption and decryption module 302, and a verification module 303. The NFC read-write module 301 is used to read encrypted device information and screen cabinet identification codes in the NFC tag. The mobile terminal sends the screen cabinet identification code and / or user identity information to the remote operation background system through wired / wireless communication to enable the remote operation background system to perform operation permission authentication. The encryption and decryption module 302 is used to decrypt and display encrypted device information when operation permission authentication is passed. It can also encrypt new device information when the mobile terminal receives a user's operation and maintenance operation, and write it into the NFC tag. The verification module 303 is used to verify the compliance of the new device information generated by the power system.
[0041] The remote operation background system is used to receive screen cabinet identification codes and / or user identity information for operation permission authentication. The remote operation background system is also used to receive and store operation logs generated by the mobile terminal, associating new device information with user identity information and timestamp information.
[0042] In some embodiments, as shown in Figure 3 The remote operation background system includes a data exchange server and a remote display screen or remote display terminal. The data exchange server is used to receive device information data and real-time operation data of the substation, and to associate and integrate the two data, and upload them to the remote operation background system for centralized display and / or alarm. The remote display screen or remote display terminal is used to display relevant data transmitted from the data exchange server.
[0043] The data security management system of the NFC-based relay protection screen cabinet can be executed by a mobile terminal with a display screen and an NFC read-write module. The mobile terminal can be a mobile phone, a tablet computer, a wearable device, a vehicle-mounted device, an augmented reality (AR) / virtual reality (VR) device, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), etc. The specific type of the mobile terminal is not limited in the embodiments of the present application.
[0044] Based on the above description, the data security management system of the NFC-based relay protection screen cabinet provided by the embodiments of the present application will be described in detail.
[0045] Please continue to refer to Figure 2 , Figure 2 The flowchart of the data security management system of the NFC-based relay protection screen cabinet provided by an embodiment of the present application is shown. As Figure 2 shown, the data security management system of the NFC-based relay protection screen cabinet provided by the present application can include an NFC tag, a mobile terminal and a remote operation and maintenance background system.
[0046] The NFC tag is fixedly arranged on the relay protection screen cabinet. The NFC tag stores encrypted device information and a screen cabinet identification code. The encrypted device information and the screen cabinet identification code are used to uniquely identify the relay protection screen cabinet.
[0047] As Figure 1 shown, the NFC tag is fixedly arranged on the relay protection screen cabinet and can be clearly seen. When a user wants to know the relevant information of the relay protection screen cabinet, the user can obtain the information by scanning the NFC tag through the mobile terminal.
[0048] In some embodiments, the encrypted device information includes at least one of a screen cabinet name, a screen cabinet number, a screen cabinet size, a screen cabinet door shaft direction, a screen cabinet color, a screen cabinet modification history record, screen cabinet drawing information, a relay protection device model, a relay protection device technical parameter, a corresponding protection interval, a relay protection device ID information, a setting value list, a commissioning date, an inspection record, a fault information, a screen cabinet modification record and a device state update information.
[0049] The screen cabinet name is usually a name named according to the function and role of the relay protection screen cabinet in the power grid. The specific implementation of the screen cabinet name is not limited in the present application. For example, the screen cabinet name is 110kV A line protection screen. For another example, the screen cabinet name is No. 1 main transformer differential protection screen.
[0050] The cabinet number is usually the unique identity code of the relay protection cabinet in a certain substation or power plant. The specific implementation of the cabinet number is not limited in the present application. For example, the cabinet number is S101. For another example, the cabinet number is BP-208.
[0051] The cabinet size is usually represented by height, width and depth. For example, 2260mm (height) x 800mm (width) x 600mm (depth).
[0052] The cabinet door axis direction represents the opening direction of the cabinet door (left or right).
[0053] The cabinet modification history record is used to record the history information of all hardware changes, software upgrades and loop modifications of the relay protection cabinet since it is put into operation.
[0054] The cabinet drawing information can refer to the secondary design drawings of the cabinet, including schematic diagram, wiring diagram, terminal block diagram and layout diagram.
[0055] The relay protection device model is the specific model of the relay protection device. The specific implementation of the relay protection device model is not limited in the present application. For example, the relay protection device model is PCS-931-G.
[0056] The relay protection device technical parameters are the electrical parameters required for the normal operation of the relay protection device. For example, the relay protection device technical parameters include: working power DC 220V (±20%), AC rated current 5A, AC rated voltage 100V.
[0057] The corresponding protection interval is the primary equipment interval protected by the relay protection device.
[0058] The relay protection device identification (ID) information is the unique identification code of the relay protection device, which is usually a factory bar code or serial number. For example, the relay protection device ID information is 21C12345. The specific implementation of the relay protection device ID information is not limited in the present application.
[0059] The fixed value list (also known as protection fixed value list) includes a set of setting parameters for the correct action of the relay protection device. For example, the current I section fixed value is 1000A, the time is 0s, and the differential starting current is 0.5Ie.
[0060] The put into operation date is the date when the relay protection cabinet is put into operation for the first time, which is used to calculate the equipment life and determine the maintenance period.
[0061] The fault information can include all protection action events recorded by the relay protection device, time of protection action, alarm information, and analysis report thereof.
[0062] The screen cabinet modification record can include historical information of value modification, pressure plate on-off, program upgrade, and the like.
[0063] The device state update information can include descriptive records of the current state of the relay protection device, for example, running, maintenance, shutdown, and test.
[0064] The screen cabinet identification code is a unique identification code of the relay protection screen cabinet.
[0065] In some embodiments, the screen cabinet identification code is not usually a string of random numbers, but is coded according to a certain coding rule, and the screen cabinet identification code itself carries part of the information. The coding rule can be: [substation code]-[voltage level]-[function type]-[serial number].
[0066] For example, the screen cabinet identification code is B1-110kV-LP-006. B1 represents No. 1 substation. 110kV represents that the voltage level to which the relay protection screen cabinet belongs is 110 kilovolts. LP is used to represent line protection, indicating that the function of the relay protection screen cabinet is line protection. 006 represents that the relay protection screen cabinet is the 6th cabinet in the sequence of 110kV line protection screen cabinets in the substation. The user identity information is used to uniquely identify the user. The user identity information can include but is not limited to at least one parameter of user ID, mobile phone number, user name, email, and the like. The user ID can include but is not limited to an ID card number. The user name can be represented by characters, letters, binary numbers, and the like. The specific implementation of the user identity information is not limited in the application.
[0067] The mobile terminal is internally provided with an NFC reading and writing module, an encryption and decryption module, and a verification module. The mobile terminal establishes a communication connection with the NFC tag through a wireless manner, for example, reads the device information and the screen cabinet identification code in the NFC tag which are encrypted by using the encryption strategy through a near field communication manner.
[0068] The remote operation and maintenance background system is in wired or wireless communication connection with the mobile terminal. The mobile terminal sends an operation permission authentication request including a screen cabinet identification code and / or user identity information to the remote operation and maintenance background system to enable the remote operation and maintenance background system to perform operation permission authentication. In response to the operation permission authentication request of the mobile terminal, the remote operation and maintenance background system performs operation permission authentication and sends an authentication result to the mobile terminal. When the operation permission authentication is passed, the mobile terminal uses the encryption and decryption module to decrypt and display the encrypted device information. The mobile terminal can also generate new device information in response to the user's operation and maintenance operation, and write the new device information into the NFC tag after encryption by the encryption and decryption module. When the operation permission authentication is not passed, the mobile terminal is prohibited from decrypting and displaying the encrypted device information.
[0069] The communication connection between the remote operation and maintenance background system and the mobile terminal can be wired or wireless transmission. The wired transmission includes Ethernet, RS-485 / RS-232, Type-C or USB transmission. The wireless transmission includes WiFi, Bluetooth, Zigbee, LoRa, 4G, and NB-IoT. The application does not limit the communication connection between the remote operation and maintenance background system and the mobile terminal.
[0070] When the mobile terminal is close to the NFC tag and detects that the NFC tag enters the sensing range of the mobile terminal, the built-in NFC read-write module of the mobile terminal is used to read the encrypted device information and screen cabinet identification code in the NFC tag, and write the generated new device information into the NFC tag. It should be understood that the sensing range is determined by the sensing ability of the NFC read-write module in the mobile terminal to the NFC tag. For example, the sensing range can be [1, 10] cm. When the distance between the mobile terminal and the NFC tag is 4 cm, the mobile terminal can detect the existence of the NFC tag and determine that the NFC tag enters the sensing range of the mobile terminal. The application does not limit the sensing range.
[0071] The encryption and decryption module is used to decrypt and display the encrypted device information when the operation permission authentication is passed. The encryption and decryption module can also encrypt the new device information when the mobile terminal receives the user's operation and maintenance operation and generates the new device information, and write the new device information into the NFC tag.
[0072] If the mobile terminal sends an operation permission authentication request including the screen cabinet identification code to the remote operation background system, after receiving the screen cabinet identification code, the process of operation permission authentication can specifically include: obtaining the screen cabinet identification code in the task sheet included in the mobile terminal, the screen cabinet identification code in the task sheet corresponding to the relay protection screen cabinet needing operation and maintenance processing, if the screen cabinet identification code in the task sheet is the same as the screen cabinet identification code sent by the mobile terminal to the remote operation background system, the operation permission authentication is passed, if the screen cabinet identification code in the task sheet is different from the screen cabinet identification code sent by the mobile terminal to the remote operation background system, the operation permission authentication is not passed.
[0073] If the mobile terminal sends an operation permission authentication request including user identity information to the remote operation background system, after receiving the user identity information, the process of operation permission authentication can specifically include: determining whether the user identity information exists in the pre-stored operation personnel information library in the operation background device, if the user identity information exists, the operation permission authentication is passed, if the operation permission authentication is not passed, the operation permission authentication is not passed.
[0074] If the mobile terminal sends an operation permission authentication request including the screen cabinet identification code and the user identity information to the remote operation background system, after receiving the screen cabinet identification code and the user identity information, the process of operation permission authentication can specifically include the above two kinds of operation permission authentication processes, which will not be described in detail here.
[0075] If the authentication is passed, the device information can be displayed in the interface of the mobile terminal after the encrypted device information is decrypted by the encryption and decryption module of the mobile terminal, in this way, the user can see all the device information through the interface of the mobile terminal.
[0076] Among them, the operation and maintenance operation includes: patrol information input operation and / or equipment state update operation. Among them, the patrol information input operation is: the substation operation and maintenance personnel in the substation field operation and maintenance patrol, the substation patrol information input operation on the mobile terminal, the patrol information includes but is not limited to the identity information of the field operation and maintenance personnel, the operation and maintenance patrol timestamp information, the operation and maintenance patrol record, etc.; the equipment state update operation is: in response to the operation and maintenance demand of the substation field, the software update and / or hardware update of the relay protection device in the protection screen cabinet is carried out by the field operation and maintenance personnel, and the update record is formed.
[0077] When the operation and maintenance operation includes the patrol information input operation, the new device information generated includes the patrol record corresponding to the patrol information input operation.
[0078] Similarly, when the operation and maintenance operation includes the equipment state update operation, the new device information generated includes the equipment state update information corresponding to the equipment state update operation.
[0079] In some embodiments, the mobile terminal further comprises a verification module configured to verify the new device information for power system compliance before the new device information is encrypted and generated.
[0080] It should be understood that the new device information is not readable after encryption, and must be decrypted before verification, which increases the computational overhead and time delay. Therefore, verification before encryption can directly operate on plaintext data, which is more efficient.
[0081] In some embodiments, the verification module calls an embedded compliance verification rule library to verify the new device information for power system compliance.
[0082] Among them, the compliance verification rule library is a database or knowledge base that stores various power device (such as relay protection device) data setting rules.
[0083] Among them, the compliance verification library is used to verify whether the modified power system parameters are within the allowed range (such as the voltage setting value cannot exceed the rated value of the device), whether the control logic conforms to the grid operation procedure, and whether the configuration conflicts with the current grid state (such as some key parameters cannot be modified in the running state). The compliance verification library includes but is not limited to: 1) Range value verification rule: The safe upper and lower limits are predefined for different types of protection setting values (such as overcurrent protection current setting value I and action time setting value T). For example, for the overcurrent setting value of a certain line, the rule library limits its value range to between 0A and 99A, and any input value exceeding this range will be judged as invalid.
[0084] 2) Logic relationship verification rule: Defines the logical coordination relationship that must be met between different setting values within the same device. For example, the rule library states that "the overcurrent protection action time T of the current line must be greater than the overcurrent protection action time T of the next line", and the time difference ΔT must be greater than or equal to 0.3s. If the user modifies it and breaks this coordination relationship, the verification will fail.
[0085] 3) Device compatibility verification rule: Specifies the matching relationship between the setting value and the inherent parameters such as device model and capacity, for example, the input setting value cannot be greater than the maximum technical capacity that the protection device of this model can support; specifies the relay protection screen information table, and performs table lookup verification on the input screen information, for example: If the input screen size information is not in the relay protection screen information table, the modification is not allowed.
[0086] 4) Grid operation mode verification rule: In some advanced applications, the rule library can also integrate the current grid operation mode constraints. For example, in a certain wiring mode, some protection functions must be put into or withdrawn, and the corresponding setting value modification will also be constrained.
[0087] The new device information is subjected to power system compliance verification. If the new device information meets the rules in the compliance verification rule library, the verification is passed, otherwise, the verification is failed.
[0088] In some embodiments, when the data to be verified is constant value data, the verification module calls the range value verification rule and the logical relationship verification rule in the compliance verification rule library, and the data verification process is as follows: First step of data extraction: the verification module extracts the constant value data set Data1 to be written from the user input interface of the mobile terminal, for example, the overcurrent I section protection constant value to be written is 10A.
[0089] Second step of rule matching: match the rule subset S1 corresponding to the constant value data set Data1 from the compliance verification rule library. For example, the constant value data set Data1 includes the data of the line protection device (which can be the device model), and the verification rule subset S1 corresponding to the data of the line protection device is matched.
[0090] Third step of item-by-item verification: call the selected rule subset S1 to perform range verification and logical relationship verification on each constant value D in the constant value data set Data1. The logical relationship verification needs to traverse the related constant values and perform cross comparison.
[0091] Fourth step of verification result output: If all verifications are passed: the verification module returns a "verification success" signal to the main program, the process continues, the mobile terminal operation interface allows the user to continue inputting / modifying data, or the mobile terminal continues to perform encryption and writing operation.
[0092] If any verification fails: the verification module immediately terminates the process, prohibits subsequent encryption and writing operation, and at the same time pops up a prominent prompt box on the mobile terminal display interface, clearly indicating the specific items and reasons of verification failure (for example: "Error: action time constant value does not meet the cooperation requirements with the next level device"), guiding the user to re-input.
[0093] Fifth step of data uploading: after the compliance verification is passed, the mobile terminal encrypts the new device information (modified data + user identity information + modification timestamp, etc.) through the encryption and decryption module, writes it into the NFC tag, and synchronously uploads the operation log record to the remote operation and maintenance background system, completing the update and archiving of the relay protection screen cabinet device information.
[0094] In some embodiments, the remote operation and maintenance background system is further configured to receive and permanently store the operation log sent by the mobile terminal, and the operation log is associated with the new device information.
[0095] The operation log can include user identity information and timestamp information, and is used to indicate that the user adjusts the device information at a certain time.
[0096] For example, the operation log includes the name of user A, Zhang San, and the timestamp information corresponds to the time 2025-09-23 10:00. The operation log indicates that Zhang San adjusts the device information at 2025-09-23 10:00.
[0097] In some embodiments, the data security management system further comprises: an NFC communication device fixedly arranged on the relay protection screen cabinet, the NFC communication device being electrically connected with the NFC tag; wherein the NFC communication device is configured to periodically read the encrypted device information stored in the NFC tag, and send the encrypted device information to the station control layer network; wherein the station control layer network is configured to associate and integrate the received encrypted device information with real-time operation data of the substation, and upload to a remote operation and maintenance background system for centralized display and / or alarm.
[0098] The NFC communication device is a device fixedly installed on the relay protection screen cabinet, has a near field communication function, and is used for data interaction with the NFC tag on the screen cabinet. Generally, the NFC communication device is a small embedded module, and has the ability to read, analyze and forward NFC tag data. The NFC tag is usually passive and stores encrypted device information. The NFC communication device is usually active and is responsible for actively reading encrypted device information and uploading data to the station control layer network.
[0099] The station control layer network is the core communication network in the substation automation system, and belongs to the top layer in the three-layer structure (process layer, bay layer, and station control layer) of the substation. The station control layer network is responsible for data collection, monitoring, control of devices in the substation, and communication with remote systems.
[0100] The above-mentioned periodic reading is periodic reading according to a preset period. The present application does not limit the specific implementation mode of the preset period. For example, the preset period can be 1 minute, 5 minutes, 10 minutes, etc. When the preset period is 10 minutes, the NFC communication device is configured to read the encrypted device information stored in the NFC tag once every 10 minutes.
[0101] The real-time operation data of the substation can include, but is not limited to, power system parameter data such as current, voltage, switch state, etc.
[0102] The station control layer network associates the received encrypted device information (which can be decrypted first) with the real-time operation data of the substation, and uploads to the remote operation and maintenance background system for centralized display, which can facilitate relevant operation and maintenance personnel to real-time master the relevant situations of each relay protection screen cabinet in the substation and the operation of the substation.
[0103] The station control layer network associates the received encryption device information with real-time operation data of the substation, and uploads to the remote operation and maintenance background system. If the remote operation and maintenance background system finds that there is information anomaly (for example, the state of a switch in the substation is abnormal, the ID information of a relay protection device is tampered), an alarm can be triggered.
[0104] In addition, there can be various alarm modes. For example, the alarm content is displayed in the interface of the remote operation and maintenance background system; for another example, a warning mark related to the alarm content is displayed in the interface of the remote operation and maintenance background system. The application does not limit the alarm mode.
[0105] Therefore, after receiving the alarm, the operation and maintenance personnel can remotely view the related data to confirm the anomaly, or the operation and maintenance personnel can go to the site to check and restore the correct data of the NFC tag through the operation on the mobile terminal.
[0106] In some embodiments, the NFC communication device and the NFC tag are electrically connected through a serial bus.
[0107] Wireless communication can be subject to electromagnetic interference (especially near power equipment), resulting in unstable data reading. Therefore, the NFC communication device and the NFC tag are electrically connected through a serial bus, so that the NFC communication device can stably read the data in the NFC tag, and the reliability of data transmission can be ensured.
[0108] The serial bus can be any one of a universal asynchronous receiver / transmitter (UART), an inter-integrated circuit (I2C), and a serial peripheral interface (SPI), and the application does not limit this.
[0109] Based on the above description, the data security management method for the NFC-based relay protection screen cabinet provided by the embodiments of the application will be described in detail.
[0110] Please refer to Figure 4 , Figure 4 The figure shows the flowchart of the data security management method for the NFC-based relay protection screen cabinet provided by an embodiment of the application. As Figure 4 shown, the data security management method for the NFC-based relay protection screen cabinet provided by the application can include: S101, the mobile terminal is operated to approach the relay protection screen cabinet, and when the mobile terminal detects a signal of the NFC tag arranged on the relay protection screen cabinet, the mobile terminal establishes a near field communication connection with the NFC tag, and reads encrypted device information and a screen cabinet identification code stored in the NFC tag.
[0111] The description of S101 can be referred to the description of reading the encrypted device information and the screen cabinet identification code in the NFC tag through the near field communication mode, which will not be repeated here.
[0112] S102, the mobile terminal sends the obtained screen cabinet identification code and / or user identity information to the remote operation and maintenance background system, so that the remote operation and maintenance background system performs operation permission authentication, and after receiving an instruction that the operation permission authentication is passed, the mobile terminal decrypts and displays the encrypted device information.
[0113] The description of S102 can be referred to the description of sending an operation permission authentication request including the screen cabinet identification code and / or the user identity information to the remote operation and maintenance background system, so that the remote operation and maintenance background system performs operation permission authentication, and decrypting and displaying the encrypted device information through the encryption and decryption module, which will not be repeated here.
[0114] S103, in response to the operation and maintenance operation of the user, the mobile terminal generates new device information.
[0115] The description of S103 can be referred to the description of generating new device information in response to the operation and maintenance operation of the user, which will not be repeated here.
[0116] S104, the mobile terminal encrypts the new device information and writes it into the NFC tag.
[0117] The description of S104 can be referred to the description of encrypting the new device information through the encryption and decryption module in the mobile terminal and writing it into the NFC tag, which will not be repeated here.
[0118] In the embodiment of the application, the device information is stored in the NFC tag, the mobile terminal can be connected with the NFC tag through the near field communication mode, read and decrypt the device information stored in the NFC tag, and display it on the interface of the mobile terminal. In this way, all information related to the relay protection screen cabinet and the relay protection device, i.e. the device information, can be obtained, the device information acquisition efficiency is high and the operation is simple, and the device information can be effectively tracked, so that the device information can be timely paid attention to, and the possibility of occurrence of power grid safe operation and responsibility tracing accident reduction and other situations can be reduced.
[0119] And the device information is stored in an encrypted manner, so that the privacy of the device information can be ensured, and the device information can be prevented from being leaked or tampered with, and the security of the information storage can be ensured. The existing data encryption methods include symmetric encryption (such as AES and DES), asymmetric encryption (such as RSA and ECC), and hash algorithm (such as SHA-256). The symmetric encryption uses the same key for encryption and decryption, and has high efficiency but needs to ensure the security of the key distribution; the asymmetric encryption realizes secure transmission through public key and private key pairing, and solves the key distribution problem but has large calculation amount; the hash algorithm generates a fixed-length digest through one-way encryption, and is used to verify the data integrity. For example, in the embodiment, a hybrid encryption (such as the TLS / SSL protocol) can be used for data encryption, so that the confidentiality, integrity and identity authentication requirements of the data can be ensured in all directions. The data encryption method is not limited in the application.
[0120] And when the device information is read, the mobile terminal needs to send the screen cabinet identification code and / or user identity information to the remote operation and maintenance equipment, so that the remote operation and maintenance background system performs operation permission authentication through the screen cabinet identification code and / or user identity information. When the authentication is passed, the mobile terminal decrypts and displays the encrypted device information. In this way, only authorized users or equipment can access the encrypted device information, unauthorized operation or data leakage can be effectively prevented, and the device information can be prevented from being obtained by other irrelevant equipment or users, so that the privacy and security of the device information can be ensured.
[0121] Based on the description of the embodiment shown in Figure 4 After obtaining the new device information, the mobile terminal can also verify the new device information, and perform other steps when the verification is passed.
[0122] Next, the specific implementation process of the data security management method of the relay protection screen cabinet based on NFC provided by the application will be described in detail. Figure 5
[0123] Please refer to Figure 5 , Figure 5 Fig. 1 shows a flowchart of the data security management method of the relay protection screen cabinet based on NFC provided by an embodiment of the application. As shown in Figure 5 The data security management method of the relay protection screen cabinet based on NFC provided by the application includes the following steps: S201, when the mobile terminal detects the signal of the NFC tag arranged on the relay protection screen cabinet, the mobile terminal establishes a near field communication connection with the NFC tag, and reads the encrypted device information and the screen cabinet identification code stored in the NFC tag.
[0124] S202, the mobile terminal sends the cabinet identification code and / or user identity information to the remote operation and maintenance background system to enable the remote operation and maintenance background system to perform operation permission authentication; after receiving an instruction that the operation permission authentication is passed, the mobile terminal decrypts the encrypted device information and displays it.
[0125] S203, the mobile terminal generates new device information in response to the user's operation and maintenance operation.
[0126] S201, S202, and S203 are respectively similar to the implementation manners of S101, S102, and S103 in the embodiment shown in Figure 4 The implementation manners of S101, S102, and S103 in the embodiment shown in
[0127] S204, the mobile terminal calls the embedded compliance verification rule library to perform power system compliance verification on the new device information.
[0128] S204 can refer to the related description of the power system compliance verification on the new device information described above, and will not be repeated here.
[0129] If the verification is passed, the mobile terminal can perform S205 and S206, otherwise, no step is performed.
[0130] S205, the mobile terminal encrypts the new device information and writes it into the NFC tag.
[0131] S205 is similar to the implementation manner of S104 in the embodiment shown in Figure 4
[0132] S206, the mobile terminal associates the new device information with the user identity information and the timestamp information, generates an operation log, and uploads the operation log to the remote operation and maintenance background system.
[0133] The operation log can refer to the description of the operation log described above, and will not be repeated here, S206 can refer to the related description of the remote operation and maintenance background system also being configured to receive and permanently store the operation log sent by the mobile terminal described above, and will not be repeated here.
[0134] In addition, it should be noted that the execution order of S205 and S206 is not sequential, and they can be executed simultaneously or sequentially. When executed sequentially, S205 can be executed first, and then S206 can be executed. S206 can be executed first, and then S205 can be executed. In the embodiment of the application, after the mobile terminal obtains the device information, it can also be verified. After the verification is passed, the new device information is encrypted by the encryption module and written into the NFC tag, so that the new device information meets the relevant specifications of the power system.
[0135] And, after the check passes, the new device information can also be associated with the operation log, and the log record associated with the new device information is uploaded to the remote operation background system. The content in the log record can indicate that the user adjusted the device information at a certain time. In this way, subsequent operation personnel can view the adjustment of the device information on the remote operation background system, which can improve the remote operation efficiency and facilitate subsequent tracking of the source of the problem or analysis of operation compliance.
[0136] It should be understood that the size of the serial number of each step in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0137] The data security management method of the relay protection screen cabinet based on NFC corresponding to the above embodiment, Figure 6 The structure block diagram of the data security management device of the relay protection screen cabinet based on NFC provided by the embodiments of the present application is shown. For ease of illustration, only the parts related to the embodiments of the present application are shown.
[0138] Referring to Figure 6 The device comprises: The NFC read-write module 301 is configured to, when detecting the signal of the NFC tag arranged on the relay protection screen cabinet, establish a near field communication connection with the NFC tag, and read the encrypted device information and the screen cabinet identification code stored in the NFC tag. The screen cabinet identification code and / or user identity information are also sent to the remote operation background system for operation permission authentication by the remote operation background system.
[0139] The encryption and decryption module 302 is configured to, after receiving the instruction that the operation permission authentication is passed, decrypt and display the encrypted device information. The encryption and decryption module 302 is also configured to encrypt the new device information. The encryption and decryption module 302 is also configured to generate new device information in response to the operation of the user.
[0140] The NFC read-write module 301 is also configured to write the new device information into the NFC tag.
[0141] The device further comprises a verification module 303, which is configured to call the compliance verification rule library embedded in the mobile terminal to verify the power system compliance of the new device information. The encryption and decryption module 302 is configured to encrypt the new device information if the verification passes. The NFC read-write module 301 is also configured to associate the new device information with the user identity information and the timestamp information and generate an operation log if the verification passes, and upload the operation log to the remote operation background system.
[0142] It should be noted that the information interaction, execution process and the like between the above apparatuses / units are based on the same concept as the method embodiments of the present application, and specific functions and brought technical effects can be referred to the method embodiments part, which will not be repeated here.
[0143] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or software. In addition, the specific name of each functional unit and module is only for easy distinction, and does not limit the protection scope of the present application. The specific working process of the unit and module in the system can be referred to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0144] The embodiment of the present application also provides a mobile terminal, which comprises at least one processor, a memory and a computer program stored in the memory and executable on the at least one processor, and the processor implements the steps in any of the above method embodiments when executing the computer program.
[0145] Exemplarily, the present application also provides a structural schematic diagram of a mobile terminal. As shown in the figure, Figure 7 The mobile terminal 400 comprises a processor 401, a memory 402, a communication interface 403 and a bus 404. The processor 401, the memory 402 and the communication interface 403 communicate through the bus 404, and can also communicate through wireless transmission and other means. The memory 402 is used for storing instructions, and the processor 401 is used for executing the instructions stored in the memory 402. The memory 402 stores program code 4021, and the processor 401 can call the program code 4021 stored in the memory 402 to execute the numerical control machining method in the above embodiment.
[0146] It should be understood that, in the present application, the processor 401 can be a CPU, and the processor 401 can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0147] The memory 402 may include read-only memory and random access memory, and provides instructions and data to the processor 401. The memory 402 may also include non-volatile random access memory. The memory 402 may be volatile memory or non-volatile memory, or may include both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0148] In addition to the data bus, the 404 bus may also include a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 7 The general will label all buses as Bus 404.
[0149] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.
[0150] This application provides a computer program product that, when run on a mobile terminal, enables the mobile terminal to implement the steps described in the above-described method embodiments.
[0151] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying the computer program code to the aforementioned device / mobile terminal, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks.
[0152] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0153] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0154] In the embodiments provided in this application, it should be understood that the disclosed devices / mobile terminals and methods can be implemented in other ways. For example, the device / mobile terminal embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0155] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0156] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A data security management system for a relay protection cabinet based on NFC, characterized in that, include: An NFC tag is fixedly installed on the relay protection cabinet. The NFC tag stores encryption device information and cabinet identification code. The encryption device information and cabinet identification code are used to uniquely identify the relay protection cabinet. The mobile terminal has a built-in NFC read / write module and encryption / decryption module; A remote operation and maintenance backend system, wherein the remote operation and maintenance backend system is communicatively connected to the mobile terminal; The mobile terminal is configured to: read the encryption device information and the cabinet identification code in the NFC tag using the NFC read / write module via near-field communication, and send an operation permission authentication request including the cabinet identification code and / or user identity information to the remote operation and maintenance backend system so that the remote operation and maintenance backend system can perform operation permission authentication. The remote operation and maintenance backend system is configured to: perform operation permission authentication in response to the operation permission authentication request from the mobile terminal, and send the authentication result to the mobile terminal; wherein, When the operation permission authentication is successful, the mobile terminal decrypts and displays the encrypted device information through the encryption and decryption module. It can also generate new device information in response to the user's operation and maintenance operation, and write the new device information into the NFC tag after encrypting it through the encryption and decryption module. When the operation permission authentication fails, the mobile terminal is prohibited from decrypting and displaying the encrypted device information.
2. The data security management system according to claim 1, characterized in that, The user's operation and maintenance operations include: inspection information entry operation and / or equipment status update operation; The device information includes at least one of the following: cabinet name, cabinet number, cabinet size, cabinet door hinge direction, cabinet color, cabinet modification history, cabinet drawing information, relay protection device model, relay protection device technical parameters, corresponding protection interval, relay protection device ID information, setting list, commissioning date, inspection record, fault information, cabinet modification record, and equipment status update information.
3. The data security management system according to claim 2, characterized in that, The mobile terminal also has a built-in verification module, configured to perform power system compliance verification on the new device information after it is generated and before it is encrypted.
4. The data security management system according to claim 3, characterized in that, The remote operation and maintenance backend system is also configured to receive and permanently store the operation logs sent by the mobile terminal, and the operation logs are associated with the new device information.
5. The data security management system according to claim 2, characterized in that, Also includes: An NFC communication device is fixedly mounted on the relay protection cabinet, and the NFC communication device is electrically connected to the NFC tag; wherein... The NFC communication device is configured to periodically read the encryption device information stored in the NFC tag and send the encryption device information to the station control layer network; wherein, the station control layer network is configured to associate the received encryption device information with the real-time operation data of the substation and upload it to the remote operation and maintenance backend system for centralized display and / or alarm.
6. The data security management system according to claim 5, characterized in that, The NFC communication device is electrically connected to the NFC tag via a serial bus.
7. A data security management method for a relay protection cabinet based on NFC, applied to a mobile terminal, characterized in that, include: When the mobile terminal detects the signal of the NFC tag set on the relay protection cabinet, it establishes a near-field communication connection with the NFC tag and reads the encryption device information and cabinet identification code stored in the NFC tag. The mobile terminal sends the cabinet identification code and / or user identity information to the remote operation and maintenance backend system so that the remote operation and maintenance backend system can perform operation permission authentication; after receiving the operation permission authentication successful instruction, the mobile terminal decrypts and displays the encryption device information; The mobile terminal also generates new device information in response to user operation and maintenance commands. The mobile terminal encrypts the new device information and then writes it into the NFC tag.
8. The data security management method according to claim 7, characterized in that, The mobile terminal is configured to: perform power system compliance verification on the new device information by calling the compliance verification rule library embedded in the mobile terminal; if the verification passes, the new device information is encrypted and written to the NFC tag.
9. The data security management method according to claim 8, characterized in that, The mobile terminal is also configured to associate the new device information with user identity information and timestamp information to generate an operation log, and upload the operation log to the remote operation and maintenance backend system.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the data security management method as described in any one of claims 7 to 9.
Citation Information
Patent Citations
Intelligent inspection system for electrical devices
CN105868927A
NFC-based wireless intelligent electric power inspection system
CN106920290A
Electric power machine room equipment management system and method based on near field communication NFC intelligent terminal
CN109214479A
Security verification and transmission method applied to radio frequency field data
CN117221877A
Equipment security authentication method and system
CN117955740A