Management system and management method for data of multiple nuclear power stations
By introducing an identification field and a transport layer security protocol into the nuclear power plant data management system, the problem of insufficient data isolation under the shared schema mode of the shared database was solved, and logical isolation and security of operation and maintenance data were achieved, meeting the high security protection requirements of nuclear power data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-18
- Publication Date
- 2026-03-24
AI Technical Summary
In the nuclear power industry, the data isolation method of shared database shared schema mode is difficult to meet the industry standards for high sensitivity and security protection, and there is a risk of unauthorized access.
By introducing identification fields into the data management systems of multiple nuclear power plants, using cloud servers for data filtering and verification, the operation and maintenance data is logically isolated, encrypted transmission is carried out using transport layer security protocols, and a customized visualization interface is provided for each nuclear power plant.
It achieves logical isolation of operation and maintenance data in a multi-tenant environment, ensuring the independence and security of data from each nuclear power plant, preventing unauthorized data leakage, and meeting the high security protection standards for nuclear power data.
Smart Images

Figure CN121728107A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of nuclear power, in particular to a multi-nuclear power plant data management system and a management method. BACKGROUND
[0002] In the field of nuclear power, there are mainly three modes for multi-tenant data isolation: independent database isolation mode, shared database independent Schema mode and shared database shared Schema mode. Among them, the shared database shared Schema mode can serve multiple nuclear power units at a lower cost, but its data isolation mainly depends on software layer logic control, and the isolation strength is limited.
[0003] In this specific scenario of the field of nuclear power, the shared database shared Schema mode has obvious defects, and its isolation method cannot meet the industry standards of high sensitivity and safety protection of nuclear power data, and there is a potential risk of unauthorized access. Therefore, there is room for improvement. SUMMARY
[0004] The present application provides a multi-nuclear power plant data management system and a management method to solve the technical problem that the data of multiple nuclear power plants is difficult to isolate.
[0005] The present application provides a multi-nuclear power plant data management system, comprising a plurality of data acquisition modules, a client and a cloud server; The plurality of data acquisition modules are respectively deployed in different nuclear power plants for collecting operation and maintenance data of the corresponding nuclear power plant and uploading to the cloud server; the operation and maintenance data includes an identification field for identifying the nuclear power plant; The client is used to receive and verify the login credentials of the user of the nuclear power plant, and upload the user information in the login credentials to the cloud server when the verification is passed; the user information includes an identification field for identifying the nuclear power plant; The cloud server is used to store the operation and maintenance data of all nuclear power plants; The cloud server is also used to receive user information and determine the nuclear power plant associated with the user according to the identification field contained therein; The cloud server is also used to, during user access, when receiving a data access request initiated through the client, add the identification field of the nuclear power plant associated with the user to the data access request as a data filtering condition, so that the user obtains the operation and maintenance data of the nuclear power plant associated with him.
[0006] In an embodiment of the present application, the cloud server is also used to verify the identification field of the operation and maintenance data when receiving it: store the operation and maintenance data in the corresponding data table when the identification field matches the identification field of the corresponding nuclear power plant; the fields of the data table at least include identification information of the operation and maintenance device, a timestamp, collected data, and the identification field.
[0007] In an embodiment of the present application, when the client receives and verifies the login credentials of the user, the client is configured to: verify an identification field included in the user information in the login credentials, and verify validity of the user information; determine that the login credential verification is passed when the identification field included in the user information matches the identification field of the corresponding nuclear power plant and the user information is in a valid state; generate corresponding alarm information when the identification field included in the user information does not match the identification field of the corresponding nuclear power plant and / or the user information is in an invalid state.
[0008] In an embodiment of the present application, the client is further configured to store configuration information of an independent and customizable visualization interface for each nuclear power plant; the configuration information at least includes layout of a monitoring component, a chart type, and an alarm threshold, and is bound to the identification field of the nuclear power plant.
[0009] In an embodiment of the present application, after the client verifies that the login credentials of the user are passed, the client is further configured to display the visualization interface corresponding to the identification field included in the user information according to the identification field.
[0010] In an embodiment of the present application, when the client displays the visualization interface, the client is further configured to: initiate a corresponding data access request to the cloud server according to the monitoring component in the visualization interface; receive operation and maintenance data returned by the cloud server after the cloud server performs data filtering according to the data access request; fill the received operation and maintenance data into the monitoring component corresponding to the visualization interface for display.
[0011] In an embodiment of the present application, the client is further configured to, after displaying the visualization interface, respond to an editing operation of the user on the visualization interface; the editing operation includes selecting a monitoring component provided by the client and adjusting configuration information of the visualization interface according to the selected monitoring component.
[0012] In an embodiment of the present application, the client is further configured to: determine operation permissions of the user according to the login credentials and a preset permission list; When the visual interface is displayed and in response to a user operation, a monitoring component associated with the user operation in the visual interface is controlled according to a result of judging the operation permission.
[0013] In an embodiment of the present application, data transmission between the cloud server and the client and between the data collection module and the cloud server is encrypted using a transport layer security protocol.
[0014] The present application also provides a management method for nuclear power plant data, which is applied to a management system for nuclear power plant data, and the management system comprises a plurality of data collection modules, a client and a cloud server. The operation and maintenance data of the corresponding nuclear power plant are collected by the plurality of data collection modules and uploaded to the cloud server, and the operation and maintenance data comprises an identification field for identifying the nuclear power plant. The operation and maintenance data of all nuclear power plants are stored by the cloud server. The login credentials of the user of the nuclear power plant are received and verified by the client, and the user information in the login credentials is uploaded to the cloud server when the verification is passed, and the user information comprises an identification field for identifying the nuclear power plant. The user information is received by the cloud server, and the nuclear power plant associated with the user is determined according to the identification field contained in the user information. During the user access, when the data access request initiated by the client is received, the identification field of the nuclear power plant associated with the user is added to the data access request as a data filtering condition, so that the user obtains the operation and maintenance data of the nuclear power plant associated with the user.
[0015] The present application has the beneficial effect that the logical isolation of the operation and maintenance data in the multi-tenant environment is realized by embedding the identification field in the data table and automatically adding the filtering condition, and the independence and security of the data of each nuclear power plant are ensured. BRIEF DESCRIPTION OF DRAWINGS
[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application. It is apparent that the accompanying drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0017] In the drawings: Figure 1 A schematic diagram of a management system for nuclear power plant data is provided for an embodiment of the present application. Figure 2A flow chart of a method for managing data of multiple nuclear power plants is provided in an embodiment of the present application. DETAILED DESCRIPTION
[0018] The present application is described and explained with additional specificity and detail through the use of the accompanying drawings in which:
[0019] It should be noted that the drawings included herewith are included merely for purposes of illustration and are not intended to limit the scope of the present application. The drawings are also included to enable persons with ordinary skills and / or knowledge in the art in which the application resides to make and use the application.
[0020] In the following description, numerous specific details are discussed so as to provide a thorough understanding of embodiments of the present application. However, the embodiments of the present application can be practiced without these specific details. In other instances, well-known structures and devices are not described in detail so as not to obscure the description of the embodiments of the present application with unnecessary detail.
[0021] Referring to Figure 1 The present application discloses a system for managing data of multiple nuclear power plants, which can be applied in the field of nuclear power equipment state monitoring and operation and maintenance management. In the scenario where a nuclear power group provides unified cloud management services to multiple subordinate nuclear power plants, the system can solve the problem that the traditional shared database shared schema mode is difficult to meet the high security protection standard of nuclear power data and there is a risk of unauthorized access. The management system can include multiple data acquisition modules 100, a cloud server 200, and a client 300.
[0022] Referring to Figure 1 In some implementations, the multiple data acquisition modules 100 are respectively deployed in different nuclear power plants, and are used to acquire operation and maintenance data of the corresponding nuclear power plants and upload the data to the cloud server 200. The operation and maintenance data include an identification field used to identify the nuclear power plant.
[0023] In some embodiments, the data collection module 100 is a set of edge hardware deployed on site of each nuclear power unit (i.e. nuclear power plant) for unified collection, pre-processing and uploading of operation and maintenance data (such as equipment temperature, pressure, vibration, etc.). Specifically, one nuclear power plant can be configured with one independent data collection module 100. The data collection module 100 can integrate or logically connect various terminals on site of the nuclear power plant, such as sensors (e.g. temperature sensors, pressure transmitters) directly serving specific equipment (e.g. steam generators), programmable logic controller (PLC) devices and various intelligent instrument devices. These remote devices are the original source of operation and maintenance data.
[0024] In some embodiments, when the data collection module 100 is working, it first reads original data from remote devices periodically or event-triggered. Subsequently, the data collection module 100 encapsulates the original data according to a predefined format and automatically embeds a unique identification field (Tenant ID) for each encapsulated data, which refers to the code of the corresponding nuclear power plant. Through this mechanism, any operation and maintenance data from the nuclear power plant A is marked as belonging to it when leaving its data collection module 100.
[0025] In some embodiments, the cloud server 200 is used to store operation and maintenance data of all nuclear power plants. The cloud server 200 is also used to verify the identification field of the operation and maintenance data when receiving it: when the identification field matches the identification field of the corresponding nuclear power plant, the operation and maintenance data is stored in the corresponding data table; the fields of the data table at least include: identification information of the operation and maintenance equipment, timestamp, collected data, identification field.
[0026] In some embodiments, when the cloud server 200 receives the operation and maintenance data uploaded by the data collection module 100 through the network, it will perform verification of the identification field. First, according to the source information of the operation and maintenance data, the identity of the nuclear power plant corresponding to the data collection module 100 is parsed. Then, the built-in identification field in the operation and maintenance data is extracted and compared with the identification field of the parsed nuclear power plant. For example, an operation and maintenance data is expected to come from "nuclear power plant A" (its identification field is, for example, "Tenant_A"), if the identification field encapsulated inside is also "Tenant_A", the verification is passed.
[0027] In some embodiments, after the identification field is verified, the cloud server 200 routes the operation and maintenance data to a corresponding data table for storage according to the type of the operation and maintenance data (e.g., temperature data, vibration data, pressure data). For example, if a specific temperature sensor data is received, the cloud server 200 writes the data collected by the temperature sensor into a "TemperatureData" data table. The data table is designed to store the temperature data of the specific temperature sensor, and the structure of the data table includes the following core fields: identification information of the operation and maintenance device (DeviceID), which is used to uniquely identify the sensor that generates the temperature data; a timestamp (Timestamp), which records the time when the temperature data is collected; the collected data (e.g., for a temperature sensor, the temperature value collected, such as "45.6°C"); and an identification field (TenantID), such as "Tenant_A" or "Tenant_B". If the verification fails, the operation and maintenance data needs to be discarded.
[0028] In some embodiments, the client 300 is configured to receive and verify the login credentials of a user of the nuclear power plant, and upload the user information in the login credentials to the cloud server 200 when the verification is passed. The user information includes an identification field for identifying the nuclear power plant. The number of clients 300 can be multiple or one, which is not limited herein.
[0029] In some embodiments, when the client 300 receives and verifies the login credentials of the user, the client 300 is configured to verify the identification field included in the user information in the login credentials, and verify the validity of the user information. When the identification field included in the user information matches the identification field of the corresponding nuclear power plant and the user information is in a valid state, it is determined that the login credential verification is passed. When the identification field included in the user information does not match the identification field of the corresponding nuclear power plant and / or the user information is in an invalid state, corresponding alarm information is generated.
[0030] In some embodiments, the client 300 is an entrance for engineers of the nuclear power plant to access and manage the operation and maintenance data, which can be a graphical application or a web interface that needs to be actively logged in by the user. The client 300 can perform a user identity verification process to ensure that only authorized engineers can access their corresponding data.
[0031] In some embodiments, when an engineer needs to access the corresponding nuclear power plant, he or she first needs to input his or her login credentials on the login interface of the client 300. The login credentials include a username and a password, or a combination of more advanced multi-factor authentication information. After receiving the login credentials submitted by the user, the client 300 does not immediately send them to the cloud server 200, but first performs a preliminary verification locally.
[0032] In some embodiments, client 300 verifies the validity of the user information itself in the login credentials. This includes checking if the username exists, if the password matches, if the account is locked or disabled, and if any time-based access policies (such as account expiration) are still permitted.
[0033] In some embodiments, the client 300 also verifies the identification field contained in the user information. Each user account is pre-assigned and associated with an identification field that indicates the nuclear power plant the user is authorized to access. The client 300 extracts this identification field from the login credentials and matches it with the identification field of the corresponding nuclear power plant configured in the client 300 itself. For example, if the identification field in an engineer's user information is "Tenant_QS", and the corresponding nuclear power plant's identification field in the client 300 is also "Tenant_QS", then the identification field match is successful.
[0034] In some embodiments, if during the verification process, the identifier field contained in the user information does not match the identifier field of the corresponding nuclear power plant (for example, a user with the identifier field "Tenant_DYW" attempts to match a nuclear power plant with the identifier field "Tenant_QS"), and / or the user information itself is invalid (e.g., the account has expired), the client 300 will determine that the login has failed and generate and record a corresponding alarm message. This alarm message will record the time of the abnormal login attempt, the username used, the IP address, and the specific reason for the failure (e.g., "identifier field mismatch"), so that potential security risks, such as credential theft or unauthorized access attempts, can be detected and investigated in a timely manner later.
[0035] In some embodiments, the cloud server 200 is further configured to receive user information and determine the nuclear power plant associated with the user based on the identification field contained therein. The cloud server 200 is also configured to, during user access, when receiving a data access request initiated through the client 300, append the identification field of the nuclear power plant associated with the user as a data filtering condition to the data access request, so that the user can obtain the operation and maintenance data of the nuclear power plant associated with them.
[0036] In some embodiments, after a user successfully completes login verification through client 300, client 300 uploads the verified user information to cloud server 200. The user information includes an identification field used to identify the nuclear power plant; for example, "Tenant_A" represents nuclear power plant A, and "Tenant_B" represents nuclear power plant B. Upon receiving this user information, cloud server 200 immediately parses it and extracts the identification field. Based on this identification field, cloud server 200 can determine the specific nuclear power plant associated with the user. For example, if the identification field in the user information is parsed to be "Tenant_A", cloud server 200 knows that the currently logged-in user is an authorized personnel of nuclear power plant A.
[0037] In some embodiments, during the user's entire access period, when the user initiates a data access request to the cloud server 200 through the client 300, such as requesting to query the readings of a specific temperature sensor in the past 24 hours, the cloud server 200 will dynamically append the identification field of the nuclear power plant associated with the user as an unavoidable data filtering condition to the original data access request in the background.
[0038] In some embodiments, taking temperature data as an example, a user might simply send a data access request like "SELECT * FROM TemperatureData" through client 300. However, before the cloud server 200 actually executes the database query, it automatically rewrites this data access request into a form like "SELECT * FROM TemperatureData WHERE TenantID=Tenant_A". This "WHERE TenantID=Tenant_A" is the additional data filtering condition. This additional process is completely transparent to the user; the user does not need to manually specify this data filtering condition in the data access request.
[0039] In some embodiments, this approach ensures that regardless of the type of data access request initiated by the user—whether it's a simple data query, complex data analysis, report generation, or alarm threshold setting—the cloud server 200 guarantees that the final operation is strictly limited to the data scope of its associated nuclear power plant. This automatically applied, identifier-based data filtering condition achieves logical data isolation for operational data. Users can only ever see and manipulate operational data whose identifier fields exactly match the identifier fields of the nuclear power plant to which they are associated.
[0040] In some embodiments, therefore, all data access requests from a user at nuclear power plant A, after being processed by the cloud server 200, will only return maintenance data marked "Tenant_A"; similarly, users at nuclear power plant B can only access maintenance data marked "Tenant_B". This design ensures the privacy and security of maintenance data, completely eliminating unauthorized disclosure or obfuscation of maintenance data between different nuclear power plants from the access perspective.
[0041] In some embodiments, the client 300 is also used to store configuration information for an independent and customizable visualization interface for each nuclear power plant; the configuration information includes at least the layout of the monitoring components, chart types, alarm thresholds, and is bound to the identification field of the nuclear power plant.
[0042] In some embodiments, the client 300 stores a separate and customizable set of configuration information for the visualization interface for each nuclear power plant. This configuration information is strongly bound to the identification field of the nuclear power plant. For example, for nuclear power plant A, whose identification field is "Tenant_A", the configuration information stored in the client 300 may define the layout of the main control room screen: a reactor pressure trend graph in the upper left corner, a cooling loop hotspot graph in the lower right corner, and a temperature alarm threshold set to 85°C. Nuclear power plant B, whose identification field is "Tenant_B", may use a different layout and set its temperature alarm threshold to 80°C based on its equipment characteristics. This configuration information specifically includes the specific layout position of the monitoring components on the screen, the chart type used by each monitoring component (such as line chart, bar chart, dashboard, topology diagram), and parameters such as the specific alarm threshold associated with the component. All configuration information is logically isolated through its bound identification field, ensuring that users of nuclear power plant A can only see and modify the interface settings belonging to "Tenant_A" during configuration and cannot access or affect the configuration of nuclear power plant B.
[0043] In some embodiments, after the client 300 verifies the user's login credentials, the client 300 is also used to display a visual interface corresponding to the identifier field contained in the user information.
[0044] In some embodiments, after the client 300 successfully verifies the user's login credentials, in addition to uploading the user information to the cloud server 200, it also retrieves and displays a visualization interface uniquely corresponding to the identifier field contained in the user information from local storage or a configuration service. Specifically, when an engineer from nuclear power plant A successfully logs in, the client 300 extracts the identifier field "Tenant_A" from their user information, and then automatically loads and renders the visualization interface previously customized for nuclear power plant A.
[0045] In some embodiments, when the client 300 displays the visualization interface, the client 300 is further configured to: initiate a corresponding data access request to the cloud server 200 based on the monitoring component in the visualization interface; receive the operation and maintenance data returned by the cloud server 200 after filtering the data according to the data access request; and fill the received operation and maintenance data into the monitoring component corresponding to the visualization interface for display.
[0046] In some embodiments, when the client 300 displays the visualization interface, it first initiates corresponding, precise data access requests to the cloud server 200 based on the various monitoring components (such as temperature trend charts) configured in the current visualization interface. For example, the temperature trend chart component might trigger a data access request, requesting readings from one or more specific temperature sensors over the past 12 hours. Next, the client 300 receives maintenance data returned by the cloud server 200. It is important to emphasize that this maintenance data is not the full dataset, but rather the result obtained by the cloud server 200 after automatically applying a filtering rule based on the user identifier field according to the data access request. In other words, the client 300 only receives temperature data labeled "Tenant_A". Finally, the client 300 populates the corresponding monitoring component in the visualization interface with this received maintenance data for graphical display. Thus, the trend chart seen by the engineers at nuclear power plant A only reflects the temperatures of one or more specific temperature sensors in nuclear power plant A.
[0047] In some embodiments, the client 300 is further configured to respond to the user's editing operation on the visualization interface after displaying the visualization interface; the editing operation includes selecting from the monitoring components provided by the client 300 and adjusting the configuration information of the visualization interface according to the selected monitoring components.
[0048] In some embodiments, after displaying the visualization interface, the client 300 is capable of responding to user editing operations. Authorized users (such as senior engineers) can personalize the visualization interface. Editing operations mainly involve selecting from a visualization component repository provided by the client 300, and then adjusting the configuration information of the visualization interface based on the selected monitoring component. For example, a user can select a "pump vibration frequency spectrum" component from the component repository, drag it to a blank area on the interface, and adjust its position and size. The client 300 records these changes and saves them as new configuration information bound to the nuclear power plant identification field.
[0049] In some embodiments, the client 300 is further configured to: determine the user's operation permissions based on the login credentials and a preset permission list; and, when displaying the visual interface and responding to user operations, control the monitoring components associated with the user operations in the visual interface based on the determination result of the operation permissions.
[0050] In some embodiments, the client 300 also assumes the responsibility of front-end access control to optimize user experience and provide initial security protection. First, after a user successfully logs in, the client 300 determines the user's specific operational permissions based on their login credentials and a preset permission list. For example, the cloud server 200 might return a permission list in the login response, indicating that ordinary engineers have the permission to only view data, while senior engineers might also have the permission to configure alarm rules. The client 300 stores this permission information in memory.
[0051] In some embodiments, when displaying the visual interface and responding to various user operations, the client 300 will visually control the monitoring components or function buttons associated with the user operations in the interface based on the current operation permission determination result. For interface elements corresponding to ordinary engineers (such as the "Modify Alarm Threshold" button), the client 300 will hide or disable them, thereby preventing users from performing unauthorized operations visually and interactively. For ordinary engineers, the edit button for dragging and dropping to add new components will not appear on their client 300 interface, or the submit button for saving configurations will be hidden.
[0052] In some embodiments, in the nuclear power plant operation and maintenance monitoring scenario, the visualization interface displayed on the client 300 needs to present the near real-time equipment operating status. Therefore, the data rendered on the visualization interface must be refreshed regularly to reflect the latest operation and maintenance data collected by the data acquisition module 100.
[0053] In some embodiments, the data acquisition module 100 can collect operational data of various maintenance equipment in real time, including key process parameters such as temperature, pressure, flow rate, and vibration. This real-time collected maintenance data is synchronously sent by the data acquisition module 100 to the cloud server 200 for storage.
[0054] In some embodiments, in order to update the data of the visualization interface, after the user successfully logs in and loads the customized visualization interface, the client 300 will start one or more timers to periodically send data access requests to the cloud server 200 at preset fixed time intervals (e.g., once every 5 seconds). Each data access request needs to obtain the current operation and maintenance data.
[0055] In some embodiments, for example, for each dynamic data monitoring component on the visualization interface (e.g., a trend chart displaying the reactor primary loop temperature), the client 300 sets an independent time interval during initialization. This time interval can be configured according to the characteristics of the monitored data and user needs. For frequently changing key parameters, a shorter interval (e.g., 2 seconds) may be set, while for slowly changing auxiliary parameters, a longer interval (e.g., 30 seconds) may be set to balance data real-time performance and system load. When the timer is triggered, the client 300 automatically assembles and sends the corresponding data query request to the cloud server 200 based on the data of interest to each monitoring component in the current visualization interface.
[0056] In some embodiments, upon receiving these requests, the cloud server 200 automatically appends the identification field of the nuclear power plant associated with the current user as a data filtering condition to the request. Subsequently, in the hybrid storage database, it quickly retrieves maintenance data generated within a specified time range that matches the identification field of the requesting user. This filtered maintenance data is then returned to the client 300.
[0057] In some embodiments, after receiving maintenance data from the cloud server 200, the client 300 will populate the current maintenance data into the corresponding monitoring components. For example, the temperature trend chart will plot the latest temperature point, the dashboard pointer will rotate to the new reading position, and the alarm list will determine whether to trigger a new warning based on the latest data.
[0058] In some embodiments, data transmission between the cloud server 200 and the client 300, and between the data acquisition module 100 and the cloud server 200, is encrypted using a transport layer security protocol.
[0059] In some embodiments, all network communications between the client 300 and the cloud server 200, and between the data acquisition module 100 and the cloud server 200, adopt a multi-layered security scheme combining TLS (Transport Layer Security) and AES-256 encryption technology to form a defense-in-depth system.
[0060] In some embodiments, when client 300 initiates and attempts to connect to cloud server 200, both parties perform a complex TLS handshake process. This handshake process has two components: first, it verifies the identity of cloud server 200 by having cloud server 200 present its digital certificate to client 300, effectively preventing client 300 from connecting to a fake server; second, it negotiates a key, where client 300 and cloud server 200 jointly negotiate a temporary, unique session key using an asymmetric encryption algorithm. After a successful handshake, an authenticated, secure, and encrypted transmission channel is established between client 300 and cloud server 200.
[0061] In some embodiments, data undergoes an additional layer of encryption before being placed into the encrypted transmission channel for transmission. Specifically, at client 300, highly sensitive information, such as the password entered by the user during login, is encrypted using the AES-256 symmetric encryption algorithm before being used to form login credentials and sent over the network. The AES-256 key used for encryption can be generated during the handshake phase. The AES-256 encrypted data is then transmitted through the established, equally encrypted transmission channel. When this encrypted data arrives at cloud server 200, the decryption process is reversed. Cloud server 200 first decrypts and restores the AES-256 encrypted data using the TLS protocol. Subsequently, cloud server 200 decrypts the data using the corresponding AES-256 key to obtain the final data.
[0062] Please see Figure 2 The present invention also discloses a method for managing multiple nuclear power plant data, which can be applied to the aforementioned management system. The management system includes multiple data acquisition modules, a client, and a cloud server; the management method includes: S10. Collect the corresponding nuclear power plant operation and maintenance data through multiple data acquisition modules and upload it to the cloud server; the operation and maintenance data includes an identification field used to identify the nuclear power plant; S20. Store all nuclear power plant operation and maintenance data through cloud servers; S30. Receive and verify the login credentials of the nuclear power plant user through the client, and upload the user information in the login credentials to the cloud server when the verification is successful; the user information includes an identification field used to identify the nuclear power plant; S40. Receive user information through a cloud server and determine the nuclear power plant associated with the user based on the identification field it contains; When the S50 cloud server receives a data access request initiated by the client during a user's access, it will attach the identification field of the nuclear power plant associated with the user as a data filtering condition to the data access request, so that the user can obtain the operation and maintenance data of the nuclear power plant associated with him / her.
[0063] As can be seen, the above solution achieves logical isolation of operation and maintenance data in a multi-tenant environment by embedding an identifier field in the data table and automatically adding filtering conditions, ensuring the independence and security of data for each nuclear power plant. Through the construction of a component-based visual repository, each nuclear power plant can flexibly select and orchestrate monitoring components according to its own operation and maintenance needs, generating personalized monitoring interfaces, effectively meeting the differentiated needs of different nuclear power plants in terms of monitoring content and display format.
[0064] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.
Claims
1. A management system for data from multiple nuclear power plants, characterized in that, Includes multiple data acquisition modules, client software, and cloud servers; The multiple data acquisition modules are deployed at different nuclear power plants to collect the corresponding operation and maintenance data of the nuclear power plants and upload it to the cloud server; the operation and maintenance data includes an identification field for identifying the nuclear power plants. The client is used to receive and verify the login credentials of users of the nuclear power plant, and upload the user information in the login credentials to the cloud server when the verification is successful; the user information includes an identification field for identifying the nuclear power plant; The cloud server is used to store the operation and maintenance data of all nuclear power plants; The cloud server is also used to receive user information and determine the nuclear power plant associated with the user based on the identification field it contains; The cloud server is also used to, during user access, when receiving a data access request initiated through the client, append the identification field of the nuclear power plant associated with the user as a data filtering condition to the data access request, so that the user can obtain the operation and maintenance data of the nuclear power plant associated with him / her.
2. The management system for multiple nuclear power plant data according to claim 1, characterized in that, The cloud server is also used to verify the identification field of the received operation and maintenance data: When the identification field matches the identification field of the corresponding nuclear power plant, the operation and maintenance data is stored in the corresponding data table; The data table must include at least the following fields: identification information of the maintenance equipment, timestamp, collected data, and identification field.
3. The management system for multiple nuclear power plant data according to claim 1, characterized in that, When the client receives and verifies the user's login credentials, the client is used to: Verify the identifier field contained in the user information in the login credentials, and verify the validity of the user information; When the identifier field contained in the user information matches the identifier field of the corresponding nuclear power plant, and the user information is in a valid state, the login credential verification is deemed successful. When the identification field contained in the user information does not match the identification field of the corresponding nuclear power plant and / or the user information is invalid, a corresponding alarm message is generated.
4. The management system for multiple nuclear power plant data according to claim 3, characterized in that, The client is also used to store configuration information for an independent and customizable visualization interface for each nuclear power plant; the configuration information includes at least the layout of monitoring components, chart types, alarm thresholds, and is bound to the identification field of the nuclear power plant.
5. The management system for multiple nuclear power plant data according to claim 4, characterized in that, After the client verifies the user's login credentials, the client is also used to display a visual interface corresponding to the identifier field contained in the user information.
6. The management system for multiple nuclear power plant data according to claim 5, characterized in that, When the client displays the visual interface, the client is also used to: Based on the monitoring components in the visualization interface, a corresponding data access request is initiated to the cloud server; Receive the operation and maintenance data returned by the cloud server after filtering the data according to the data access request; The received operation and maintenance data is populated into the monitoring component corresponding to the visualization interface for display.
7. The management system for multiple nuclear power plant data according to claim 5, characterized in that, The client is also used to respond to the user's editing operations on the visual interface after it is displayed; The editing operation includes selecting a monitoring component provided by the client and adjusting the configuration information of the visualization interface based on the selected monitoring component.
8. The management system for multiple nuclear power plant data according to claim 7, characterized in that, The client is also used for: The user's operation permissions are determined based on the login credentials and the preset permission list; When displaying the visualization interface and responding to user operations, the monitoring components associated with the user operations in the visualization interface are controlled based on the judgment result of the operation permissions.
9. The management system for multiple nuclear power plant data according to claim 1, characterized in that, Data transmission between the cloud server and the client, and between the data acquisition module and the cloud server, is encrypted using a transport layer security protocol.
10. A method for managing data from multiple nuclear power plants, characterized in that, The management system, applied to a plurality of nuclear power plant data as described in any one of claims 1 to 9, comprises a plurality of data acquisition modules, a client, and a cloud server; the management method comprises: The operation and maintenance data of the corresponding nuclear power plant is collected by multiple data acquisition modules and uploaded to the cloud server; the operation and maintenance data includes an identification field for identifying the nuclear power plant. The cloud server stores the operation and maintenance data of all nuclear power plants; The client receives and verifies the login credentials of users of the nuclear power plant, and uploads the user information in the login credentials to the cloud server when the verification is successful; the user information includes an identification field for identifying the nuclear power plant; The cloud server receives user information and determines the nuclear power plant associated with the user based on the identification field it contains. When a user accesses a cloud server and receives a data access request initiated by the client, the cloud server will append the identification field of the nuclear power plant associated with the user as a data filtering condition to the data access request, so that the user can obtain the operation and maintenance data of the nuclear power plant associated with him / her.