Equipment access method and device of power system, computer equipment and storage medium
By acquiring data through a bypass mirror port in the power system and combining it with database and model evaluation, the problems of compatibility and transformation costs during the power system equipment access process are solved. This enables secure and observable data and reliable and continuous evaluation of access strategies, thereby improving the security and reliability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-08
- Publication Date
- 2026-04-10
AI Technical Summary
In power systems, there is a wide variety of equipment and protocols, which are highly heterogeneous and require real-time performance. Existing technologies struggle to build reliable, continuous, secure, and observable capabilities without affecting existing network services, leading to problems such as poor compatibility, uncontrollable latency, and high upgrade costs during equipment access.
By acquiring system operation data through the bypass mirror port of the target switch, using situation analysis and status assessment models, the device operation status is determined and system access policies are generated. Combined with relational and time-series databases to store data, non-intrusive monitoring and security status assessment are achieved.
Without shutting down the system or requiring any modifications, the system achieved a safety status assessment of power system equipment and determined the access strategy, thereby improving the safety and reliability of the power system and reducing modification costs.
Smart Images

Figure CN121841879A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power system technology, and in particular to a method, apparatus, computer equipment, and storage medium for connecting equipment to a power system. Background Technology
[0002] As a critical national infrastructure, the safe and stable operation of the power industry is of paramount importance to the national economy, people's livelihood, and social order. With the networking process of critical infrastructure such as digital grids, business systems have transformed from traditional point-to-point applications into complex collaborative systems that span regions and levels, widely involving numerous scenarios such as dispatch control, production operation management, metering and trading, and centralized control and maintenance.
[0003] In critical infrastructure and industrial control networks, the field environment is complex, highly heterogeneous, and requires real-time monitoring. The diverse types of equipment and protocols present stringent requirements for continuous operation and security compliance. Therefore, building reliable, continuous, secure, and observable capabilities without impacting existing network services has become a critical issue that urgently needs to be addressed in power system equipment integration scenarios. Summary of the Invention
[0004] Therefore, it is necessary to provide a method, apparatus, computer equipment, and storage medium for power system equipment access to address the aforementioned technical problems, which can provide security support for power system equipment access and improve the security of the power system.
[0005] In a first aspect, this application provides a method for connecting equipment to a power system, including:
[0006] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0007] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0008] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0009] In one embodiment, the system operation data of the target power system during the current time period is obtained from the target switch to which the target power system is connected, including:
[0010] The system operation data of the target power system during the current time period is obtained from the target switch through the target port of the target switch.
[0011] In one embodiment, the target port is a bypass mirror port; the system operation data of the target power system in the current time period is obtained from the target switch through the target port of the target switch, including:
[0012] By bypassing the mirror port, the system operation data of the target power system is obtained through mirroring.
[0013] In one embodiment, the system operation data includes at least one of equipment online data and equipment flow data corresponding to different power devices in the target power system; accordingly, determining the equipment operation status corresponding to different power devices in the target power system based on the system operation data includes:
[0014] For any given power device, based on its online data and historical online data, determine the current online anomaly situation for that device during the current time period; and...
[0015] Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current period.
[0016] Based on the abnormal online conditions and / or abnormal traffic conditions, determine the operating status of the corresponding power equipment.
[0017] In one embodiment, a safety status assessment of the power equipment is performed based on the equipment's operating status, including:
[0018] Receive device identification information from power equipment in response to information acquisition instructions;
[0019] Based on the operating status of the power equipment and its identification information, a safety status assessment is conducted on the power equipment.
[0020] In one embodiment, the system access strategy corresponding to the power equipment is determined based on the evaluation results, including:
[0021] When the evaluation results characterize the equipment state security of the power equipment, the initial access policy will be used as the system access policy corresponding to the power equipment.
[0022] When the assessment results indicate that the equipment status of the power equipment is unsafe, the conditions for new access are determined.
[0023] Based on the new access conditions and the initial access strategy, generate the system access strategy corresponding to the power equipment.
[0024] In one embodiment, after obtaining the system operation data of the target power system in the current time period from the target switch to which the target power system is connected, the method further includes:
[0025] Based on the data type of the system operation data, the system operation data is divided into Category I operation data and Category II operation data; Category I operation data has a higher access frequency than Category II operation data.
[0026] Store one type of runtime data in one type of database; and,
[0027] The two types of runtime data are stored in a two-type database; the first type of database is a relational database; and the second type of database is a time-series database.
[0028] Secondly, this application also provides a power system equipment access device, comprising:
[0029] The data acquisition module is used to acquire system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0030] The operation status determination module is used to determine the equipment operation status of different power equipment in the target power system based on system operation data.
[0031] The security status assessment module is used to assess the security status of any power device based on its operating conditions, and to determine the corresponding system access strategy based on the assessment results.
[0032] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0033] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0034] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0035] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0036] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0037] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0038] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0039] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0040] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0041] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0042] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0043] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0044] The aforementioned power system equipment access methods, devices, computer equipment, and storage media, derived through the technical features described in the proprietary patent, can achieve beneficial effects to address the technical problems in the background art. Attached Figure Description
[0045] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0046] Figure 1 This is a flowchart illustrating a method for connecting equipment in a power system in one embodiment;
[0047] Figure 2 This is a flowchart illustrating the steps for determining the device's operating status in one embodiment;
[0048] Figure 3 This is a flowchart illustrating the security status assessment steps in one embodiment;
[0049] Figure 4 This is a flowchart illustrating a power system equipment access method in another embodiment;
[0050] Figure 5 This is a structural block diagram of a power system equipment access device in one embodiment;
[0051] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0053] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.
[0054] Before introducing the embodiments of this application, it should be noted that the power industry, as a critical national infrastructure, is directly related to the national economy, people's livelihood, and social order through its safe and stable operation. With the network development of critical infrastructure such as digital grids, business systems have evolved from traditional point-based applications to complex systems that collaborate across regions and levels, covering various scenarios such as dispatch control, production operation management, metering and trading, and centralized control and maintenance. In critical infrastructure and industrial control networks, the field environment is highly heterogeneous, real-time, and diverse in terms of equipment and protocol types, with strict requirements for continuous operation and security compliance. Directly introducing traditional on-grid security equipment into the production side often faces problems such as poor compatibility, uncontrollable latency, and high transformation costs, which may actually affect business stability. At the same time, internal threats and persistent attacks are becoming more covert, with related clues scattered in network traffic, host / system logs, and industrial protocol interactions. These sources are diverse, with different formats and inconsistent time bases, and there is a lack of objective measurement of the quality of collection and the authenticity of evidence, making subsequent correlation analysis and evidence collection difficult. Therefore, establishing reliable, continuous, and observable security capabilities without interfering with existing network operations has become a common demand in the industry.
[0055] Based on the aforementioned constraints and pain points, this application continuously and with low overhead acquires key network / session / protocol elements without altering the existing network, simultaneously generates quantifiable data quality indicators and unified identifiers / time stamps, and provides verifiable evidence elements, thus providing a reliable data foundation for subsequent power system equipment access strategies.
[0056] In one exemplary embodiment, such as Figure 1 As shown, a method for connecting equipment in a power system is provided, including the following steps:
[0057] S110: Obtain system operation data of the target power system in the current time period from the target switch connected to the target power system.
[0058] The target power system can be understood as a power system with updated equipment access policies; the target power system corresponds to a target switch; the current time period includes the current moment and the preset historical time period before the current moment; the system operation data is used to characterize the operating status of the target power system in the current time period, such as the safe operating status.
[0059] Optionally, system operation data may include network traffic data of the target power system in the current time period, and equipment operation data of different power devices in the target power system, such as terminal devices, user behavior, network traffic, and equipment logs.
[0060] To ensure that the normal operation of the target power system is not affected during the acquisition of system operation data—that is, to acquire system operation data without shutting down or requiring any modifications to the target power system—in one optional implementation, the system operation data of the target power system for the current time period can be obtained from the target switch via the target port of the target switch. For example, the target port is a bypass mirror port; correspondingly, the system operation data of the target power system is obtained by mirroring through the bypass mirror port.
[0061] For example, by setting up mirroring on the port of the target switch, the traffic of the target power system during the current time period can be copied to a separate port. The network traffic data quintuple (source Internet Protocol Address (IP), target IP, source port, target port, protocol type) of the target power system or different power devices in the target power system can be collected in real time and used as system operation data, thereby realizing non-intrusive monitoring of the target power system.
[0062] In another alternative implementation, physical layer bypass optical copying can be achieved at both ends of the critical link using a Terminal Access Point / Network Packet Broker (TAP). This allows for the collection of original packets generated by the target power system during the current time period without any rewriting, and provides heartbeat keep-alive mechanisms to ensure that the service link is not affected when equipment malfunctions or power outages. The output is a unified 5-tuple of data as the system operation data of the target power system.
[0063] To facilitate subsequent processing and analysis, this embodiment can also preprocess the collected system operation data. For example, the collected system operation data and necessary headers are accessed in batch / stream mode, and a finite state machine is used for header and control field-level parsing (such as Application Service Data Unit (ASDU) type / function code / object address / quality bits, etc.) for industrial protocols such as IEC-104, Modbus, and DNP3. Then, integrity and consistency checks (field boundaries, required fields, time monotonicity) are performed on the parsing results, and duplicate records are removed using a sliding window strategy based on a 5-tuple + sequence number / arrival time to complete deduplication. Based on this, heterogeneous records are mapped to a unified data template, and field families such as "record key / identifier and time key" are standardized to achieve data standardization and facilitate subsequent processing.
[0064] S120, based on system operation data, determine the equipment operation status of different power devices in the target power system.
[0065] In one alternative implementation, system operation data can be input into a pre-trained situation analysis model to obtain the equipment operation status of different power devices in the target power system.
[0066] In another alternative implementation, the reference operating conditions corresponding to the system operating data can be used as the equipment operating conditions corresponding to different power equipment in the target power system based on a predetermined comparison relationship.
[0067] S130: For any power equipment, perform a safety status assessment on the power equipment based on the equipment operation status, and determine the system access strategy corresponding to the power equipment based on the assessment results.
[0068] In one alternative implementation, the operating status of the power equipment can be input into a pre-trained state assessment model to obtain the safety status assessment result of the corresponding power equipment.
[0069] In another alternative implementation, the equipment operation status of the corresponding power equipment can directly represent the safety status of the corresponding power equipment. For example, if the equipment operation status is abnormal, the safety status is abnormal; if the equipment operation status is normal, the safety status is normal.
[0070] Optionally, different security status assessment results correspond to different reference access strategies. In this embodiment, the reference access strategy corresponding to the security status assessment result of the power equipment is used as the system access strategy of the power equipment.
[0071] For example, each power device has an initial access policy, which characterizes the conditions that the power device must meet before the current time to access the target power system. In one optional implementation, if the evaluation result indicates that the power device's device state is safe, the initial access policy is used as the system access policy for the power device; if the evaluation result indicates that the power device's device state is unsafe, new access conditions are determined; and a system access policy for the power device is generated based on the new access conditions and the initial access policy.
[0072] The new access conditions can be determined based on human experience or through extensive experimentation; this application does not impose any limitations on this. For example, the new access conditions may include at least one of two-factor authentication or token authentication.
[0073] In one optional implementation, the system operation data is divided into a first-class operation data and a second-class operation data according to the data type of the system operation data; the first-class operation data is stored in a first-class database; and the second-class operation data is stored in a second-class database.
[0074] Of these, Category 1 operational data is accessed more frequently than Category 2 operational data. Category 1 operational data can be structured data requiring rapid access, such as status records of power equipment, control command history, power equipment logs, and configuration files. Category 2 operational data can be time-series data of the target power system or power equipment, such as equipment operating status, sensor data, and flow data. Category 1 databases are relational databases, such as MySQL / SQLite; Category 2 databases are time-series databases, such as TDengine.
[0075] In addition, to ensure data security and reliability, all stored data will be encrypted and backed up regularly. Redundant storage technology ensures rapid data recovery in the event of hardware failure or system crash.
[0076] This process, characterized by "high-concurrency writing, fast retrieval, and traceable auditing," employs a layered persistence strategy combining relational and time-series databases, and integrates cold / hot tiering with encryption / backup mechanisms to ensure reliability and compliance.
[0077] In the aforementioned power system equipment access method, system operation data of the target power system in the current time period is obtained from the target switch to which the target power system is connected. The current time period includes the current moment and a preset historical time period prior to the current moment. Based on the system operation data, the equipment operation status corresponding to different power devices in the target power system is determined. For any power device, a safety status assessment is performed on the power device based on its corresponding equipment operation status, and the system access strategy corresponding to the power device is determined based on the assessment results. In this process, the system operation data of the target power system in the current time period is obtained by connecting to the target switch to which the target power system is connected, and then subsequent processing is performed. During the acquisition of system operation data, the target power system does not need to be shut down or modified; that is, the acquisition of system operation data does not affect the normal operation of the target power system.
[0078] Based on the technical solutions of the above embodiments, this application also provides an optional embodiment. In this optional embodiment, the system operation data includes at least one of equipment online data and equipment flow data corresponding to different power devices in the target power system. In this case, the process of determining the equipment operation status of different power devices in the target power system based on the system operation data is refined.
[0079] See Figure 2 The steps for determining the equipment's operating status, as shown, include:
[0080] S210: For any power equipment, based on the equipment online data corresponding to the power equipment and the historical online data of the power equipment, determine the abnormal online status of the power equipment in the current time period.
[0081] Among them, the equipment online data is used to characterize the online pattern of power equipment in the current period.
[0082] In this embodiment, the abnormal online status of the power equipment in the current period can be determined based on the difference between the online data of the power equipment and the historical online data of the power equipment.
[0083] In one alternative implementation, anomaly detection technology can be used to identify events deviating from normal behavior patterns in device online data. For example, the system first establishes a "normal baseline" using historical data, such as user login patterns, terminal device operation frequency, and network traffic distribution. During real-time operation, device online data is compared with the baseline. If the behavioral characteristics show significant deviations, it is judged as an anomaly, thus determining that the online status of the power equipment in the current time period is abnormal.
[0084] For example, suppose the behavioral feature vector of an electrical device or user is x, with a normal distribution mean of μ and a covariance of μ. Then, the Mahalanobis distance can be used to measure the deviation:
[0085] ;
[0086] In the formula, For abnormal online indicators of power equipment x, when they exceed a set threshold... At this time, the online status of the power equipment is abnormal during the current period. For example, if a user fails to log in multiple times in a short period of time, or if the equipment issues a command stream that is completely different from usual, an alarm may be triggered.
[0087] In another alternative implementation, normal and abnormal behaviors can be automatically distinguished by modeling the operating habits of users and power equipment. For example, a user's usual login location, access to resources, and set of operating commands will form a specific "behavioral fingerprint."
[0088] Clustering methods can be used to divide behavioral samples into several pattern clusters. The newly arrived sample x is assigned to the nearest cluster center c. i If the distance Greater than the set threshold If this is not the case, it indicates that the behavior does not belong to the existing pattern and should be judged as an abnormal pattern. For example, if a user usually only accesses a fixed server but suddenly accesses a sensitive database, it will be identified as an unauthorized operation, thus determining that the online status of the power equipment in the current time period is abnormal.
[0089] S220: Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current period.
[0090] Among them, equipment flow data is used to characterize the flow output and input data of the corresponding power equipment.
[0091] In this embodiment, the abnormal flow of the power equipment in the current time period can be determined based on the difference between the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment.
[0092] Understandably, a single anomaly often fails to reveal the full extent of an attack intent. Therefore, correlation and time-series analysis can be used to uncover relationships between different events. In one alternative implementation, user behavior logs, device state changes, and network traffic events can be placed on a unified timeline to analyze their sequential relationships. If multiple devices simultaneously initiate abnormal connection requests within a short period, or if a user's abnormal login immediately follows an abnormal operation by a critical device, it may indicate that these events belong to the same attack chain.
[0093] Let the time of occurrence of a series of events be... By constructing a time difference function If in the set window If multiple highly related events appear within a given context, it is considered a potential attack chain. Additionally, similarity is calculated:
[0094] ;
[0095] In the formula, sim(e i ,e j This can be understood as the current event e. i With historical events e j The similarity between them is a weighted average of the similarities of each attribute. If Then event e i With e j Establish connecting edges. In this way, an event graph can be formed to identify potential attack paths and sources.
[0096] S230, determine the equipment operation status corresponding to the power equipment based on the online abnormality and / or traffic abnormality.
[0097] For example, in cases of abnormal online status and abnormal traffic flow, if one of them indicates abnormal operation of the power equipment, the power equipment is determined to be operating abnormally; if both abnormal online status and abnormal traffic flow indicate normal operation of the power equipment, the power equipment is determined to be operating normally.
[0098] The above embodiments provide a specific process for determining the operating status of power equipment, which makes the determination of equipment operating status more accurate by considering at least one of online abnormality and flow abnormality.
[0099] Based on the technical solutions of the above embodiments, this application also provides an optional embodiment. In this optional embodiment, the process of assessing the safety status of power equipment based on the operating conditions of the corresponding equipment is refined.
[0100] See Figure 3 The safety status assessment steps shown include:
[0101] S310 receives the device identification information fed back by the power equipment in response to the information acquisition command.
[0102] The information acquisition instruction is used to acquire the equipment identification information of the power equipment; the equipment identification information is the unique identifier of the power equipment, which may include, for example, the equipment name, equipment serial number, etc.
[0103] For example, in order to determine the security of access power equipment, an information retrieval command can be sent to the power equipment to instruct it to provide equipment identification information.
[0104] S320 assesses the safety status of power equipment based on its operating conditions and identification information.
[0105] For example, the consistency between the device identification information and the stored hardware fingerprint of the power device can be used to determine whether there is a counterfeit power device security status. Then, based on the device's operating status and security status, a security status assessment of the power device can be performed.
[0106] When the assessment results are ambiguous or uncertain, the system triggers multi-factor authentication (such as two-factor authentication or token authentication) to enhance the authentication strength. Ultimately, based on the real-time assessment, the system decides whether to allow, delay, or deny access, thereby preventing insecure entities from entering critical network environments.
[0107] In the above embodiments, the safety status of power equipment is determined by obtaining equipment identification information, and then the safety status of power equipment is assessed based on the safety tail and equipment operation status, so that the safety status assessment results are more accurate.
[0108] Furthermore, the system operation data collected in this application can also be used for security measurement and risk assessment. For example, a comprehensive analysis of terminal devices, user behavior, and system configuration can be performed, and a security score and risk label can be generated for each object using the risk scoring model provided by the data analysis module. The results are output in report form, providing quantitative support for access control and permission management. Through real-time updated security measurements, the system can ensure that only objects that meet security standards can continue to operate normally.
[0109] Alternatively, it can be used for access behavior security auditing: to ensure long-term compliance and post-event traceability, all access operations can be monitored and logged in real time, including access time, operation content, and access target. If unauthorized access or abnormal behavior occurs, the system can issue an alert in a timely manner and include it in the audit report. This report not only provides a basis for security administrators to identify potential risks, but also provides evidentiary support for compliance checks and accountability.
[0110] Based on the technical solutions of the above embodiments, this application also provides an optional embodiment. In this optional embodiment, the equipment access method for a power system provided by this application is described in detail.
[0111] See Figure 4 The equipment connection method of the power system shown includes:
[0112] S410, through the bypass mirror port, mirrors the system operation data of the target power system;
[0113] The current time period includes the current moment and the preset historical time periods preceding the current moment;
[0114] It should be noted that, based on the data type of the system operation data, the system operation data is divided into Category I operation data and Category II operation data; Category I operation data is accessed more frequently than Category II operation data; Category I operation data is stored in Category I database; and Category II operation data is stored in Category II database; Category I database is a relational database; Category II database is a time-series database.
[0115] S420: For any power equipment, based on the equipment online data corresponding to the power equipment and the historical online data of the power equipment, determine the abnormal online status of the power equipment in the current time period;
[0116] S430: Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current period.
[0117] S440, determine the equipment operation status of the corresponding power equipment based on the online abnormality and / or traffic abnormality;
[0118] S450, for any power equipment, receives the equipment identification information fed back by the power equipment in response to the information acquisition command;
[0119] S460 assesses the safety status of power equipment based on its operating conditions and identification information.
[0120] S470, if the evaluation results characterize the equipment state security of the power equipment, the initial access policy shall be used as the system access policy corresponding to the power equipment.
[0121] S480, when the assessment results indicate that the equipment status of the power equipment is unsafe, determine the conditions for new access;
[0122] S490 generates the system access policy corresponding to the power equipment based on the new access conditions and the initial access policy.
[0123] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0124] Based on the same inventive concept, this application also provides a power system device access apparatus for implementing the power system device access method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more power system device access apparatus embodiments provided below can be found in the limitations of the power system device access method described above, and will not be repeated here.
[0125] In one exemplary embodiment, such as Figure 5 As shown, a power system equipment access device is provided, including: a data acquisition module 510, an operating status determination module 520, and a security status assessment module 530, wherein:
[0126] The data acquisition module 510 is used to acquire system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current time and the preset historical time period before the current time.
[0127] The operation status determination module 520 is used to determine the equipment operation status of different power equipment in the target power system based on system operation data.
[0128] The security status assessment module 530 is used to assess the security status of any power equipment based on its operating conditions, and to determine the system access strategy corresponding to the power equipment based on the assessment results.
[0129] In one embodiment, the data acquisition module 510 is used to acquire system operation data of the target power system in the current time period from the target switch through the target port of the target switch.
[0130] In one embodiment, the target port is a bypass mirror port, and correspondingly, the data acquisition module 510 is used to mirror and acquire the system operation data of the target power system through the bypass mirror port.
[0131] In one embodiment, the system operation data includes at least one of equipment online data and equipment flow data corresponding to different power devices in the target power system; correspondingly, the operation status determination module 520 includes a first determination unit, used to determine the online anomaly status of any power device in the current time period based on the equipment online data corresponding to the power device and the historical online data of the power device; a second determination unit, used to determine the flow anomaly status of the power device in the current time period based on the equipment flow data corresponding to the power device and the historical flow data of the power device; and a third determination unit, used to determine the equipment operation status corresponding to the power device based on the online anomaly status and / or the flow anomaly status.
[0132] In one embodiment, the safety status assessment module 530 includes an information receiving unit for receiving device identification information fed back by the power equipment in response to an information acquisition instruction; and a safety status assessment unit for assessing the safety status of the power equipment based on the equipment operation status and the device identification information.
[0133] In one embodiment, the security status assessment module 530 includes a fourth determining unit, configured to use the initial access policy as the system access policy corresponding to the power equipment when the assessment result indicates that the equipment status of the power equipment is secure; a fifth determining unit, configured to determine new access conditions when the assessment result indicates that the equipment status of the power equipment is insecure; and a sixth determining unit, configured to generate the system access policy corresponding to the power equipment based on the new access conditions and the initial access policy.
[0134] In one embodiment, the equipment access device of the power system further includes a data storage module, comprising a classification unit for dividing the system operation data into a first-class operation data and a second-class operation data according to the data type of the system operation data; the access frequency of the first-class operation data is higher than that of the second-class operation data; a first storage unit for storing the first-class operation data in a first-class database; and a second storage unit for storing the second-class operation data in a second-class database; the first-class database is a relational database; and the second-class database is a time-series database.
[0135] Each module in the aforementioned power system's equipment access device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can call and execute the corresponding operations of each module.
[0136] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 6 As shown, the computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interface is used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a device access method for a power system. The display unit is used to form a visually visible image and can be a display screen, projection device, or virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.
[0137] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0138] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0139] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0140] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0141] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0142] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0143] The system operation data of the target power system during the current time period is obtained from the target switch through the target port of the target switch.
[0144] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0145] By bypassing the mirror port, the system operation data of the target power system is obtained through mirroring.
[0146] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0147] For any given power device, based on its online data and historical online data, determine the current online anomaly situation for that device during the current time period; and...
[0148] Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current period.
[0149] Based on the abnormal online conditions and / or abnormal traffic conditions, determine the operating status of the corresponding power equipment.
[0150] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0151] Receive device identification information from power equipment in response to information acquisition instructions;
[0152] Based on the operating status of the power equipment and its identification information, a safety status assessment is conducted on the power equipment.
[0153] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0154] When the evaluation results characterize the equipment state security of the power equipment, the initial access policy will be used as the system access policy corresponding to the power equipment.
[0155] When the assessment results indicate that the equipment status of the power equipment is unsafe, the conditions for new access are determined.
[0156] Based on the new access conditions and the initial access strategy, generate the system access strategy corresponding to the power equipment.
[0157] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0158] Based on the data type of the system operation data, the system operation data is divided into Category I operation data and Category II operation data; Category I operation data has a higher access frequency than Category II operation data.
[0159] Store one type of runtime data in one type of database; and,
[0160] The two types of runtime data are stored in a two-type database; the first type of database is a relational database; and the second type of database is a time-series database.
[0161] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0162] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0163] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0164] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0165] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0166] The system operation data of the target power system during the current time period is obtained from the target switch through the target port of the target switch.
[0167] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0168] By bypassing the mirror port, the system operation data of the target power system is obtained through mirroring.
[0169] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0170] For any given power device, based on its online data and historical online data, determine the current online anomaly situation for that device during the current time period; and...
[0171] Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current period.
[0172] Based on the abnormal online conditions and / or abnormal traffic conditions, determine the operating status of the corresponding power equipment.
[0173] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0174] Receive device identification information from power equipment in response to information acquisition instructions;
[0175] Based on the operating status of the power equipment and its identification information, a safety status assessment is conducted on the power equipment.
[0176] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0177] When the evaluation results characterize the equipment state security of the power equipment, the initial access policy will be used as the system access policy corresponding to the power equipment.
[0178] When the assessment results indicate that the equipment status of the power equipment is unsafe, the conditions for new access are determined.
[0179] Based on the new access conditions and the initial access strategy, generate the system access strategy corresponding to the power equipment.
[0180] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0181] Based on the data type of the system operation data, the system operation data is divided into Category I operation data and Category II operation data; Category I operation data has a higher access frequency than Category II operation data.
[0182] Store one type of runtime data in one type of database; and,
[0183] The two types of runtime data are stored in a two-type database; the first type of database is a relational database; and the second type of database is a time-series database.
[0184] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0185] Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment;
[0186] Based on system operation data, determine the equipment operation status of different power devices in the target power system;
[0187] For any power equipment, a safety status assessment is conducted based on the equipment's operating conditions, and the corresponding system access strategy is determined based on the assessment results.
[0188] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0189] The system operation data of the target power system during the current time period is obtained from the target switch through the target port of the target switch.
[0190] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0191] By bypassing the mirror port, the system operation data of the target power system is obtained through mirroring.
[0192] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0193] For any given power device, based on its online data and historical online data, determine the current online anomaly situation for that device during the current time period; and...
[0194] Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current period.
[0195] Based on the abnormal online conditions and / or abnormal traffic conditions, determine the operating status of the corresponding power equipment.
[0196] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0197] Receive device identification information from power equipment in response to information acquisition instructions;
[0198] Based on the operating status of the power equipment and its identification information, a safety status assessment is conducted on the power equipment.
[0199] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0200] When the evaluation results characterize the equipment state security of the power equipment, the initial access policy will be used as the system access policy corresponding to the power equipment.
[0201] When the assessment results indicate that the equipment status of the power equipment is unsafe, the conditions for new access are determined.
[0202] Based on the new access conditions and the initial access strategy, generate the system access strategy corresponding to the power equipment.
[0203] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0204] Based on the data type of the system operation data, the system operation data is divided into Category I operation data and Category II operation data; Category I operation data has a higher access frequency than Category II operation data.
[0205] Store one type of runtime data in one type of database; and,
[0206] The two types of runtime data are stored in a two-type database; the first type of database is a relational database; and the second type of database is a time-series database.
[0207] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0208] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0209] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0210] The above embodiments merely illustrate several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of this application's patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for connecting equipment in a power system, characterized in that, The method includes: Obtain the system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and the preset historical time period before the current moment; Based on the system operation data, determine the equipment operation status of different power devices in the target power system; For any power device, a safety status assessment is performed on the power device based on its operating status, and a system access strategy for the power device is determined based on the assessment results.
2. The method according to claim 1, characterized in that, The step of obtaining the system operation data of the target power system in the current time period from the target switch connected to the target power system includes: The system operation data of the target power system during the current time period is obtained from the target switch through the target port of the target switch.
3. The method according to claim 2, characterized in that, The target port is a bypass mirror port; obtaining the system operation data of the target power system in the current time period from the target switch through the target port of the target switch includes: The system operation data of the target power system is obtained by mirroring through the bypass mirror port.
4. The method according to any one of claims 1-3, characterized in that, The system operation data includes at least one of equipment online data and equipment flow data corresponding to different power devices in the target power system; correspondingly, determining the equipment operation status of different power devices in the target power system based on the system operation data includes: For any given power device, based on the device's online data and its historical online data, determine the abnormal online status of the power device in the current time period; and, Based on the equipment flow data corresponding to the power equipment and the historical flow data of the power equipment, determine the abnormal flow situation of the power equipment in the current time period; Based on the online anomaly and / or the traffic anomaly, determine the equipment operation status corresponding to the power equipment.
5. The method according to any one of claims 1-3, characterized in that, The step of assessing the safety status of the power equipment based on its operational status includes: Receive the device identification information fed back by the power equipment in response to the information acquisition command; Based on the operating status of the power equipment and the equipment identification information of the power equipment, a safety status assessment is performed on the power equipment.
6. The method according to any one of claims 1-3, characterized in that, The step of determining the system access strategy corresponding to the power equipment based on the evaluation results includes: If the evaluation results indicate that the power equipment is in a safe state, the initial access policy will be used as the system access policy for the power equipment. If the assessment results indicate that the equipment status of the power equipment is unsafe, then new access conditions are determined. Based on the new access conditions and the initial access strategy, a system access strategy corresponding to the power equipment is generated.
7. The method according to any one of claims 1-3, characterized in that, After obtaining the system operation data of the target power system in the current time period from the target switch connected to the target power system, the method further includes: Based on the data type of the system operation data, the system operation data is divided into Category I operation data and Category II operation data; the access frequency of Category I operation data is higher than that of Category II operation data. The aforementioned type of runtime data is stored in a database; and, The two types of runtime data are stored in two types of databases; the first type of database is a relational database; the second type of database is a time-series database.
8. A device for connecting equipment in a power system, characterized in that, The device includes: The data acquisition module is used to acquire system operation data of the target power system in the current time period from the target switch connected to the target power system; the current time period includes the current moment and a preset historical time period before the current moment; The operation status determination module is used to determine the equipment operation status of different power devices in the target power system based on the system operation data. The security status assessment module is used to assess the security status of any power device based on its operating status, and to determine the system access strategy corresponding to the power device based on the assessment results.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-7.