Power plant access control permission dynamic management and control method under cloud-edge collaboration architecture
Patent Information
- Application Number
- CN202610061413.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-16
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-01-16
AI Technical Summary
[0005]为解决上述现有发电厂门禁静态授权模式存在的权限与业务状态不同步、突发安全状态响应滞后、与多因素风险叠加难以量化的技术问题,本发明在如下的多个方面中提供方案
[0022]本发明的有益效果在于:实现门禁权限与工作票状态、操作票进度、安全资质有效期、违章记录等生产业务状态的实时联动,工作票中止或终结、资质过期、违章记分超限等场景下可立即熔断通行权限,彻底杜绝静态授权模式下权限失效滞后导致的高危区域非法出入风险;通过动态安全信任值的分级管控逻辑,将人员风险划分为不同等级并匹配差异化通行策略,既对高风险人员执行强制阻断,又为低风险隐患人员提供伴随监护的灵活通行方案,避免一刀切管理对现场作业效率的影响,兼顾安全生产与运维便捷性;云边协同架构赋予边缘侧独立决策能力,网络中断时可基于本地缓存的权限基线与环境数据执行应急管控,网络恢复后自动同步决策记录,确保极端工况下门禁系统持续有效运行,提升管控体系的抗干扰能力与可靠性;闭环修正机制通过人员实际通行行为数据反向优化动态安全信任值,精准识别权限合规但频繁越界、逗留超时等行为异常的隐性风险,使管控策略随人员作业习惯、现场风险特征的变化持续迭代,不断提升风险识别的精准度。
Smart Images

Figure CN121904866B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information system integration service technology. More specifically, this invention relates to a method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture. Background Technology
[0002] With the deepening of the standardization of power safety production, power plants, as high-risk operating environments, have access control systems that are not only physical barriers to isolate areas, but also key means to ensure production safety. In actual operation and maintenance, personnel access rights should be closely linked to work permits, operation permits, and safety training qualifications to ensure that specific personnel can only enter specific areas during periods when they have valid work tasks and safety qualifications.
[0003] Existing access control systems in power plants typically employ a preset static authorization model. Based on work requests, administrators grant access to personnel for a fixed time window in the backend system, then distribute this static list to the access controller or store it in a central database. During actual operation, as long as the current time falls within the preset valid time period and the personnel's identity matches, the access control system grants access. This approach relies heavily on periodic manual maintenance or scheduled batch synchronization to update the access control data.
[0004] However, the aforementioned static authorization method exhibits significant lag and security control loopholes when dealing with on-site operating conditions at power plants. On the one hand, the lifecycle of permissions often fails to synchronize with the status of work tasks. For example, when a work permit for an outsourced construction team is temporarily suspended or prematurely terminated, the preset permissions in the access control system remain valid, allowing personnel without tasks to freely enter and exit high-risk areas using their old permissions. On the other hand, it lacks real-time response capabilities to sudden safety incidents. When personnel violate regulations within the plant or their safety qualifications expire during operations, traditional static access control logic cannot immediately detect and suspend their access. This disconnect between permission control and actual business conditions prevents the access control system from fulfilling its intended real-time blocking function. Summary of the Invention
[0005] To address the technical problems of asynchronous permissions and business status, delayed response to sudden security situations, and difficulty in quantifying multiple overlapping risks in the existing static authorization mode for power plant access control, this invention provides solutions in the following aspects.
[0006] In a first aspect, the present invention provides a method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture, comprising: constructing a cloud-based business data aggregation center to acquire basic information of power plant personnel and production business status data in real time; generating an initial dynamic permission baseline based on the basic information and production business status data; the basic information includes personnel identity information, job information, and safety qualification information; the production business status data includes work order status, operation order execution progress, qualification validity period, and violation points; and the initial dynamic permission baseline is structured data containing a unique personnel identifier ID, a set of allowed access areas, a basic access time period, and a business-bound tag; constructing a cloud-based business data aggregation center to acquire basic information of power plant personnel and production business status data in real time; and generating an initial dynamic permission baseline based on the basic information of power plant personnel and production business status data in real time. The dynamic monitoring engine monitors the production business status data in real time. When any data changes, a dynamic weighted evaluation algorithm is triggered. This algorithm calculates a dynamic security trust value by combining the work order status mapping function, operation ticket progress contribution coefficient, violation score upper limit threshold, risk sensitivity coefficient, and time step function. Then, it generates hierarchical dynamic control instructions based on preset warning thresholds. The edge-side access control node receives the dynamic control instructions, combines real-time environmental parameters and personnel identification requests, calculates the final access judgment coefficient, and drives the access control execution mechanism to act. A personnel behavior trajectory analysis model is constructed, and a spatiotemporal consistency deviation index is calculated. This index is used as a penalty factor to correct the dynamic security trust value, forming a closed-loop control system.
[0007] This method addresses the issues of scattered data sources and asynchronous updates in traditional permission systems by constructing a cloud-based business data aggregation center to integrate heterogeneous data from multiple systems and establish a unique and authentic data source for permission generation. The cloud-based business status monitoring engine triggers a dynamic weighted evaluation algorithm in an event-driven mode, quantifying discrete business states into continuous dynamic security trust values. This overcomes the limitations of traditional binary Boolean judgments, enabling precise quantification of gray-scale risks and multi-factor risks. Edge-side access control nodes employ a fusion decision-making mechanism that prioritizes cloud policies while rejecting local environment decisions. This allows for simultaneous execution of cloud commands and response to sudden physical risks on-site, mitigating the compatibility contradiction between remote control and on-site conditions under a cloud architecture. Personnel behavior trajectory analysis and a reverse correction mechanism for trust values enable the self-evolution and self-calibration of control strategies.
[0008] Preferably, the basic information includes personnel identity information, job information, and safety qualification information, and the production business status data includes work order status, operation order execution progress, qualification validity period, and violation points.
[0009] Preferably, the method for obtaining the work order status mapping function includes: setting the work order status mapping function. When the work ticket status When the work order status mapping function is in effect The value is 1, when the work order status is... Work order status mapping function for pause or termination The value is 0.
[0010] Preferably, the method for obtaining the operation ticket progress contribution coefficient includes: operation ticket progress contribution coefficient Progress of Operation Ticket Execution It exhibits a 1:1 linear mapping relationship, that is ; The calculation method is: the ratio of the number of completed standardized operation steps to the total number of standardized operation steps. A standardized operation step is the smallest indivisible operation unit confirmed by the safety supervision department. When the operation ticket progress is suspended... and If it remains unchanged, the operation ticket progress will terminate. and Forced zeroing; if the operation ticket contains parallel operation steps, the calculation is based on the ratio of the actual number of completed parallel operation steps to the total number of parallel operation steps. If the operation ticket is returned for rectification due to execution errors, the number corresponding to the erroneous steps must be deducted and the calculation is recalculated.
[0011] This method simplifies coefficient calculation logic through a 1:1 linear mapping relationship, achieving accurate correspondence between progress and contribution without complex algorithms. This reduces system computational overhead and maintenance difficulty, ensuring efficient and real-time access control. Using standardized operating procedures approved by safety supervision departments as the calculation benchmark, it establishes a unified and authoritative basis for progress statistics, avoiding coefficient deviations caused by ambiguous definitions of operating units and ensuring consistency in access control across multiple scenarios. Differentiated processing rules are established for different operation ticket states such as pause and termination. Forced zeroing of coefficients upon termination quickly severes corresponding access permissions, eliminating security risks caused by invalid operation tickets. Maintaining stable coefficients during pause ensures operational continuity. It adapts to the special calculation methods of parallel operation steps, accurately quantifying actual progress in complex operational scenarios and avoiding statistical distortion of parallel tasks affecting access control adaptation. The mechanism of deducting the corresponding step for recalculation upon error rollback can conversely constrain operational standardization, reducing safety hazards caused by misoperation, while ensuring that coefficients accurately reflect operational quality. This makes the calculation of dynamic safety trust values more aligned with actual operational risks, further improving the accuracy and security of access control and meeting the standardization requirements of power safety production.
[0012] Preferably, calculating the dynamic security trust value of the current personnel includes: In the formula, It represents the current dynamic security trust value of personnel. It is the work order status mapping function; It is the contribution coefficient of the operation ticket progress; and These are the weights of the work order status mapping function and the operation order progress contribution coefficient, respectively, and satisfy the following conditions: ; This is the current penalty point value for violations by the personnel. It is the upper limit threshold for traffic violation points; Risk sensitivity coefficient; This refers to the current validity period of the personnel's qualifications; It is the current time; Let it be a time step function, when the qualification validity period Greater than the current time hour, The value is 1 if it is not 1, otherwise the value is 0.
[0013] This method employs a multi-dimensional parameter fusion mathematical modeling approach to construct a scientifically rigorous dynamic security trust value calculation logic, achieving precise quantification of personnel access compliance: using work ticket status and operation ticket progress as core foundational dimensions, and through weighting... and The system flexibly adjusts the weighting of the two factors on the trust value, allowing for differentiated configuration based on the risk focus of different work scenarios to adapt to diverse control needs. It employs an exponential decay model to quantify the impact of violations, adjusting the penalty intensity through a risk sensitivity coefficient. The closer the violation score is to the upper threshold, the more significant the trust value decay, highlighting the warning effect of high-risk violations while reasonably differentiating the impact of varying violation levels. A time step function is used to achieve rigid constraints on safety qualifications; when qualifications expire, the trust value is directly reduced to zero, blocking unqualified personnel from accessing the system at the source and safeguarding the safety bottom line. All parameters are dimensionless and their values converge uniformly to [0,1], ensuring the consistency and comparability of calculation results. This provides precise data support for the generation of hierarchical control instructions, effectively addressing the technical shortcomings of traditional binary judgments that cannot quantify gray-scale risks and are difficult to assess risks arising from multiple factors. This ensures that access control is highly matched with the actual on-site safety risk level, further enhancing the scientific nature and reliability of the control system.
[0014] Preferably, the hierarchical dynamic control instructions include: when the dynamic security trust value is equal to 0, a control instruction of type forced blocking is generated; when the dynamic security trust value is greater than 0 and less than a preset warning threshold, a control instruction of type accompanying monitoring is generated; when the dynamic security trust value is greater than or equal to the preset warning threshold, a control instruction of type maintaining access is generated; wherein, the preset warning threshold ranges from [missing value]. It can be set differently according to the risk level of different areas of the power plant.
[0015] Preferably, the calculation of the final passage determination coefficient includes: In the formula, It is the final passage determination coefficient for the current personnel; It is a cloud command mapping value; This is the moment when the person initiates the card swipe request; This refers to the basic travel period; It is a time window determination function; It is the first The status value corresponding to the risk type; It is an index for risk types; It is the total number of risk types; It is the first The weighting coefficients corresponding to the risk type, and satisfying the common... The sum of all weight coefficients corresponding to each risk type equals 1.
[0016] This method constructs a final access determination model through logical operations involving the superposition of multi-dimensional constraints, achieving precise adaptation between cloud-based strategies and on-site conditions: It uses cloud-based instruction mapping values to meet hierarchical control requirements, ensuring the effective implementation of cloud-based decisions at the edge and maintaining consistency in control logic; it strengthens compliance verification during access periods through a time window determination function, preventing unauthorized access attempts; and it integrates multiple environmental risk factors in a product form, combined with weighting coefficients. The impact weights of different risk types can be flexibly allocated, and the configuration can be differentiated according to the regional environmental risk characteristics to highlight the control priority of core risks; environmental risk items The design enables a single risk alarm to significantly reduce the judgment coefficient, forming a rapid response to sudden physical risks on site, achieving dual protection of business compliance and environmental safety, further improving the reliability of access control, and meeting the safety control needs of power plants in high-risk environments.
[0017] Preferably, the dynamic control method for power plant access control under the cloud-edge collaborative architecture includes: when the final access determination coefficient... At that time, the edge-side access control node initiates the accompanying verification mode, opens a preset monitoring and verification time window, and after detecting the identity of a valid monitoring personnel, it will... The setting is corrected to 1 and access control is enabled. If the attempt to violate the rules is not detected within the time limit, it is recorded. The edge side has a built-in local data caching module. When the cloud-edge network is interrupted, emergency decisions are made based on the cached data. After the network is restored, the local decision records are synchronized.
[0018] Preferably, the calculation of the spatiotemporal consistency deviation index includes: In the formula, It is a spatiotemporal consistency deviation index; This indicates the cumulative number of times a person crosses the boundary outside the set of permitted access areas during the operation. This refers to the actual duration of time that personnel spend within the permitted access area. The standard duration estimated for the work plan; and These are the weight coefficients for the spatial and temporal out-of-bounds dimensions, respectively, and they satisfy the following conditions: and .
[0019] This method constructs a scientifically quantifiable behavioral deviation assessment system through a linear weighted model that integrates spatiotemporal dimensions, providing a precise basis for trust value correction: based on the number and rate of spatial boundary violations. As the core evaluation indicator, it comprehensively covers the spatial compliance and temporal rationality of personnel operations, effectively identifying abnormal behaviors such as boundary crossing and time exceeding limits. The constraint of the weighting coefficient highlights the safety control priority of spatial boundary crossing risk over time deviation. Time deviation is quantified in the form of a ratio to eliminate the impact of different work plan durations on deviation assessment, ensuring the comparability of deviation indices in different scenarios. By quantifying spatiotemporal consistency deviation, implicit behavioral anomalies are transformed into calculable index indicators, providing objective data support for the reverse correction of dynamic safety trust values, making closed-loop management more targeted, further improving the level of precision in access control, and preventing potential security risks of compliant but abnormal behavior.
[0020] Preferably, the step of correcting the dynamic security trust value to form a closed-loop control includes: In the formula, This is the revised dynamic security trust value; This is the feedback adjustment coefficient, and its value range is... If the corrected dynamic security trust value Below the preset warning threshold If so, the individual's subsequent access permissions will be tightened, and the abnormal behavior data will be synchronized to the safety supervision system and included in the individual's safety credit file.
[0021] This method uses the spatiotemporal consistency deviation index as the core penalty criterion and flexibly adjusts the impact of abnormal behavior on trust values through feedback adjustment coefficients. It can be configured differently according to the risk levels of different regions, avoiding excessive impact of minor deviations on permissions while effectively constraining serious abnormal behaviors. It clearly defines the tightening of permissions when the corrected trust value falls below a preset warning threshold, realizing a linkage response of abnormal behavior, decreased trust value, and tightened permissions, curbing the risk of continuous violations from the source. The design of synchronizing abnormal behavior data to the safety supervision system and incorporating it into personnel safety credit files constructs a long-term safety constraint mechanism, which not only provides a reference for subsequent work approval and qualification review, but also guides personnel to standardize their work behavior, further strengthening the binding and guiding nature of the control system, and meeting the long-term requirements of power safety production standardization.
[0022] The beneficial effects of this invention are as follows: It enables real-time linkage between access control permissions and production / business statuses such as work permit status, operation permit progress, safety qualification validity period, and violation records. In scenarios such as work permit suspension or termination, qualification expiration, or violation points exceeding limits, access permissions can be immediately suspended, completely eliminating the risk of unauthorized entry into high-risk areas due to delayed permission expiration under static authorization mode. Through a dynamic security trust value-based hierarchical control logic, personnel risk is divided into different levels and matched with differentiated access strategies. This not only enforces mandatory blocking for high-risk personnel but also provides flexible access solutions with accompanying monitoring for low-risk personnel, avoiding a one-size-fits-all approach that negatively impacts on-site operational efficiency. The cloud-edge collaborative architecture, while considering both safe production and convenient operation and maintenance, empowers the edge side with independent decision-making capabilities. In the event of network interruption, emergency control can be performed based on locally cached permission baselines and environmental data. After network recovery, decision records are automatically synchronized to ensure the continuous and effective operation of the access control system under extreme conditions, thereby improving the anti-interference capability and reliability of the control system. The closed-loop correction mechanism optimizes the dynamic security trust value in reverse through actual personnel access behavior data, accurately identifying hidden risks such as frequent boundary violations and overstaying despite compliant permissions. This allows the control strategy to continuously iterate with changes in personnel work habits and on-site risk characteristics, thereby continuously improving the accuracy of risk identification. Attached Figure Description
[0023] Figure 1 This is a flowchart illustrating the dynamic control method for access control of power plants under the cloud-edge collaborative architecture of the present invention; Figure 2 This is a schematic diagram illustrating the trust value correction effect of the dynamic control method for access control of power plants under the cloud-edge collaborative architecture in this invention. Figure 3 This diagram schematically illustrates the advantages of the dynamic control method for power plant access control under the cloud-edge collaborative architecture of this invention. Detailed Implementation
[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0025] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0026] This invention discloses a method for dynamic management of access control permissions in power plants under a cloud-edge collaborative architecture, referring to... Figure 1 This includes steps S1-S4: S1. Construct a cloud-based business data aggregation center to obtain basic information of power plant personnel and production business status data in real time. Generate an initial dynamic permission baseline based on the production business status data and synchronously distribute the initial dynamic permission baseline to the edge-side access control node.
[0027] It should be noted that the cloud-based business data aggregation center achieves interconnection with the power plant's internal human resources system, ticket management system, and safety supervision system through standardized interfaces. It conducts consistency verification and correlation integration on the multi-source heterogeneous data output by each system, thereby establishing a unique and authentic data source for permission generation and solving the technical defects of traditional access control systems where permission data sources are scattered and updates are not synchronized.
[0028] Based on this, this step abandons the traditional access control system's single mode of simply importing static personnel lists, and deeply binds the permission generation logic with the real-time status of production business, so that every permission data issued to the edge side has business compliance from the initial moment, laying the data foundation for subsequent dynamic adjustment of permissions.
[0029] Specifically, the basic information of power plant personnel includes personnel identity information, job information, and safety qualification information; the production and operational status data of power plant personnel includes work permit status. Operation ticket execution progress Qualification validity period And the points deducted for violations within the factory. Among them, work order status The status includes three states: active, suspended, and terminated. Based on the basic information of the power plant personnel and the production and operation status data mentioned above, an initial dynamic permission baseline is generated. The initial dynamic permission baseline is a set of structured data, which specifically includes the personnel's unique identifier ID and the set of allowed access areas. Basic travel periods and business binding tags The unique personnel ID corresponds one-to-one with the personnel identity information in the human resources system, and the set of permitted access areas... The basic passage period is precisely matched with the work area specified in the work order and operation ticket. The business binding tag is completely consistent with the effective execution period of the ticket. It is used to indicate whether the permission is subject to strong constraints of a specific business process, and is divided into three levels: high risk, medium risk, and low risk based on the risk level of the work area.
[0030] Furthermore, in the process of synchronously distributing the initial dynamic permission baseline to the edge-side access control nodes, a transmission strategy combining incremental synchronization and full calibration is adopted, targeting the business-bound tags. For permission data marked as high-risk, a dedicated status subscription mechanism is established in the cloud business data aggregation center. When the production business status data corresponding to this type of permission changes, the cloud can automatically trigger an active push process for permission adjustment instructions, thereby ensuring the timeliness of permission control in high-risk areas. For medium-risk and low-risk permission data, an incremental synchronization method is used to perform update operations when the data changes, and full calibration is carried out according to a preset cycle to ensure that the permission data stored in the edge access control node is completely consistent with the cloud.
[0031] S2. Build a cloud-based business status monitoring engine to monitor production business status data in real time. Use a dynamic weighted evaluation algorithm to comprehensively calculate the work order status, operation order execution progress, qualification validity period and violation points to obtain the dynamic security trust value of the current personnel, and then generate corresponding dynamic control instructions for the current personnel.
[0032] It should be noted that the cloud-based business status monitoring engine adopts an event-driven architecture. Based on the production business status data integrated by the cloud-based business data aggregation center in step S1, it continuously monitors the data. When any of the data such as work ticket status, operation ticket execution progress, qualification validity period, or violation score changes, the recalculation process of the dynamic weighted evaluation algorithm is immediately triggered. This step abandons the traditional access control permission determination that only uses the binary Boolean judgment logic, i.e., compliance or non-compliance. It uses mathematical modeling to quantify the discrete multi-source business status data into a continuous dynamic security trust value indicator. This solves the technical defects of the traditional control mode in that it cannot handle gray-scale risks under complex working conditions and is difficult to quantify the superposition effect of multiple risk factors, thus realizing refined hierarchical control of personnel access permissions.
[0033] Based on this, this step solves the problems of inconsistent weights of multi-source business data and difficulty in quantifying the superposition of risks through mathematical modeling. It can not only identify the failure of a single business condition, but also keenly perceive the potential security changes that may be caused by the superposition of multiple low-risk factors, ensuring that the access control strategy is strictly matched with the actual risk level on site.
[0034] Specifically, set the work ticket status mapping function. It is directly related to the three states of the work order defined in step S1: effective, suspended, and terminated. When the work order status... When the work order status mapping function is in effect The value is 1, when the work order status is... Work order status mapping function for pause or termination Set the value to 0; set the operation ticket progress contribution coefficient. A dimensionless linear coefficient used to characterize the matching degree between the actual execution progress of the operation ticket and the access permission, with its value range strictly limited to 1. Its core logic is: the execution progress of the operation ticket. The higher the level, the greater the personnel's familiarity with the work area environment and safety regulations, the lower the on-site operational risk, and the higher the corresponding access permission adaptability. Therefore, the operation ticket progress contribution coefficient increases. As the operation ticket is executed The increase shows a strictly monotonically increasing linear relationship.
[0035] Furthermore, the progress of the operation ticket execution. The progress contribution coefficient is quantified based on the total number of standardized operating steps specified in the operation ticket. The calculation method is the ratio of the number of completed standardized operating steps to the total number of standardized operating steps specified in the operation ticket. A standardized operating step refers to the smallest indivisible operating unit verified and confirmed by the power plant's safety supervision department, excluding non-core operating procedures such as preparation and final acceptance. Progress of Operation Ticket Execution It exhibits a 1:1 linear mapping relationship, that is The specific scenario for this value is: when the operation ticket has not been initiated and the number of completed steps is 0. correspond When the operation ticket is being executed, and the number of completed steps is greater than 0 but less than the total number of steps, correspond When all operation tickets are completed, that is, when the number of completed steps equals the total number of steps, correspond .
[0036] Specifically, for special execution scenarios of operation tickets, if an operation ticket is suspended for special reasons, the number of completed steps will no longer increase, and the operation ticket progress contribution coefficient will remain unchanged. and the progress of operation ticket execution All values remain unchanged from when the operation was paused. If the operation ticket is terminated, the progress contribution coefficient of the operation ticket will be adjusted. and the progress of operation ticket execution Forced zeroing; when the operation ticket progress is paused, and If it remains unchanged, the operation ticket progress will terminate. and Forced zeroing; if the operation ticket has parallel operation steps, the calculation is based on the ratio of the number of parallel operation steps actually completed to the total number of parallel operation steps. If the operation ticket is returned for rectification due to execution errors, the number corresponding to the erroneous steps must be deducted and the calculation is recalculated to ensure that the coefficient can reflect the real compliance execution status of the operation ticket in real time.
[0037] Specifically, based on the power plant safety management regulations, the upper limit threshold for violation points is obtained and recorded as follows: Dimensionless; based on the work order state mapping function Contribution coefficient of operation ticket progress And the current penalty points for violations by personnel. Qualification validity period and current time The dynamic security trust value of the current personnel is calculated using the following formula: ; In the formula, It is the current dynamic security trust value of personnel, and its value range is... The value directly represents the compliance level of the access permissions currently held by the personnel. The closer the value is to 1, the higher the compliance level, and the closer it is to 0, the lower the compliance level. It is the work order status mapping function; It is the contribution coefficient of the operation ticket progress; and These are the weights of the work order status mapping function and the operation order progress contribution coefficient, respectively, and satisfy the following conditions: Exemplary ; This is the current penalty point value for violations by the personnel. It is the upper limit threshold for traffic violation points; This is the risk sensitivity coefficient, a dimensionless positive number, used to adjust the exponential penalty for violations on the dynamic security trust value. The higher the value, the more significant the attenuation effect of the violation on the trust value; This refers to the current validity period of the personnel's qualifications; It is the current time; Let it be a time step function, when the qualification validity period Greater than the current time hour, The value is 1 if it is not 1, otherwise the value is 0.
[0038] It should be noted that the construction logic of this relation is guided by the core business constraints of power plant access control, using work order status and operation order execution progress as the basic dimensions for determining dynamic security trust values. This is compounded by the exponential risk penalties of violation records, and the mandatory constraint of the validity period of safety qualifications ensures bottom-line control of trust values, guaranteeing that the calculation results strictly match the actual on-site safety risk level. In the relation... The range of values is It belongs to the dimensionless coefficient. and It is also a dimensionless coefficient, meaning that multiplying the individual parameters does not introduce any additional dimensions, and the final calculated dynamic security trust value is obtained. It is a dimensionless evaluation index to ensure the rigor and rationality of the formula at the mathematical logic level.
[0039] Furthermore, the cloud-based business status monitoring engine uses dynamically calculated security trust values... Combined with preset warning thresholds Generate hierarchical control instructions (CMD), the specific operations of which include: when the dynamic security trust value... When the value equals 0, it indicates that the personnel have committed at least one serious violation, such as an invalid work permit, expired qualifications, or excessive violation points. In this case, a mandatory blocking control command is generated, requiring the edge-side access control node to immediately revoke all access permissions for the personnel. When the dynamic security trust value... Greater than 0 and less than the preset warning threshold When this indicates that a person poses a minor risk but does not meet the criteria for serious violation, a control instruction of type "accompanied supervision" is generated, restricting the person to entering authorized areas only when accompanied by a designated guardian; when the dynamic security trust value... Greater than or equal to the preset warning threshold When this condition is met, it indicates that the personnel's current business status and security qualifications fully comply with the control requirements. At this time, a control instruction of type "maintain permissions" is generated to preserve the personnel's normal access permissions. A preset warning threshold is also included. The range of values is For example, a preset warning threshold The risk levels of different areas of the power plant can be differentiated, and this tiered mechanism avoids rigid, one-size-fits-all management and improves the flexibility and safety of on-site operations.
[0040] S3: The edge-side access control node receives dynamic control instructions from the cloud, combines real-time environmental parameters and personnel identification requests, calculates the final access judgment coefficient for the current personnel, and drives the access control actuator accordingly.
[0041] It should be noted that the edge-side access control node is not a passive terminal that merely executes cloud commands, but an intelligent management and control unit with local data acquisition, logical operation, and independent decision-making capabilities. Its core function is to handle in real time the uncertainty of command execution caused by sudden situations in the physical environment and network transmission delays, based on the execution of the access control policies issued by the cloud. It aims to solve the contradiction between the adaptability of remote cloud commands and real-time on-site conditions, and make up for the technical shortcomings of traditional cloud architecture access control that relies solely on cloud decision-making and cannot respond to instantaneous risks on-site.
[0042] Based on this, this step adopts a fusion decision-making mechanism that is cloud-driven and local environment-rejected. The core logic of this mechanism is as follows: the edge access control node uses the dynamic control command (CMD) issued by the cloud as the core basis for permission determination, while superimposing security verification of the on-site environment; even if the cloud issues a permission instruction, if the edge side detects any physical safety risk in the work area through sensors in real time, such as fire alarm, toxic gas leak, abnormal equipment shutdown, or excessive personnel density, it can still automatically trigger the permission circuit breaker mechanism to cut off personnel access. This ensures the consistency between the permission control strategy and the cloud business status, and can also cope with sudden physical risks on-site, achieving dual verification of business compliance and environmental security, forming a dual security guarantee system for access control.
[0043] Specifically, set the cloud command mapping value. These correspond strictly to the three types of control instructions generated in step S2. When the instruction is a normal passage instruction that maintains permissions, When the instruction is a restricted access instruction accompanied by monitoring, When the instruction is a mandatory blocking instruction that prohibits passage, Record the moment when the current person initiates the card swipe request as... Combined with basic travel periods Construct a time window decision function When the current person initiates a card swipe request During the basic traffic period Within the time range, the time window determination function The value is 1, and the value is 0 otherwise, in order to realize the time period compliance verification of the passage request; It is an index for risk types; It is the total number of risk types; It is the first The state value corresponding to the risk type, such as fire, toxic gas, and personnel density, is determined according to the following rule: when the environment is in a safe state, The value is 0, which is set when the environment triggers a risk alarm. The value is 1.
[0044] Furthermore, based on cloud command mapping values Time window determination function Total number of risk types and on-site environmental monitoring and the Risk type corresponding status value The final passage determination coefficient for the current personnel is obtained using the following formula: ; In the formula, It is the final passage determination coefficient for the current personnel; It is a cloud command mapping value; This is the moment when the person initiates the card swipe request; This refers to the basic travel period; It is a time window determination function; It is the first The status value corresponding to the risk type; It is an index for risk types; It is the total number of risk types; It is the first The weighting coefficients corresponding to different risk types range from [value range missing]. It can be configured differently according to the environmental risk level of different areas of the power plant; the higher the risk level, the corresponding... The larger the value, and the more common the condition. The sum of all weight coefficients corresponding to each risk type equals 1; the physical meaning of this relationship is that the access control opening signal is the logical and computational result of cloud authorization, time period compliance, and no risk in the on-site environment. The negation of any one of them will cause the coefficient to return to zero, thus refusing passage.
[0045] Furthermore, when the final passage determination coefficient of the current personnel is calculated... When this occurs, it indicates that the personnel need to perform a restricted access procedure with accompanying supervision. At this time, the edge-side access control node automatically starts the accompanying verification mode: First, it pushes a supervision verification prompt message to the personnel who initiated the access request, and at the same time opens a preset supervision verification time window. The duration of this time window can be flexibly configured according to the power plant safety management specifications. If the edge-side access control node detects a valid identity of a person with the corresponding supervision qualifications within the time window, it will correct the final access judgment coefficient to 1 and drive the access control execution mechanism to open. If no valid supervision identity is detected after the time window, it is judged as an attempted violation of access. The access control execution mechanism remains locked, and at the same time, the time, personnel identity, and reason for failure of the attempted access request are uploaded to the cloud business data aggregation center and included in the personnel violation record system to provide data support for the subsequent calculation of dynamic security trust value. Here, 0.5 is an example value.
[0046] It should be noted that the edge access control node has a built-in local data caching module. When the cloud-edge network is interrupted, it can make emergency decisions based on the cached initial dynamic permission baseline and recent environmental monitoring data. Once the network is restored, the local decision records will be synchronized to the cloud immediately to ensure the consistency of cloud-edge data and the continuity of management and control strategies.
[0047] S4. Collect access control logs and on-site captured images generated at the edge and upload them to the cloud to build a personnel behavior trajectory analysis model, calculate the spatiotemporal consistency deviation index, and use this to correct the dynamic security trust value of personnel, thus forming a closed-loop management system.
[0048] It should be noted that traditional access control systems only issue and execute permissions, lacking the ability to conduct post-event behavior audits and iteratively optimize strategies. They cannot identify hidden security risks where permissions are compliant but behavior is abnormal. For example, personnel may have valid permissions to enter authorized areas but linger in non-work areas for extended periods or frequently move between areas. Such behavior can easily lead to unexpected security incidents in high-risk environments. This step collects all behavioral data from the edge and feeds it back to the cloud for in-depth analysis. It compares actual personnel access behavior with preset work requirements, aiming to achieve behavior traceability and risk identification throughout the entire work process. At the same time, it uses behavioral data to correct dynamic security trust values, constructing a closed-loop control system that includes permission issuance, execution monitoring, behavior analysis, trust value calibration, and permission optimization, thus solving the technical deficiencies of traditional control models.
[0049] Based on this, this step maps the actual access behavior data of personnel in the physical world to the trust assessment model in the digital world. This makes the dynamic security trust value of personnel not only depend on static qualifications and ticket status, but also subject to the dynamic constraints of historical access behavior compliance. This enables the self-evolution and self-calibration of the dynamic security trust value, ensuring that the access control strategy can be continuously optimized as personnel behavior changes, and further improving the accuracy and adaptability of the control system.
[0050] Specifically, the edge-side access control node collects two types of core data in real time: the first type is access control logs, which are structured data containing key information such as unique personnel IDs, access timestamps, access control points, corresponding access command types, and final access judgment results; the second type is on-site captured images, which are linked to the access control logs through timestamps to verify the authenticity of personnel access behavior. Both types of data are uploaded to the cloud business data aggregation center using a transmission strategy combining incremental upload and breakpoint resume. When the cloud-edge network is interrupted, the data is temporarily stored in the local cache module on the edge side and automatically re-uploaded after the network is restored, ensuring data integrity and continuity. When the edge side continuously collects access control logs and on-site captured images for a preset analysis period (for example, one week), the cloud constructs a personnel behavior trajectory analysis model based on the above data. This model uses the set of allowed access areas generated in step S1, the basic access time period, and the standard dwell time estimated by the work plan. Based on this, the spatiotemporal characteristics of the actual travel trajectories of personnel are extracted, and the spatiotemporal consistency deviation index is calculated. The relationship is as follows: ; In the formula, It is the spatiotemporal consistency deviation index, with a value range of... The closer the value is to 1, the greater the deviation between the actual behavior of the personnel and the preset requirements, and the lower the compliance of the behavior. This represents the cumulative number of times a person crosses the boundary outside the set of permitted access areas during the operation. It is a dimensionless non-negative integer, and its value is linked to the severity of the boundary crossing behavior. A single brief boundary crossing is counted as 1 time, and a long stay in an unauthorized area is counted as 2 times. The actual duration of time that people stay within the permitted access area. Both are standard durations estimated for the work plan, measured in minutes, and the difference between them is a ratio. It is a dimensionless coefficient used to reflect the degree of deviation in the duration of personnel stay; and These are the weight coefficients for the spatial and temporal out-of-bounds dimensions, respectively, and they satisfy the following conditions: and This setting is based on the power plant safety management principle that the risk of spatial boundary crossing is higher than the risk of time deviation, and can be flexibly adjusted according to the risk level of different operating scenarios; when the number of times personnel cross the boundary or the ratio is high... The larger the value, the higher its spatiotemporal consistency deviation index, and vice versa.
[0051] Furthermore, the cloud-based system uses the calculated spatiotemporal consistency deviation index as a penalty factor to introduce into the dynamic security trust value assessment system of step S2, and updates the personnel's current dynamic security trust value using the following correction formula: ; In the formula, This is the corrected dynamic security trust value, with a lower limit of 0, to ensure that the corrected dynamic security trust value is non-negative. This is the feedback adjustment coefficient, and its value range is... This is used to adjust the penalty applied to the dynamic security trust value by the spatiotemporal consistency deviation index. The larger the value, the more significant the impact of behavioral deviations on the trust score.
[0052] If the corrected dynamic security trust value Below the preset warning threshold The cloud-based business status monitoring engine will automatically trigger the control policy adjustment process, tightening the personnel's access permissions the next time permissions are generated, such as shortening the access period, narrowing the authorized area, or forcibly enabling the accompanying monitoring mode; at the same time, abnormal behavior data collected on the edge side will be synchronized to the power plant safety monitoring system and included in the personnel safety credit file, providing a basis for decision-making for subsequent work application approvals.
[0053] Based on the above steps, the dynamic control results of access permissions for power plants under the cloud-edge collaborative architecture can be obtained, leading to a trust value correction effect diagram and an advantage diagram of the dynamic control method. Figure 2 It is a dynamic control effect diagram. Figure 3 This is a diagram illustrating the advantages of dynamic management and control methods.
[0054] in, Figure 2 By comparing the dynamic safety trust values of 15 workers before and after correction, and overlaying a reference line with a preset warning threshold, the differences in trust value changes among different personnel are visually presented. This reflects the reverse adjustment effect of the spatiotemporal deviation of personnel's actual passage behavior on their dynamic safety trust values. Some personnel's corrected trust values are lower than the warning threshold due to abnormal behavior, such as exceeding boundaries or deviations in duration, clearly showing a corresponding correlation between behavioral deviation and trust value decline. This proves that the mechanism of correcting dynamic safety trust values through the spatiotemporal consistency deviation index is effective, accurately linking actual personnel behavior with permission assessment results, achieving closed-loop control of behavior monitoring, trust value optimization, and permission adjustment, and verifying the method's ability to identify and constrain hidden behavioral risks.
[0055] in, Figure 3 By presenting the trends of dynamic safety trust values of 15 individuals before and after correction, and simultaneously labeling the specific trust values of each individual, and overlaying a preset warning threshold reference line, this invention reflects the precise adjustment effect of the spatiotemporal deviation of actual work behavior on the dynamic safety trust value. Specifically, before correction, the trust values of some individuals were at a high level, but after correction, they decreased accordingly based on the degree of behavioral abnormality. The corrected trust values of some individuals were below the warning threshold, clearly showing the corresponding relationship between the degree of behavioral deviation and the decrease in trust value. This demonstrates that, compared with existing static authorization methods, the method of this invention can dynamically iterate the trust value evaluation results based on the actual passage behavior of individuals, rather than maintaining fixed static permissions. It can effectively identify hidden risks of compliant permissions but abnormal behavior, achieving dynamic and precise permission control, and solving the core defects of existing methods that cannot be linked to actual behavior and have lagging risk control.
[0056] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture, characterized in that, include: A cloud-based business data aggregation center is constructed to obtain basic information of power plant personnel and production business status data in real time. Based on the basic information and production business status data, an initial dynamic permission baseline is generated. The initial dynamic permission baseline is structured data that includes a unique personnel ID, a set of allowed access areas, a basic access time period, and a business-bound tag. Business binding tags are used to indicate whether the permission is strongly constrained by a specific business process, and are divided into three levels: high risk, medium risk, and low risk based on the risk level of the work area. A cloud-based business status monitoring engine is built to monitor the production business status data in real time. When any data changes, a dynamic weighted evaluation algorithm is triggered. The algorithm combines the work ticket status mapping function, operation ticket progress contribution coefficient, violation score upper limit threshold, risk sensitivity coefficient and time step function to calculate the dynamic safety trust value of the current personnel. Then, a hierarchical dynamic control instruction is generated based on the preset warning threshold. The edge-side access control node receives the dynamic control instructions, combines real-time environmental parameters and personnel identification requests, calculates the final access judgment coefficient, and drives the access control execution mechanism to act. It continuously collects access control logs and on-site captured images at the edge side. When the preset analysis period is reached, it constructs a personnel behavior trajectory analysis model and calculates the spatiotemporal consistency deviation index, which is used as a penalty factor to correct the dynamic security trust value, thus forming a closed-loop control.
2. The method for dynamic control of access permissions for power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The basic information includes personnel identity information, job information, and safety qualification information. The production business status data includes work order status, operation order execution progress, qualification validity period, and violation points.
3. The method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The method for obtaining the work order status mapping function includes: setting the work order status mapping function. When the work ticket status When the work order status mapping function is active, The value is 1, when the work order status is... Work order status mapping function for pause or termination The value is 0.
4. The method for dynamic control of access permissions for power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The method for obtaining the progress contribution coefficient of the operation ticket includes: Operation ticket progress contribution coefficient Progress of Operation Ticket Execution It exhibits a 1:1 linear mapping relationship, that is ; The calculation method is: the ratio of the number of completed standardized operation steps to the total number of standardized operation steps. A standardized operation step is the smallest indivisible operation unit confirmed by the safety supervision department. When the operation ticket progress is suspended... and If it remains unchanged, the operation ticket will terminate when the process ends. and Forced zeroing; if the operation ticket contains parallel operation steps, the calculation is based on the ratio of the actual number of completed parallel operation steps to the total number of parallel operation steps. If the operation ticket is returned for rectification due to execution errors, the number corresponding to the erroneous steps must be deducted and the calculation is recalculated.
5. The method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The calculation of the current person's dynamic security trust value includes: ; In the formula, It represents the current dynamic security trust value of personnel. It is the work order status mapping function; It is the contribution coefficient of the operation ticket progress; and These are the weights of the work order status mapping function and the operation order progress contribution coefficient, respectively, and satisfy the following conditions: ; This is the current penalty point value for violations by the personnel. It is the upper limit threshold for traffic violation points; Risk sensitivity coefficient; This refers to the current validity period of the personnel's qualifications; It is the current time; Let it be a time step function, when the qualification validity period Greater than the current time hour, The value is 1 if it is not 1, otherwise the value is 0.
6. The method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The hierarchical dynamic control instructions include: When the dynamic security trust value is 0, a control command of type forced blocking is generated; when the dynamic security trust value is greater than 0 but less than the preset warning threshold, a control command of type accompanying monitoring is generated; when the dynamic security trust value is greater than or equal to the preset warning threshold, a control command of type maintaining access is generated; the preset warning threshold ranges from [value missing]. It can be set differently according to the risk level of different areas of the power plant.
7. The method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The calculation of the final passage determination coefficient includes: ; In the formula, It is the final passage determination coefficient for the current personnel; It is a cloud command mapping value; This is the moment when the person initiates the card swipe request; This refers to the basic travel period; It is a time window determination function; It is the first The status value corresponding to the risk type; It is an index of risk types; It is the total number of risk types; It is the first The weighting coefficients corresponding to the risk type, and satisfying the common... The sum of all weight coefficients corresponding to each risk type equals 1.
8. The method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture as described in claim 1, characterized in that, The method for dynamic management of access control permissions for power plants under the cloud-edge collaborative architecture includes: When the final passage determination coefficient At that time, the edge-side access control node initiates the accompanying verification mode, opens a preset monitoring and verification time window, and after detecting the identity of a valid monitoring personnel, it will... The access control is set to 1 and enabled. If the access is not detected within the time limit, the attempted violation is recorded. The edge side has a built-in local data caching module. When the cloud-edge network is interrupted, emergency decisions are made based on the cached data. After the network is restored, the local decision records are synchronized.
9. The method for dynamic control of access permissions in power plants under a cloud-edge collaborative architecture as described in claim 5, characterized in that, The calculation of the spatiotemporal consistency deviation index includes: ; In the formula, It is the spatiotemporal consistency deviation index; This indicates the cumulative number of times a person crosses the boundary outside the set of permitted access areas during the operation. This refers to the actual duration of time that personnel spend within the permitted access area. The standard duration estimated for the work plan; and These are the weight coefficients for the spatial and temporal out-of-bounds dimensions, respectively, and they satisfy the following conditions: and .
10. The method for dynamic control of access permissions for power plants under a cloud-edge collaborative architecture as described in claim 9, characterized in that, The modified dynamic security trust value, forming a closed-loop control, includes: ; In the formula, This is the revised dynamic security trust value; This is the feedback adjustment coefficient, and its value range is... ; If the corrected dynamic security trust value Below the preset warning threshold If so, the individual's subsequent access permissions will be tightened, and the abnormal behavior data will be synchronized to the safety supervision system and included in the individual's safety credit file.
Citation Information
Patent Citations
Behavior processing method and device based on work ticket, computer and storage medium
CN112488488A
Smart park access control management method and system based on Internet of Things
CN120071490A