Dynamic authority authorization and work order intelligent linkage optimization method for video evidence storage system
By setting up an association mapping between work order type configuration nodes and user nodes for the video evidence storage system, the problem of consistency between permissions and work order configuration status under multi-source heterogeneous systems is solved, realizing refined site-level work order management and business operation continuity, and improving the compliance and legal validity of the video evidence storage system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING CENTURY CONCORD OPERATION & MAINTENANCE CO LTD
- Filing Date
- 2026-04-02
- Publication Date
- 2026-05-15
AI Technical Summary
In existing technologies, video evidence storage systems suffer from several problems when there are cross-pushing issues from multiple heterogeneous systems, dynamic user attribution across multiple sites, and coupling of permissions and work order configurations. These problems include the failure of state consistency management between the user permission view and the site work order configuration view, the break in the reliable association between the entire business operation chain and the video evidence storage chain, and the failure of the mapping and adaptation between site-level compliance requirements and operation records.
The system adopts a dynamic permission authorization and intelligent work order linkage optimization method for video evidence storage system. By setting a work order type configuration node for each site, an association mapping relationship between user nodes and site work order type configuration nodes is established, site-level permission snapshots are generated, multi-source push conflict resolution rules are executed, and dynamic adjustment of permission granting and work order configuration is realized. Operation records are associated with video evidence storage files and a compliance risk forward warning mechanism is established.
It has achieved refined management and full lifecycle compatibility of work order types at the site level, breaking the rigid model caused by the system-wide uniformity of work types, ensuring the continuity of business operations and legal validity, and improving the initiative of compliance management and risk warning capabilities.
Smart Images

Figure CN122053059A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of video surveillance and evidence preservation technology, and in particular to a method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence preservation system. Background Technology
[0002] With the rapid and large-scale development of new energy industries such as wind power and photovoltaics, the requirements for safety production compliance management of new energy power plants are constantly increasing. As a core information carrier for realizing the full-process recording of power plant operations, safety incident tracing, and compliance auditing, video evidence storage systems have been widely used in the daily operation and maintenance and safety management of various new energy power plants. Under the development model of group-based and cross-regional management of new energy power plants, the user coverage of video evidence storage systems continues to expand, and the user sources are becoming more diversified. This includes users created synchronously through third-party business systems such as EAM and identity management systems, as well as various operation, maintenance, management, and operation personnel manually created by administrators. At the same time, different regions and different types of power plants have significantly different needs for operation control requirements and work order business scenarios.
[0003] The aforementioned and existing related technologies often suffer from the following drawbacks: 1. Due to the simultaneous occurrence of three situations—cross-source heterogeneous system cross-pushing, dynamic user affiliation across multiple sites, and the coupling of permissions and work order configurations—the consistency management of state between the user permission view and the site work order configuration view fails across dimensions, sites, and time sequences. 2. Because account security operations, permission authorization changes, and work order configuration adjustments are intertwined and temporally related to video evidence files, the reliable connection between the entire business operation chain and the video evidence chain is broken, and the mapping and adaptation between site-level compliance requirements and operation records fails. Summary of the Invention
[0004] The technical problem to be solved by this invention is the shortcomings of the existing technology. To address this, we propose an optimization method for dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system.
[0005] To achieve the above objectives, this application adopts the following technical solution: a method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system, comprising the following steps: Step 1: Setting up a work order type configuration node for each site, carrying site identifier, work order type option set, and configuration version information; Step 2: Creating user accounts, receiving user push data from third-party system push interfaces, receiving user manually created data from manual creation interfaces, generating user creation nodes corresponding to different user sources, constructing source-aware permission granting rules, automatically adding review / browse roles and run / upload roles for users pushed by third-party systems, setting the push department information to the user's department, and automatically adding review / browse roles and run / upload roles for manually created users if no specified role is configured; Step 3: Establishing an association mapping relationship between user nodes and site work order type configuration nodes, generating site-level permission snapshots for each user node, recording the user's permission role list and operable work order type list under each site; when the same user is pushed from multiple third-party systems... When processing data, execute multi-source push conflict resolution rules, and determine the conflict field retention strategy based on the initial creation source and manually configured priority markers; Step 4: In response to the password reset trigger operation, generate a random complex password, pop up a password display window to display the username and the random complex password simultaneously, set a one-click copy control, and remove the password field on the personnel details page and editing page; Step 5: When creating a new work order, the job type drop-down box initially only contains the training work order item. In response to the operation of selecting the target power station, obtain the work order type configuration node information of the power station. If the work order type has been configured, load the configuration list; if not, keep the training work order item; Step 6: When editing an existing work order, if the job type field is in an editable state, refresh the drop-down box according to the rules in Step 5; if it is grayed out, keep the original job type unchanged; Step 7: Associate and store the operation records of password reset operation, permission change operation, and work order configuration adjustment operation with video evidence files. When a user's permission is downgraded or revoked during the execution of a key operation node in a work order, allow the completion of the current operation node and lock subsequent operation permissions after completion.
[0006] Preferably, step 2, which constructs source-aware permission granting rules, further includes: identifying the user's creation source, which includes three categories: automatic push from the EAM system, automatic push from the Zhuyun identity system, and manual creation by the administrator, and establishing independent permission granting logic for users from different sources.
[0007] Preferably, step 4 further includes: setting the execution conditions for full user password reset; when a system initialization or security policy update event is detected, the full user password reset process is triggered, and random complex passwords are generated for all user nodes. The random complex passwords meet the complexity requirements of containing uppercase letters, lowercase letters, numbers, and special characters.
[0008] Preferably, step 5 further includes: after refreshing the job type drop-down box, synchronously loading the compliance requirements bound to the selected work order type, and verifying whether the current user has the permission to operate the work order type in the site-level permission snapshot;
[0009] Calculate the adaptability index of the current work order operation request. If the adaptability index is greater than the preset threshold, the work order operation is allowed to be executed; otherwise, the operation is blocked and a risk warning is displayed.
[0010] Preferably, step 7 further includes: establishing a compliance risk forward warning mechanism, regularly scanning user permission status, site work order configuration status, and user account security status, identifying potential compliance risk events and proactively pushing warning prompts; for existing work orders affected by permission changes, performing existing work order status reconstruction, re-verifying permissions for work orders that users have created but not completed, and marking work orders with unmet permissions as having permissions pending review status.
[0011] Preferably, step 7, which associates the operation records with the video evidence file, further includes: when a work order is created, encapsulating the user permission snapshot at the time of creation and the site work order type configuration version into a preliminary operation record; during the execution of the work order, capturing event data of key operation nodes, and encapsulating the event timestamp, operator identity identifier, and permission snapshot at the time of operation into an operation process record; when user permissions change or the site work order type configuration changes, generating a change traceability record; and binding and storing the preliminary operation record, operation process record, change traceability record, and corresponding video evidence file.
[0012] Preferably, step 3, generating site-level permission snapshots, further includes: establishing a compliance requirement version management mechanism for each site, automatically generating a new compliance version number each time the video evidence compliance requirements of a site are modified, and associating historical versions with video evidence files created within the corresponding time period.
[0013] Preferably, step 7 further includes: when a user's permission is downgraded or revoked during a critical operation node of a work order, an operation buffering mechanism is executed to allow the user to complete the current operation node and lock the subsequent operation permissions of the work order after the operation is completed.
[0014] Preferably, the fit index in step 5 is calculated using the following formula: ;in, The step is the igmoid function, used to determine whether the work order operation is allowed. It compresses the input value to the (0,1) interval. As an intermediate variable for comprehensive permissions and security, it is calculated by weighting factors such as the number of user permission roles, work order type matching degree, compliance satisfaction degree, time decay, historical success rate, user activity, job complexity, and password security risk. As an intermediate variable between compliance and evidence preservation, it reflects the combined impact of the degree to which multiple compliance requirements tied to the work order type are met, the completeness of evidence preservation, the risk of unauthorized access, and the effectiveness of resolving multi-source conflicts. To buffer intermediate variables between versions, the parameters are jointly determined by the operation buffer trigger coefficient, the compliance version matching coefficient, the freshness of the permission snapshot, the risk bias item, the operation frequency, and the abnormal operation flag. The intermediate variable for video evidence quality is derived from a non-linear combination of factors such as video file integrity, hash verification consistency, user response efficiency, work order processing efficiency, and site equipment complexity. This serves as an intermediate variable between user experience and work order attributes, reflecting the correlation between the user and the work order creator, work order priority, urgency, historical processing time range, and user experience level. To preset adjustable parameters, control The steepness of the effect on the first Sigmoid component, To preset the exponent parameter, control The degree of non-linear scaling of the ratio To preset linear coefficients, adjust the contribution weights of the logarithmic terms. Adjust the preset coefficient. Scaling ratio in the logarithmic term.
[0015] A video evidence storage system with dynamic permission authorization and intelligent work order linkage optimization system includes a processor and a memory, wherein the memory stores a computer program.
[0016] The technical effects and advantages of this invention are as follows: By independently setting up work order type configuration nodes for each station and establishing a user-work order association mapping, coupled with a mechanism that dynamically loads the configuration list based on the selected station when creating a new work order and intelligently refreshes the existing work orders based on field status, this invention achieves refined management and full lifecycle compatibility of station-level work order types. It breaks the rigid model of existing technologies where work types are unified across the entire system and configuration changes render existing work orders unusable. Through a complete interactive design that displays the username and random password in a password reset pop-up window, facilitates forwarding with a one-click copy control, and completely removes the password field from the personnel details page, it balances the convenience of password distribution with front-end security. Combined with the immutable association storage of password reset, permission change, and work order configuration adjustment operation records and video evidence files, a complete chain of business operation evidence is constructed, effectively strengthening the legal validity of video evidence. An operation buffer mechanism allows users to complete the current key operation node and then lock subsequent permissions when permissions change. Combined with proactive compliance risk warnings and existing work order status reconstruction, this invention achieves a leap from passive compliance management to proactive risk warning while ensuring business continuity. Attached Figure Description
[0017] The disclosure of this invention is illustrated with reference to the accompanying drawings. It should be understood that the drawings are for illustrative purposes only and are not intended to limit the scope of protection of this invention. In the drawings, the same reference numerals are used to refer to the same parts:
[0018] Figure 1 This is a flowchart of the multi-source user push and permission authorization process of the present invention; Figure 2 This is a diagram showing the overall architecture of the new energy power station video evidence storage system of the present invention; Figure 3 This is a flowchart illustrating the configuration version adaptation process for editing existing work orders in this invention. Detailed Implementation
[0019] It is readily understood that, based on the technical solution of this invention, those skilled in the art can propose various interchangeable structural methods and implementations without altering the essential spirit of the invention. Therefore, the following detailed embodiments and accompanying drawings are merely illustrative examples of the technical solution of this invention and should not be considered as the entirety of the invention or as limitations or restrictions on the technical solution of this invention.
[0020] Example 1: Refer to Figure 1-3 As shown, the present invention provides a technical solution: a method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system, including the following steps: Step S110: Set a work order type configuration node for each wind farm, carrying the wind farm identifier, work order type option set, and configuration version information. In this embodiment, it is necessary to initialize the wind farm-level business configuration of the video evidence storage system. The initialization process includes setting a work order type configuration node for each wind farm. Each configuration node carries the basic business attribute information of the wind farm, specifically including: wind farm identifier, used to uniquely distinguish different wind farms, such as wind farm A corresponding to identifier L-001; work order type option set, which is consistent with the full data of the operation type in the video upload module, including various types such as training work orders, maintenance work orders, patrol work orders, and defect elimination work orders; and configuration version information, which records the version number and effective time of the work order type configuration of the wind farm.
[0021] Step S120: Receive user push data from the third-party system push interface and user manually created data from the manual creation interface. Generate user creation nodes corresponding to different user sources and construct source-aware permission granting rules. After completing the initialization of the site-level business configuration, it is necessary to process user creation requests from different channels. Specifically, it is necessary to receive user push data from the push interfaces of third-party systems such as the EAM system and the Zhuyun Identity Management System. This data includes the user's basic identity information, department, and job information. At the same time, it is necessary to receive user data manually created by the administrator from the system's manual creation interface. Based on the different sources of this data, corresponding user creation nodes are generated for users pushed by the third-party system and users created manually. Source-aware permission granting rules are constructed for each user creation node. For example, for users pushed by the EAM system, the system identifies its source identifier as EAM-PUSH and records that the user was created through automatic push. For users created manually by the administrator, the system identifies its source identifier as MANUAL-CREATE and records the user's creation method.
[0022] Step S130: For users pushed by third-party systems, generate a first-type user creation node, carrying the push source identifier, push department information, and default role granting mark. Automatically add the review / browse role and the run / upload role, and set the push department information to the user's department. In this video evidence storage system scenario, when generating nodes for users pushed by the EAM system, the primary task is to extract user identity information and department information from the push data. User identity information includes user name, employee ID, contact information, etc. Department information is the user's department carried in the push data, such as the operations and maintenance department. Based on this information, generate a first-type user creation node for the pushed user. This node carries the push source identifier, push department information, and default role granting mark. After the system performs the role addition operation, it automatically adds the review / browse role and the run / upload role to the user, and sets the push department information to the user's department. For example, if a push user is a newcomer, their push source identifier is EAM-PUSH, and their push department information is the operations and maintenance department, the system automatically adds two basic roles for them and sets their department to the operations and maintenance department.
[0023] Step S140: For manually created users, generate a second type of user creation node, carrying a manual creation identifier and a role configuration status marker. If no specified role is configured, the review / browse role and the run / upload role are automatically added. In this video evidence storage system scenario, when the administrator needs to temporarily add a field worker to the wind farm, the system enters user information through the manual creation interface. The system receives the user identity information and optional specified role information entered by the administrator. Based on this information, a second type of user creation node is generated for the manually created user. This node carries a manual creation identifier and a role configuration status marker. If the role configuration status marker is "no specified role configured," it means that the administrator did not assign any role to the user when creating the user. At this time, the system executes the default role fallback authorization and automatically adds the two basic roles of review / browse and run / upload to the user. For example, if the administrator creates a user for Li Si, enters the user identity information but does not specify any role, the system automatically adds two basic roles for him. If the administrator selects the run / upload role when creating a new user, the system uses the manually configured role and does not add any additional roles.
[0024] Step S150: Establish the association mapping relationship between user nodes and site work order type configuration nodes, generate site-level permission snapshots for each user node, record the user's permission role list and operable work order type list under each site, and when the same user is cross-pushed by multiple source systems, execute the multi-source push conflict resolution rules, and determine the conflict field retention strategy based on the initial creation source and manually configured priority flag.
[0025] In this embodiment, a user may simultaneously manage video evidence storage for multiple wind farms, and different wind farms may have different authorization scope requirements for the user. Therefore, the system establishes an association mapping relationship between each user node and the station work order type configuration node, and generates a station-level permission snapshot for each user. This permission snapshot is based on the station and records the user's permission role list and operable work order type list for each station. For example, if a user manages both wind farm A and wind farm B, their permission snapshot for wind farm A records that they have the review and browsing role, and the operable work order types are the maintenance work order and patrol work order configured for wind farm A. Their permission snapshot for wind farm B records that they have the run and upload role, and the operable work order type is the training work order configured for wind farm B. When a user switches stations, the system dynamically loads the corresponding station's permission snapshot, realizing the synchronous switching between the permission view and the work order configuration view.
[0026] When the same user is pushed to both the EAM system and the Zhuyun system and the pushed data conflicts, the system executes the multi-source push conflict resolution rules. The system checks the user node's initial creation source record: if the user node was first created through the EAM system, subsequent pushes from the Zhuyun system will use the data from the source system at the time of the user's initial creation as the standard. Subsequent pushes will only update non-conflicting fields, while conflicting fields will retain the initial data. At the same time, the system checks whether the user node has a manually configured priority flag: if the administrator manually modifies the department or role information after the user's initial creation, then any data pushed by any third-party system will not overwrite the manually modified fields. For example, if a user is first created through the EAM system with the department as Operations Department, and then manually changed to Safety Supervision Department by the administrator, and then the Zhuyun system pushes the same user again with the department information as Operations Department, the system recognizes that the department field conflicts and the user node has a manually configured priority flag. Therefore, it retains the Safety Supervision Department manually set by the administrator as the final department information.
[0027] Step S160: In response to the password reset trigger operation, a random complex password is generated, and a password display window pops up, simultaneously displaying the username and the random complex password. A one-click copy control is set up, and the password field is removed from the personnel details page and the edit page. In the user management interface of the New Energy Group's video evidence storage system, the administrator enters the target user's personnel edit page. The page has a password reset operation button. When the administrator clicks this button, the system responds to the trigger operation, immediately calls the random password generation algorithm to generate a random complex password that meets the complexity requirements, containing uppercase letters, lowercase letters, numbers, and special characters, and pops up a modal window at the front end of the page displaying the password. The password display window simultaneously shows the target user's username and the generated random complex password, ensuring that administrators can intuitively obtain the password information. To facilitate administrators in quickly forwarding the reset password to the corresponding user, a one-click copy control is provided in the password display window. When the administrator clicks the one-click copy button, the system copies the username and random complex password displayed in the pop-up window to the system clipboard according to the preset format. In the personnel details page and personnel editing page, the system completely removes the original password field display area. Neither plaintext passwords nor masked passwords are displayed anymore. The password information of the user node is only temporarily displayed in the pop-up window of the aforementioned password reset operation.
[0028] Step S170: When creating a new work order, the job type dropdown initially only contains the training work order item. In response to the operation of selecting the target power station, the work order type configuration node information of the power station is obtained. If the work order type has been configured, the configuration list is loaded; if not, the training work order item is retained. After the job type dropdown is refreshed, the compliance requirements bound to the selected work order type are loaded synchronously, and it is verified whether the current user has the permission to operate the work order type in the site-level permission snapshot. Further, the adaptability index of the current work order operation request is calculated. When the adaptability index is greater than a preset threshold, the work order operation is allowed to be executed; otherwise, the operation is blocked and a risk warning is displayed.
[0029] In this embodiment, after completing the permission verification, the system further performs a quantitative calculation of the adaptability index. First, the system collects the normalized value of the number of permission roles of the current user in the site-level permission snapshot, the matching degree between the selected work order type and the site work order type configuration node, the compliance requirement satisfaction degree of the selected work order type binding, the time interval of the user's most recent permission change, the user's historical work order operation success rate, the number of logins and operations in the past 30 days, the work order operation complexity coefficient, and the user's account password strength level, through the first intermediate variable. Perform comprehensive calculations using the formulas: Among them, A to H respectively represent the normalized value of the number of permission roles of the current user in the site-level permission snapshot, the matching degree between the selected work order type and the site work order type configuration node, the compliance requirement satisfaction degree of the selected work order type, the time decay factor, the success rate of the current user's historical work order operations under the same site, the user activity coefficient, the work order's operation complexity coefficient, and the security risk coefficient. The system collects the degree of satisfaction of various compliance requirements bound to the work order and their weight coefficients, the compliance requirement benchmark threshold, the evidence integrity coefficient, the unauthorized access risk coefficient, and the multi-source conflict resolution effectiveness coefficient, through a second intermediate variable. Perform comprehensive calculations using the formulas: ;in, To represent the degree of satisfaction of the i-th compliance requirement, Let be the weighting coefficient for the i-th compliance requirement. Let I be the baseline threshold for the i-th compliance requirement, J be the evidence integrity coefficient, K be the unauthorized access risk coefficient, and K be the multi-source conflict resolution effectiveness coefficient. Simultaneously, the system collects operation buffer trigger coefficients, compliance version matching coefficients, permission snapshot freshness, risk bias items, operation frequency coefficients, and abnormal operation marking coefficients, using a third intermediate variable. Perform comprehensive calculations using the formulas: Where L is the operation buffer trigger coefficient, M is the compliance version matching coefficient, N is the permission snapshot freshness, O is the risk bias term, P is the operation frequency coefficient, Q is the abnormal operation marking coefficient; and the integrity coefficient of the collected video evidence file, hash verification coefficient, user historical response time, work order type processing time, and site equipment complexity coefficient are all determined by the fourth intermediate variable. Perform comprehensive calculations using the formulas: ;in, For preset adjustable parameters, R is the integrity coefficient of the video evidence file associated with the current work order, S is the hash verification coefficient of the video evidence file, U is the normalized value of the average response time of the user's historical work order operations, V is the normalized value of the average processing time of the work order type, and W is the complexity coefficient of the site equipment.
[0030] Finally, the system collects the correlation coefficient between the current user and the work order creator, the work order priority coefficient, the urgency coefficient, the minimum and maximum processing time of historical work orders at the site, and the user experience coefficient, and uses a fifth intermediate variable. Perform comprehensive calculations using the formulas: Where X is the correlation coefficient between the current user and the ticket creator, Y is the ticket priority coefficient, and Z is the urgency coefficient. This is the normalized value of the minimum processing time for historical work orders at the current station. This is the normalized value of the maximum historical processing time for work orders at the current station. The user experience coefficient is used as the basis for calculations based on the five intermediate variables mentioned above. The system then calculates the final fit index using the main formula. ;in, The step is the igmoid function, used to determine whether the work order operation is allowed. It compresses the input value to the (0,1) interval. As an intermediate variable for comprehensive permissions and security, it is calculated by weighting factors such as the number of user permission roles, work order type matching degree, compliance satisfaction degree, time decay, historical success rate, user activity, job complexity, and password security risk. As an intermediate variable between compliance and evidence preservation, it reflects the combined impact of the degree to which multiple compliance requirements tied to the work order type are met, the completeness of evidence preservation, the risk of unauthorized access, and the effectiveness of resolving multi-source conflicts. To buffer intermediate variables between versions, the parameters are jointly determined by the operation buffer trigger coefficient, the compliance version matching coefficient, the freshness of the permission snapshot, the risk bias item, the operation frequency, and the abnormal operation flag. The intermediate variable for video evidence quality is derived from a non-linear combination of factors such as video file integrity, hash verification consistency, user response efficiency, work order processing efficiency, and site equipment complexity. This serves as an intermediate variable between user experience and work order attributes, reflecting the correlation between the user and the work order creator, work order priority, urgency, historical processing time range, and user experience level. To preset adjustable parameters, control The steepness of the effect on the first Sigmoid component, To preset the exponent parameter, control The degree of non-linear scaling of the ratio To preset linear coefficients, adjust the contribution weights of the logarithmic terms. Adjust the preset coefficient. Scaling ratio in the logarithmic term.
[0031] Step S180: When editing an existing work order, if the job type field is editable, the drop-down list is refreshed according to the rules in step S124; if it is grayed out, the original job type remains unchanged. In this video evidence storage system, when an administrator edits an existing work order, the system first checks the editing status of the job type field on the work order editing page. If the field is grayed out and cannot be edited, the system keeps the original job type unchanged and does not perform any linked refresh operations to ensure the stability of existing business and the integrity of the approval process. If the job type field is editable, the system refreshes the drop-down list according to the rules in step S124: based on the power station associated with the current work order, the work order type configuration of the power station is reloaded, and the job type option list is refreshed. For example, an existing work order is associated with Wind Farm A, the original job type is maintenance work order, and the field is editable. If the work order type configuration of Wind Farm A has been updated to inspection work order and defect elimination work order when the administrator edits this work order, the job type drop-down list is refreshed with the newly configured options.
[0032] Step S190: Associate and store the operation records of password reset, permission change, and work order configuration adjustment with the video evidence file. When a user's permission is downgraded or revoked during a key operation node of a work order, allow the user to complete the current operation node and lock subsequent operation permissions after completion.
[0033] In this embodiment, to ensure the video evidence files have complete legal validity, the system establishes a binding mechanism between business operations and the video evidence chain. The system extracts full-chain operation records from multiple log modules: password reset operation records from user operation logs, role granting and permission modification records from permission change logs, and site work order type configuration modification records from work order configuration change logs. When a work order is created, the system encapsulates the user permission snapshot and site work order type configuration version at the time of creation into a pre-operation record. During work order execution, the system captures event data of key operation nodes and encapsulates the event timestamp, operator identity, and permission snapshot at the time of operation into an operation process record. When user permissions change or site work order type configuration changes, a change traceability record is generated, including the state before the change, the state after the change, the changed operator, and the change timestamp. The above-mentioned pre-operation records, operation process records, and change traceability records are bound and stored with the corresponding video evidence files to form a complete evidence chain.
[0034] When a user's permissions are downgraded or revoked at a critical operation node in a work order, the system implements an operation buffer mechanism: instead of immediately interrupting the current operation, it allows the user to complete the ongoing operation node. Once the operation node is completed, the system immediately locks the subsequent operation permissions for the work order and displays a pop-up message: "Your permissions have been changed. Subsequent operations for this work order have been locked. Please contact the administrator for assistance." This design ensures that completed operations are not lost due to permission changes and prevents users from continuing to perform subsequent operations after permission downgrades.
[0035] Example 2: In this example, the specific operational logic under the scenario of cross-push from multiple systems is further described. Taking the actual operating environment of the EAM system and the Zhuyun identity management system as an example, the two systems may push the same user data at different times, and the pushed department information and role information may conflict. When the system performs user creation or update, it first checks the initial creation source record of the user node. Assuming that the user is first created through the EAM system and the department is the Operations Department, the system generates a first-type user creation node for the user and automatically adds the roles of review, browsing, and operation upload. Subsequently, according to the actual business needs, the administrator manually changes the user's department to the Security Supervision Department on the user management page. The system records this operation as manual configuration and establishes a manual configuration priority mark. Afterwards, the Zhuyun system pushes the user again with the department information as the Operations Department. At this time, the system recognizes that there is a conflict in the department field and that the user node has a manual configuration priority mark. Therefore, the Security Supervision Department set by the administrator is retained as the final department information, and other non-conflicting fields pushed by Zhuyun are updated normally. At the same time, a conflict log is generated for the administrator to check.
[0036] For scenarios where a user belongs to multiple wind farms, the system configures an independent permission set for each mapping unit of each wind farm. If a user manages both wind farm A and wind farm B, the snapshot record of their permission at wind farm A shows that they have the review and browsing role, and the work order types they can operate are maintenance work orders and patrol work orders. The snapshot record of their permission at wind farm B shows that they have the run and upload role, and the work order types they can operate are training work orders.
[0037] When switching between wind farms after logging into the system, the system dynamically loads the corresponding wind farm's permission snapshot to achieve synchronous switching between the permission view and the work order configuration view, avoiding cross-permission interference. For example, when creating a work order in wind farm A, the operation type drop-down box only displays maintenance work orders and patrol work orders. After switching to wind farm B, the operation type drop-down box automatically switches to display only training work orders.
[0038] In this embodiment, the mechanism for handling the impact of changes in station work order type configuration on existing work orders is further described. The system establishes a version management mechanism for the work order configuration of each station, and automatically generates a new version number each time the configuration is modified.
[0039] When an administrator edits an existing work order, the system first checks the editing status of the job type field. If the work order has not yet entered the approval process and the field is editable, the system prompts the administrator that the current work order's job type, maintenance work order, no longer exists in the new version, and provides two options: one is to update the work order's job type to defect elimination work order or inspection work order, and the other is to retain the original job type, maintenance work order, mark it as a historical compatible type and continue to allow editing, but generate a compliance prompt. If the work order has already entered the approval process and the field is grayed out and cannot be edited, the system keeps the original job type unchanged and does not perform a linked refresh to ensure the integrity of the approval process.
[0040] In this embodiment, the specific implementation of the compliance risk forward warning mechanism and the reconstruction of the status of existing work orders is further described. The system is set to perform a scheduled task every Monday morning to scan the permission status of all user nodes, the site work order configuration status, and the user account security status. When it is detected that a user's permission is less than 7 days away from expiration, the system will proactively push a warning message on the user's operation homepage after login: Your review and browsing role will expire in 5 days. Please contact the administrator to renew it in time. Otherwise, you will not be able to continue creating work orders. When it is detected that a user's password is about to expire, the system will proactively push a password change reminder.
[0041] When user permissions change, the system automatically restructures the status of existing work orders. The system iterates through all existing work orders created but not yet completed by the new user, re-verifies the operation permissions for each work order based on the user's new permission snapshot. For maintenance work orders created but not yet completed by the new user, the system marks their status as "permissions pending review" and sends a pending notification to the administrator. Upon receiving the notification, the administrator can choose to reassign permissions, assign another user to take over the work order, or change the work order status to "terminated" and record the reason. The system will not automatically terminate work order execution to avoid business interruption.
[0042] The technical scope of this invention is not limited to the content described above. Those skilled in the art can make various modifications and variations to the above embodiments without departing from the technical concept of this invention, and all such modifications and variations should fall within the protection scope of this invention.
Claims
1. A method for optimizing dynamic permission authorization and intelligent work order linkage in a video evidence storage system, characterized in that, Includes the following steps: S1: Configure a work order type node for each site, carrying the site identifier, work order type option set, and configuration version information; S2: Create user accounts, receive user push data from the third-party system push interface, receive user manually created data from the manual creation interface, generate user creation nodes for different user sources, build source-aware permission granting rules, automatically add review and browsing roles and run and upload roles for users pushed by third-party systems, and set the push department information to the user's department; for manually created users, if no specified role is configured, automatically add review and browsing roles and run and upload roles. S3: Establish the association mapping relationship between user nodes and site work order type configuration nodes, generate site-level permission snapshots for each user node, and record the user's permission role list and operable work order type list under each site; When the same user data is pushed from multiple third-party systems, the multi-source push conflict resolution rules are executed, and the conflict field retention strategy is determined based on the initial source creation and manually configured priority flags. S4: In response to a password reset trigger, generate a random complex password, pop up a password display window to show both the username and the random complex password, set up a one-click copy control, and remove the password field from the personnel details page and the edit page; S5: When creating a new work order, the job type dropdown initially only contains the training work order item. In response to the selection of the target power station, obtain the work order type configuration node information for that power station. If the work order type has been configured, load the configuration list; otherwise, keep the training work order item; S6: When editing an existing work order, if the job type field is editable, refresh the dropdown according to the rules in step S5; if it is grayed out, keep the original job type unchanged. S7: Link and store operation records of password reset, permission change, and work order configuration adjustment operations with video evidence files. When a user's permission is downgraded or revoked during a critical operation node of a work order, the user is allowed to complete the current operation node and subsequent operation permissions are locked after completion.
2. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: The source-aware permission granting rules in S2 further include: identifying the user's creation source, which includes three categories: automatic push from the EAM system, automatic push from the Zhuyun identity system, and manual creation by the administrator, and establishing independent permission granting logic for users from different sources.
3. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: S4 further includes: setting the execution conditions for resetting the passwords of all users; when a system initialization or security policy update event is detected, the process of resetting the passwords of all users is triggered, and random complex passwords are generated for all user nodes. The random complex passwords meet the complexity requirements of containing uppercase letters, lowercase letters, numbers, and special characters.
4. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: S5 further includes: after the job type drop-down box is refreshed, synchronously loading the compliance requirements bound to the selected work order type, and verifying whether the current user has the permission to operate the work order type in the site-level permission snapshot; calculating the adaptability index of the current work order operation request, and allowing the work order operation to be executed when the adaptability index is greater than a preset threshold, otherwise blocking the operation and prompting a risk.
5. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: The S7 further includes: establishing a compliance risk forward warning mechanism, regularly scanning user permission status, site work order configuration status, and user account security status, identifying potential compliance risk events and proactively pushing warning prompts; for existing work orders affected by permission changes, performing existing work order status reconstruction, re-verifying permissions for work orders that users have created but not completed, and marking work orders with unmet permissions as having permissions pending review.
6. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: The step S7 of associating and storing the operation record with the video evidence file further includes: when a work order is created, encapsulating the user permission snapshot at the time of creation and the site work order type configuration version into a pre-operation record; during the execution of the work order, capturing event data of key operation nodes, and encapsulating the event timestamp, operator identity identifier, and permission snapshot at the time of operation into an operation process record; when user permissions change or the site work order type configuration changes, generating a change traceability record; and binding and storing the pre-operation record, the operation process record, the change traceability record, and the corresponding video evidence file.
7. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: The generation of site-level permission snapshots in S3 further includes: establishing a compliance requirement version management mechanism for each site, automatically generating a new compliance version number each time the video evidence storage compliance requirements of a site are modified, and associating historical versions with video evidence storage files created within the corresponding time period.
8. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 1, characterized in that: S7 further includes: when a user's permissions are downgraded or revoked during a critical operation node of a work order, an operation buffer mechanism is executed to allow the user to complete the current operation node and lock the subsequent operation permissions of the work order after the operation is completed.
9. The method for optimizing dynamic permission authorization and intelligent linkage of work orders in a video evidence storage system according to claim 4, characterized in that: The fit index in S5 is calculated using the following formula: ;in, The Sigmoid function compresses the input values to the (0,1) interval. As an intermediate variable for integrating permissions and security, As an intermediate variable between compliance and evidence preservation, To buffer intermediate variables between versions, As an intermediate variable for video evidence quality, As an intermediate variable between user experience and work order attributes, For preset adjustable parameters, To preset the exponent parameter, To preset linear coefficients, These are preset coefficients.
10. A dynamic permission authorization and intelligent work order linkage optimization system for video evidence storage, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program, and the computer program, when executed by the processor, implements the method of any one of claims 1 to 8.