Measurement and control center dispatching management system
By implementing hierarchical configuration management, duplex hot standby management, operation scheduling management, and hierarchical permission management modules, the problems of complex configuration management, low operation efficiency, and fragmented permission management in the measurement and control center information system have been solved, enabling the system to operate efficiently, reliably, and securely.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA ELECTRONICS CORP 6TH RES INST
- Filing Date
- 2025-12-26
- Publication Date
- 2026-05-29
AI Technical Summary
The lack of a unified scheduling and management mechanism in the measurement and control center's information system leads to complex configuration management, low operational efficiency, poor system reliability, and fragmented access control, which affects operational efficiency and reliability.
The system employs a hierarchical configuration management module to automatically merge shared and unique configuration information, a duplex hot standby management module to achieve automatic switching, an operation scheduling management module to achieve permission matching, a measurement and control integration module to achieve intelligent matching of commands and software, and a hierarchical permission management module to achieve dynamic permission control.
Reduce human error rate, improve task execution efficiency, enhance system security, ensure the accuracy of configuration management and the efficiency of operation scheduling, and prevent unauthorized operations and system anomalies.
Smart Images

Figure CN122111530A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information technology for aerospace telemetry, tracking and command centers, and in particular to a telemetry, tracking and command center scheduling and management system. Background Technology
[0002] Currently, the scheduling and management in the measurement and control center's information system mainly adopts a decentralized management model, with each subsystem operating independently and lacking a unified scheduling and management mechanism.
[0003] The existing technology has the following prominent problems: First, the independent configuration of each software module leads to high complexity in configuration management. Shared configuration information needs to be repeatedly entered in multiple software programs, which is not only labor-intensive but also prone to inconsistencies due to human input errors. Second, the lack of a unified scheduling mechanism requires operators to operate each software module one by one, making it impossible to achieve batch operations through unified commands, which can easily lead to operation delays or omissions in time-sensitive launch missions. Third, resource management is inefficient, as it is impossible to monitor the hardware status, software operating status, and performance indicators of the central computer in real time, and resource allocation mainly relies on experience-based judgment. In addition, full-duplex hot standby switching mainly relies on manual judgment and manual switching, lacking an automated fault detection and switching mechanism. Finally, the independent permission management of each software module leads to fragmented user permissions, increasing the complexity of permission management and making it easy for permission conflicts or unauthorized operations to occur.
[0004] These problems seriously affect the operational efficiency and reliability of the measurement and control center's information system, and existing technologies urgently need to be improved to address these issues. Summary of the Invention
[0005] This invention provides a scheduling and management system for a measurement and control center, which addresses the shortcomings of low operating efficiency and poor reliability in existing measurement and control center information systems.
[0006] On one hand, the present invention provides a telemetry and control center scheduling and management system, which includes: The hierarchical configuration management module is used to receive shared configuration information and unique configuration information, and automatically merge the shared configuration information and the unique configuration information to generate complete configuration information required for the execution of each software. The duplex hot standby management module is used to monitor the hardware status, software running status and performance indicators of the central computer in real time, automatically perform duplex hot standby switching based on the monitoring results, and provide an interface for switching between automatic execution mode and manual execution mode. The operation scheduling and management module is used to match the corresponding measurement and control scenarios according to the user's permission type, maintain the software's executable operation instructions, and schedule the execution of operation instructions. The measurement and control integration module is used to maintain the association between software and operation commands, perform command parsing operations, match operation commands with software based on the association between software and operation commands, and call the software corresponding to the operation commands. The hierarchical permission management module is used to define the permission levels of different users, as well as the visual information and executable operations of each permission level. It also uses a central database to authenticate users and dynamically displays the operation interface and operation options based on user permissions.
[0007] The measurement and control center scheduling and management system provided by this invention automatically merges shared and unique configuration information through a hierarchical configuration management module, implements an automatic switching mechanism through a duplex hot standby management module, implements instruction scheduling with permission matching through an operation scheduling management module, implements intelligent matching of instructions and software through a measurement and control joint debugging module, and implements dynamic permission control through a hierarchical permission management module. This effectively solves the problems of complex configuration management, low operation scheduling efficiency, poor system reliability, and fragmented permission management in the prior art, and has the advantages of reducing the error rate of manual operation, improving task execution efficiency, and enhancing system security. Attached Figure Description
[0008] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0009] Figure 1 This is a schematic diagram of the structure of the measurement and control center scheduling and management system provided in an embodiment of the present invention. Detailed Implementation
[0010] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0011] In existing technologies, the telemetry, tracking, and command (TT&C) center information system adopts a decentralized management model, with each subsystem operating independently and lacking a unified scheduling mechanism. Operators need to log in to different software interfaces to perform repetitive configurations, leading to redundant configuration information and potential errors. Resource allocation relies on manual judgment based on experience, duplex hot standby switching requires manual operation, and access control is scattered across multiple independent modules. This architecture suffers from low operational efficiency and insufficient system reliability in time-sensitive scenarios such as aerospace launches.
[0012] To address the aforementioned issues, this paper considers separating and storing common and specific parameters to address the pain point of repetitive configuration information entry; to address the low efficiency of manual operations, it proposes an automated configuration merging and command scheduling mechanism; to meet system reliability requirements, it designs real-time monitoring and duplex switching functions; and to address the current chaotic access control situation, it proposes a unified authentication and dynamic interface control scheme. Through a modular design approach, complex management requirements are decomposed into collaborative functional units.
[0013] Therefore, the present invention proposes the following technical solution: Figure 1 This is a schematic diagram of the structure of the measurement and control center scheduling and management system provided in an embodiment of the present invention. Figure 1 As shown, the telemetry and control center scheduling management system of this embodiment may include a scheduling management layer 1 formed by a hierarchical configuration management module 11, a duplex hot standby management module 12, an operation scheduling management module 13, a telemetry and control joint debugging module 14, and a hierarchical permission management module 15. Those skilled in the art will understand that the above modules can interact with different software in the business software layer 3 through a unified scheduling interface 2, and the different software in the business software layer 3 also interact with the central computer in the resource layer 4. The business software layer 3 may include real-time data exchange software 31, telemetry data processing software 32, GNSS data processing software 33, external measurement data processing software 34, real-time integrated data processing software 35, display customization software 36, etc.
[0014] The hierarchical configuration management module 11 is used to receive shared configuration information and unique configuration information, and automatically merge the shared configuration information and the unique configuration information to generate complete configuration information required for the execution of each software. The duplex hot standby management module 12 is used to monitor the hardware status, software running status and performance indicators of the central computer in real time, automatically perform duplex hot standby switching based on the monitoring results, and provide an interface for switching between automatic execution mode and manual execution mode. The operation scheduling management module 13 is used to match the corresponding measurement and control scenario according to the user permission type, maintain the software's executable operation instructions, and schedule the execution of operation instructions. The measurement and control integration module 14 is used to maintain the association between software and operation instructions, perform instruction parsing operations, match operation instructions with software based on the association between software and operation instructions, and call the software corresponding to the operation instructions.
[0015] The hierarchical permission management module 15 is used to define the permission levels of different users, as well as the visual information and executable operations of each permission level. It also uses the central database to authenticate users and dynamically displays the operation interface and operation options based on user permissions.
[0016] In a specific implementation, the hierarchical configuration management module 11 primarily functions to classify, store, and integrate shared and unique configuration information. Specifically, shared configuration information can be predefined and stored in a unified database using templates, while unique configuration information can be input through independent configuration files or dedicated interfaces. Furthermore, the automatic merging process can employ rule-based matching algorithms, such as using keyword extraction technology to identify common fields in shared configuration information and logically combine them with specific fields in unique configuration information to generate complete configuration information.
[0017] The duplex hot standby management module 12 can monitor hardware status, software operating status, and performance indicators in various ways. For example, hardware status monitoring can be achieved by collecting data through sensors and combining it with preset thresholds to determine whether to trigger an alarm; software operating status monitoring can be achieved through a heartbeat detection mechanism, periodically sending probe signals to confirm whether the software is running normally; performance indicator monitoring can be based on log analysis technology to extract key performance parameters and perform trend prediction. Furthermore, the interface for switching between automatic and manual execution modes can be implemented through a graphical interface or command-line tool. Specifically, users can select and switch modes through interface buttons or command input.
[0018] The core function of the operation scheduling management module 13 is to match measurement and control scenarios based on user permission types and execute scheduling. Specifically, matching user permission types can be achieved through a role mapping table, for example, associating user role identifiers with a predefined set of permissions; matching measurement and control scenarios can be achieved through a scenario template library, filtering applicable scenario templates based on user permissions. Furthermore, the scheduling of operation instructions can be achieved through a task queue mechanism, for example, sorting the operation instructions to be executed according to priority and assigning them to the target software in sequence.
[0019] The main function of the measurement and control integration module 14 is to achieve intelligent matching between operation commands and software. Specifically, command parsing can be achieved through natural language processing technology, such as structurally decomposing the input commands based on grammatical rules; the association between software and operation commands can be achieved through mapping tables or rule engines, such as binding keywords of operation commands with functional interfaces of the software. Furthermore, calling the software corresponding to the operation command can be achieved through remote procedure call protocols, such as triggering the execution of the target software through HTTP requests or message queues.
[0020] The hierarchical permission management module 15 functions to achieve unified management and dynamic control of user permissions. Specifically, permission levels can be defined through a hierarchical model, such as dividing users into multiple levels and assigning a fixed set of permissions to each level; the definition of visual information and executable operations can be achieved through a permission matrix, such as binding user permissions to interface elements or operation options. Furthermore, user authentication can be achieved through a multi-factor authentication mechanism, such as combining password verification with biometric recognition technology to ensure the authenticity of the user's identity.
[0021] This invention solves the problems of complex configuration management, low operation scheduling efficiency, poor system reliability, and fragmented permission management in the prior art by using a hierarchical configuration management module 11 to automatically merge shared and unique configuration information, a duplex hot standby management module 12 to realize an automatic switching mechanism, an operation scheduling management module 13 to realize permission-matched instruction scheduling, a measurement and control joint debugging module 14 to realize intelligent matching of instructions and software, and a hierarchical permission management module 15 to realize dynamic permission control. It has the advantages of reducing the error rate of manual operation, improving task execution efficiency, and enhancing system security.
[0022] In some embodiments, the present invention further proposes a measurement and control joint debugging module 14 to perform permission matching, format standardization, scenario adaptation, and state compatibility verification on operation instructions, and obtain multiple verification results; if all verification results indicate that they pass, the instruction parsing operation is executed.
[0023] The process includes several key aspects: **Permission matching:** Verifying whether a user possesses the necessary permissions to execute the current operation command. This can be achieved using a role-based access control (RBAC) permission matrix, matching user permission identifiers with the command's operation level. **Format standardization:** Verifying whether the syntax and parameter format of the operation command conform to preset standards. This can be achieved using regular expression matching and data type validation algorithms to ensure the integrity of the command structure and the validity of parameters. **Scenario adaptation:** Verifying the compatibility between the operation command and the current measurement and control task phase. This can be achieved using a scenario state machine model, judging by whether the command content matches the set of operations allowed in the task phase. **State compatibility:** Verifying the compatibility between the operation command and the system's current operating state. This can be achieved using a resource state snapshot comparison mechanism, detecting conflicts by real-time acquisition of hardware resource utilization and software operating status.
[0024] Specifically, after receiving an operation command, the measurement and control integration module 14 first extracts the user identifier and operation code from the command, and then calls the permission database in the hierarchical permission management module 15 to perform permission matching verification, confirming that the user has the permission level to execute the command in the current task scenario. Next, it performs syntax parsing on the command text, verifies the format specifications using a predefined command template library, and checks whether the command structure is complete and whether the parameter format meets data type requirements. Then, it combines the current measurement and control scenario identifier provided by the task scheduling module, retrieves the set of allowed operations from the scenario-operation mapping table, and performs scenario adaptation verification. Finally, it obtains real-time system status data through the duplex hot standby management module 12 to perform status compatibility verification, ensuring that command execution will not cause resource conflicts with running processes. Only when all four verifications pass will the command parsing engine convert the operation command into executable machine code and distribute it to the corresponding software module for execution.
[0025] This invention effectively prevents the execution of unauthorized operations, incorrectly formatted commands, mismatched scenario commands, and conflicting state commands, reducing the risk of system anomalies caused by invalid commands. This verification mechanism ensures the legality of commands while reducing manual intervention through automated processing, thus improving the efficiency and reliability of command processing in measurement and control tasks.
[0026] In some embodiments, see continue to see Figure 1 The present invention further proposes a software registration management module 16, which is used to maintain the information of each software in the system, bind the software with the configuration information, define the executable operation interface of each software, and manage the resources required for the operation of each software.
[0027] Maintaining information for each software within the system involves recording basic attributes such as software name, version number, and operating parameters using a structured database. This can be achieved using a relational database table structure, with each software having its own independent data storage unit for easy subsequent querying and version tracking. Binding software to configuration information involves establishing a mapping relationship between software entities and configuration parameters. This can be implemented using hash tables or key-value pair storage methods to ensure that the corresponding configuration is automatically loaded when the software starts. Defining the executable operation interfaces for each software involves standardizing the control instruction set for each software. This can be achieved using an interface description language to generate a unified calling specification, enabling cross-software operation compatibility. Managing the resources required for each software operation involves allocating and monitoring the computing resources used during software runtime. This can be achieved using a resource quota management mechanism, dynamically adjusting resource allocation strategies through operating system-level interfaces.
[0028] Specifically, the software registration management module 16 centrally stores the basic data of all software by establishing a software information registry. When new software is connected to the system, it must complete the registration process and generate a unique identifier. The binding process between software and configuration information is completed in the configuration management phase, achieving automatic association by parsing the metadata characteristics of the configuration file. The operation interface definition adopts standardized protocol encapsulation, and each software must provide basic operation interfaces such as start, stop, and status query that conform to the specifications. Resource management dynamically adjusts priorities by monitoring the memory usage and CPU utilization of software in real time, combined with preset resource allocation strategies, to ensure that critical tasks receive sufficient resources.
[0029] This invention enables centralized management and resource coordination and allocation of heterogeneous software within a measurement and control system, effectively solving problems such as software version confusion and configuration loading errors, ensuring stability and execution efficiency when multiple software programs work together, and providing a standardized access method for expanding new functional modules into the system.
[0030] In some embodiments, the present invention further proposes a hierarchical configuration management module 11, which is used to receive shared configuration information and unique configuration information, automatically merge the shared configuration information and the unique configuration information to generate complete configuration information required for the execution of each software, and is also used to perform type matching checks and standardization verification on the shared configuration information and the unique configuration information.
[0031] Type matching check verifies the consistency of the data type of the configuration information with preset requirements. This can be achieved using a data format parser combined with a regular expression matching algorithm to ensure that numeric configuration items are valid numbers and string configuration items meet length limits. Normative verification reviews the logical compliance of the configuration content. This can be implemented using a rule engine-based validation framework. By loading a predefined business rule library, it verifies whether configuration parameters meet value range constraints and the logical consistency between related parameters.
[0032] Specifically, when an operator inputs configuration information, the system first performs structured parsing of the data in the shared and unique configuration libraries. For numerical parameters, the system automatically detects whether the input is in integer or floating-point format. For example, if the task code requires a six-digit combination, non-numeric characters or inputs with incorrect length will be blocked. For logically related parameters, the system verifies the constraints between parameters. For example, when the longitude value of the monitoring and control equipment's station coordinates exceeds a preset range, an alarm is automatically triggered. Through this dual verification mechanism, incorrect configurations are identified before integration, ensuring that the final generated complete configuration information meets the execution requirements of each software.
[0033] This invention can effectively avoid system malfunctions caused by incorrect configuration information formats or logical contradictions, reduce the workload of manual verification, improve the accuracy and efficiency of configuration management, and ensure that the configuration information obtained by each software module is complete and compliant.
[0034] In some embodiments, the present invention further proposes a hierarchical configuration management module 11, which is also used to automatically push matching configuration templates based on the measurement and control scenario, with each configuration template marked with a recommended type and filling specifications.
[0035] Among them, "Measurement and Control Scenarios" refers to a set of operational environments categorized according to task types. This can be implemented through combinations of task parameters and definitions of operational procedures, used to identify the type of measurement and control task to be executed. "Configuration Templates" refers to a pre-defined standardized configuration framework, implemented using structured documents in XML or JSON format, containing a set of configuration items required for a specific scenario. "Recommended Types" refers to data type suggestions for configuration items, implemented through field annotations, used to guide users in correctly selecting numeric, character, or boolean parameters. "Fill-in Specifications" refers to the constraints on input values for configuration items, implemented using a combination of regular expressions and value range definitions, used to ensure that input content meets system requirements.
[0036] Specifically, when a user selects the current telemetry and control scenario in the configuration interface, the system matches the corresponding configuration template using a scenario recognition engine. This template is displayed visually with recommended type identifiers and filling specifications. For example, in a telemetry data processing scenario, the sampling frequency parameter is labeled as an integer value and its range is limited to 1-100Hz. After the user completes the configuration according to the template guidance, the system automatically performs type validation and format checks. If a type mismatch or value exceeding the range is found, an error message is immediately triggered and submission is blocked. This process, through pre-defined template logic and a real-time validation mechanism, ensures that configuration operations in different scenarios meet the system's operational requirements.
[0037] This invention enables precise guidance for the configuration of measurement and control tasks, reduces the learning cost for operators to learn complex configuration rules, reduces system anomalies caused by parameter type mismatch or format errors, and improves configuration efficiency and accuracy when switching between multiple scenarios.
[0038] In some embodiments, since users may not be able to determine whether the configuration information to be entered belongs to public configuration information or unique configuration information when entering configuration information, the present invention also provides the following technical solutions in order to accurately store the configuration information to be stored: In response to a user's configuration recommendation request, the system receives the configuration information to be stored in the recommended configuration interface; extracts key fields from the configuration information to be stored to form feature data for classification; and identifies the type of the configuration information to be stored based on preset classification rules or a lightweight classification algorithm to determine whether it belongs to shared configuration information or unique configuration information. If the configuration information to be stored belongs to shared configuration information, it is stored in the shared configuration library; if the configuration information to be stored belongs to unique configuration information, it is stored in the unique configuration library.
[0039] Specifically, the recommended configuration interface refers to a dedicated interactive window provided to users for inputting and managing configuration information. It can be implemented using a graphical user interface or a command-line interface, aiming to standardize the input process and reduce the risk of human error. Key fields refer to core data items that reflect the essential attributes of the configuration information, such as task identifiers and device parameters. These can be extracted using regular expression matching, natural language processing, and other methods, aiming to provide an objective basis for subsequent classification. Preset classification rules refer to explicit judgment criteria based on domain knowledge, while lightweight classification algorithms refer to classification methods with low computational complexity but high accuracy. Both can be implemented using decision tree models, Naive Bayes classifiers, etc., with the aim of efficiently and accurately completing the automatic classification of configuration information.
[0040] In detail, this solution addresses the error risks and efficiency bottlenecks caused by manual classification through an intelligent configuration classification mechanism. First, users submit their configuration information to be stored in the recommended configuration interface. This process ensures standardized and guided input, avoiding formatting issues caused by arbitrary input. Next, the system extracts key fields to generate feature data. The selection of these fields focuses on the core elements of the configuration information, accurately reflecting its universality or specificity. Then, the configuration information is type-identified based on preset classification rules or lightweight classification algorithms. This automated identification mechanism eliminates subjective interference from manual type assignment, ensuring that configuration information is scientifically determined to be either common or unique. Finally, based on the identification results, the configuration information is stored in the corresponding configuration library. The common configuration library centrally manages information shared across software, while the unique configuration library stores parameters specific to certain software. This precise classification lays the foundation for the automatic merging of hierarchical configuration management, fundamentally eliminating the potential for configuration inconsistencies and strengthening the overall coordination capability of the system.
[0041] In some embodiments, this application further proposes that the hierarchical permission management module 15 is also used for: collecting and recording user login information and operation behavior data to form user behavior feature data; constructing a multi-factor authentication mechanism by combining account password verification and auxiliary authentication methods during user login; dividing user permissions into basic permissions and temporary permissions, wherein basic permissions are valid for a long time, and temporary permissions are bound to specific tasks and are automatically enabled or revoked as the task lifecycle changes; generating operation logs and performing integrity verification for each permission adjustment and key operation execution, and using the operation logs for auditing and traceability; and establishing association records between users, operation instructions and tasks to achieve traceable management of permission changes and operation behaviors.
[0042] Specifically, behavioral characteristic data refers to a set of user behavior patterns formed by collecting information such as user login time, login location, operation frequency, and operation type. This data can be implemented using machine learning algorithms or rule engines. Multi-factor authentication mechanisms can be understood as an identity verification process combining multiple verification methods, such as dynamic passwords, biometric recognition, and hardware tokens, aiming to improve the security of identity verification. The division between basic and temporary permissions is a dynamic permission management model based on task requirements. The automatic activation or revocation of temporary permissions can be achieved through task state machines or timers. Operation log integrity verification refers to ensuring that log content is not tampered with using hash algorithms or digital signature technology, aiming to provide reliable audit evidence. The association records between users, operation instructions, and tasks can be implemented using relational databases or graph databases, aiming to support end-to-end operation traceability.
[0043] In detail, the hierarchical access control module 15 collects user login information and operational behavior data to form behavioral characteristic data, enabling real-time assessment of user risk and avoiding the limitations of relying solely on static role definitions. During user login, a multi-factor authentication mechanism is constructed by combining account password verification with auxiliary authentication methods, significantly improving the reliability of identity confirmation. By dividing permissions into basic and temporary permissions and dynamically adjusting permission allocation according to the task lifecycle, refined permission management is achieved. Operation logs generated during each permission adjustment and critical operation execution undergo integrity verification, ensuring the credibility of audit data. Simultaneously, by establishing association records between users, operation instructions, and tasks, end-to-end tracking of permission changes and operational behaviors is achieved. These technical measures work together to solve the problems of security vulnerabilities and traceability deficiencies in access control, thereby effectively preventing unauthorized operations and improving system security.
[0044] In some embodiments, this application further proposes a hierarchical permission management module 15 to define permission levels for different users, as well as the visual information and executable operations for each permission level, and to perform user authentication through a central database, dynamically displaying the operation interface and operation options according to user permissions. In addition, it is used to obtain a user's basic score, which is set according to the user's role and position; to calculate a dynamically adjusted score in real time based on the user's historical operation records and recent task execution; to sum the basic score and the dynamic score to obtain the user's comprehensive risk score; to determine an adjustment coefficient according to the current system operating status, and to perform a product calculation on the adjustment coefficient and the comprehensive risk score; and to use the product result as the user's permission level for dynamically controlling the range of operations that the user can execute.
[0045] Specifically, the basic score refers to the initial permission assessment value pre-set based on the user's role and position in the system. This can be implemented using a predefined rule table or a job responsibility matrix, aiming to provide a baseline for permission management and ensure that permission allocation matches user responsibilities. The dynamic score can be understood as a risk assessment value generated in real-time based on user behavior data. It can be implemented using machine learning models or statistical analysis methods, aiming to capture trends in user behavior. The comprehensive risk score is a comprehensive assessment indicator formed by combining the basic and dynamic scores. It can be implemented using a weighted summation algorithm or fuzzy comprehensive evaluation method, aiming to integrate multi-dimensional data to form an accurate risk view. The adjustment coefficient refers to the parameter that dynamically adjusts the risk assessment based on the system's operating status. It can be implemented using a state-aware algorithm or an environmental adaptability model, aiming to enhance the responsiveness of permission management to changes in the system environment.
[0046] Specifically, this technical solution achieves real-time adaptive adjustment of access control by constructing a dynamic risk assessment mechanism. First, the basic score is based on user roles and job responsibilities, ensuring a close correlation between access standards and user duties. Second, a dynamic score is calculated based on the user's historical operation records and recent task execution. This process integrates long-term behavioral patterns and short-term task performance, enabling the dynamic score to accurately capture the latest trends in user behavior, such as changes in operational standardization or task execution deviations, thus providing real-time behavioral basis for access control adjustments. Third, the basic score and dynamic score are summed to obtain a comprehensive risk score, forming a comprehensive risk view by integrating inherent user attributes and real-time behavioral data. Subsequently, an adjustment coefficient is determined based on the current system operating status, and the adjustment coefficient is multiplied by the comprehensive risk score. This step introduces system environmental factors as dynamic adjustment factors, such as amplifying the risk impact under high load or emergency modes, allowing access control adjustments to adapt to the needs of different operating scenarios. Finally, the multiplication result is directly used as the access control level for dynamically controlling the scope of operations, achieving seamless integration from risk assessment to access control execution. This ensures that user access always matches the current risk level, automatically restricting high-risk operations when risk increases and reasonably opening operation permissions when risk decreases.
[0047] In some embodiments, this application further proposes that the hierarchical permission management module 15 is also used to: obtain the initial basic score corresponding to the user's preset role, as well as the user's risk preference parameters and operation proficiency parameters; perform a weighted summation of the risk preference parameters and operation proficiency parameters to obtain a correction coefficient; combine the correction coefficient with the initial basic score to obtain a corrected basic score; and periodically update the basic score according to the user's operation records in the current recording period to reflect the user's actual operation ability.
[0048] Specifically, the initial base score refers to the initial scoring framework based on the user's preset role, which can be implemented using a fixed value or a dynamic range value. The risk preference parameter refers to the user's subjective acceptance of risk, which can be obtained through questionnaires, historical behavior analysis, etc. The operational proficiency parameter refers to the user's skill proficiency in a specific task, which can be quantitatively assessed through indicators such as operation success rate and task completion time. The correction coefficient is an adjustment factor obtained by weighted summation of the above two parameters, aiming to scientifically reflect the comprehensive impact of individual user differences on risk levels. The corrected base score is calculated by combining the correction coefficient with the initial base score, aiming to transform the scoring from fixed role dependence to dynamic individual adaptation. The periodic update mechanism refers to the continuous adjustment of the base score based on the user's operation records within the current recording period, aiming to ensure the timeliness of the scoring system and avoid access control deviations caused by scoring lag.
[0049] In detail, this solution first obtains the initial base score corresponding to the user's preset role, as well as the user's risk preference and operational proficiency parameters, providing multi-dimensional personalized input for subsequent score adjustments. Based on this, a correction coefficient is formed by weighted summation of the risk preference and operational proficiency parameters. This correction coefficient is then combined with the initial base score to generate a revised base score. Finally, by regularly updating the base score, it is ensured that the score can promptly reflect changes in the user's actual operational ability.
[0050] In some embodiments, this application further proposes to statistically analyze a user's operation compliance rate, abnormal command cancellation rate, and number of permission overreach attempts based on historical operation logs; to obtain a compliance score by weighting the operation compliance rate, abnormal command cancellation rate, and number of permission overreach attempts; to statistically analyze a user's high-risk operation success rate, emergency handling deviation value, and continuous operation error rate based on historical operation logs; to obtain an operation risk control score by weighting the high-risk operation success rate, emergency handling deviation value, and continuous operation error rate; and to obtain a dynamic score by weighted summation of the compliance score and the operation risk control score, which is used to adjust the user's permission level in real time.
[0051] Specifically, the operational compliance rate refers to the degree to which users strictly follow standard procedures in daily operations, which can be achieved by comparing user operation records with preset standard operation procedures. The abnormal command cancellation rate can be understood as the frequency with which users actively correct erroneous operations, which can be quantified by statistically analyzing the ratio of the number of abnormal command cancellations to the total number of operations. The number of permission violation attempts refers to the number of times a user attempts to access unauthorized resources, which can be statistically analyzed through access denial records in system logs. The purpose of introducing these metrics is to comprehensively capture the compliance characteristics of users in routine operations.
[0052] Meanwhile, the high-risk operation success rate refers to the reliability of a user's operations when handling important tasks, which can be measured by statistically analyzing the ratio of successful operations in high-risk scenarios to the total number of operations. The emergency handling deviation value can be understood as the accuracy of a user's response in emergency situations, which can be assessed by comparing the difference between the user's actual operation and the emergency plan. The continuous operation error rate refers to the frequency of a user's continuous operational errors over a period of time, which can be quantified by analyzing records of consecutive erroneous operations. The purpose of introducing these indicators is to deeply assess the stability of user behavior under stress.
[0053] Specifically, a compliance score is generated by weighting the operational compliance rate, abnormal command cancellation rate, and number of permission overreach attempts. This score reflects the degree of compliance with user behavior in daily operations. An operational risk control score is generated by weighting the success rate of high-risk operations, emergency handling deviation, and continuous operation error rate. This score reflects the user's risk control capabilities in critical task scenarios. Finally, the compliance score and the operational risk control score are weighted and summed to form a dynamic score. This two-dimensional fusion mechanism balances the evaluation weights of routine and high-risk operations, thereby supporting precise and dynamic adjustment of permission levels.
[0054] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0055] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A telemetry and control center scheduling and management system, characterized in that, include: The hierarchical configuration management module is used to receive shared configuration information and unique configuration information, and automatically merge the shared configuration information and the unique configuration information to generate complete configuration information required for the execution of each software. The duplex hot standby management module is used to monitor the hardware status, software running status and performance indicators of the central computer in real time, automatically perform duplex hot standby switching based on the monitoring results, and provide an interface for switching between automatic execution mode and manual execution mode. The operation scheduling and management module is used to match the corresponding measurement and control scenarios according to the user's permission type, maintain the software's executable operation instructions, and schedule the execution of operation instructions. The measurement and control integration module is used to maintain the association between software and operation commands, perform command parsing operations, match operation commands with software based on the association between software and operation commands, and call the software corresponding to the operation commands. The hierarchical permission management module is used to define the permission levels of different users, as well as the visual information and executable operations of each permission level. It also uses a central database to authenticate users and dynamically displays the operation interface and operation options based on user permissions.
2. The measurement and control center scheduling and management system according to claim 1, characterized in that, The measurement and control integration module is also used for: The operation instructions are verified for permission matching, format standardization, scenario adaptation, and state compatibility, resulting in multiple verification results. If all verification results indicate that the operation is successful, execute the instruction parsing operation.
3. The measurement and control center scheduling and management system according to claim 1, characterized in that, Also includes: The software registration management module is used to maintain information about each software in the system, bind software with configuration information, define the executable operation interfaces of each software, and manage the resources required for each software to run.
4. The telemetry and control center scheduling management system according to claim 1, characterized in that, The hierarchical configuration management module is also used for: The shared configuration information and the unique configuration information are subjected to type matching checks and standardization verification.
5. The measurement and control center scheduling and management system according to claim 4, characterized in that, The hierarchical configuration management module is also used for: Based on the aforementioned measurement and control scenario, matching configuration templates are automatically pushed; each configuration template includes a recommended type and filling specifications.
6. The telemetry and control center scheduling management system according to claim 1, characterized in that, The hierarchical configuration management module is also used for: In response to the user's configuration recommendation request, the configuration information to be stored is received in the recommended configuration interface; The key fields of the configuration information to be stored are extracted to form feature data for classification; Based on preset classification rules or lightweight classification algorithms, the configuration information to be stored is identified by type to determine whether it belongs to shared configuration information or unique configuration information. If the configuration information to be stored belongs to shared configuration information, then it is stored in the shared configuration library; If the configuration information to be stored is unique configuration information, then it is stored in the unique configuration library.
7. The telemetry and control center scheduling management system according to claim 1, characterized in that, The hierarchical access control module is also used for: Collect and record user login information and operation behavior data to form user behavior characteristic data; During the user login process, a multi-factor authentication mechanism is constructed by combining account password verification with auxiliary authentication methods; User permissions are divided into basic permissions and temporary permissions. The basic permissions are valid indefinitely, while the temporary permissions are bound to specific tasks and are automatically enabled or revoked as the task's lifecycle changes. For each permission adjustment and critical operation, an operation log is generated and its integrity is verified. The operation log is used for auditing and traceability. Establish a record of associations between users, operation instructions, and tasks to enable traceable management of permission changes and operational behaviors.
8. The measurement and control center scheduling and management system according to claim 1, characterized in that, The hierarchical access control module is also used for: Obtain a user's basic rating, which is set based on the user's role and position; Calculate a dynamic score that is adjusted in real time based on the user's historical operation records and recent task execution. The user's comprehensive risk score is obtained by summing the basic score and the dynamic score. The adjustment coefficient is determined based on the current operating status of the system, and the adjustment coefficient is multiplied by the comprehensive risk score. The product result is used as the user's permission level to dynamically control the scope of operations that the user can perform.
9. The measurement and control center scheduling and management system according to claim 8, characterized in that, The hierarchical access control module is also used for: Obtain the initial base score corresponding to the user's preset role, as well as the user's risk preference parameters and operational proficiency parameters; The risk preference parameter and the operational proficiency parameter are weighted and summed to obtain the correction coefficient; The correction coefficient is combined with the initial base score to calculate the corrected base score; The basic score is updated periodically based on the user's operation records for the current recording period to reflect the user's actual operation ability.
10. The telemetry and control center scheduling management system according to claim 8, characterized in that, The hierarchical access control module is also used for: Based on historical operation logs, the user's operation compliance rate, abnormal command cancellation rate, and number of permission overreach attempts are statistically analyzed. The compliance score is obtained by weighting the operation specification matching rate, the abnormal instruction cancellation rate, and the number of permission overrun attempts. Based on the historical operation logs, the success rate of high-risk operations, the deviation value of emergency handling, and the error rate of continuous operations of users are statistically analyzed. The operation risk control score is obtained by weighting the success rate of the high-risk operation, the deviation value of the emergency handling, and the error rate of the continuous operation. The compliance score and the operational risk control score are weighted and summed to obtain the dynamic score, which is used to adjust the user's permission level in real time.