A communication device security operation and maintenance method and system
By verifying the digital signature and integrity of maintenance work order documents, the target asset group is identified and dynamic maintenance credentials are generated. This solves the problem of insufficient correlation between maintenance results and data in communication equipment maintenance, realizes the traceability of the maintenance process and the continuity of authentication control, and improves the accuracy of anomaly detection and response scheduling.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAIBEI INST OF TECH
- Filing Date
- 2026-03-24
- Publication Date
- 2026-06-02
AI Technical Summary
In existing communication equipment operation and maintenance solutions, the correlation between operation and maintenance work ticket files and operation and maintenance requests is weak, the constraints between operation and maintenance permission policies and operation and maintenance instruction information are weak, and the evidence chain between the session process and operation and maintenance results is broken. This results in unclear input and output relationships between the encrypted operation and maintenance results and the anomaly detection results and response scheduling policies of operation and maintenance related data, making it difficult to form a continuous link traceability.
By acquiring operation and maintenance work ticket files, performing digital signature verification and integrity checks, identifying target operation and maintenance asset groups and generating operation and maintenance permission policies, using timestamp assembly and quantum key digital signature processing to generate dynamic operation and maintenance credentials, generating secondary authentication requests and authentication judgments, generating allow or block status, generating session keys and issuing access control rules, constructing dynamic network security graphs and static graph matrices, and generating anomaly detection results and response scheduling policies.
It enables traceable association between operation and maintenance results and process data within the same data organization framework, reduces semantic drift of operation and maintenance requests across devices and command scenarios, forms a traceable authentication and control path, and maintains a consistent reference relationship between anomaly detection results and response scheduling strategies, supporting full-link traceability and anomaly review.
Smart Images

Figure CN122137557A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication equipment operation and maintenance, and in particular to a method and system for secure operation and maintenance of communication equipment. Background Technology
[0002] In the field of communication equipment operation and maintenance (O&M), existing solutions typically rely on the identity information of O&M personnel and the target terminal device information to establish access control rules. They then use session keys in conjunction with O&M operation instructions to execute O&M projects, generating relevant O&M data for post-event auditing or alarm handling. However, this approach suffers from limitations such as weak correlation between O&M work order files and O&M requests, weak constraints between O&M permission policies and O&M operation instructions, and broken evidence chains between the session process and O&M results. Existing methods often perform a one-time verification of O&M personnel identity information after an O&M request arrives, or perform static whitelist matching of the target terminal device information, before issuing access control rules and generating session keys to drive O&M project execution. In scenarios involving continuous links of O&M work order files, O&M permission policies, O&M operation instructions, and encrypted O&M results, inconsistencies in policy interpretation and unclear session boundaries easily arise, making it difficult to form a closed-loop process consistent with secondary authentication request generation, authentication judgment processing, and response scheduling policies. For the joint processing of encrypted operation and maintenance results and operation and maintenance related data, existing technologies generally store the operation and maintenance related data as separate records, or store the encrypted operation and maintenance results as an independent storage product without correlation analysis. There is a lack of a unified organization method for constructing dynamic network security graphs, static segmentation and static graph matrix generation. It is difficult to form anomaly detection results based on the input of encrypted operation and maintenance results and operation and maintenance related data, and further support the continuous connection of target probability level determination, target impact level determination and matrix coordinate graph mapping processing. This results in unclear input and output relationship between anomaly detection results and response scheduling strategy and insufficient consistency of link tracing. Summary of the Invention
[0003] To address the aforementioned technical problems, this invention provides a method for secure operation and maintenance of communication equipment, comprising:
[0004] S100: Obtain the maintenance work ticket file, perform digital signature verification and integrity check processing, and obtain maintenance task execution information;
[0005] S200. Based on the operation and maintenance task execution information, identify the target operation and maintenance asset group, generate specific permission information of operation and maintenance personnel, and generate operation and maintenance permission policy.
[0006] S300. Based on the operation and maintenance permission policy, perform timestamp assembly and quantum key digital signature processing to obtain dynamic operation and maintenance credentials;
[0007] S400. Based on the dynamic operation and maintenance certificate, perform secondary authentication request generation and authentication judgment processing to generate a release command or blocking status.
[0008] S500: Based on the release command or blocking status, perform session key generation, access control rule distribution and operation and maintenance project execution processing to generate operation and maintenance result ciphertext and operation and maintenance related data.
[0009] S600. Based on the encrypted operation and maintenance results and operation and maintenance related data, perform dynamic network security graph construction, static segmentation and static graph matrix generation processing to generate anomaly detection results.
[0010] S700. Based on the anomaly detection results, determine the target probability level, determine the target impact level, and perform matrix coordinate graph mapping to generate a response scheduling strategy.
[0011] The following are its main beneficial effects:
[0012] (1) In view of the common problem in the prior art that the encrypted operation and maintenance results and operation and maintenance related data are recorded in a scattered manner and it is difficult to form a unified correlation analysis link, the dynamic network security graph construction, the static segmentation and the static graph matrix generation process are used to form a traceable correlation expression of the results and process data after the operation and maintenance execution within the same data organization framework, so that the anomaly detection results have a verifiable evidence connection relationship, and maintain the correlation consistency of the encrypted operation and maintenance results in the scenario of changing operation and maintenance session boundaries.
[0013] (2) In view of the common problems in the prior art, such as weak constraints on operation and maintenance permission policies and operation and maintenance operation instructions, and unclear boundaries caused by the reuse of operation and maintenance requests within a session, the dynamic operation and maintenance certificate is generated by the timestamp assembly and the quantum key digital signature processing, so that the operation and maintenance personnel identity information, the target terminal device information and the operation and maintenance operation instructions form a verifiable binding at the certificate level, thereby reducing the semantic drift of the operation and maintenance request in cross-device and cross-instruction scenarios.
[0014] (3) To address the problem of lack of integrated control with the operation and maintenance execution process after the one-time verification in the existing technology, the secondary authentication request is generated and the authentication judgment process outputs the release instruction or blocking status. The release instruction or blocking status constrains the session key generation, the access control rule issuance and the operation and maintenance project execution process, so that the authentication conclusion forms a traceable effective path in the control link, and establishes a consistent correspondence between the operation and maintenance result ciphertext and the operation and maintenance related data and the authentication status.
[0015] (4) In view of the problem that the input-output relationship between the anomaly detection result and the handling scheduling is unclear in the prior art, the anomaly detection result is used as a unified input object for the determination of the target probability level, the determination of the target impact level and the matrix coordinate diagram mapping processing, so that the response scheduling strategy and the anomaly detection result have a consistent reference relationship at the data object level, reducing the loss and reinterpretation of the scheduling basis in the link transmission process.
[0016] (5) In view of the problem that the relationship between operation and maintenance work ticket file and operation and maintenance request is weak in the existing technology and it is difficult to support the whole link traceability, the operation and maintenance work ticket file is processed by digital signature verification and integrity verification to obtain the operation and maintenance task execution information, and is processed by target operation and maintenance asset group identification and operation and maintenance personnel specific permission information generation to form the operation and maintenance permission policy, and then connected to the dynamic operation and maintenance certificate, the release instruction or blocking status, the operation and maintenance result ciphertext and the operation and maintenance related data, so that key objects have continuous reference and transmission relationship in the same main process, which facilitates link backtracking in operation and maintenance audit and anomaly review scenarios. Attached Figure Description
[0017] Figure 1 A flowchart illustrating a security operation and maintenance method for communication equipment provided in an embodiment of this application;
[0018] Figure 2 This is a structural block diagram of a communication equipment security operation and maintenance system provided in an embodiment of this application. Detailed Implementation
[0019] Example 1: Refer to Figure 1 This is a flowchart illustrating a secure operation and maintenance method for communication equipment provided in an embodiment of the present invention. The process may include at least steps S100-S700:
[0020] S100: Obtain the maintenance work ticket file, perform digital signature verification and integrity check processing, and obtain maintenance task execution information;
[0021] S200. Based on the operation and maintenance task execution information, identify the target operation and maintenance asset group, generate specific permission information of operation and maintenance personnel, and generate operation and maintenance permission policy.
[0022] S300. Based on the operation and maintenance permission policy, perform timestamp assembly and quantum key digital signature processing to obtain dynamic operation and maintenance credentials;
[0023] S400. Based on the dynamic operation and maintenance certificate, perform secondary authentication request generation and authentication judgment processing to generate a release command or blocking status.
[0024] S500: Based on the release command or blocking status, perform session key generation, access control rule distribution and operation and maintenance project execution processing to generate operation and maintenance result ciphertext and operation and maintenance related data.
[0025] S600. Based on the encrypted operation and maintenance results and operation and maintenance related data, perform dynamic network security graph construction, static segmentation and static graph matrix generation processing to generate anomaly detection results.
[0026] S700. Based on the anomaly detection results, determine the target probability level, determine the target impact level, and perform matrix coordinate graph mapping to generate a response scheduling strategy.
[0027] S100: Obtain the maintenance work ticket file, perform digital signature verification and integrity check processing, and obtain maintenance task execution information;
[0028] This step is completed collaboratively by the remote operation and maintenance platform and the operation and maintenance management platform. The remote operation and maintenance platform is responsible for the access, parsing, importing, and verification process of the operation and maintenance work order files, while the operation and maintenance management platform is responsible for the receipt, registration, retention, and traceability of the operation and maintenance work order files. The operation and maintenance work order files originate from the distribution process of the power grid dispatch automation master station system or the centralized initiation process of the remote operation and maintenance platform. When the operation and maintenance work order file enters the remote operation and maintenance platform, the platform first performs access registration on the file carrier. Access registration includes a binding record of the receiving time, sender information, service type, and file identifier. The file identifier is written into the same registration record in the form of a combination of the work order number and the target operation and maintenance asset group information. The sender information is represented by the power grid dispatch automation master station system identifier or the remote operation and maintenance platform identifier. The service type is represented by a category field obtained by mapping operation and maintenance project and operation and maintenance instruction information. Understandably, the maintenance work order file serves as the carrier of maintenance tasks. The file contains a set of content required for the execution of the maintenance task, including maintenance personnel identity information, maintenance account, user group, target terminal device information, maintenance operation instruction information, maintenance time field, maintenance target file, and user password. Specifically, the maintenance personnel identity information identifies the maintenance personnel performing the task; the maintenance account and user group indicate the scope of permissions; the target terminal device information indicates the terminal devices connected to the network; the maintenance operation instruction information indicates the maintenance operation instructions to be issued in this maintenance project; the maintenance time field indicates the effective time window of this maintenance task; the maintenance target file indicates the set of target files involved in the maintenance project; and the user password is an authentication auxiliary field representing the maintenance account. Upon receiving the maintenance work order file, the remote maintenance platform triggers this processing step. The triggering condition is that access registration is complete and the file identifier is not registered as processed. This status is written into the maintenance management platform's registration record as a basis for subsequent queries and verification.
[0029] Before performing digital signature verification and integrity checks, the remote operations and maintenance (O&M) platform performs format constraint checks on the O&M work order files. These constraints focus on whether the file contains a digital signature field, an integrity check field, and a work order number field. The digital signature field carries the digital signature content, the integrity check field carries the integrity check content, and the work order number field is used to associate the same O&M task with the registration record in the O&M management platform. The format constraint checks are implemented using a combination of field existence checks and field length checks. For missing fields, the field existence check outputs the reason for the missing field and registers the O&M work order file as pending completion. For empty or truncated fields, the field length check outputs the reason for the error and registers the O&M work order file as an error. The remote O&M platform performs different handling arrangements for pending completion and error states. The pending completion state triggers a re-reception process, while the error state triggers a security alarm generation process. The security alarm generation process only completes alarm content assembly and registration in this step and does not involve subsequent secondary authentication or response scheduling strategy execution. After format constraint determination, the remote operation and maintenance platform performs digital signature verification processing on the operation and maintenance work order file. This digital signature verification process includes four steps: signature material extraction, signature content parsing, signature comparison, and signature result registration. Signature material extraction extracts the digital signature field, sender information field, and work order number field from the operation and maintenance work order file and combines them to form the signature verification input. Signature content parsing standardizes the content of the digital signature field, using character sets and delimiters as parsing rules. The parsed digital signature content is written into the signature result registration record in a unified format. Signature comparison performs consistency verification between the signature verification input and the digital signature content. This consistency verification uses a pre-set key-based verification calculation process. The pre-set key is stored in the key management area of the remote operation and maintenance platform and mapped to the sender information field. This mapping is established by the operation and maintenance management platform during deployment and is read-only during runtime. Signature result registration writes the consistency verification result into the registration record of the operation and maintenance management platform and writes the digital signature verification status into the processing status field of the remote operation and maintenance platform. Understandably, the digital signature verification status represents the verification conclusion of the operation and maintenance work ticket file at the source trust level. Its value includes two categories: pass and fail. Pass corresponds to the consistency verification being passed, and fail corresponds to the consistency verification failing or the signature calculation being abnormal. The signature calculation being abnormal includes three scenarios: the preset key is missing, the sender information field is not mapped, or the digital signature field parsing fails. The reason for the abnormality corresponding to each scenario is written into the signature result registration record as the basis for subsequent review.
[0030] After the digital signature verification is successful, the remote operation and maintenance platform performs integrity verification on the operation and maintenance work ticket file. This integrity verification process checks whether the content of the operation and maintenance work ticket file has been modified during transmission and storage. The integrity verification process includes four steps: determining the verification scope, standardizing the verification content, reviewing the integrity verification fields, and registering the integrity conclusion. Determining the verification scope involves identifying the set of fields participating in the integrity verification from the operation and maintenance work ticket file. This set of fields includes operation and maintenance personnel identity information, operation and maintenance account, user group, target terminal device information, operation and maintenance operation instruction information, operation and maintenance time domain, operation and maintenance target file, and work ticket number fields. This set of fields is the minimum set of core parameters for this step; the absence of any field will prevent the operation and maintenance task execution information from forming a closed loop. Understandably, the user password field is an authentication auxiliary field, and its participation in the integrity verification field set is determined by the remote operation and maintenance platform according to the registration policy of the operation and maintenance management platform. The registration policy includes two categories: inclusion and exclusion. Inclusion of the corresponding user password field participates in the integrity verification; exclusion removes the corresponding user password field from the integrity verification scope, retaining only the field's existence record. The verification content standardization process standardizes the field content within the verification scope. This standardization includes handling whitespace, fixing the field order, and unifying the delimiters. The field order is rearranged by the remote operation and maintenance platform according to a preset order. The delimiter is a single delimiter used to concatenate field values to form the verification input string. The integrity verification field review parses and compares the integrity verification field content in the operation and maintenance work ticket file. In this embodiment, the integrity verification field is represented by the digest value form of Message Digest Algorithm 5. The remote operation and maintenance platform calculates the digest of the verification input string and compares it with the digest value in the integrity verification field to obtain the integrity comparison result. The integrity conclusion registration process writes the integrity comparison result into the operation and maintenance management platform's registration record and writes the integrity verification status into the remote operation and maintenance platform's processing status field. The integrity verification status includes two categories: pass and fail. A pass corresponds to a consistent digest value comparison, while a fail corresponds to an inconsistent digest value comparison or an abnormal digest calculation. Abnormal digest calculation includes three scenarios: missing fields within the verification scope, failure of verification content standardization, or failure of integrity verification field parsing. The reason for each scenario is written into the integrity conclusion registration record. If the digital signature verification or integrity verification fails, the remote operation and maintenance platform will register the operation and maintenance work ticket file as a blocked state associated object and generate a blocked state identifier, which will be written into the operation and maintenance management platform registration record. The blocked state identifier will be used in subsequent steps to constrain the operation and maintenance request acceptance logic, so that the work ticket number of the blocked state associated object cannot enter the target operation and maintenance asset group identification and operation and maintenance personnel specific permission information generation and processing link of S200.
[0031] After the digital signature verification and integrity check pass, the remote operation and maintenance platform enters the parsing and import processing stage, parsing the operation and maintenance work ticket file into operation and maintenance task execution information. This parsing and import processing includes four stages: field extraction, field consistency check, rule matching, and structured assembly. Field extraction extracts the operation and maintenance personnel identity information, operation and maintenance account, user group, target terminal device information, operation and maintenance operation instruction information, operation and maintenance time domain, operation and maintenance target file, user password, and work ticket number according to the field definitions in the operation and maintenance work ticket file. The extraction results are written to the parsing buffer and bound to the file identifier. Field consistency checks perform consistency verification on the extracted fields. This verification includes format verification of the target terminal device information, time window verification of the operation and maintenance time domain, and instruction set verification of the operation and maintenance operation instruction information. The format verification of the target terminal device information determines whether the device information meets the terminal device identification rules for the network already connected; the time window verification of the operation and maintenance time domain determines whether the start and end relationships of the time domain conform to the registration rules; and the instruction set verification of the operation and maintenance operation instruction information determines whether the instruction set contains empty or duplicate instructions. Rule matching maps the business type field and operation operation instruction information in the operation and maintenance work ticket file to the operation and maintenance project category, and associates the operation and maintenance target file with the operation and maintenance time domain to form an operation and maintenance project execution boundary record. Rule matching is implemented using a preset rule table, which is stored in the operation and maintenance management platform and retrieved by the remote operation and maintenance platform at runtime. The retrieval process is constrained by the aforementioned file identifier and sender information binding record to avoid mixing rules from different senders. Structured assembly merges the field extraction results, field consistency check results, and rule matching results to form operation and maintenance task execution information. This information includes the work ticket number, sender information, business type, operation and maintenance personnel identity information, operation and maintenance account, user group, target terminal device information, operation and maintenance operation instruction information, operation and maintenance time domain, operation and maintenance target file, user password, digital signature verification status, integrity verification status, and parsing and import status fields. The digital signature verification status and integrity verification status are used for subsequent steps to determine the legality of the input, and the parsing and import status describes whether the parsing and import process is complete. Understandably, the operation and maintenance task execution information is a key output product of the cross-step connection of the present invention. Its internal fields have a one-to-one correspondence with the subsequent S200 target operation and maintenance asset group identification and operation and maintenance personnel specific permission information generation and processing. In particular, the work ticket number, target terminal device information, operation and maintenance account, user group and operation and maintenance instruction information will be used as the direct input content for S200 to identify the target operation and maintenance asset group and generate operation and maintenance personnel specific permission information.
[0032] Regarding the output and destination of this step, after the structured assembly is completed, the remote operation and maintenance platform registers the output field name "Operation and Maintenance Task Execution Information" as the final output product of this step, and provides this operation and maintenance task execution information as the "Operation and Maintenance Task Execution Information" for the next input location S200. At the same time, the operation and maintenance management platform retains the digital signature verification status and integrity verification status bound to the work ticket number as the basis for determining the legality of the input in the S200 processing link, and maintains the traceable association between the same work ticket number in S100 and S200 in the cross-step connection.
[0033] S200. Based on the operation and maintenance task execution information, identify the target operation and maintenance asset group, generate specific permission information of operation and maintenance personnel, and generate operation and maintenance permission policy.
[0034] This step uses the operation and maintenance task execution information output by S100 as the sole input source. The operation and maintenance task execution information is parsed and imported by the remote operation and maintenance platform and bound to the registration record of the operation and maintenance management platform. When entering this step, the remote operation and maintenance platform triggers the permission orchestration process. The triggering condition is that the digital signature verification status and integrity verification status of the operation and maintenance task execution information are both passed and the parsing and import status is completed. If the operation and maintenance task execution information has a blocking status identifier associated object, the remote operation and maintenance platform registers the operation and maintenance task execution information corresponding to the work ticket number as not allowed to enter the permission orchestration status and terminates the processing link of this step. At the same time, the reason for termination is written into the registration record of the operation and maintenance management platform. Specifically, the remote operation and maintenance platform performs field loading and consistency verification on the operation and maintenance task execution information. Field loading includes assembling the work ticket number, sender information, service type, operation and maintenance personnel identity information, operation and maintenance account, user group, target terminal device information, operation and maintenance operation instruction information, operation and maintenance time domain, operation and maintenance target file, and user password into a set of objects to be identified. A session identifier for a processing session is generated on the remote operation and maintenance platform side to form the same traceability chain for subsequent identification and generation processes. The consistency verification is carried out around the time window relationship of the operation and maintenance time domain, the network access status of the target terminal device information, and the affiliation relationship of the operation and maintenance account and user group. The network access status is provided by the host asset table maintained by the operation and maintenance management platform. At the beginning of this step, the remote operation and maintenance platform pulls a snapshot of the host asset table and binds it with the session identifier. Understandably, the host asset table is an asset ledger for communication equipment operation and maintenance. The host asset table contains target terminal equipment information and asset attribute fields. The asset attribute fields include at least the asset identifier, network access status, user group, and service type mapping fields. The network access status indicates the terminal equipment that has connected to the network, the user group is used for consistency comparison with the user group, and the service type mapping field is used for consistency comparison with the service type. The act of pulling snapshots of the host asset table is constrained by the version management policy of the operation and maintenance management platform. The version management policy includes version number registration and effective time registration. In this step, the remote operation and maintenance platform only calls the host asset table snapshot corresponding to the version number whose effective time covers the operation and maintenance time domain, ensuring that the asset identification conclusion for the same work ticket number within the operation and maintenance time domain has a verifiable source record.
[0035] In the target maintenance asset group identification process, the remote maintenance platform uses the target terminal device information as the identification primary key and the service type and user group as identification constraints to perform matching processing between the target terminal device information and the host asset table. The matching processing includes two execution paths: single-match and multi-match. In the single-match scenario, the remote maintenance platform locates the asset attribute field corresponding to the unique asset identifier from the host asset table snapshot and performs network access status determination processing. The determination process outputs a conclusion that the terminal device has accessed the network. If the determination conclusion is that the terminal device has accessed the network, the remote maintenance platform continues to perform consistency comparison between the user group and service type mapping fields and the user group and service type, respectively. If the consistency comparison passes, the asset identifier is added to the target maintenance asset group, forming a member record for the target maintenance asset group. In multi-match scenarios, the remote operation and maintenance platform performs disambiguation processing on multiple asset identifiers corresponding to the same target terminal device information. The disambiguation process is executed in the order of network access status priority, user group consistency priority, and service type mapping consistency priority. The asset identifiers removed during disambiguation and the reasons for removal are recorded in the operation and maintenance management platform's registration record. If multiple candidate asset identifiers still exist after disambiguation, the remote operation and maintenance platform registers the operation and maintenance task execution information corresponding to the work ticket number as pending manual review and terminates this step's processing link. Understandably, the target operation and maintenance asset group is a constraint object generated by subsequent operation and maintenance permission policies. The target operation and maintenance asset group contains a set of asset identifiers and their corresponding target terminal device information mapping relationship. The asset identifier set is used to perform consistency verification of the target terminal device information when subsequent operation and maintenance requests are accepted, and the mapping relationship is used to deliver operation and maintenance operation instructions to the correct target terminal device information during operation and maintenance project execution. The minimum set of core parameters for identifying the target maintenance asset group consists of target terminal device information, host asset table, and user group. The absence of any parameter will prevent the target maintenance asset group from forming stable member records. Business type is a constraint enhancement field. It participates in consistency comparison when the business type exists, and is only written as a registration field into the member record of the target maintenance asset group when it does not exist.
[0036] In the generation and processing of specific permission information for operations and maintenance (O&M) personnel, the remote O&M platform uses the O&M personnel's identity information, the O&M account, and the user group as the primary keys for generation, and the O&M operation instruction information, the O&M time domain, and the O&M target file as generation constraints to assemble and process the permission information and generate specific permission information for O&M personnel. Specifically, the remote O&M platform first performs identity field normalization processing on the O&M personnel's identity information. Identity field normalization processing includes field structure verification and field content consistency verification of the O&M personnel's identity information. Field structure verification is used to determine whether the O&M personnel's identity information contains O&M personnel ID and name fields, and field content consistency verification is used to determine whether the binding relationship between the O&M personnel ID and the O&M account meets the account allocation rules of the O&M management platform. The account allocation rules are maintained by the O&M management platform and distributed to the remote O&M platform at the beginning of this step. The remote O&M platform registers the version number of the account allocation rules and binds it to the session identifier. Subsequently, the remote operation and maintenance platform performs attribution verification on the user group. This verification involves comparing the user group's data with the corresponding user group field in the host asset table snapshot, and writing the consistency comparison result into the permission generation record. If the attribution verification fails, the remote operation and maintenance platform registers the operation and maintenance task execution information corresponding to the work ticket number as a blocked status associated object, and writes the blocking reason into the registration record of the operation and maintenance management platform. After completing the identity field normalization and attribution verification, the remote operation and maintenance platform performs instruction set parsing on the operation and maintenance operation instruction information. This parsing process normalizes the operation and maintenance operation instruction information into a set of instruction entries, and binds each instruction entry to the operation and maintenance target file and the operation and maintenance time domain to form an instruction boundary record. The instruction entry set represents the smallest execution unit of the operation and maintenance operation instruction information to be issued in this operation and maintenance project, and the instruction boundary record represents the execution scope of the instruction entry in the operation and maintenance target file and the operation and maintenance time domain. Understandably, the specific permission information of operation and maintenance personnel includes a combination of operation and maintenance personnel identity information, operation and maintenance account, user group and instruction boundary record. The operation and maintenance personnel identity information is used to identify the permission subject, the operation and maintenance account is used to identify the account carrier, the user group is used to identify the permission domain, and the instruction boundary record is used to identify the permission constraint boundary. This combination structure is used to bind with the target operation and maintenance asset group when generating operation and maintenance permission policies in the future, forming a closed loop relationship of "permission subject - asset object - instruction boundary".
[0037] When generating operation and maintenance (O&M) permission policies, the remote O&M platform uses the target O&M asset group and the specific permission information of O&M personnel as parallel inputs for policy assembly. Policy assembly includes three stages: policy entry generation, policy entry deduplication, and policy entry registration. Policy entry generation involves binding each instruction boundary record in the specific permission information of the O&M personnel to each asset identifier in the target O&M asset group, generating a set of policy entries. Policy entry deduplication eliminates duplicate entries caused by multiple matching disambiguation or instruction set parsing, and the number of entries before and after deduplication is written into the registration record of the O&M management platform. Policy entry registration writes the policy entry set into the O&M permission policy and establishes an association between the O&M permission policy and the work ticket number, session identifier, host asset table snapshot version number, and account allocation rule version number. Understandably, the operation and maintenance (O&M) permission policy is a key prerequisite constraint data for the subsequent generation of dynamic O&M credentials by the S300. The O&M permission policy includes a set of policy entries and a policy version number field. The set of policy entries consists of O&M personnel identity information, O&M account, user group, asset identifier, target terminal device information, O&M operation instruction information, O&M time domain, and O&M target file. The policy version number field is generated by the O&M management platform and written into the policy entry registration. The policy version number field, together with the session identifier, supports the auditability of the O&M permission policy. During operation, the remote O&M platform uses an overwrite registration method to update the O&M permission policy for the same work ticket number. The overwrite registration is triggered by a change in the host asset table snapshot version number or a change in the account allocation rule version number. During overwrite registration, the old version of the policy entry set is retained, and the version chain relationship is written into the O&M management platform's registration record, ensuring consistent policy source traceability for subsequent authentication of O&M requests.
[0038] Regarding the output and destination of this step, the remote operation and maintenance platform registers the output field name "Operation and Maintenance Permission Policy" as the final output product of this step, and provides the "Operation and Maintenance Permission Policy" as the input position S300 for the next step. This allows for the execution of consistency constraints and assembly constraints when extracting the identity information of operation and maintenance personnel, target terminal device information, and operation and maintenance instruction information from operation and maintenance requests. At the same time, the target operation and maintenance asset group and the specific permission information of operation and maintenance personnel formed in this step are registered in the policy record of the operation and maintenance management platform as components of the operation and maintenance permission policy. This serves as the policy basis for timestamp assembly and quantum key digital signature processing when S300 generates dynamic operation and maintenance credentials. In the cross-main step connection, the hierarchical input relationship is maintained from the operation and maintenance task execution information of S100 to the operation and maintenance permission policy of S200 and then to the dynamic operation and maintenance credentials of S300.
[0039] S300. Based on the operation and maintenance permission policy, obtain the operation and maintenance request and extract the operation and maintenance personnel identity information, target terminal device information and operation and maintenance operation instruction information, perform timestamp assembly and quantum key digital signature processing to obtain dynamic operation and maintenance credentials.
[0040] This step uses the operation and maintenance permission policy output by S200 as the sole policy input, and establishes a common source association with the operation and maintenance task execution information output by S100 in the operation and maintenance management platform registration record through the work ticket number. When entering this step, it is triggered by the operation and maintenance personnel initiating an operation and maintenance request. The operation and maintenance request is generated by the mobile terminal and forwarded to the quantum access controller through the quantum authentication switch. Here, the mobile terminal is the terminal device used by the operation and maintenance personnel, the quantum authentication switch is the network device that carries the operation and maintenance data flow release or blocking status, and the quantum access controller is the control device that generates dynamic operation and maintenance credentials and initiates a secondary authentication request to the authentication service center. Understandably, the operation and maintenance (O&M) permission policy serves as the constraint basis for accepting O&M requests. It contains a set of policy entries and a policy version number field. The policy entry set consists of O&M personnel identity information, O&M account, user group, asset identifier, target terminal device information, O&M operation instruction information, O&M time domain, and O&M target file. The policy version number field is written when the policy entry registration is completed in S200. This step loads the current valid version of the O&M permission policy on the quantum access controller side. The determination of the current valid version is based on the policy version number and effective time registration in the O&M management platform registration record. When the quantum access controller receives an O&M request, it reads the work ticket number carried in the O&M request and retrieves the corresponding O&M permission policy and policy version number accordingly. If the work ticket number does not match a registration record or the corresponding record has a blocking status identifier associated object, the quantum access controller registers the O&M request as a rejected request and stops the processing link of this step. Simultaneously, it issues a blocking status flag to the quantum authentication switch, causing the data stream corresponding to the O&M request to be in a blocked state.
[0041] In the maintenance request acquisition phase, the quantum access controller performs access registration and session identifier generation processing on maintenance requests arriving via the quantum authentication switch. The access registration includes a binding record of the reception time, quantum authentication switch identifier, mobile terminal identifier, and work ticket number. The session identifier is generated by the quantum access controller and written together with the access registration into the registration area that can be queried by the authentication service center for subsequent secondary authentication requests. In this embodiment, the content set of the maintenance request includes maintenance personnel identity information, target terminal device information, and maintenance operation instruction information. This content set is assembled by the mobile terminal when the maintenance personnel trigger the execution of the maintenance project. The assembly process is constrained by the work ticket number and maintenance account issued by the maintenance management platform. The maintenance personnel identity information is used to identify the initiator, the target terminal device information is used to identify the terminal device that is connected to the network and is being maintained, and the maintenance operation instruction information is used to describe the maintenance operation instructions to be executed. The quantum access controller performs field parsing and normalization on the maintenance request. Field parsing extracts the maintenance personnel's identity information, the target terminal device information, and the maintenance operation instruction information from the maintenance request. Field normalization verifies the extracted results for field structure and content consistency. Field structure verification determines whether the maintenance personnel's identity information includes maintenance personnel ID and name fields, whether the target terminal device information conforms to the terminal device identification rules of the network, and whether the maintenance operation instruction information forms a set of instruction entries. Field content consistency verification determines whether the binding relationship between the maintenance personnel's identity information and the maintenance account meets the account allocation rules registered on the maintenance management platform, and whether the target terminal device information is consistent with the asset identifier mapping relationship in the maintenance permission policy. For maintenance requests that fail field structure verification or field content consistency verification, the quantum access controller registers the maintenance request as rejected and writes the rejection reason, work ticket number, and session identifier into the maintenance management platform registration record, ensuring a consistent traceability chain for subsequent maintenance requests with that work ticket number.
[0042] In the extraction of maintenance personnel identity information, target terminal device information, and maintenance operation instruction information, the quantum access controller, constrained by the maintenance permission policy, performs policy matching processing on the maintenance personnel identity information, target terminal device information, and maintenance operation instruction information. Policy matching processing includes three sub-processes: subject matching, object matching, and instruction matching. Subject matching uses the maintenance personnel ID in the maintenance personnel identity information as the matching key, and performs a consistency comparison with the maintenance account and user group to determine whether the maintenance request falls within the subject scope of the policy entry set of the maintenance permission policy. Object matching uses the target terminal device information as the matching key, and performs a consistency comparison with the mapping relationship between the asset identifier in the policy entry set and the target terminal device information to determine whether the maintenance request falls within the asset object scope of the policy entry set of the maintenance permission policy. Instruction matching uses the instruction entry set obtained from parsing the maintenance operation instruction information as the matching key, and performs a consistency comparison with the maintenance operation instruction information in the policy entry set and the maintenance time domain to determine whether the maintenance request falls within the instruction boundary record range of the policy entry set of the maintenance permission policy. Understandably, the minimum set of core parameters for policy matching processing consists of the operation and maintenance (O&M) permission policy, O&M personnel identity information, target terminal device information, and O&M operation instruction information. The absence of any parameter will prevent the formation of dynamic O&M credentials. The O&M time domain and O&M target file are constraint fields within the policy entry set. The O&M time domain is used in this step to determine whether the O&M request is within a valid time window, while the O&M target file is used to constrain whether the O&M operation instruction information involves an authorized target file. In scenarios where the O&M operation instruction information includes file operation instructions, instruction matching is included. If policy matching fails, the quantum access controller registers the O&M request as rejected and generates a rejection reason record. The rejection reason record includes the failed matching type identifier and corresponding field summary, and is written to the O&M management platform registration record. If policy matching succeeds, the quantum access controller proceeds to timestamp assembly processing and quantum key digital signature processing.
[0043] In the timestamp assembly process, the quantum access controller generates a timestamp and binds it to the session identifier. The timestamp is a component field of the dynamic operation and maintenance credential, used to identify the generation time of the credential and for validity determination in subsequent secondary authentication requests. Specifically, the quantum access controller reads the current time from the local time source and generates a timestamp field. Simultaneously, it reads the operation and maintenance time field from the operation and maintenance management platform's registration record and performs a time window consistency determination. This determination checks whether the timestamp falls within the time window range corresponding to the operation and maintenance time field. When the timestamp does not fall within the time window range, the quantum access controller registers the operation and maintenance request as rejected and writes it into the time window inconsistency reason record. Furthermore, the quantum access controller combines the work ticket number, session identifier, maintenance personnel identity information, target terminal device information, and maintenance operation instruction information with the timestamp to form a credential payload. This credential payload is part of the input data structure for quantum key digital signature processing. Specifically, the work ticket number is used to establish a cross-step association with the registration records of S100 and S200; the session identifier is used to establish a session association with subsequent secondary authentication requests; the maintenance personnel identity information, target terminal device information, and maintenance operation instruction information are used to characterize the subject, object, and instruction boundary of this maintenance request; and the timestamp is used to characterize the credential generation time and is used for validity determination on the authentication service center side. The minimum set of core parameters for the credential payload is the work ticket number, session identifier, maintenance personnel identity information, target terminal device information, maintenance operation instruction information, and timestamp. The absence of any field will result in an incomplete credential payload and trigger a rejection status registration.
[0044] In the quantum key digital signature processing stage, the quantum access controller invokes the quantum key to perform digital signature operations on the credential payload, generating a dynamic operation and maintenance credential and registering its status. Understandably, the quantum key is a key resource that the quantum access controller can access. The quantum key establishes a consistent access relationship with the quantum authentication switch and authentication service center through a registered key index. During this step, the quantum access controller reads the key index and completes the quantum key loading. The quantum key loading process includes key index verification and key validity period verification. Key index verification determines whether the quantum key corresponds to the quantum authentication switch identifier, and key validity period verification determines whether the quantum key is in a usable state. When quantum key loading fails, the quantum access controller registers the operation and maintenance request as rejected and writes the reason for the key loading failure into the key loading failure record. The quantum key digital signature processing operation is implemented by the signature processing unit of the quantum access controller. The signature processing unit performs sequential solidification and field normalization on the credential payload, then performs the signature operation and generates a signature result field. The signature result field and the credential payload combine to form the dynamic operation and maintenance credential. In this embodiment, the dynamic operation and maintenance credential includes a credential payload, a signature result field, and a policy version number field. The policy version number field is taken from the operation and maintenance permission policy and is used to verify the consistency of the policy version used for authentication at the authentication service center. The quantum access controller writes the dynamic operation and maintenance credential into the credential registration record. The credential registration record includes a work ticket number, a session identifier, a timestamp, a policy version number, and a credential status. The credential status includes two categories: generated and ungenerated. When the credential status is ungenerated, the quantum access controller writes the rejection reason record into the operation and maintenance management platform registration record and issues a blocking status flag to the quantum authentication switch, so that the data flow corresponding to the operation and maintenance request is in a blocked state.
[0045] Regarding the output and destination of this step, the quantum access controller uses the output field name "Dynamic Operation and Maintenance Certificate" as the final output product of this step, and provides the "Dynamic Operation and Maintenance Certificate" as the input position S400 for the next step, for use in subsequent secondary authentication request generation and authentication judgment processing; at the same time, the work ticket number, session identifier, timestamp and policy version number fields in the dynamic operation and maintenance certificate are bound to the registration records of the operation and maintenance management platform, so that the cross-step connection from S300 to S400 has a consistent session association and source traceability relationship.
[0046] The technical effects of this step can be summarized as follows: By using the operation and maintenance permission policy as a constraint to match the execution subject, object, and instruction of the operation and maintenance request on the quantum access controller side, and assembling the matched request with a timestamp and using quantum key execution to execute digital signature to generate dynamic operation and maintenance credentials, subsequent secondary authentication requests have a unified credential payload and signature field; by writing the policy version number into the dynamic operation and maintenance credentials and binding it with the registration record of the operation and maintenance management platform, the authentication judgment process has a consistent policy version association; and by rejecting the acceptance status registration and blocking the issuance of status flags, operation and maintenance requests that do not meet the constraints form a clear running branch before entering the S400.
[0047] S400. Based on the dynamic operation and maintenance certificate, perform secondary authentication request generation and authentication judgment processing to generate a release command or blocking status.
[0048] This step uses the dynamic operation and maintenance credential output by S300 as the sole authentication input carrier. It establishes a shared origin with the operation and maintenance permission policy output by S200 in the operation and maintenance management platform registration record through the work ticket number, session identifier, and policy version number. Upon entering this step, the quantum access controller triggers a secondary authentication request generation process and initiates a secondary authentication request to the authentication service center. This secondary authentication request is forwarded to the authentication service center via the quantum authentication switch and then enters the authentication judgment processing link. Understandably, the dynamic operation and maintenance credential is the core content of the secondary authentication request. The dynamic operation and maintenance credential includes a credential payload, a signature result field, and a policy version number field. The credential payload is formed by combining the work ticket number, session identifier, operation and maintenance personnel identity information, target terminal device information, operation and maintenance operation instruction information, and a timestamp. The authentication service center is a service device that performs secondary authentication request parsing, verification, and authentication judgment. The authentication service center and the operation and maintenance management platform maintain interoperability in the same management domain, and are used to invoke the operation and maintenance permission policy corresponding to the work ticket number and its registration record during authentication judgment. At the beginning of this step, the quantum access controller performs credential registration and verification on the dynamic operation and maintenance credential. The credential registration and verification process includes retrieving credential registration records and verifying the consistency of credential status, session identifier, and policy version number. If the credential registration and verification process fails, the quantum access controller generates a blocking status and issues a blocking status flag to the quantum authentication switch. At the same time, the reason for blocking is written into the operation and maintenance management platform registration record, so that the dynamic operation and maintenance credential does not enter the secondary authentication request processing link of the authentication service center.
[0049] In the secondary authentication request generation process, the quantum access controller performs encapsulation and assembly processing on the dynamic operation and maintenance credential and generates a secondary authentication request. This encapsulation and assembly process includes three sub-processes: request header assembly, request body assembly, and request integrity verification. The request header assembly is used to write the work ticket number, session identifier, quantum authentication switch identifier, and quantum access controller identifier. The request body assembly is used to write the dynamic operation and maintenance credential and related summary fields. The request integrity verification is used to determine whether the request header and request body meet the field structure requirements accepted by the authentication service center. Specifically, the related summary fields include a timestamp summary, an operation and maintenance personnel identity information summary, a target terminal device information summary, and an operation and maintenance instruction information summary. These summary fields are generated by the quantum access controller after normalizing the corresponding fields in the credential payload and are bound to the session identifier. The field normalization process includes field length constraints, character set constraints, and sequence fixing. Field length constraints control the fixed length of the summary field, character set constraints control the range of characters in the summary field, and sequence fixing ensures that the generation order of the same field is consistent across different devices, providing the authentication service center with a unified parsing path during verification. After completing the packaging and assembly process, the quantum access controller performs a request integrity check. This check includes verifying the integrity and consistency of the verification fields. Verifying field integrity determines that both the dynamic maintenance credential and the summary field have been written into the secondary authentication request. Verifying field consistency determines that the summary field matches the corresponding field in the credential payload of the dynamic maintenance credential. When the request integrity check fails, the quantum access controller generates a blocking status and registers the reason for the request generation failure. This reason is written into the maintenance management platform's registration record and bound to the session identifier. Understandably, the minimum set of core parameters for the secondary authentication request consists of the dynamic maintenance credential, the work ticket number, and the session identifier. The absence of any one parameter will prevent the authentication service center from establishing an association with the maintenance permission policy. The quantum authentication switch identifier and the quantum access controller identifier are link auditable fields used to register the request source on the authentication service center side. After the quantum admission controller generates the secondary authentication request, it sends the secondary authentication request to the quantum authentication switch and records the sending time. The quantum authentication switch performs forwarding registration and link state registration on the secondary authentication request. The link state registration includes two types of states: forwarding success and forwarding failure. If the link state is forwarding failure, the quantum admission controller generates a blocking state and writes it into the link state record.
[0050] In the authentication process, after receiving a secondary authentication request, the authentication service center performs acceptance registration and parsing. The acceptance registration includes a binding record of the receiving time, work ticket number, session identifier, quantum authentication switch identifier, and quantum access controller identifier, which is written to the registration area of the authentication service center. The parsing process includes extracting the dynamic operation and maintenance credential, relevant summary fields, and request header fields from the secondary authentication request, and performing structural verification on the field structure. Structural verification determines whether the dynamic operation and maintenance credential contains a credential payload, signature result field, and policy version number field; and whether the credential payload contains a work ticket number, session identifier, operation and maintenance personnel identity information, target terminal device information, operation and maintenance operation instruction information, and a timestamp. When the structural verification fails, the authentication service center generates a blocking status and writes it to the acceptance failure reason record. Furthermore, the authentication service center performs digital signature verification and timestamp validity determination on the dynamic operation and maintenance credential. Digital signature verification determines whether the correspondence between the signature result field and the credential payload meets the verification rules, and timestamp validity determination determines whether the timestamp is within a valid time window. Understandably, in this embodiment, the digital signature verification process is completed based on the registration relationship of quantum keys. The authentication service center retrieves the key index and loads the quantum key according to the quantum access controller identifier in the request header. Then, it performs field order solidification and field normalization processing on the credential payload to obtain the payload to be verified. Finally, it uses the quantum key to perform verification operations on the payload to be verified and outputs the verification conclusion. The field order solidification and field normalization processing adopts the same field length constraints, character set constraints, and order solidification rules as the quantum access controller. The version number of the rules is registered between the authentication service center and the operation and maintenance management platform and associated with the session identifier. The timestamp validity determination process includes two levels of determination: the first level is the consistency determination of the timestamp and the operation and maintenance time domain. The authentication service center retrieves the operation and maintenance time domain in the registration record of the operation and maintenance management platform according to the work ticket number and determines whether the timestamp falls within the operation and maintenance time domain; the second level is the consistency determination of the timestamp and the valid time window. The valid time window is generated and registered by the authentication service center according to the session identifier. The valid time window has a fixed correlation with the receiving time. Dynamic operation and maintenance credentials that exceed the valid time window are determined to be invalid and enter a blocking state. If either of the above two levels of judgment fails, the authentication service center generates a blocking status and writes an invalid timestamp reason record.
[0051] After completing the digital signature verification and timestamp validity determination, the authentication service center performs policy consistency verification and authentication judgment. The policy consistency verification determines whether the policy version number field in the dynamic maintenance certificate matches the current valid version of the maintenance permission policy registered in the maintenance management platform. If they do not match, the authentication service center generates a blocking status and writes a record indicating the reason for the policy version number inconsistency. The authentication judgment is based on the maintenance permission policy. The authentication service center retrieves the corresponding maintenance permission policy according to the work ticket number and performs policy matching verification on the maintenance personnel identity information, target terminal device information, and maintenance operation instruction information in the certificate payload. This policy matching verification is consistent with the subject matching, object matching, and instruction matching on the quantum access controller side. The verification process outputs either a pass or a fail conclusion. Specifically, the subject matching verification checks the binding relationship between the maintenance personnel identity information and the maintenance account / user group; the object matching verification checks the mapping relationship between the target terminal device information and the asset identifier; and the instruction matching verification checks the maintenance operation instruction information against the instruction boundary records of the maintenance time domain and maintenance target file. Understandably, the core parameter set for authentication processing consists of the operation and maintenance (O&M) permission policy and dynamic O&M credentials. The absence of any one parameter will prevent authentication from proceeding. The O&M management platform registration record serves as the associated data source for authentication, providing the current valid version and O&M time domain of the O&M permission policy. After completing the authentication processing, the authentication service center generates an authentication record, which includes the session identifier, work ticket number, authentication conclusion, and a record of the blocking reason or a summary of the passing reason. This authentication record is then written into the O&M management platform registration record, forming a traceable chain across main steps.
[0052] In the generation of release instructions or blocking statuses, the authentication service center generates release instructions or blocking statuses based on the authentication conclusion and returns the generation results to the quantum access controller via the quantum authentication switch. Specifically, when the authentication conclusion is successful, the authentication service center generates a release instruction, which includes a session identifier, work ticket number, target terminal device information, a summary of maintenance operation instructions, and a release time window. The release time window and the effective time window have a corresponding relationship and are registered. When the authentication conclusion is unsuccessful, the authentication service center generates a blocking status, which includes a session identifier, work ticket number, and a blocking reason record. After receiving the release instruction or blocking status returned by the authentication service center, the quantum access controller performs receipt registration and status transmission processing. Receipt registration includes a binding record of the reception time, session identifier, work ticket number, and returned content summary. Status transmission processing includes issuing a release instruction or blocking status flag to the quantum authentication switch, allowing the data stream corresponding to the maintenance request to enter the release or blocking path. When the quantum authentication switch receives a pass command, it registers the data stream corresponding to the maintenance request as passable and allows the data stream to enter subsequent session key generation, access control rule distribution, and maintenance project execution. When it receives a block status flag, it registers the data stream corresponding to the maintenance request as blockable and refuses the data stream from entering the subsequent processing link. Understandably, the minimum set of core parameters for pass commands and block statuses is the session identifier and work ticket number; the absence of either parameter will prevent the quantum authentication switch from locating the corresponding data stream. The target terminal device information and the maintenance operation instruction information digest are constraint fields of the pass command, used to verify the consistency between the execution object and the instruction scope in subsequent maintenance project execution.
[0053] Regarding the output and destination of this step, the release command or blocking status generated by the authentication service center is the final output of this step. The release command or blocking status of the output field name is received by the quantum access controller and sent to the quantum authentication switch to be registered as a data flow control status. The release command or blocking status is then provided as the "release command or blocking status" for the next input position S500, so that the subsequent session key generation, access control rule issuance and operation and maintenance project execution have clear entry conditions and path branches. At the same time, the authentication judgment record and receipt registration are written into the operation and maintenance management platform registration record, forming a cross-step association chain from the S300 dynamic operation and maintenance certificate to the S400 release command or blocking status.
[0054] S500: Based on the release command or blocking status, perform session key generation, access control rule distribution and operation and maintenance project execution processing to generate operation and maintenance result ciphertext and operation and maintenance related data.
[0055] This step uses the S400's output of the allow command or blocking status as the entry condition and link branch input, and establishes a consistent binding relationship with the session identifier, the work ticket number, and the target terminal device information before proceeding with the processing link. Specifically, the execution entity is jointly composed of the quantum authentication switch, the quantum access controller, the operation and maintenance terminal, the target IoT terminal, the remote operation and maintenance platform, and the operation and maintenance management platform. The quantum authentication switch is used to maintain the allow or block status of the data stream corresponding to the operation and maintenance request. The quantum access controller is used to receive the allow command and trigger subsequent session key generation and access control rule issuance. The operation and maintenance terminal is used to carry the interaction input of operation and maintenance personnel to the operation and maintenance project and act as a relay in the near-field wireless security operation and maintenance scenario. The target IoT terminal is used to receive access control rules and execute the operation and maintenance project under the rule constraints. The remote operation and maintenance platform is used to store the registered versions of the operation and maintenance target files and operation and maintenance operation instruction information required for the execution of the operation and maintenance project and to receive the encrypted operation and maintenance results. The operation and maintenance management platform is used to register the allow status, blocking status, access control rule version, and operation and maintenance project execution record at the session identifier level. Understandably, the release instruction describes the release state of the data stream, and the blocking state describes the blocking state of the data stream; both are one of the minimum input sets for this step. The other minimum input set is the session identifier and the work ticket number, used to locate the registration record and subsequent output destination of the same maintenance request. When the quantum authentication switch is in a blocking state, the quantum admission controller executes a blocking maintenance process upon receiving the blocking state. This blocking maintenance process includes establishing a blocking maintenance record for the maintenance request corresponding to the session identifier, rejecting the maintenance request from entering the session key generation and access control rule distribution process, and simultaneously writing the blocking maintenance record into the registration record of the maintenance management platform and associating it with the blocking reason record, ensuring that the blocking state output by the S400 remains consistent within the maintenance time domain. Conversely, when the quantum authentication switch is in the allow state, the quantum access controller performs an allow confirmation process after receiving the allow command. This process includes verifying whether the allow time window matches the current time, whether the target terminal device information matches the target terminal device information digest in the allow command, and whether the operation and maintenance instruction information digest matches the digest field in the allow command. If verification fails, the system enters a blocking state and records the reason for the failure. If verification succeeds, the system triggers session key generation and enters the access control rule distribution and operation and maintenance project execution processing chain. To support automated triggering and auditability, the operation and maintenance management platform registers a session audit record for each allow confirmation process. The session audit record includes the session identifier, the work ticket number, the allow confirmation conclusion, the allow time window, and the execution node identifier, and maintains field consistency with the operation and maintenance related data to be collected by the S600.
[0056] In the session key generation process, the quantum access controller performs session key generation based on the session identifier, the timestamp, and the preset key, and distributes the generated session key to the maintenance terminal and the target IoT terminal. The session key is key data used to encrypt subsequent maintenance project interaction data. The preset key is key material registered on the maintenance management platform and bound to the target IoT terminal. The timestamp is a time sampling value within the release time window corresponding to the release instruction. Specifically, the session key generation process includes four sub-processes: input assembly, random number assembly, key derivation, and key registration. Input assembly assembles the session identifier, the timestamp, and the target IoT terminal identifier into a key generation input. Random number assembly generates random numbers from both the maintenance terminal and the target IoT terminal and sends them back to the quantum access controller for merging and registration. Key derivation performs derivation operations based on the preset key and the key generation input and outputs the session key. Key registration binds the key index of the session key to the session identifier and writes it into the maintenance management platform's registration record. Understandably, key derivation uses the national standard SM4 (SM4 Block Cipher) as the implementation basis for the symmetric encryption algorithm. In this embodiment, the national standard SM4 is executed by the encryption module of the quantum access controller. The encryption module includes a key loading unit and an encryption operation unit. The key loading unit is used to load the preset key and complete the key index registration. The encryption operation unit is used to perform block encryption operation on the key generation input and output the session key material. The input of the national standard SM4 is the key generation input and the preset key, and the output is the session key. To handle boundary constraints, if the link status between the maintenance terminal and the target IoT terminal is abnormal in a near-field wireless security maintenance scenario, causing the random number transmission to fail, the quantum access controller writes a random number missing record and enters a blocking state. If the allowance time window exceeds the limit, causing the timestamp to fail the validity determination, the quantum access controller writes an invalid timestamp record and enters a blocking state. The process then proceeds to the distribution of access control rules. These access control rules are a set of constraint rules for operation and maintenance target files, operation and maintenance operations, and operation and maintenance time domains. The minimum set of access control rules consists of operation and maintenance target file constraints, operation and maintenance operation constraints, and operation and maintenance time domain constraints, and they maintain a common origin association with the operation and maintenance permission policy.Specifically, the quantum access controller extracts policy entries matching the work ticket number from the operation and maintenance permission policy and performs rule assembly processing. The rule assembly processing includes mapping the target terminal device information to the target IoT terminal identifier, mapping the operation and maintenance operation instruction information to the operation and maintenance operation entries, writing the operation and maintenance time domain into the rule validity period field, and writing the operation and maintenance target file into the target file identifier field. After the rule assembly processing is completed, an access control rule version number is generated and written into the operation and maintenance management platform registration record, so that the same session identifier can be traced back to the access control rule version number when subsequent operation and maintenance related data are collected. Access control rules are issued by the maintenance terminal acting as a relay in a near-field wireless security maintenance scenario. After receiving the access control rules from the quantum access controller, the maintenance terminal encapsulates and encrypts the rules before issuing them to the target IoT terminal. The encapsulation and encryption process uses the session key as input to encrypt the access control rule payload and generate ciphertext. Upon receiving the ciphertext, the target IoT terminal uses the session key to decrypt and recover the access control rule payload. After recovery, it binds the access control rule version number and the session identifier to register it as a local execution context. In this chain, the inputs to the maintenance terminal and the target IoT terminal are the session key and the access control rules, and the outputs are the ciphertext and the recovery result. The inputs to the quantum access controller are the permission command, the maintenance permission policy, and the session identifier, and the outputs are the session key and the access control rule version number.
[0057] During the execution of the operation and maintenance project, the target IoT terminal executes the operation and maintenance project based on the access control rules and generates encrypted operation and maintenance results and operation and maintenance related data. The operation and maintenance project belongs to a set of execution projects mapped from the operation and maintenance task execution information corresponding to the work ticket number. The inputs of the operation and maintenance project include the operation and maintenance operation instruction information, the operation and maintenance target file, and the access control rules. The outputs of the operation and maintenance project include the operation and maintenance execution status, operation and maintenance result data, and execution log data. The encrypted operation and maintenance result data is encrypted data formed by encrypting the operation and maintenance result data with a session key. The operation and maintenance related data is a structured data set formed during the execution of the operation and maintenance project and used for constructing the S600 dynamic network security graph. Specifically, before entering the operation and maintenance project execution, the target IoT terminal performs rule verification processing. The rule verification processing includes verifying whether the operation and maintenance time domain covers the current time, verifying whether the operation and maintenance operation item is consistent with the operation and maintenance operation instruction information, and verifying whether the target file identifier field is consistent with the operation and maintenance target file. If any verification fails, a blocking status is generated and written to the local execution context. Simultaneously, the blocking status is transmitted back to the operation and maintenance management platform for registration through the operation and maintenance terminal. After the rule verification is passed, the target IoT terminal executes the maintenance project corresponding to the maintenance operation instruction information. In this embodiment, the maintenance project includes three types of actions: configuration change, operation status query, and log collection. The configuration change action reads the configuration entries from the maintenance target file and writes them to the local configuration area. The operation status query action collects operation status data and forms status information data. The log collection action reads the raw log data and forms log fragments. All of the above actions are triggered within the maintenance time domain. The triggering condition is that the target IoT terminal receives the maintenance operation entry that has passed the rule verification. The execution order is determined by the instruction sequence in the maintenance operation instruction information. To adapt to link anomaly handling, if a short-range wireless link interruption causes the maintenance terminal to be unable to continuously relay, the target IoT terminal enters a pause state based on the access control rule version number in the local execution context and retains the generated maintenance result data and execution log data. After the link is restored, the maintenance terminal re-initiates a resume request bound to the session identifier. The resume request enters the resume path if the quantum authentication switch is still in the allowed state, and enters the blocked path if it is in the blocked state. The registration of the resume request and the resume path are both written into the registration record of the maintenance management platform.The generation of encrypted operation and maintenance results is performed by the target IoT terminal. Specifically, the target IoT terminal assembles operation and maintenance result data, execution log data, and status information data into an operation and maintenance result payload, performs SM4 encryption using the session key, and outputs encrypted operation and maintenance results. The encrypted operation and maintenance results are then relayed to the remote operation and maintenance platform via the operation and maintenance terminal for storage and registration. Simultaneously, the target IoT terminal categorizes operation and maintenance related data by session identifier. The operation and maintenance related data includes the session identifier, the work ticket number, the access control rule version number, the operation and maintenance operation item, the target file identifier field, the execution time record, the operation and maintenance execution status, the running status data digest, the original log data digest, and the release status flag. The operation and maintenance related data is transmitted back to the operation and maintenance management platform by the operation and maintenance terminal and registered as operation and maintenance related data records on the operation and maintenance management platform. The maintenance terminal is located at the substation site and establishes a connection with the target IoT terminal via short-range wireless. The remote maintenance platform is located in the dispatch center and receives the ciphertext of the maintenance result through the network domain of the quantum authentication switch. After receiving the release command, the quantum access controller automatically triggers session key generation and issues access control rules. After the rules are verified, the target IoT terminal executes the maintenance project according to the instruction sequence and generates the ciphertext of the maintenance result and maintenance-related data, thus forming a continuous operation link from the S400 release command to the S500 ciphertext of the maintenance result and maintenance-related data. Finally, in terms of the output and destination of this step, the output field name "ciphertext of the maintenance result" and the output field name "maintenance-related data" are the final output products of this step. After being bound with the session identifier, they are written into the registration records of the remote maintenance platform and the maintenance management platform, respectively. The ciphertext of the maintenance result and maintenance-related data are provided as the "ciphertext of the maintenance result and maintenance-related data" for the next input position S600, so that the dynamic network security graph construction, static segmentation, and static graph matrix generation processing of S600 obtain the same source input.
[0058] S600. Based on the encrypted operation and maintenance results and operation and maintenance related data, perform dynamic network security graph construction, static segmentation and static graph matrix generation processing to generate anomaly detection results.
[0059] This step uses the encrypted operation and maintenance (O&M) results and related O&M data, output and registered by the preceding S500, as input sources. The encrypted O&M results are encrypted using the national standard SM4 cryptography by the target IoT terminal based on the session key, relayed to the remote O&M platform via the O&M terminal, and stored and registered. The related O&M data is returned by the O&M terminal to the O&M management platform and registered according to the session identifier, work ticket number, and access control rule version number. Understandably, the encrypted O&M results carry the encrypted payload of O&M result data and execution log data generated during the O&M project execution. The related O&M data carries structured fields such as O&M operation entries, target file identifier fields, execution time records, O&M execution status, running status data digests, raw log data digests, and release status flags. This step maintains the session identifier as the primary index in the processing chain, retrieves records matching the session identifier from both the remote O&M platform and the O&M management platform, and merges them with the same session, thereby forming the original input set required for constructing a dynamic network security graph. In an engineering operation scenario, the remote operation and maintenance platform in the dispatch center connects with the operation and maintenance management platform to the network domain where the quantum authentication switch is located. The operation and maintenance management platform triggers a session archiving task once every preset time. The session archiving task performs batch processing and pulls the set of session identifiers that are marked as allowed and have the same access control rule version number. When the operation and maintenance project corresponding to the session identifier is in a suspended state and there is a resume request registration, the session archiving task is triggered again after the resume request registration is changed, so that the additional operation and maintenance related data of the same session identifier after the link is restored enters the same merging process and is included in the subsequent graph construction process.
[0060] In the dynamic network security graph construction process, the execution entity is jointly composed of the graph construction module in the remote operation and maintenance platform, the data access module in the operation and maintenance management platform, and the graph registration module. The data access module is used to extract fields from the operation and maintenance related data and perform session-level index binding on the encrypted payload associated with the encrypted operation and maintenance results. The graph construction module is used to map the extracted fields to graph nodes, graph edges, and their attribute fields. The graph registration module is used to register the version number, generation time, and source record of the dynamic network security graph and provide graph snapshot input for subsequent static segmentation. Specifically, the node set of the dynamic network security graph includes operation and maintenance personnel identity information nodes, target terminal device information nodes, operation and maintenance account nodes, operation and maintenance task nodes, operation and maintenance operation item nodes, operation and maintenance work ticket file nodes, access control rule version number nodes, and session identifier nodes; the edge set of the dynamic network security graph includes identity association edges between identity information nodes and operation and maintenance account nodes, ticket task edges between operation and maintenance work ticket file nodes and operation and maintenance task nodes, task asset edges between operation and maintenance task nodes and target terminal device information nodes, session operation edges between session identifier nodes and operation and maintenance operation item nodes, rule constraint edges between access control rule version number nodes and operation and maintenance operation item nodes, state edges between session identifier nodes and release status flags, and data reference edges between target terminal device information nodes and running status data digests and raw log data digests. The minimum set of nodes and edges mentioned above consists of the session identifier node, target terminal device information node, operation and maintenance entry node, access control rule version number node, and session operation edge and rule constraint edge, which is used to express the closed relationship of "operation and maintenance operation entries executed by the same session on the same target terminal device under the same rule version"; the remaining nodes and edges are extended fields to strengthen the association relationship in dimensions such as operation and maintenance account, operation and maintenance task, and operation and maintenance work ticket file, and provide a traceability link for subsequent anomaly detection results. Furthermore, the graph construction module performs field standardization processing on the input fields. This standardization process includes unifying the definitions of the work ticket number, the session identifier, the device identifier of the target terminal device information, and the identity identifier of the maintenance personnel. It also aligns the execution time records with time windows, merging multiple maintenance-related data within the same preset time period into the incremental input of the same graph snapshot. When there are interface-based acquisition channels for security alarm data, raw log data, and operational status data, the data access module also extracts alarm entries and log fragment summaries that match the session identifier from the security alarm data, raw log data, and operational status data acquired through the interface, and writes them as graph attribute fields into the session identifier node and the target terminal device information node. This ensures that the dynamic network security graph simultaneously includes maintenance-side fields and operational-side fields.To handle anomalies and boundary constraints, if the storage registration of the encrypted operation and maintenance results is incomplete or the encrypted payload is unreachable, the data access module writes a record of the missing encrypted data and forms a map snapshot using only the operation and maintenance related data. At the same time, it registers a source missing marker in the map registration module. If there are missing fields in the operation and maintenance related data, the data access module records the missing fields as missing markers and retains their source records, so that the static segmentation and static map matrix generation processes can still be executed in the case of missing data.
[0061] In the static segmentation and static graph matrix generation process, the graph registration module takes the registered snapshot of the dynamic network security graph as input, triggers the static segmentation module to perform static segmentation processing, and the data conversion module performs static graph matrix generation processing. Specifically, the static segmentation is a process of dividing the dynamic network security graph into subgraphs on the node set and edge set according to preset segmentation rules. The segmentation rules include three segmentation dimensions: segmenting the session subgraph according to the session identifier, segmenting the asset subgraph according to the target terminal device information, and segmenting the rule subgraph according to the access control rule version number. Among them, the session subgraph segmentation is the smallest segmentation set, which is used to make each subgraph correspond to a single session identifier and can establish a mapping relationship with the work ticket number. During execution, the static segmentation module first performs segmentation index construction processing on the dynamic network security graph. This process adds segmentation tags to each session operation edge, rule constraint edge, and task asset edge. The segmentation tags are derived from the session identifier, the device identifier of the target terminal device information, and the access control rule version number, and are written into the edge attribute field. Subsequently, based on the segmentation tags, the graph snapshot is split into multiple static subgraphs. The node set and edge set of each static subgraph are subsets of the node set and edge set of the dynamic network security graph. In each static subgraph, the session identifier node and the access control rule version number node are retained as anchor nodes. Further, the static segmentation module performs static segmentation consistency verification processing on the static subgraphs. This verification includes checking whether the anchor nodes in the static subgraphs are unique, whether the session operation edges are connected to the maintenance operation item nodes, and whether the rule constraint edges point to the same access control rule version number node. If the verification fails, a segmentation anomaly record is generated, and the static subgraph is marked as a low-trust input. If the verification passes, the data conversion module is initiated.
[0062] The static graph matrix generation process is executed by the data conversion module. The static graph matrix is structured data that converts the node and edge sets of a static subgraph into a matrix representation. The data conversion module takes a static subgraph as input and outputs a static graph matrix carrying source records and segmentation labels. Specifically, the data conversion module performs node encoding and edge encoding on the static subgraph. Node encoding maps maintenance personnel identity information nodes, target terminal device information nodes, maintenance account nodes, maintenance task nodes, maintenance operation item nodes, access control rule version number nodes, and session identifier nodes into a node encoding sequence according to a preset field order, and writes the attribute fields of each node into a node attribute matrix. Edge encoding maps identity-related edges, ticket task edges, task asset edges, session operation edges, rule constraint edges, status edges, and data reference edges into an edge encoding sequence, and writes the edge direction, segmentation label, and time window alignment result into an edge attribute matrix. Subsequently, the data conversion module constructs a static graph matrix based on the node encoding sequence and edge encoding sequence. The static graph matrix comprises two parts: a node adjacency matrix and an attribute matrix. The node adjacency matrix represents the connectivity between nodes, while the attribute matrix carries fields such as operation and maintenance execution status, access control status markers, running status data digests, raw log data digests, and security alarm data digests. To reduce noise input unrelated to operation and maintenance, the data conversion module performs static segmentation and field pruning on the attribute matrix. Field pruning retains only the fields directly associated with session identifiers, target terminal device information, operation and maintenance entries, access control rule version numbers, operation and maintenance execution status, and access control status markers as the minimum set of fields. The remaining fields are retained as extended fields in the source record and versioned according to the access control rule version number, ensuring consistent input assembly for subsequent pre-trained models on different versions of the attribute matrix. As an extended implementation, when the remote operation and maintenance platform has decryption permission for the ciphertext of the operation and maintenance results and has registered the key index of the session key, the data conversion module performs ciphertext parsing processing before the static graph matrix is generated. The ciphertext parsing processing retrieves the ciphertext of the operation and maintenance results from the remote operation and maintenance platform using the session identifier as an index, and decrypts the ciphertext of the operation and maintenance results according to the session key to obtain the operation and maintenance results data and execution log data. The digest of the decrypted execution log data is written into the log digest field of the attribute matrix. If the decryption conditions are not available, the ciphertext parsing processing only extracts the ciphertext payload length, ciphertext registration time, and source record of the ciphertext of the operation and maintenance results and writes them into the ciphertext digest field of the attribute matrix, thereby maintaining the executability and field consistency of the static graph matrix generation process under different deployment conditions.
[0063] In the anomaly detection result generation process, the execution entity consists of an anomaly detection module, which includes a pre-trained model, a first model, and a second model. The pre-trained model is a set of models that perform anomaly detection inference on a static graph matrix. The first model is an inference model that determines anomalies in the static graph matrix. The second model is a generation model that generates simulated attack data for attack anomaly detection. Specifically, the anomaly detection module takes the static graph matrix as input and performs input assembly processing. This input assembly processing assembles the node adjacency matrix, attribute matrix, source record, and segmentation label into a model input package, and writes the access control rule version number into the version field of the model input package, ensuring that model input packages with the same access control rule version number enter the same inference queue. Subsequently, the anomaly detection module calls the second model to perform simulated attack data generation processing. This processing extracts session operation edges, rule constraint edges, access status markers, and operation and maintenance execution status fields from the model input packet. Based on preset perturbation rules, it generates multiple sets of simulated attack data without changing the anchor nodes. Each set of simulated attack data includes a simulated sequence of operation and maintenance items, a simulated sequence of access status markers, and a simulated summary of running status data. Each set of simulated attack data shares the same session identifier with the original model input packet for comparison and inference. The minimum set of perturbation rules includes operation and maintenance item replacement perturbation, operation and maintenance time domain offset perturbation, and rule constraint edge breakage perturbation. Operation and maintenance item replacement perturbation replaces operation and maintenance item nodes with other operation and maintenance item nodes under the same operation and maintenance task node. Operation and maintenance time domain offset perturbation performs time window alignment offset on the execution time record while maintaining the segmentation label. Rule constraint edge breakage perturbation disconnects the rule constraint edge from the access control rule version number node and marks it as an abnormal edge attribute. All of these perturbations are output by the second model and registered as simulated attack data records. Subsequently, the anomaly detection module calls the first model to perform inference processing on the original model input packet and the simulated attack data record respectively. The inference processing outputs anomaly score and anomaly label, which are written into the anomaly detection result record. The anomaly detection result record includes the session identifier, the work ticket number, the device identifier of the target terminal device information, the access control rule version number, the anomaly score, the anomaly label, the comparison score corresponding to the simulated attack data, the source record, and the segmentation label. The anomaly detection module writes the anomaly detection result registration table of the operation and maintenance management platform.To adapt to continuous automated operation, the anomaly detection module triggers a batch inference task once every preset time interval. The batch inference task groups the model input packets according to the access control rule version number and binds a model version number registration record to each group. The model version number registration record is used to express the combined version of the pre-trained model, the first model and the second model, and together with the access control rule version number in the anomaly detection result record, forms an auditable dual-version index. When the access control rule version number is updated, the anomaly detection module puts the model input packet corresponding to the new version number into a new group and registers a new model version number registration record, so that the anomaly detection result records of different versions can be distinguished and traced.
[0064] Regarding the output and destination of this step, the anomaly detection result generated and registered by the anomaly detection module is the final output of this step. This anomaly detection result is indexed in the operation and maintenance management platform according to the session identifier and the work ticket number, and associated with the corresponding dynamic network security graph snapshot version number, static segmentation label, and static graph matrix source record. Therefore, the anomaly detection result is provided as the "anomaly detection result" for the next input location S700, enabling S700 to perform target probability level determination, target impact level determination, and matrix coordinate graph mapping processing on the same session identifier dimension.
[0065] The technical effects of this step can be summarized as follows: By merging the encrypted operation and maintenance results with the operation and maintenance-related data within the same session and constructing a dynamic network security graph, the operation and maintenance-side fields and the operation-side fields form a traceable association under the same session identifier index; through static segmentation and static graph matrix generation processing, the dynamic network security graph is transformed into a structured representation that can be used as input for the pre-trained model, the first model, and the second model; by introducing simulated attack data generated by the second model and comparing it with the original model input packets for inference, the anomaly detection result records have a basis for comparison and are registered and transmitted under the dual indexes of access control rule version number and model version number.
[0066] S700. Based on the anomaly detection results, determine the target probability level, determine the target impact level, and perform matrix coordinate diagram mapping to generate a response scheduling strategy.
[0067] This step uses the anomaly detection results registered in the operation and maintenance management platform by the preceding step S600 as the input source. The anomaly detection results include at least the session identifier, the work ticket number, the device identifier of the target terminal device information, the access control rule version number, the anomaly score, the anomaly tag, the comparison score, the source record, and the segmentation tag. The response evaluation module, the level determination module, and the scheduling policy generation module within the operation and maintenance management platform collaborate to complete the processing chain of this step. Understandably, the target probability level is a discrete level expression of the credibility of an anomaly occurrence, the target impact level is a discrete level expression of the scope of business and security impact caused by the anomaly, the matrix coordinate diagram is a two-dimensional coordinate mapping structure jointly determined by the target probability level and the target impact level, and the response scheduling policy is a policy data structure oriented towards subsequent handling orchestration and is bound to the session identifier and the work ticket number, facilitating policy issuance, handling execution, and auditing within the same operation and maintenance meeting context.
[0068] Specifically, the response evaluation module first performs input normalization processing on the anomaly detection results. This input normalization processing includes three sub-processes: field standardization, missing field completion marking, and anomaly detection result deduplication and association merging. Field standardization normalizes the encoding formats of the anomaly score, the control score, and the anomaly label, mapping the scoring scales generated under different model version numbers to a unified scoring scale. The access control rule version number is written into the version field of the unified scoring scale, forming a unified record with traceable scoring sources. Missing field completion marking adds missing field markers for situations such as missing source records, missing encrypted digest fields, or the existence of abnormally segmented records, and these missing field markers are written into the quality field of the anomaly detection result record. Anomaly detection result deduplication addresses multiple batch pushes triggered by the same session identifier within the same preset time period. For duplicate records caused by task interruption, the work ticket number and device identifier are used for deduplication and merging, and the most recently registered anomaly detection result record is retained as the master record. The registration time of the historical record is written into the traceability field of the master record. For multiple anomaly detection result records of the same target terminal device appearing in adjacent time windows, similarity judgment based on segmentation tags and running status data summaries is used for merging. Similar records are aggregated into the same anomaly cluster, and the anomaly cluster identifier field is written into the master record. This allows subsequent level determination to be carried out at the anomaly cluster granularity, reducing the interference of fragmented alarms on scheduling strategy generation. The input normalization processing constitutes the minimum set technical feature of this step. The absence of this processing will lead to inconsistent input criteria for level determination or repeated scheduling triggers, thereby causing strategy oscillations and audit chain breaks.
[0069] After input normalization, the level determination module performs target probability level determination processing. This target probability level determination processing is completed by the probability evaluation unit, which reads the anomaly score, control score, and anomaly label from the anomaly detection results, and combines these with the source record and segmented anomaly record to generate a probabilistic evidence set. This probabilistic evidence set includes at least three types of evidence: score difference evidence, label consistency evidence, and source quality evidence. Score difference evidence is obtained by mapping the difference magnitude between the anomaly score and the control score; label consistency evidence is obtained by determining the stability of the anomaly label within adjacent time windows; and source quality evidence is obtained by comprehensively determining the missing detection markers, segmented anomaly records, and encrypted missing records. Furthermore, the probability assessment unit performs weighted assembly processing on the probabilistic evidence set. This weighted assembly process uses the access control rule version number as an assembly condition and calls the pre-set rule version weight file within the operation and maintenance management platform. When the access control rule version number is in a newly released observation period, the weighted assembly process reduces the weight of source quality evidence and increases the weight of label consistency evidence, thereby avoiding misjudgments of probability levels caused by scoring scale drift due to rule changes. When the access control rule version number is in a stable period, the weighted assembly process increases the weight of source quality evidence and the weight of scoring difference evidence, resulting in higher probability levels for high-confidence anomalies. Subsequently, the probability assessment unit performs probability level mapping processing. This process reads the probability level mapping rule set within the operation and maintenance management platform, projects the weighted probabilistic evidence set onto a discrete level space to obtain the target probability level, and writes the target probability level into the probability level field of the anomaly detection result record, forming an enhanced record with a probability level. The probability level mapping rule set is a combined data structure of discrete thresholds and interval rules, containing at least three levels: low probability, medium probability, and high probability. Each level in the rule set corresponds to a threshold condition including a scoring difference threshold, a label stability condition, and a source quality gating condition. These threshold conditions are written as minimum set parameters into the version field of the rule set and are updated synchronously with the access control rule version number, thus ensuring version consistency and auditability in probability level determination. As anomaly boundary handling, when the anomaly cluster identifier field exists and multiple high-probability records appear within the anomaly cluster, the probability assessment unit performs intra-cluster promotion processing, raising the target probability level of the main record of the anomaly cluster to the highest level within the cluster and registering the promotion basis in the traceability field. When the missing test marker is in a severe state, the probability assessment unit triggers conservative degradation processing, downgrading the target probability level and registering the degradation reason in the quality field, ensuring that subsequent matrix coordinate graph mapping is not overly aggressive.
[0070] After the target probability level is determined, the level determination module performs target impact level determination processing. This target impact level determination processing is completed by the impact assessment unit. The impact assessment unit reads the target terminal device information, maintenance operation entries, maintenance execution status, release status markers, operation status data summaries, and security alarm data summaries from the anomaly detection results, and combines this information with the maintenance task node information associated with the work ticket number to extract impact evidence. This impact evidence extraction includes four types of evidence: asset criticality evidence, operational sensitivity evidence, operational disturbance evidence, and security alarm evidence. Asset criticality evidence is obtained by associating the device identifier of the target terminal device information with the asset classification file. The asset classification file is maintained in the operation and maintenance management platform according to the device identifier and includes fields such as business domain affiliation, service type, redundancy form, and maintenance window. Operation sensitivity evidence is obtained by mapping the operation and maintenance operation items to the operation sensitivity dictionary. The operation sensitivity dictionary classifies common operation and maintenance operation items by sensitivity, covering at least categories such as account permission changes, access control rule changes, core configuration rewriting, firmware upgrades, and log cleanup. Operation disturbance evidence is generated from fault codes, restart events, link jitter, and resource usage mutation markers extracted from the operation status data digest and the original log data digest. Security alarm evidence is generated from the alarm type, alarm frequency, and alarm-related asset range extracted from the security alarm data digest. Furthermore, the impact assessment unit performs impact scope aggregation processing. Based on asset criticality evidence, this processing aggregates multiple device identifiers belonging to the same business domain and exhibiting abnormal cluster identifiers within the same time window into an impact domain, and writes this into the impact domain identifier field of the enhancement record. When the redundancy morphology field indicates sensitivity to single-point failures, the impact scope aggregation processing upgrades the impact domain level and registers the basis in the traceability field. Subsequently, the impact assessment unit performs impact level mapping processing. This process reads the impact level mapping rule set within the operation and maintenance management platform, comprehensively maps the four types of impact evidence and the impact domain identifier field to a discrete level space to obtain the target impact level, and writes the target impact level into the impact level field of the enhancement record. The impact level mapping rule set also has a version field and is maintained in association with the access control rule version number. The judgment conditions corresponding to each impact level in the rule set include four types of gating conditions: asset criticality gating, operation sensitivity gating, operational disturbance intensity gating, and security alarm intensity gating. The gating conditions, as minimal set parameters, remain stable over a long period to avoid discontinuous changes in scheduling strategy generation during version evolution.As an exception boundary handling measure, when the operation and maintenance execution status indicates operation and maintenance failure and a rollback flag exists, the impact assessment unit performs rollback correction processing on the operation sensitivity evidence, lowers the sensitivity weight corresponding to the rollback flag, and retains the rollback correction basis; when the release status flag indicates a blocking status and the operation and maintenance operation item has not been implemented, the impact assessment unit triggers non-implementation correction processing, lowers the weight of the operation disturbance evidence, and registers the non-implementation correction reason in the quality field, so that the impact level is more in line with the actual operation status.
[0071] After obtaining the target probability level and the target impact level, the scheduling strategy generation module performs matrix coordinate graph mapping processing. This mapping process is completed by a coordinate mapping unit, which reads the probability level and impact level fields from the enhancement record and calls the matrix coordinate mapping rule set to generate matrix coordinate fields. The matrix coordinate mapping rule set belongs to a discrete coordinate mapping data structure. The rule set uses the probability level as the discrete scale of the vertical coordinate axis and the impact level as the discrete scale of the horizontal coordinate axis, and configures a response template identifier field for each set of discrete coordinates. The response template identifier field points to the response template library within the operation and maintenance management platform. This library is maintained by template version number and includes fields such as handling path, handling priority, handling window, review requirements, and notification link. The coordinate mapping unit first performs coordinate validity verification during the mapping process. This verification checks whether the probability level and impact level fields fall within the coverage range of the rule set. If they do, they are written into the matrix coordinate field and the response template identifier field. If they exceed the range, a coordinate anomaly flag is written, and the enhanced record is sent to the manual review queue. Subsequently, the coordinate mapping unit performs coordinate stability smoothing. This smoothing process addresses situations where the coordinates of the same session identifier change back and forth within adjacent time windows. It uses majority voting within the time window and a priority rule for the main record of the anomaly cluster to smooth the coordinates. After smoothing, the matrix coordinate field is written into the enhanced record, and the coordinates before smoothing are retained in the traceability field. This makes the scheduling strategy generation more stable and facilitates audit traceability. The coordinate stability smoothing process is a preferred extended function, and the minimum set technical features include coordinate mapping rule set invocation and coordinate validity verification.
[0072] Subsequently, the scheduling policy generation module generates the response scheduling policy based on the matrix coordinate field and the response template identifier field. The response scheduling policy is generated by the policy encapsulation unit, which reads the template content matching the response template identifier field from the response template library and instantiates the policy by combining the session identifier, work ticket number, device identifier, access control rule version number, and exception cluster identifier fields, forming a policy instance record. The policy instance record includes at least a policy identifier field, a policy version field, a policy trigger time field, a policy scope field, and a policy handling constraint field. The policy scope field is composed of the influence domain identifier field and the device identifier, and the policy handling constraint field is composed of the access control rule version number, the maintenance window field, and the review requirement field. Further, the policy encapsulation unit performs handling path orchestration processing, which decomposes the handling paths in the response template library into multi-stage handling sequences and writes execution gating conditions and rollback conditions for each stage. The gating conditions include target probability level gating, target impact level gating, release status flag gating, and operation and maintenance execution status gating. The rollback conditions include anomaly detection result quality field gating and coordinate anomaly flag gating. When any gating condition is not met, the policy encapsulation unit writes the blocking gating flag and marks the policy instance record as pending review. In remote operation and maintenance scenarios of the operator's core network, the operation and maintenance management platform and the remote operation and maintenance platform are deployed in the provincial operation and maintenance center. The target terminal device information corresponds to devices such as core routers, aggregation switches, and authentication gateways. After coordinate mapping, the response scheduling policy automatically triggers the notification link and pushes it to the terminal of the on-duty operation and maintenance personnel. At the same time, a disposal work order is generated on the operation and maintenance management platform. When the target impact level and the target probability level are both high, the disposal path orchestration includes a rapid isolation stage, a permission freezing stage, and an evidence collection and preservation stage, and a dual-person review constraint is written into the review requirement field. When the target impact level or the target probability level is low, the disposal path orchestration includes an observation stage and a review stage, and subsequent actions are triggered within the time period limited by the maintenance window field, so that the policy instance record matches the actual operation and maintenance rhythm. After the policy instance record is generated, it is written into the response scheduling policy registration table of the operation and maintenance management platform by the policy encapsulation unit, and the policy identifier field is written back to the policy reference field of the enhanced record, forming a closed-loop reference relationship from the anomaly detection result to the response scheduling policy.
[0073] In terms of automated triggering and version management, the operation and maintenance management platform configures triggers for the response evaluation module. These triggers activate when a new record is added to the anomaly detection result registration table and the release status is indicated by a release status marker. When the anomaly cluster identifier field or access control rule version number in the anomaly detection result registration table is updated, the trigger is activated again, marking the old policy instance record as requiring review. Simultaneously, a new policy instance record is generated, and the basis for policy replacement is registered in the traceability field. The probability level mapping rule set, impact level mapping rule set, and matrix coordinate mapping rule set all maintain a rule version number field. This rule version number field is bound to the access control rule version number and written into the policy version field of the policy instance record, ensuring traceability of the policy instance record during rule evolution. When the rule version number field is updated, the operation and maintenance management platform registers the update event in the policy audit log and retains a read-only snapshot of historical policy instance records related to the same session identifier, thus providing consistent data for subsequent review and auditing.
[0074] Regarding the output and destination of this step, the target probability level output and registered by the level determination module is written into the probability level field of the enhancement record, the target impact level is written into the impact level field of the enhancement record, the matrix coordinate field output by the coordinate mapping unit is written into the matrix coordinate field of the enhancement record, and the response scheduling policy finally output by the policy encapsulation unit is written into the response scheduling policy registration table of the operation and maintenance management platform and associated with the session identifier, the work ticket number, the device identifier, and the access control rule version number. Thus, this step transforms the anomaly detection result into an executable response scheduling policy data structure. The policy identifier field and policy handling constraint field in the response scheduling policy registration table are available for subsequent handling execution systems to read and call, while the policy reference field points back to the anomaly detection result registration table, forming a closed-loop index from anomaly to policy.
[0075] Example 2: Figure 2 A structural block diagram of a communication equipment security operation and maintenance system according to an embodiment of the present invention is shown. Figure 2 As shown, the structure may include:
[0076] The maintenance task parsing module 01 is used to obtain maintenance work order files and perform digital signature verification and integrity verification to obtain maintenance task execution information. Specifically, this module receives maintenance work order files from the power grid dispatch automation master station system or its own centrally initiated process, performs access registration on the maintenance work order files, and the registration record includes the reception time, sender information, service type, and file identifier. Subsequently, the module sequentially performs format constraint determination, digital signature verification, and integrity verification on the maintenance work order files; wherein, the digital signature verification process calls a preset key to perform signature verification calculation on the extracted digital signature fields, and the integrity verification process normalizes the field content within the verification range, calculates the digest value, and compares it with the integrity verification field. After verification and validation, the module parses the maintenance work ticket file into maintenance task execution information. The maintenance task execution information includes the work ticket number, sender information, business type, maintenance personnel identity information, maintenance account, user group, target terminal device information, maintenance operation instruction information, maintenance time domain, maintenance target file, user password, digital signature verification status, integrity verification status, and parsing and import status fields. The module then outputs the maintenance task execution information to the maintenance permission policy generation module.
[0077] The operation and maintenance permission policy generation module 02 is used to perform target operation and maintenance asset group identification and operation and maintenance personnel specific permission information generation processing based on the operation and maintenance task execution information, and generate operation and maintenance permission policies. Specifically, this module receives operation and maintenance task execution information from the operation and maintenance task parsing module, and triggers the permission orchestration process when its digital signature verification status and integrity verification status are both passed and the parsing and import status is completed. The module first performs field loading and consistency verification on the operation and maintenance task execution information. Field loading forms a set of objects to be identified, and consistency verification is carried out around the operation and maintenance time domain, the network access status of the target terminal device information, and the affiliation relationship between the operation and maintenance account and user group. Subsequently, the module uses the target terminal device information as the identification primary key, combined with the business type and user group as identification constraints, to perform matching processing on the host asset table snapshot to identify the target maintenance asset group. Simultaneously, using maintenance personnel identity information, maintenance accounts, and user groups as generation primary keys, combined with maintenance operation instruction information, maintenance time domain, and maintenance target files as generation constraints, the module performs identity field normalization processing, attribution verification processing, and instruction set parsing processing to generate specific maintenance personnel permission information. Finally, the module performs policy assembly processing on the target maintenance asset group and the specific maintenance personnel permission information, generating a maintenance permission policy containing a set of policy entries and a policy version number field. This maintenance permission policy is then output to the dynamic maintenance credential generation module for invocation, and the policy entries are registered in the maintenance management platform.
[0078] The dynamic maintenance credential generation module 03 is used to obtain maintenance requests according to the maintenance permission policy and extract maintenance personnel identity information, target terminal device information, and maintenance operation instruction information. It then performs timestamp assembly and quantum key digital signature processing to obtain dynamic maintenance credentials. Specifically, this module is triggered when a maintenance personnel initiates a maintenance request, which is generated by a mobile terminal and forwarded by a quantum authentication switch. The module first performs access registration and session identifier generation processing on the maintenance request, and extracts maintenance personnel identity information, target terminal device information, and maintenance operation instruction information from the request. Next, constrained by the maintenance permission policy, the module performs policy matching processing on the extracted maintenance personnel identity information, target terminal device information, and maintenance operation instruction information, including three sub-processes: subject matching, object matching, and instruction matching. After successful policy matching, the module performs timestamp assembly processing, generating a timestamp and binding it to the session identifier. The work ticket number, session identifier, maintenance personnel identity information, target terminal device information, maintenance operation instruction information, and timestamp are combined to form the credential payload. Subsequently, the module calls the quantum key to perform a digital signature operation on the credential payload, generating a dynamic operation and maintenance credential that includes the credential payload, a signature result field, and a policy version number field, and outputs the dynamic operation and maintenance credential to the secondary authentication control module.
[0079] The secondary authentication control module 04 is used to generate a secondary authentication request based on the dynamic operation and maintenance certificate and perform authentication judgment processing to generate a release command or a blocking status. Specifically, this module receives the dynamic operation and maintenance certificate from the dynamic operation and maintenance certificate generation module and performs certificate registration and verification processing on it. After successful verification, the module performs encapsulation and assembly processing on the dynamic operation and maintenance certificate to generate a secondary authentication request. The encapsulation and assembly processing includes request header assembly, request body assembly, and request integrity verification. The module sends the generated secondary authentication request to the quantum authentication switch, which forwards it to the authentication service center. After receiving the secondary authentication request, the authentication service center performs acceptance registration and parsing processing, and sequentially performs digital signature verification processing, timestamp validity determination processing, policy consistency verification, and authentication judgment processing on the dynamic operation and maintenance certificate. The authentication judgment processing is based on the operation and maintenance permission policy and performs policy matching and verification processing on the operation and maintenance personnel identity information, target terminal device information, and operation and maintenance operation instruction information in the certificate payload. Based on the authentication conclusion, the authentication service center generates a release command or a blocking status. The release command includes a session identifier, work ticket number, target terminal device information, a summary of operation and maintenance instructions, and a release time window. The blocking status includes a session identifier, work ticket number, and a blocking reason record. The generated release command or blocking status is returned via the quantum authentication switch and output to the operation and maintenance execution and access control module.
[0080] The operation and maintenance execution and access control module 05 is used to perform session key generation, access control rule distribution, and operation and maintenance project execution processing according to the release command or blocking status, generating encrypted operation and maintenance results and operation and maintenance related data. Specifically, this module receives the release command or blocking status from the secondary authentication control module. When in the release status, the module performs release confirmation processing, and triggers session key generation processing after verification. The session key generation processing generates a session key based on the session identifier, timestamp, and preset key, and distributes the session key to the operation and maintenance terminal and the target IoT terminal. Subsequently, the module extracts the policy entry matching the work ticket number from the operation and maintenance permission policy, performs rule assembly processing, generates access control rules and their version numbers, and distributes the encrypted access control rules to the target IoT terminal through the operation and maintenance terminal. The target IoT terminal performs rule verification processing based on the received access control rules. After successful verification, it executes the maintenance project according to the maintenance operation instructions, generating maintenance result data and execution log data. The maintenance result payload is then encrypted using a session key to obtain the maintenance result ciphertext. Simultaneously, maintenance-related data is aggregated, including a session identifier, work ticket number, access control rule version number, maintenance operation item, target file identifier field, execution time record, maintenance execution status, running status data digest, original log data digest, and release status marker. The maintenance result ciphertext is sent to a remote maintenance platform for storage and registration, and the maintenance-related data is transmitted back to the maintenance management platform for registration. Both are then output to the security graph and anomaly detection module.
[0081] The security graph and anomaly detection module 06 is used to perform dynamic network security graph construction, static segmentation, and static graph matrix generation processing based on the encrypted operation and maintenance results and the operation and maintenance related data, generating anomaly detection results. Specifically, this module pulls the encrypted operation and maintenance results and operation and maintenance related data records that match the session identifier from the remote operation and maintenance platform and operation and maintenance management platform, and performs session merging to form the original input set. The module maps the input fields to graph nodes and edges through the graph construction module, constructing a dynamic network security graph containing operation and maintenance personnel identity information nodes, target terminal device information nodes, operation and maintenance operation item nodes, access control rule version number nodes, and session operation edges and rule constraint edges. Subsequently, the graph registration module outputs a graph snapshot to the static segmentation module, which performs static segmentation processing on the graph snapshot according to three dimensions: session identifier, target terminal device information, and access control rule version number, splitting it into multiple static subgraphs. The data conversion module performs node encoding and edge encoding processing on the static subgraphs to generate a static graph matrix composed of a node adjacency matrix and an attribute matrix. Finally, the anomaly detection module assembles the static graph matrix into a model input package, calls the second model to generate simulated attack data, and calls the first model to perform inference processing on the original model input package and the simulated attack data. It outputs anomaly detection results containing session identifier, work ticket number, target terminal device information, access control rule version number, anomaly score, anomaly label and comparison score. The anomaly detection results are registered in the operation and maintenance management platform and output to the response scheduling strategy generation module.
[0082] The response scheduling strategy generation module 07 is used to perform target probability level determination, target impact level determination, and matrix coordinate graph mapping processing based on the anomaly detection results to generate a response scheduling strategy. Specifically, this module receives anomaly detection results registered in the operation and maintenance management platform. First, the response evaluation module performs input normalization processing on the anomaly detection results, including field standardization, missing field completion marking, and deduplication and association merging of anomaly detection results. The level determination module reads the normalized anomaly detection results. Its probability evaluation unit determines the target probability level based on anomaly score, comparison score, anomaly label, and source quality evidence. Its impact evaluation unit determines the target impact level based on impact evidence such as target terminal device information, operation and maintenance operation items, operation and maintenance execution status, running status data summary, and security alarm data summary. Subsequently, the coordinate mapping unit of the scheduling strategy generation module maps the target probability level and target impact level to matrix coordinate fields and corresponding response template identifier fields according to the matrix coordinate mapping rule set. Finally, the policy encapsulation unit matches template content from the response template library based on the matrix coordinate field and the response template identifier field, and instantiates the policy by combining the session identifier, work ticket number, device identifier, and access control rule version number, generating a response scheduling policy that includes a policy identifier field, a policy version field, a policy trigger time field, a policy scope field, and a policy handling constraint field, and registers the response scheduling policy in the response scheduling policy registration table of the operation and maintenance management platform.
Claims
1. A method for secure operation and maintenance of communication equipment, characterized in that, include: S100: Obtain the maintenance work ticket file, perform digital signature verification and integrity check processing, and obtain maintenance task execution information; S200. Based on the operation and maintenance task execution information, identify the target operation and maintenance asset group, generate specific permission information of operation and maintenance personnel, and generate operation and maintenance permission policy. S300. Based on the operation and maintenance permission policy, perform timestamp assembly and quantum key digital signature processing to obtain dynamic operation and maintenance credentials; S400. Based on the dynamic operation and maintenance certificate, perform secondary authentication request generation and authentication judgment processing to generate a release command or blocking status. S500: Based on the release command or blocking status, perform session key generation, access control rule distribution and operation and maintenance project execution processing to generate operation and maintenance result ciphertext and operation and maintenance related data. S600. Based on the encrypted operation and maintenance results and operation and maintenance related data, perform dynamic network security graph construction, static segmentation and static graph matrix generation processing to generate anomaly detection results. S700. Based on the anomaly detection results, determine the target probability level, determine the target impact level, and perform matrix coordinate graph mapping to generate a response scheduling strategy.
2. The method according to claim 1, characterized in that, Digital signature verification and integrity checks include: The digital signature verification and integrity verification process includes performing format constraint determination, digital signature verification, and integrity verification on the maintenance work ticket file. The digital signature verification process includes signature material extraction, signature content parsing, signature comparison, and signature result registration. The integrity verification process includes determining the verification scope, standardizing the verification content, reviewing the integrity verification fields, and registering the integrity conclusion.
3. The method according to claim 1, characterized in that, The process of identifying target maintenance asset groups, generating specific permission information for maintenance personnel, and generating maintenance permission policies includes: The target maintenance asset group identification process includes using target terminal device information as the identification primary key, combined with business type and user group as identification constraints, and performing matching and disambiguation processing on the host asset table snapshot. The maintenance personnel specific permission information generation process includes performing identity field normalization processing on maintenance personnel identity information, performing attribution verification processing on user groups, and performing instruction set parsing processing on maintenance operation instruction information to generate instruction boundary records, generating maintenance permission policies containing a set of policy entries and a policy version number field. The set of policy entries is composed of maintenance personnel identity information, maintenance account, user group, asset identifier, target terminal device information, maintenance operation instruction information, maintenance time domain, and maintenance target file.
4. The method according to claim 1, characterized in that, The process of assembling timestamps and performing quantum key digital signature processing to obtain dynamic operation and maintenance credentials includes: The extracted information is subjected to policy matching processing, including subject matching, object matching, and instruction matching, based on the aforementioned operation and maintenance permission policy. Then, timestamp assembly and quantum key digital signature processing are performed. The timestamp assembly process includes generating a timestamp and determining whether the timestamp falls within the valid window of the operation and maintenance time domain. The quantum key digital signature processing includes calling the quantum key to perform digital signature operation on the credential payload, resulting in a dynamic operation and maintenance credential containing the credential payload, a signature result field, and a policy version number field. The credential payload is formed by combining the work ticket number, session identifier, operation and maintenance personnel identity information, target terminal device information, operation and maintenance operation instruction information, and timestamp.
5. The method according to claim 1, characterized in that, The process of generating and processing a secondary authentication request includes: The secondary authentication request generation process includes encapsulating and assembling dynamic operation and maintenance credentials. The encapsulation and assembly process includes request header assembly, request body assembly, and request integrity verification. The authentication judgment process includes performing digital signature verification, timestamp validity determination, policy consistency verification, and policy matching review based on operation and maintenance permission policies on dynamic operation and maintenance credentials, generating a release instruction or blocking status. The release instruction includes a session identifier, work ticket number, target terminal device information, operation and maintenance operation instruction information summary, and release time window.
6. The method according to claim 1, characterized in that, The process of generating session keys, issuing access control rules, and executing operations and maintenance projects to generate encrypted operation and maintenance results and related data includes: The session key generation process includes input assembly, random number assembly, key derivation, and key registration based on the session identifier, timestamp, and preset key. The access control rule distribution process includes extracting policy entries from the operation and maintenance permission policy, performing rule assembly to generate access control rules, and then encrypting and distributing them to the target IoT terminal via the operation and maintenance terminal. The operation and maintenance project execution process includes the target IoT terminal performing rule verification based on the access control rules, and executing the operation and maintenance project according to the operation and maintenance operation instructions after the verification is passed, generating encrypted operation and maintenance results and operation and maintenance related data. The operation and maintenance related data includes the session identifier, work ticket number, access control rule version number, operation and maintenance operation entry, target file identifier field, execution time record, operation and maintenance execution status, running status data digest, raw log data digest, and release status flag.
7. The method according to claim 1, characterized in that, The process of constructing a dynamic network security graph, static segmentation, and generating a static graph matrix includes: The dynamic network security graph construction process includes mapping the identity information of operation and maintenance personnel, target terminal device information, operation and maintenance operation items, access control rule version number, and session identifier to graph nodes, and constructing session operation edges and rule constraint edges. The static segmentation process includes segmenting the dynamic network security graph according to three dimensions: session identifier, target terminal device information, and access control rule version number, to obtain multiple static subgraphs. The static graph matrix generation process includes performing node encoding and edge encoding on the static subgraphs to generate a static graph matrix containing a node adjacency matrix and an attribute matrix. Based on the static graph matrix, a pre-trained model, a first model, and a second model are called to perform anomaly detection inference processing. The second model is used to generate simulated attack data, and the first model is used to perform inference on the original model input packet and the simulated attack data.
8. The method according to claim 1, characterized in that, Anomaly detection results include: The anomaly detection results include session identifier, work ticket number, device identifier of target terminal device information, access control rule version number, anomaly score, anomaly label and comparison score.
9. The method according to claim 1, characterized in that, The process of determining the target probability level, the target impact level, and mapping the matrix coordinates includes: The target probability level determination process includes performing input normalization on the anomaly detection results and determining the target probability level based on anomaly scores, comparison scores, anomaly labels, and source quality evidence. The target impact level determination process includes determining the target impact level based on target terminal device information, operation and maintenance items, operation and maintenance execution status, running status data summary, and security alarm data summary. The matrix coordinate graph mapping process includes mapping the target probability level and target impact level to matrix coordinate fields and corresponding response template identifier fields according to the matrix coordinate mapping rule set. Based on the matrix coordinate fields and response template identifier fields, a response scheduling strategy is generated. The response scheduling strategy includes a strategy identifier field, a strategy version field, a strategy trigger time field, a strategy application scope field, and a strategy handling constraint field.
10. A security operation and maintenance system for communication equipment, characterized in that, include: The system comprises an operation and maintenance task parsing module, an operation and maintenance permission policy generation module, a dynamic operation and maintenance credential generation module, a secondary authentication control module, an operation and maintenance execution and access control module, a security graph and anomaly detection module, and a response scheduling policy generation module; these modules are connected in sequence to implement the method described in any one of claims 1-9.