Safety Management and Control System and Methods for Operation and Maintenance of Power Equipment

By using an authentication and management terminal to relay and perform dual authentication on inputs from on-site hosts, the low security issues caused by direct USB key plugging in are resolved, thereby improving the security management and maintenance security of power equipment.

CN122316698APending Publication Date: 2026-06-30STATE GRID BEIJING ELECTRIC POWER CO
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID BEIJING ELECTRIC POWER CO
Filing Date
2026-03-27
Publication Date
2026-06-30

Smart Images

  • Figure CN122316698A_ABST
    Figure CN122316698A_ABST
Patent Text Reader

Abstract

This invention discloses a power equipment operation and maintenance security management system and method. The system includes: an operation and maintenance system comprising: a station control switch, an in-station host, a monitor, and a mouse and keyboard for system operation; the station control switch is communicatively connected to the in-station host, the monitor is connected to the in-station host, and the in-station host is configured with shielding software and proxy software; an authentication key, wherein the authentication key includes at least: role information for authentication and identification; and an authentication management terminal, configured with a key connection port for authentication key access, the mouse and keyboard being connected to the authentication management terminal, and the in-station host being connected to and controlled by the authentication management terminal to establish or disconnect the communication connection between the authentication management terminal and the in-station host. This invention solves the problems of frequent alarms and low security of in-station hosts in power systems, effectively preventing unauthorized personnel from operating the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system operation and maintenance technology, and more specifically, to a power equipment operation and maintenance safety management system and method. Background Technology

[0002] As control devices within the power system, power equipment ensures the stable operation of the power network. Therefore, its security and reliability are of paramount importance. To guarantee power safety, many power companies require dispatching stations, substations, and power plants to be equipped with maintenance gateways (bastion hosts), dedicated security USB drives, and dedicated maintenance terminals. Important hosts such as monitoring backends must have USB drive monitoring capabilities. Unnecessary optical drives, USB interfaces, and serial ports must be removed or disabled. Strict control must be exercised over the access of removable media to the production control area. Strict requirements are in place for the maintenance of power equipment and the plug-ins used in power equipment to ensure its safety.

[0003] Figure 1 A structural diagram of an operation and control system for a power system in the prior art is shown, such as... Figure 1 As shown, the structure of the power system operation and control system includes a station host 10P, a display 20P, and a station control switch 30P. The station host 10P is connected to the station control switch 30P, and the display 20P is connected to the station host 10P. The station host 10P is configured with USB interfaces for connecting a keyboard 40P, a mouse 50P, and a USB key 60P (a secure hardware device that connects to a computer or electronic device via a USB interface), and is also configured with blocking software 11P. The keyboard 40P and mouse 50P are connected to the station host 10P. When the USB key 60P is not connected to the station host 10P, it is in an unverified state, the operation of the keyboard 40P and mouse 50P is invalid, and the blocking software 11P blocks the operation and maintenance interface. At this time, no operation can be performed on the system. Only when the certified USBkey60P is connected to the on-site host 10P will the blocking software 11P remove the blocking of the display, and the keyboard 40P and mouse 50P can be operated normally. This is to achieve control over system operation and maintenance and prevent unauthorized personnel from operating the system.

[0004] However, the aforementioned control system still requires the USBkey 60P to be directly plugged into the on-site host 10P. On the one hand, the frequent plugging and unplugging of the USBkey 60P will trigger the system security detection device to generate a large number of alarm messages for USB interface insertion / removal events. On the other hand, the security of the USBkey 60P itself cannot be guaranteed, and there is a risk that viruses from connected USB devices may be implanted into the on-site host 10P. Summary of the Invention

[0005] This invention provides a power equipment operation and maintenance safety management system and method to at least solve the technical problem in related technologies where the security of the station host is low due to the direct plugging of the USB key into the station host.

[0006] According to one aspect of the present invention, a power equipment operation and maintenance security management system is provided. The system includes: an operation and maintenance system, wherein the system further includes: a station control switch, an in-station host, a monitor, and a mouse and keyboard for system operation; the station control switch is communicatively connected to the in-station host, the monitor is connected to the in-station host, and the in-station host is configured with shielding software and proxy software; an authentication key, wherein the authentication key includes at least: role information for authentication identification; and an authentication management terminal, wherein the authentication management terminal is configured with a key connection port for authentication key access, the mouse and keyboard are connected to the authentication management terminal, and the in-station host is connected to the authentication management terminal and controlled by... The authentication management terminal controls whether the communication connection between the authentication management terminal and the on-site host is established or terminated. The on-site host is configured to prohibit the access of USB devices other than the authentication management terminal. When the authentication key is not connected to the key connection port, the authentication management terminal disconnects from the on-site host. In response to the disconnection status of the authentication management terminal and the on-site host, the blocking software blocks the display of the operation and maintenance interface. When the authentication key is connected to the authentication management terminal, the authentication management terminal identifies the role information. If the role information exists in the role library, the authentication management terminal establishes the communication connection with the on-site host, removes the blocking software from the display, and allows mouse and keyboard input.

[0007] Furthermore, the authentication and control terminal also includes: a role library, which stores different types of roles and their operation permissions; a role recognition module, wherein, when the authentication key is connected to the authentication and control terminal, the role recognition module obtains role information and compares the role information with the role library to identify whether the role information exists in the role library. If the role information exists in the role library, keyboard and mouse input is allowed. When keyboard and / or mouse input is allowed, the authentication and control terminal generates input information corresponding to the keyboard and / or mouse input content and transmits the input information to the on-site host to allow the input information to be displayed on the monitor; and a permission management module, wherein the permission management module parses the input information to identify the control command corresponding to the input information, and identifies whether the control command is a permission in the role library and whether the control command is within the permission scope of the role information. If the control command is a permission in the role library and the control command is within the permission scope of the role information, the control command is transmitted to the on-site host, and the on-site host is triggered to execute the operation corresponding to the control command.

[0008] Furthermore, the role library stores at least two types of roles and the operation permissions for each type of role. The operation permissions for each type of role are different, and each authentication key is configured with one type of role information.

[0009] Furthermore, the agent software is configured to recognize only the control commands transmitted by the authentication and control terminal, and the agent software is used to execute the control commands transmitted by the authentication and control terminal.

[0010] Furthermore, the authentication and management terminal also includes a log storage module, which generates and stores the system's operation and maintenance logs. The operation and maintenance logs record the role information of the access authentication key, the input information, and the executed control commands. When the role information does not exist in the role library, and / or the control command does not have the permissions in the role library, and / or the control command is not within the permission scope of the role information, the log storage module generates and stores a warning log, and the alarm log records alarm information.

[0011] According to another aspect of the present invention, the present invention also provides a method for operation and maintenance security management of power equipment, applied to an operation and maintenance security management system for power equipment. The method includes: monitoring whether an authentication key is accessing a key connection port; if no authentication key is detected accessing a key connection port, controlling the authentication management terminal to disconnect the communication connection with the on-site host in the operation and maintenance system; if an authentication key is detected accessing a key connection port, obtaining the role information carried by the authentication key; based on the role information, searching in a role database to obtain the search result; if the search result indicates that role information is found in the role database, controlling the authentication management terminal to establish a communication connection with the on-site host to display the operation and maintenance interface on the display of the operation and maintenance system.

[0012] Furthermore, the operation and maintenance safety management method for power equipment also includes: monitoring whether the mouse and / or keyboard of the operation and maintenance system is used for input, and displaying the input information on the monitor when mouse and / or keyboard input is detected; parsing the input information to obtain the control command corresponding to the input information; identifying whether the control command is a permission in the role library and whether the control command is within the permission scope of the role information; if the control command is a permission in the role library and the control command is within the permission scope of the role information, transmitting the control command to the on-site host; and the on-site host executing the operation corresponding to the control command.

[0013] Furthermore, the communication connection established between the authentication and control terminal and the host within the station is the only USB input path for the host within the station.

[0014] Furthermore, before searching in the role library based on role information to obtain the search results, the power equipment operation and maintenance security management method also includes: binding a role type to each authentication key and configuring operation permissions for the role corresponding to each role type; constructing a role library based on the roles of all role types and the operation permissions corresponding to the roles, wherein the role library stores at least two types of roles and the operation permissions of each type of role.

[0015] Furthermore, after searching the role database based on role information and obtaining the search results, the power equipment operation and maintenance safety management method also includes: triggering an alarm and generating alarm information when the search results indicate that no role information is found in the role database, and / or when the control command does not have the permissions in the role database, and / or when the control command is not within the permission scope of the role information, and recording the alarm information to the log storage module.

[0016] One objective of this invention is to provide a power equipment operation and maintenance safety management system and method, which controls the input of the power system's station host. Communication connection with the station host is only established when the identity of the operation and maintenance personnel meets the requirements (i.e., the role information is found in the role library), thereby effectively controlling the input of the station host.

[0017] Another objective of this invention is to provide a power equipment operation and maintenance safety management system and method. The system manages and relays the input of the station host through an authentication management terminal. Communication connection with the station host is established only when the identity of the operation and maintenance personnel meets the requirements. Therefore, for the station host, it is not connected to any device when it is not in operation and maintenance state or when the identity of the operation and maintenance personnel does not meet the requirements, which can effectively shield abnormal operations.

[0018] Another objective of this invention is to provide a power equipment operation and maintenance security management system and method. By using an authentication management terminal as the sole USB device for connecting to the on-site host, and establishing a communication connection with the on-site host only when the identity of the operation and maintenance personnel meets the requirements, security is effectively guaranteed and the risk of viruses being implanted into the on-site host via USB devices is avoided.

[0019] Another objective of this invention is to provide a power equipment operation and maintenance safety management system and method. Based on the authentication management terminal, the system manages and relays the input of the station host. The station host will only be triggered to execute when the instruction input by the operation and maintenance personnel meets the requirements and permissions (i.e., the control instruction is within the permissions of the role library and the control instruction is within the permission range of the role information). This effectively isolates abnormal operations and ensures operation and maintenance safety.

[0020] Another objective of this invention is to provide a power equipment operation and maintenance safety management system and method, wherein the authentication and management terminal is configured as the only USB input path of the station host, and the station host prohibits the access of USB devices other than the authentication and management terminal, thereby effectively blocking the risk of abnormal operation and virus transmission.

[0021] Another objective of this invention is to provide a power equipment operation and maintenance safety management system and method, which realizes dual authentication management of operation and maintenance operations. The operation and maintenance operation is initiated by identifying the identity of the operation and maintenance personnel, and the instructions entered by the operation and maintenance personnel are authenticated twice during the operation and maintenance operation. The on-site host will only be triggered to execute when the instruction meets the requirements and permissions. Operation and maintenance safety is ensured through dual authentication. Attached Figure Description

[0022] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:

[0023] Figure 1 A structural block diagram of an operation and control system for a power system in the prior art is shown;

[0024] Figure 2 This is a schematic diagram of a power equipment operation and maintenance safety management system according to an embodiment of the present invention;

[0025] Figure 3 This is a structural block diagram of an authentication and control terminal for a power equipment operation and maintenance safety management and control system according to an embodiment of the present invention;

[0026] Figure 4 This is a schematic diagram of the authentication process of the authentication control terminal according to an embodiment of the present invention;

[0027] Figure 5 This is a schematic diagram of the operation and maintenance safety management system for power equipment according to an embodiment of the present invention. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] It should be noted that all related information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data) collected and involved in this invention are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of this data comply with the relevant laws, regulations, and standards of the relevant regions, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse. For example, this system has an interface with relevant users or organizations. Before obtaining relevant information, a request to obtain the information needs to be sent to the aforementioned user or organization through the interface, and the relevant information is obtained only after receiving consent from the aforementioned user or organization.

[0031] In this invention, the input of the station host is controlled and relayed through the authentication and management terminal. Communication connection with the station host is only established when the identity of the maintenance personnel meets the requirements. During the operation and maintenance process, the instructions entered by the maintenance personnel are subject to secondary authentication. The station host will only be triggered to execute if the instruction has the permissions in the role library and is within the permission scope of the role information. Through dual authentication, effective isolation between power equipment and external equipment can be formed, effectively ensuring security and avoiding the risk of viruses being implanted into the station host through the equipment.

[0032] Specifically, the present invention provides a power equipment operation and maintenance safety management and control system, such as... Figure 2 and Figure 3 As shown, Figure 2 This is a schematic diagram of a power equipment operation and maintenance safety management system according to an embodiment of the present invention. Figure 3This is a structural block diagram of an authentication and control terminal for a power equipment operation and maintenance security management system according to an embodiment of the present invention. The power equipment operation and maintenance security management system includes an operation and maintenance system 10, an authentication and control terminal 20, and an authentication key 30 for initiating maintenance and performing identity authentication. The operation and maintenance system 10 includes an in-station host 11, a station control switch 13, a monitor 12, and a keyboard 14 and a mouse 15 for system operation. The station control switch 13 is communicatively connected to the in-station host 11, and the monitor 12 is connected to the in-station host 11. The authentication and management terminal 20 is configured with a key connection port 203 suitable for the access of the authentication key 30. The keyboard 14 and mouse 15 are respectively connected to the two keyboard and mouse ports 201 of the authentication and management terminal 20. The in-station host 11 is connected to the host connection port 202 of the authentication and management terminal 20 and is controlled by the authentication and management terminal 20 to connect or disconnect the communication connection between the authentication and management terminal 20 and the in-station host 11. The in-station host 11 is configured with blocking software 111. When the authentication key 30 is not inserted into the key connection port 203, the authentication and management terminal 20 disconnects the communication connection with the in-station host 11. In response to the disconnection state of the authentication and management terminal 20 and the in-station host 11, the blocking software 111 blocks the display of the operation and maintenance interface on the monitor 12. The host 11 is also equipped with agent software 112, which is used to execute control commands transmitted by the self-authentication control terminal 20.

[0033] Optionally, the number of components in the operation and maintenance safety management system of power equipment can be one, while in another embodiment, the number of components can be multiple, and there is no limit to the number.

[0034] exist Figure 3 In addition, the authentication and control terminal 20 also includes a role recognition module 21, a permission management module 22, a role library 23, and a log storage module 24.

[0035] In this embodiment, the authentication key 30 has role information for authentication and identification, such as... Figure 4 As shown, Figure 4This is a schematic diagram of the authentication process of the authentication management terminal according to an embodiment of the present invention. When the authentication key 30 is inserted into the authentication management terminal 20, the authentication management terminal 20 checks whether the role information of the authentication key 30 exists in the role database. If the role information does not exist in the role database, a warning is issued and recorded. If the role information exists in the role database, the authentication management terminal 20 establishes a communication connection with the on-site host 11 and removes the blocking software 111 from the display 12, allowing input via the keyboard 14 and mouse 15. At this time, maintenance personnel can see the maintenance interface on the display 12 and can input via the keyboard 14 and mouse 15. When the user inputs content via the keyboard 14 and / or mouse 15, the authentication management terminal 20 is equivalent to a mouse and keyboard to the on-site host 10. When maintenance personnel input content via the keyboard 14 and mouse 15, it will not be immediately executed by the on-site host 11 to prevent unauthorized instructions from being executed. Specifically, when the keyboard 14 and / or mouse 15 are in the input state, the corresponding input information is parsed to obtain the control command corresponding to the input information, and it is identified whether the control command is a permission in the role library and whether the control command is within the permission scope of the role information. If the control command is not a permission in the role library and / or the control command is not within the permission scope of the role information, a warning is issued and recorded. Only when the control command is a permission in the role library and the control command is within the permission scope of the role information, the command is sent to the site host 202, and the site host 202 executes the operation.

[0036] The authentication control terminal 20 also includes a control unit. A keyboard and mouse port 201, a host connection port 202, and a key connection port 203 are connected to the control unit. When the key connection port 203 is not connected to the authentication key 30, the control unit disconnects the communication connection between the host connection port 202 and the host 11 in the station. When the key connection port 202 is connected to the authentication key 30, the control unit identifies the role information of the authentication key 30. If the role information exists in the role library, the control unit connects the host connection port 202 to the host 11 in the station and allows input from the keyboard 14 and mouse 15.

[0037] Optionally, the authentication control terminal 20 and the on-site host 11 have data links and command links. When the role information of the authentication key 30 exists in the role library, the authentication control terminal 20 establishes a data link with the on-site host 11 to map the keyboard 14 and mouse 15, so that the input of the operator through the keyboard 14 and mouse 15 can be displayed on the monitor 12. However, at this time, the content input by the keyboard 14 and mouse 15 will not be executed by the on-site host 11 as a command. Only when the authentication control terminal 20 recognizes that the command is a permission in the role library and the recognition control command is within the permission scope of the role information, the authentication control terminal 20 establishes a command link with the on-site host 11 and transmits the command to the on-site host 11. Only then will the on-site host 11 be triggered to execute, thus ensuring the security control of operation and maintenance.

[0038] Optionally, the control unit may include a role recognition module 21 and an access control module 22. The authentication control terminal 20 establishes a role database 23. When the authentication key 30 is inserted into the authentication control terminal 20, the role recognition module 21 obtains the role information of the authentication key 30 and compares it with the role database 23 to identify whether the role information exists in the role database. When the role information exists in the role database, keyboard 14 and mouse 15 input are allowed, i.e., the data link is established. When keyboard 14 and / or mouse 15 are used for input, the authentication control terminal 20 generates typing information corresponding to the keyboard 14 and / or mouse 15 input content and transmits the typing information to the station host 11 to allow the typing information to be displayed on the display 12, i.e., forming... The mapping of keyboard 14 and / or mouse 15 input content involves the permission management module 22 parsing the input information to identify the corresponding control command, and determining whether the control command is a permission in the role library and whether it is within the permission scope of the role information. If the control command is a permission in the role library and within the permission scope of the role information, the command link is established, and the control command is transmitted to the on-site host 11. The on-site host 11 is triggered to execute the corresponding operation, thereby completing the corresponding operation and maintenance operation. In this way, the input of the on-site host 11 is controlled and relayed through the authentication management terminal 20. The on-site host 11 will only be triggered to execute when the command entered by the operation and maintenance personnel meets the permissions, effectively isolating abnormal operations and ensuring operation and maintenance security.

[0039] In this embodiment of the invention, the authentication and management terminal 20 implements dual authentication and management for operation and maintenance operations. It initiates operation and maintenance operations by identifying the identity of the operation and maintenance personnel, and performs secondary authentication on the instructions entered by the operation and maintenance personnel during the operation and maintenance process. Only when the instruction is a permission in the role library and the control instruction is within the permission scope of the role information will the on-site host 11 be triggered to execute. Operation and maintenance security is ensured through dual authentication.

[0040] In summary, the authentication and control terminal 20 continuously monitors its key connection port 203 to ensure that communication with the on-site host 11 is automatically disconnected when no compliant authentication key 30 is connected, preventing unauthorized access. When the authentication key 30 is detected to be connected, the system quickly reads the role information in the key and compares it with the role database to verify whether the identity meets the requirements. This ensures that only maintenance personnel with compliant identities can establish communication with the on-site host 11 and perform operations, guaranteeing the security and compliance of power system operation and maintenance. At the same time, it reduces system alarms caused by frequent device plugging and unplugging, improving operation and maintenance efficiency and system stability. By deploying an authentication and control terminal that integrates key access monitoring, role information acquisition and verification, and access control functions, comprehensive security control of power equipment operation and maintenance is achieved, thereby solving the technical problem of low security of the on-site host caused by the direct plugging of the USB key into the on-site host in related technologies.

[0041] Optionally, the station host 11 is configured to prohibit the access of USB devices other than the authentication control terminal 20. That is, the communication connection between the authentication control terminal 20 and the station host 11 is the only USB input path of the station host 11, thereby preventing other USB devices from accessing the station host 11, effectively blocking the risk of abnormal operation and virus transmission, and also avoiding frequent insertion / removal prompts.

[0042] The authentication control terminal 20 establishes a communication connection with the on-site host 11 only when the identity of the maintenance personnel meets the requirements, effectively controlling the input of the on-site host 11. Furthermore, for the on-site host 11, when it is not in a maintenance state or when the identity of the maintenance personnel does not meet the requirements, it does not connect to any device, which can effectively shield abnormal operations.

[0043] Optionally, the on-site host 11 is configured with proxy software 112. Proxy software 112 executes control commands transmitted by the self-authentication management terminal 20 and is configured to only recognize control commands transmitted by the authentication management terminal 20. That is, the authentication management terminal 20 establishes a connection with the blocking software 111 by identifying the identity of the maintenance personnel, and performs secondary authentication on the commands entered by the maintenance personnel during the maintenance operation. The connection with the proxy software 112 is established only if the command has permissions in the role library and is within the permission scope of the role information, thus ensuring maintenance security through dual authentication.

[0044] Optionally, the role library 23 stores roles of at least two types and corresponding operation permissions for each type of role. Each type of role has different operation permissions, and each authentication key 30 is configured with exactly one type of role information to ensure that each operations and maintenance personnel performs operations and maintenance according to their permissions. Figure 5 As shown, Figure 5This is a schematic diagram of the workflow of the power equipment operation and maintenance safety management system according to an embodiment of the present invention. The types of roles include, but are not limited to, administrator (admin), operator (oper), and auditor (aduit). Each type of role has different permissions. For example, the administrator's permissions are to create users, delete users, and change passwords; the operator's permissions are to modify configurations, perform business operations, and start business software; and the auditor's permissions are to view logs and export logs.

[0045] For example, when an auditing and maintenance personnel inserts their authentication key 30 into the authentication management terminal 20, the authentication management terminal 20 recognizes that the role information of the authentication key 30 is Auditor A, which exists in the role library and meets the requirements. Therefore, the data link is established to map the keyboard 14 and mouse 15, so that the input of the operator through the keyboard 14 and mouse 15 can be displayed on the monitor 12. When the operator inputs an instruction to perform a business operation, the input content will be displayed on the monitor 12 through the data link. However, at this time, the instruction link is not yet opened, and the agent software 112 will not perform any operation. The authentication management terminal 20 recognizes the instruction and finds that the instruction is a permission in the role library but the instruction is not within the permission scope of the role information. Therefore, the instruction link will not be established, and the instruction will not be executed, thereby effectively avoiding unauthorized operations.

[0046] Optionally, the authentication and control terminal 20 achieves full traceability of the operation and maintenance process through log management to meet compliance requirements. The storage of the operation and maintenance process is independent of the on-site host 11, ensuring the integrity of the records and avoiding memory occupation of the on-site host 11. Specifically, the authentication and control terminal 20 includes a log storage module 24, which is used to generate and store the system's operation and maintenance logs. The operation and maintenance logs record the role information of the inserted authentication key 30, the input information, and the executed control commands.

[0047] If the role information of the inserted authentication key 30 does not exist in the role library, and / or the input control command does not have the permissions in the role library, and / or the control command is not within the permission scope of the role information, the log storage module 24 generates and stores a warning log. The alarm log records alarm information, which helps managers and / or auditors to grasp the abnormal operation of the system and facilitates the implementation of corresponding risk control operations.

[0048] In this embodiment of the invention, by setting up an authentication control terminal 20 and an operation and maintenance system in the power equipment operation and maintenance security management system, fine-grained access control and full-process security auditing of operation and maintenance operations are achieved. The authentication control terminal 20 can verify the role information of the authentication key, ensuring that only operation and maintenance personnel with the required identity can remove the blocking software from the display and operate the station host 11 through the keyboard and mouse input device. At the same time, the operation and maintenance system further identifies the keyboard and mouse input content, and only executes the operation command corresponding to the content when it is within the permission of the role library and the operation command is within the permission range of the role information. All operations and permission verification results are automatically recorded by the log storage module 24. Any unauthorized or unauthorized operation is immediately triggered and recorded, providing audit clues for abnormal behavior, improving the security and compliance of the power equipment operation and maintenance process, avoiding the execution of unauthorized commands, reducing the risk of virus transmission, and ensuring the transparency and traceability of operation and maintenance activities through access control and log auditing mechanisms, thereby enhancing the stability and security of power system operation.

[0049] According to an embodiment of the present invention, a method for operation and maintenance security management of power equipment is also provided. It should be noted that the operation and maintenance security management system for power equipment provided in this application embodiment can be applied to execute the operation and maintenance security management method for power equipment in this application embodiment. The operation and maintenance security management system includes at least: an operation and maintenance system 10 and an authentication and management terminal 20. The authentication and management terminal 20 is configured with a key connection port 203 and a role library 23. The operation and maintenance security management method for power equipment includes the following steps:

[0050] The system monitors whether an authentication key 30 is connected to the key connection port 203. If no authentication key 30 is detected connected to the key connection port 203, the system controls the authentication management terminal 20 to disconnect the communication connection with the on-site host 11 in the operation and maintenance system 10.

[0051] If the presence of authentication key 30 on access key connection port 203 is detected, the role information carried by authentication key 30 is obtained;

[0052] Based on the role information, a search is performed in role database 23 to obtain the search results;

[0053] If the search results indicate that role information is found in the role library 23, the control authentication management terminal 20 establishes a communication connection with the on-site host 11 to display the operation and maintenance interface on the display 12 of the operation and maintenance system 10.

[0054] At this time, input via keyboard 14 and mouse 15 is allowed, and maintenance personnel can see the maintenance interface on monitor 12. Input can be made via keyboard 14 and mouse 15. When the user inputs content via keyboard 14 and / or mouse 15, the authentication management terminal 20 is equivalent to a mouse and keyboard for the on-site host 10.

[0055] Optionally, the system monitors whether the mouse 15 and / or keyboard 14 of the operation and maintenance system 10 inputs content. If the mouse 15 and / or keyboard 14 of the operation and maintenance system are detected to input content, the input information corresponding to the input content is displayed on the monitor 12. The input information is parsed to obtain the control command corresponding to the input information. The system identifies whether the control command is a permission in the role library and whether the control command is within the permission scope of the role information. If the control command is a permission in the role library and the control command is within the permission scope of the role information, the control command is transmitted to the on-site host 11, and the on-site host 11 executes the operation corresponding to the control command.

[0056] That is, when maintenance personnel input content through keyboard 14 and mouse 15, it will not be immediately executed by the site host 11 to avoid executing commands that are not allowed. Only when the control command has permissions in the role library and the control command is within the permission scope of the role information will the control command be transmitted to the site host 202.

[0057] Optionally, the communication connection established between the authentication control terminal 20 and the on-site host 11 is the only USB input path for the on-site host 11. The on-site host 11 prohibits the access of other USB devices, effectively blocking the risk of abnormal operation and virus transmission, while also avoiding frequent insertion / removal prompts.

[0058] Optionally, in the power equipment operation and maintenance security management method provided in the embodiments of this application, before searching in the role library based on the role information and obtaining the search result, the method further includes: binding a unique role type to each authentication key 30 and configuring operation permissions for the role corresponding to each role type; constructing a role library 23 based on the roles of all role types and the operation permissions corresponding to the roles, wherein the role library stores at least two types of roles and the operation permissions of each type of role.

[0059] For example, such as Figure 5As shown, the created user roles include administrator (admin), operator (oper), and auditor (aduit). Each authentication key 30 is configured with one and only one type of role information (i.e., user initialization, binding key). When an authentication key 30 is detected to be connected to the key connection port 203 (i.e., key insertion), it is determined whether the role information of the authentication key 30 is a role bound in the role library 23. If not, an alarm is triggered and recorded. If so, the role type of the role is determined, and the control command corresponding to the content input by the mouse 15 and / or keyboard 14 is identified as having permissions in the role library. If not, an alarm is triggered and recorded. If so, it is identified whether the control command conforms to the permissions of the corresponding type of role in the role library 23 (i.e., whether the control command is within the permission range of the role information). If yes, it is considered to have met the permissions, and the control command is transmitted to the on-site host agent software 112. Otherwise, it is considered an unauthorized operation, and an alarm is triggered and recorded.

[0060] Optionally, if the search results indicate that no role information is found in the role library 23, and / or if the control command is not a permission in the role library, and / or if the control command is not within the permission scope of the role information, an alarm is triggered and alarm information is generated. The alarm information is recorded in the log storage module 24, which helps managers and / or auditors to understand the abnormal operation of the system and facilitates the implementation of corresponding risk control operations.

[0061] In summary, this invention enables effective isolation and authentication between power equipment and external devices. It employs dual authentication, allowing input from external devices only when the identity authentication meets the requirements, and triggering execution only when the instruction has permissions in the role library and is within the permission scope of the role information. This satisfies the stringent requirements of power systems for operation and maintenance security and external device access security, ensuring the safety of power equipment.

[0062] According to another aspect of the present invention, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the power equipment operation and maintenance safety management method described above.

[0063] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors cause the one or more processors to implement the above-described method for the operation and maintenance safety management of power equipment.

[0064] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0065] The embodiments or examples disclosed herein are not exhaustive, but merely illustrative of some embodiments or examples, and are not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment or example can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment or example can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment or example can be arbitrarily interchanged. Furthermore, optional methods or examples in a particular embodiment or example can be arbitrarily combined; moreover, embodiments or examples can be arbitrarily combined. For example, some or all steps of different embodiments or examples can be arbitrarily combined, and a particular embodiment or example can be arbitrarily combined with optional methods or examples of other embodiments or examples.

[0066] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0067] In the several embodiments provided by this invention, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces; the indirect coupling or communication connection of units or modules can be electrical or other forms.

[0068] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0069] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0070] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0071] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A power equipment operation and maintenance safety management and control system, characterized in that, The operation and maintenance security management system includes: The operation and maintenance system includes: a station control switch, an in-station host, a monitor, and a mouse and keyboard for system operation. The station control switch is communicatively connected to the in-station host, and the monitor is connected to the in-station host. The in-station host is configured with shielding software and proxy software. An authentication key, wherein the authentication key includes at least: role information used for authentication and identification; An authentication and control terminal is provided, wherein the authentication and control terminal is configured with a key connection port for accessing the authentication key, the mouse and the keyboard are connected to the authentication and control terminal, and the on-site host is connected to the authentication and control terminal and controlled by the authentication and control terminal to establish or disconnect the communication connection between the authentication and control terminal and the on-site host. The on-site host is configured to prohibit the access of USB devices other than the authentication and control terminal. When the authentication key is not connected to the key connection port, the authentication and control terminal disconnects the communication connection with the on-site host. In response to the disconnection state of the authentication and control terminal and the on-site host, the blocking software blocks the display of the operation and maintenance interface. When the authentication key is connected to the authentication and control terminal, the authentication and control terminal identifies the role information. If the role information exists in the role library, the authentication and control terminal establishes the communication connection with the on-site host, removes the blocking software from the display, and allows input from the mouse and the keyboard.

2. The power equipment operation and maintenance safety management system according to claim 1, characterized in that, The authentication control terminal also includes: A role library, which stores different types of roles and their operation permissions; A role recognition module, wherein, when the authentication key is connected to the authentication management terminal, the role recognition module acquires the role information and compares the role information with the role database to identify whether the role information exists in the role database. When the role information exists in the role database, keyboard and mouse input are allowed. When keyboard and / or mouse input is allowed, the authentication management terminal generates typing information corresponding to the keyboard and / or mouse input and transmits the typing information to the on-site host to allow the typing information to be displayed on the display. The permission management module parses the input information to identify the control command corresponding to the input information, identifies whether the control command is a permission in the role library, and identifies whether the control command is within the permission range of the role information. If the control command is a permission in the role library and the control command is within the permission range of the role information, the control command is transmitted to the on-site host, and the on-site host is triggered to execute the operation corresponding to the control command.

3. The power equipment operation and maintenance safety management system according to claim 2, characterized in that, The role library stores at least two types of roles and the operation permissions for each type of role, wherein the operation permissions for each type of role are different, and each authentication key is configured with one type of role information.

4. The power equipment operation and maintenance safety management system according to claim 2, characterized in that, The proxy software is configured to recognize only the control commands transmitted by the authentication and control terminal, and the proxy software is used to execute the control commands transmitted by the authentication and control terminal.

5. The power equipment operation and maintenance safety management system according to claim 2, characterized in that, The authentication control terminal also includes: A log storage module is provided, wherein the log storage module is used to generate and store system operation and maintenance logs. The operation and maintenance logs record the role information of the authentication key that is accessed, the input information, and the executed control commands. When the role information does not exist in the role library, and / or the control command does not have the permissions in the role library, and / or the control command is not within the permission scope of the role information, the log storage module generates and stores alarm logs, and the alarm logs record alarm information.

6. A method for safe operation and maintenance management of power equipment, characterized in that, A security management and control system for the operation and maintenance of power equipment, comprising at least: an authentication key, an operation and maintenance system, and an authentication and control terminal, wherein the authentication and control terminal is configured with a key connection port and a role library, and the security management and control method for the operation and maintenance of power equipment includes: The system monitors whether an authentication key is connected to the key connection port. If no authentication key is detected connected to the key connection port, the system controls the authentication management terminal to disconnect the communication connection with the on-site host in the operation and maintenance system. If an authentication key is detected to be connected to the key connection port, the role information carried by the authentication key is obtained; Based on the character information, a search is performed in the character database to obtain the search results; If the search result indicates that the role information is found in the role database, the authentication management terminal is controlled to establish a communication connection with the on-site host to display the operation and maintenance interface on the display of the operation and maintenance system.

7. The method for safe operation and maintenance management of power equipment according to claim 6, characterized in that, The operation and maintenance safety management method for the power equipment also includes: Monitor whether the mouse and / or keyboard of the operation and maintenance system input content, and if the mouse and / or keyboard of the operation and maintenance system are detected to input content, display the typing information corresponding to the input content on the display. The input information is parsed to obtain the control command corresponding to the input information; Identify whether the control command is a permission in the role library, and identify whether the control command is within the permission scope of the role information; If the control command is a permission in the role library and the control command is within the permission scope of the role information, the control command will be transmitted to the on-site host. The host computer within the station executes the operation corresponding to the control command.

8. The method for safe operation and maintenance management of power equipment according to claim 7, characterized in that, The communication connection established between the authentication and control terminal and the host within the station is the unique USB input path for the host within the station.

9. The method for safe operation and maintenance management of power equipment according to claim 6, characterized in that, Before searching the role database based on the role information to obtain the search results, the operation and maintenance safety management method for power equipment further includes: Each authentication key is bound to a role type, and operation permissions are configured for the role corresponding to each role type. Based on all the roles of the aforementioned role types and the corresponding operation permissions of the roles, a role library is constructed, wherein the role library stores at least two types of the aforementioned roles and the operation permissions of each type of the aforementioned role.

10. The method for safe operation and maintenance management of power equipment according to claim 7, characterized in that, After searching the role database based on the role information and obtaining the search results, the operation and maintenance safety management method for power equipment further includes: If the search result indicates that the role information is not found in the role library, and / or if the control command does not have the permissions in the role library, and / or if the control command is not within the permission scope of the role information, an alarm is triggered and alarm information is generated, and the alarm information is recorded to the log storage module.