A role permission adaptive management method and system

By using biometric verification, on-site anomaly description, and multi-source data fusion analysis, the system automatically adjusts the operating permissions of power equipment, solving the problem of permission lag in the existing system when dealing with potential risk anomalies, and improving the response speed and security of power equipment operation and maintenance.

CN122333507BActive Publication Date: 2026-08-04FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID
Filing Date
2026-06-02
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

The existing power equipment access control system cannot dynamically and adaptively adjust permissions when dealing with equipment anomalies that are not alarms but pose potential risks in the early stages. This results in operators being unable to obtain the appropriate operating permissions in time-sensitive scenarios, increasing the risk of fault escalation, and there is also a data gap between multiple independent monitoring systems and the access control system.

Method used

The system identifies operators by collecting their biometric information, receives descriptions of on-site anomalies, acquires auxiliary monitoring data and professional background data, performs semantic parsing and fusion analysis to calculate risk consensus values, automatically adjusts operating permissions, temporarily elevates permissions when safety thresholds are met, monitors the permission status, and restores permissions to their initial state.

Benefits of technology

It enables smooth and secure adaptive adjustment of permissions, shortens the delay of critical diagnosis and intervention, reduces the risk of fault escalation, breaks down the barriers of multi-source heterogeneous data, and improves the response speed and security of power equipment operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122333507B_ABST
    Figure CN122333507B_ABST
Patent Text Reader

Abstract

The application provides a role permission adaptive management method and system, and relates to the technical field of permission management. The method comprises the following steps: after identity verification, initial access permission corresponding to a preset role of an operator is granted; receiving on-site abnormality description information submitted by the operator, and combining acquired auxiliary monitoring data and professional background data of the operator, a risk consensus value reflecting the real degree of the on-site abnormality is calculated; when the risk consensus value reaches or exceeds a safety threshold, the access permission of the operator is automatically adjusted so that the operator obtains temporary operation permission; the survival state of the temporary operation permission is monitored, and when a preset revocation condition is met, the access permission of the operator is restored to the initial access permission. The method of the application aims to solve the problem of lagging permission adjustment and low efficiency of a traditional static permission management system in handling on-site abnormalities, and significantly improves the response speed and safety of power equipment operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access control technology, and more specifically, to a method and system for adaptive role-based access control. Background Technology

[0002] In the daily operation and maintenance of modern power infrastructure, a static access control system based on identity recognition is widely used in the control terminals of critical power equipment to ensure operational safety and equipment stability. This system accurately identifies the operator and automatically assigns operating permissions based on their preset roles (such as junior maintenance personnel and senior repair personnel). This mechanism effectively prevents unauthorized operations and improves the operational security of the power system.

[0003] However, in real-world power operation and maintenance scenarios, operators sometimes discover initial, non-alarm-like, but potentially risky anomalies in equipment. In these situations, existing systems reveal limitations in dynamic and adaptive permission management when handling scenarios requiring higher-level diagnostic or intervention capabilities. The system lacks intelligent awareness of the current operational context and cannot smoothly, safely, and adaptively adjust permissions based on operator reports, real-time equipment operating status (even without alarms), and the urgency of potential risks. Instead, the system typically relies on time-consuming manual approval processes to escalate permissions. This rigid management model directly leads to delays in critical diagnostics and interventions, increases the risk of escalation, and leaves operators facing operational dilemmas when dealing with time-sensitive anomalies.

[0004] More importantly, substations may contain multiple independent monitoring systems, such as high-precision vibration monitoring systems, partial discharge monitoring systems, and online oil chromatography monitoring systems. These systems may have detected weak anomalies related to oil stains discovered by operators. However, due to the lack of a real-time, intelligent correlation mechanism between this auxiliary monitoring data and the access control system, the access control system cannot utilize this multi-source heterogeneous information to determine the rationality and urgency of access escalation requests. It relies solely on operator identity and preset roles, resulting in crucial supporting information failing to be promptly transformed into access control decision-making criteria in scenarios requiring rapid response. This exacerbates information lag and decision-making inefficiency, creating a "data silo" effect and making the access control system an "information blind spot" at critical moments.

[0005] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention

[0006] The purpose of this invention is to provide a role-based adaptive permission management method and system, which aims to solve the problems of slow and inefficient permission adjustment when dealing with on-site anomalies in traditional static permission management systems, and significantly improve the response speed and security of power equipment operation and maintenance.

[0007] In a first aspect, the present invention provides a role-based permission adaptive management method, comprising the following steps: S1. Collect the operator's biometric information for identity verification, and grant the operator initial access permissions corresponding to the preset role based on the verification results; S2. Receive the on-site anomaly description information submitted by the operator for the target equipment; S3. Obtain auxiliary monitoring data associated with the target device, as well as the professional background data of the operator; S4. Perform semantic parsing on the on-site anomaly description information, and calculate a risk consensus value that reflects the authenticity of the on-site anomaly by integrating the parsing results with the auxiliary monitoring data and the professional background data; S5. Compare the risk consensus value with the preset safety threshold, and when the risk consensus value reaches or exceeds the safety threshold, automatically adjust the access permissions of the operator so that the operator can obtain temporary operating permissions that match the handling of the on-site anomaly. S6. Monitor the duration of the temporary operation permission, and restore the operator's access permission to the initial access permission when the preset revocation conditions are met.

[0008] The role-based adaptive permission management method provided by this invention can realize dynamic and adaptive management of operator permissions, effectively solving the problems of slow and inefficient permission adjustment when dealing with on-site anomalies in traditional static permission management systems, and significantly improving the response speed and security of power equipment operation and maintenance.

[0009] Secondly, this invention provides a role-based access control system, comprising: The identification and verification unit is used to collect the operator's biometric information for identity verification and grant the operator initial access permissions corresponding to a preset role based on the verification result. The information feedback unit is used to receive on-site anomaly description information submitted by the operator for the target equipment; The data acquisition unit is used to acquire auxiliary monitoring data associated with the target device, as well as the professional background data of the operator; The data processing unit is used to perform semantic parsing on the on-site anomaly description information, and calculate a risk consensus value that reflects the authenticity of the on-site anomaly by integrating the parsing results with the auxiliary monitoring data and the professional background data. The permission adjustment unit is used to compare the risk consensus value with a preset security threshold, and automatically adjust the access permissions of the operator when the risk consensus value reaches or exceeds the security threshold, so that the operator can obtain temporary operation permissions that match the handling of the on-site anomaly. The permission restoration unit is used to monitor the existence status of the temporary operation permission and restore the operator's access permission to the initial access permission when the preset revocation conditions are met.

[0010] As can be seen from the above, the role-based adaptive permission management method provided by this invention overcomes the limitation of existing static permission management systems, which cannot dynamically and adaptively adjust permissions when dealing with equipment anomalies that are not alarms but have potential risks in the initial stage. This application achieves smooth, secure, and adaptive permission adjustment by intelligently sensing the operational context and utilizing multi-source heterogeneous data (including on-site reports from operators, real-time equipment operating status, and professional background data) for comprehensive risk assessment. This avoids time-consuming manual approval processes, significantly shortens the delay in critical diagnosis and intervention, and reduces the risk of fault escalation. Simultaneously, this application effectively solves the "data silo" effect caused by the lack of real-time intelligent correlation between multiple independent monitoring systems and the permission management system within a substation, enabling auxiliary monitoring data to be promptly transformed into permission decision-making basis, improving decision-making efficiency and system security. Therefore, this application provides an efficient, intelligent, and secure power equipment operation and maintenance permission management solution with significant and superior technical effects.

[0011] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing embodiments of the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings. Attached Figure Description

[0012] Figure 1 This is a flowchart of a role-based permission adaptive management method provided in an embodiment of the present invention.

[0013] Figure 2 This is a schematic diagram of a role-based access control system provided in an embodiment of the present invention.

[0014] Label Explanation: 100. Identification and verification unit; 200. Information feedback unit; 300. Data acquisition unit; 400. Data processing unit; 500. Permission adjustment unit; 600. Permission restoration unit. Detailed Implementation

[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0016] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this invention, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0017] In traditional power equipment operation and maintenance access control systems, existing technologies assign permissions statically based on preset roles, failing to adaptively adjust permissions according to on-site anomalies, real-time equipment operating status, and operator qualifications. Specifically, the system lacks semantic parsing capabilities for operator on-site reports, and cannot integrate unstructured anomaly descriptions with equipment auxiliary monitoring data and personnel professional background data. This results in permission decisions relying solely on manual approval processes when initial non-alarm anomalies are detected. Data silos between different independent monitoring systems are particularly prominent; auxiliary information such as vibration monitoring data, partial discharge data, and oil chromatography data cannot be effectively integrated for permission assessment, creating information silos. Consequently, anomaly handling is significantly prolonged, and operators cannot promptly obtain temporary operating permissions matching the risk level, increasing the likelihood of escalation and posing a potential threat to the safe and stable operation of the power system.

[0018] For example, during a routine inspection of a substation transformer cooling system, operators visually identified minute oil stains on the bottom of the cooling fan. While these stains did not trigger a system alarm threshold, they matched the characteristics of a potential leak. The operators attempted to access equipment structural drawings and fault diagnosis manuals for in-depth analysis, but due to predefined role permissions, the system refused access to advanced technical documents. Subsequently, the operators submitted a temporary permission escalation request, requiring them to fill out an application form and await supervisor approval. During this period, the approval process was suspended because the supervisor was remotely handling a fault and communication was limited. Simultaneously, the high temperature and oil mist caused fluctuations in the confidence level of biometric information collection during subsequent identity verification, triggering additional security confirmation steps. The system failed to comprehensively evaluate the operator's description of the on-site anomaly, the vibration monitoring data trends of the cooling equipment, and the operator's professional background data (including certification qualifications and fault handling experience scores), thus failing to automatically adjust permissions, and the critical diagnostic operation was forced to stop.

[0019] If these issues are not addressed, operators in time-sensitive scenarios will be unable to promptly implement necessary diagnostic measures based on the veracity of on-site anomalies. Potential initial faults may rapidly escalate into equipment outages due to delays in access control. Furthermore, the data silo effect prevents access control systems from utilizing multi-source monitoring information to verify anomaly risks, leading to a singular decision-making basis and a continuous accumulation of operational risks. Consequently, the reliability of power infrastructure will be continuously affected, the stable operation of the power grid will face uncontrollable factors, and may ultimately trigger a chain reaction.

[0020] For reference, see the appendix. Figure 1 This invention provides a role-based permission adaptive management method, comprising the following steps: S1. Collect the operator's biometric information for identity verification, and grant the operator initial access permissions corresponding to the preset role based on the verification results; S2. Receive on-site anomaly description information submitted by the operator for the target equipment; S3. Obtain auxiliary monitoring data associated with the target equipment, as well as the professional background data of the operators; the auxiliary monitoring data includes at least one of the target equipment's vibration data, partial discharge data, and oil chromatography data; the professional background data includes the operators' identity information, training records, certification qualifications, cumulative number of completed tasks, number of times they have participated in advanced maintenance, experience scores for handling various types of faults, and previous permission level records; S4. Perform semantic parsing on the description information of on-site anomalies, and calculate the risk consensus value that reflects the authenticity of on-site anomalies by integrating the parsing results with auxiliary monitoring data and professional background data. S5. Compare the risk consensus value with the preset safety threshold, and automatically adjust the operator's access permissions when the risk consensus value reaches or exceeds the safety threshold, so that the operator can obtain temporary operating permissions that match the handling of the on-site anomaly. S6. Monitor the duration of temporary operation permissions and restore the operator's access permissions to the initial access permissions when the preset revocation conditions are met.

[0021] For ease of understanding, the following explains some key terms in this embodiment: Biometric information refers to data that identifies an individual through their physiological or behavioral characteristics, such as fingerprints, facial features, iris scans, and voiceprints. This information is unique and stable, and is often used for identity verification to improve security.

[0022] "Preset roles" refer to a set of permissions predefined for different types of operators in system management. Each role corresponds to specific responsibilities and operational scope. For example, a "junior maintenance worker" may only have viewing permissions, while a "senior repair worker" may have diagnostic and some operational permissions.

[0023] "Initial access permissions" refer to the default operating permissions granted to operators after authentication, based on their pre-defined roles. These permissions are typically basic permissions that meet daily work needs and are designed to ensure operational security and stable equipment operation.

[0024] "Target equipment" refers to the specific electrical equipment that operators perform on-site operations or maintenance, such as transformers, switchgear, and relay protection devices.

[0025] "On-site anomaly description information" refers to the descriptive information submitted to the system by operators in text, voice, or other forms when they discover abnormal conditions in the equipment. This information is usually an initial discovery based on the operator's experience and may include a description of the abnormal phenomenon, location, and severity.

[0026] "Auxiliary monitoring data" refers to various real-time or historical monitoring data related to the operating status of the target equipment, such as vibration data, partial discharge data, and oil chromatography data. This data is collected by an independent monitoring system and can objectively reflect the equipment's operating status and potential failure risks.

[0027] "Professional background data" refers to data reflecting the professional competence and experience of operators, including their identity information, training records, certifications, cumulative number of completed tasks, number of times they have participated in advanced maintenance, experience scores for handling various types of faults, and previous access level records. This data is used to assess the operator's professional ability to handle specific anomalies.

[0028] Semantic parsing refers to the analysis of textual information in natural language form, extracting key information, entities, relationships, and intentions, and transforming them into a structured, computable data representation.

[0029] The "Risk Consensus Value" is a quantitative indicator calculated by integrating and analyzing on-site anomaly descriptions, auxiliary monitoring data, and professional background data. It reflects the authenticity and potential risk level of on-site anomalies. The higher the value, the greater the authenticity and urgency of the anomaly.

[0030] "Security threshold" refers to a pre-set risk consensus value limit set by the system. When the risk consensus value reaches or exceeds this threshold, the system will determine that further permission adjustment measures are required.

[0031] "Temporary operating permissions" refer to time-limited operating permissions that the system automatically grants to operators based on risk consensus values ​​under specific abnormal circumstances. These permissions exceed the scope of their initial access permissions. The purpose of these permissions is to enable operators to perform diagnostic and intervention operations required to handle on-site anomalies.

[0032] "Revocation conditions" refer to the system's preset conditions for automatically revoking temporary operation permissions, such as the expiration of the temporary permission's validity period, the completion of exception handling and submission of a report, or the system's determination that the exception has been resolved.

[0033] This embodiment provides a role-based adaptive permission management method, which aims to solve the problems of traditional static permission management in power operation and maintenance scenarios, which cannot adaptively adjust operation permissions based on on-site anomalies, equipment status and operator qualifications, rely on manual approval leading to delays in anomaly handling, and have data gaps between different independent monitoring systems that cannot provide effective decision-making basis for permission adjustment.

[0034] In step S1, the operator's biometric information is collected for identity verification, and initial access permissions corresponding to a preset role are granted based on the verification results. Specifically, the operator can be identified through a facial recognition module on the power appliance control terminal. This facial recognition module can be an industrial-grade camera integrating a high-resolution CMOS image sensor and an infrared fill light, with its built-in microprocessor running a facial detection and recognition algorithm. After the operator's facial image is captured, the microprocessor extracts facial feature points and compares them with authorized personnel facial feature templates stored in a local secure storage area or on a remote server. The comparison algorithm can use a convolutional neural network in deep learning for feature extraction and calculate the matching degree using cosine similarity. If the matching degree is higher than a preset threshold, identity verification is successful. Based on the successfully identified operator's identity, the system grants the operator the basic operating permissions corresponding to their current role from a preset role permission list. This role permission list is stored in a permission management database, which contains the functional modules, data range, and operation types that each role can access. For example, a junior maintenance worker is granted permissions to view equipment operating parameters, record inspection data, and access basic safety procedure documents.

[0035] In step S2, the system receives a description of the on-site anomaly submitted by the operator for the target device. When an operator, during the execution of basic tasks, discovers a minor, potential-risk initial anomaly in the device through their professional judgment, without triggering a system alarm, the operator can submit an on-site anomaly report in voice or text format via the report submission module of the control terminal. This report submission module can be a touchscreen interface, providing a voice input button and a text input box. Voice input is captured by the terminal's built-in microphone and converted into text in real time via a speech-to-text service. The text content is then sent to the backend server. Upon receiving the on-site anomaly report, a dedicated software module on the backend server, namely the risk consensus engine, is immediately activated and started. This engine can be deployed on edge computing devices or cloud servers, running as an independent microservice.

[0036] In step S3, auxiliary monitoring data associated with the target equipment and the professional background data of the operators are acquired. Auxiliary monitoring data includes at least one of the following: vibration data, partial discharge data, and oil chromatography data of the target equipment. Professional background data includes the operator's identity information, training records, certification qualifications, cumulative number of completed tasks, number of advanced maintenance participations, experience scores for handling various types of faults, and previous permission level records. After the risk consensus engine is activated, it will proactively perform the following information integration operations: Query auxiliary monitoring data: The engine sends query requests to multiple independent monitoring systems related to the abnormal equipment within the substation through standardized data interfaces. These systems may include high-precision vibration monitoring systems, partial discharge monitoring systems, online oil chromatography monitoring systems, etc. The query request will specify the equipment identifier and time range; for example, it may request vibration frequency data, partial discharge pulse counts, and the content data of specific chemical components in the cooling oil related to the transformer cooling system within 30 minutes before and after the submission time of the on-site anomaly report. Even if these data have not yet reached the alarm threshold of their respective systems, they will still be collected. Obtain operator background information: The engine retrieves the identity information of the operator who submitted the report, their past experience level records in the system, and their current basic permission level from the permission management database.

[0037] In step S4, semantic parsing is performed on the description of the on-site anomaly. The parsing results are then integrated with auxiliary monitoring data and professional background data to calculate a risk consensus value reflecting the authenticity of the on-site anomaly. The engine performs semantic analysis on the on-site anomaly reports submitted by operators. This can be achieved using natural language processing technology, such as using keyword extraction algorithms to identify core words in the report and combining them with a pre-defined power equipment fault dictionary to determine the anomaly type and potential urgency. For example, if the report contains words like "oil stain" or "leakage," the system will associate them with the potential risk of transformer oil leakage. The risk consensus engine comprehensively evaluates the integrated multi-source monitoring data, operator background information, and on-site report content to calculate a risk consensus value. The calculation logic for this risk consensus value considers the following factors: Monitoring data anomaly trend: Analyzing whether there are weak anomaly trends or correlated changes in the auxiliary monitoring data that match the on-site report description. For example, if the operator reports "minor oil stains," and oil chromatography monitoring data shows a slight but continuous upward trend in the acetylene content of the cooling oil over the past 30 minutes, a high correlation is considered to exist. This trend analysis can be achieved using statistical methods such as linear regression or moving average. Operator Experience Weighting: The weight of an operator's field report is adjusted based on their experience level. For example, experience levels are divided into 1 to 5, corresponding to weighting factors from 1.0 to 1.5. The initial risk assessment value of the operator's report is multiplied by this weighting factor when calculating the risk consensus value. Report Detail and Consistency: The level of detail in the field report and its logical consistency with monitoring data are assessed. For example, if the report is specific, clear, and consistent with subtle anomaly trends in the monitoring data, the risk consensus value is increased. Potential Risk Level: Based on the anomaly type and equipment importance, the potential escalation risk of the initial anomaly is assessed. This can be based on a pre-defined risk assessment matrix, cross-evaluating "anomaly type" and "equipment importance" to derive the initial risk level. The formula for calculating the risk consensus value can be expressed as: Risk Consensus Value = W1 × (Monitoring Data Anomaly Index) + W2 × (Operator Experience Weight) + W3 × (Report Detail Consistency Index) + W4 × (Potential Risk Level Index), where W1, W2, W3, and W4 are preset weighting coefficients, and W1 + W2 + W3 + W4 = 1. All indices are normalized to between 0 and 1.

[0038] In step S5, the risk consensus value is compared with a preset safety threshold. When the risk consensus value reaches or exceeds the safety threshold, the operator's access permissions are automatically adjusted to grant the operator temporary operational permissions appropriate to handle the on-site anomaly. The system compares the calculated risk consensus value with the preset safety threshold. This safety threshold can be configured based on the importance and potential risk level of the power equipment; for example, for a core transformer, the threshold might be set to 0.75. Automatic permission escalation: If the risk consensus value reaches or exceeds the safety threshold, the system will determine that the on-site anomaly has sufficient authenticity and urgency, thereby automatically triggering a specific permission escalation for the current operator. Permission escalation is achieved by modifying the operator's temporary permission record in the permission management database. For example, temporarily expanding the permissions of a junior maintenance worker to access advanced diagnostic tools, detailed technical documents, or specific operational functions. Synchronous notification and recording: After successful permission escalation, the system will immediately send a notification to relevant supervisors via the enterprise instant messaging platform or SMS service, informing them that the permission has been automatically escalated, and attaching the risk consensus value and a summary of relevant evidence. Meanwhile, the entire permission adjustment process, including the time, operator, elevated permissions, rating, and triggering reason, is recorded in detail in the operation log for subsequent auditing and traceability. Permission validity management: Granted temporary permissions have preset validity periods, for example, automatically expiring 2 hours after permission elevation. The system monitors the validity period of temporary permissions through a scheduled task. The system will remind the operator before the permission expires. After the operator completes the exception handling and submits a processing report, the system will evaluate the report content and, based on the evaluation results, prematurely revoke the temporary permission or extend the permission if necessary.

[0039] In step S6, the system monitors the duration of temporary operating permissions and restores the operator's access permissions to their initial access permissions when preset revocation conditions are met. The system compares the calculated risk consensus value with a preset safety threshold. This safety threshold can be configured according to the importance and potential risk level of the power equipment; for example, for a core transformer, the threshold may be set to 0.75. Automatic permission escalation: If the risk consensus value reaches or exceeds the safety threshold, the system will determine that the on-site anomaly has sufficient authenticity and urgency, thereby automatically triggering a specific permission escalation for the current operator. Permission escalation is achieved by modifying the operator's temporary permission record in the permission management database; for example, temporarily expanding the permissions of a junior maintenance worker to access advanced diagnostic tools, detailed technical documents, or specific operating functions. Synchronous notification and recording: After successful permission escalation, the system will immediately send a notification to the relevant supervisor through the enterprise instant messaging platform or SMS service, informing them that the permission has been automatically escalated, and attaching the risk consensus value and a summary of relevant evidence. At the same time, the entire permission adjustment process, including the time, operator, escalated permissions, score, and triggering reason, will be recorded in detail in the operation log for subsequent auditing and traceability. Permission expiration management: Granted temporary permissions have a preset expiration time, for example, automatically expiring 2 hours after permission elevation. The system monitors the validity period of temporary permissions through a scheduled task. The system will remind the operator before the permission is about to expire. After the operator completes the exception handling and submits a processing report, the system will evaluate the report content and, based on the evaluation results, revoke the temporary permission in advance or extend the permission if necessary.

[0040] The following example will provide a more detailed explanation of the above technical solution: Suppose that in a power substation, operator A, identified by the system as a "junior maintenance worker," is conducting a routine inspection of a core transformer. Operator A authenticates their identity through the facial recognition module on the control terminal. Based on their preset "junior maintenance worker" role, the system grants them initial access permissions, such as viewing equipment operating parameters and recording inspection data. During the inspection, operator A, relying on their extensive field experience, discovers a tiny oil stain at the bottom of the transformer's cooling fan. This oil stain is very inconspicuous, almost imperceptible to the naked eye, and does not trigger any system alarms, but its location and shape arouse operator A's suspicion.

[0041] Operator A realized this might be a sign of an early potential malfunction, requiring further investigation. He submitted a field anomaly report in text format via the control terminal's report submission module, describing "fine oil stains found at the bottom of the transformer cooling fan." Upon receiving this report, the system's risk consensus engine was immediately activated.

[0042] The risk consensus engine first acquires auxiliary monitoring data associated with the transformer. It sends query requests via data interfaces to the high-precision vibration monitoring system, partial discharge monitoring system, and online oil chromatography monitoring system within the substation, obtaining vibration frequency data, partial discharge pulse counts, and the content data of specific chemical components such as acetylene and methane in the cooling oil for the transformer's cooling system within 30 minutes before and after the report submission time. Even if these data have not yet reached the alarm thresholds of their respective systems, they are still collected. Simultaneously, the engine retrieves the professional background data of operator A from the access control database, including their employee ID, cumulative number of completed tasks, number of advanced maintenance participations, experience ratings for handling various types of faults, and previous access level records.

[0043] Subsequently, the risk consensus engine performs semantic analysis on the on-site anomaly description information submitted by operator A. Using natural language processing technology, it identifies the core term "oil stain" in the report and, combined with a pre-set power equipment fault dictionary, associates it with the potential risk of transformer oil leakage.

[0044] Next, the engine integrates the semantic parsing results with auxiliary monitoring data and professional background data to calculate a risk consensus value reflecting the authenticity of the on-site anomaly. Specifically, the engine's analysis of oil chromatography monitoring data showed a slight but continuous upward trend in the acetylene content of the cooling oil over the past 30 minutes, which is highly correlated with the "minor oil stains" reported by operator A. Simultaneously, based on operator A's professional background data, their experience level is high, therefore the weight of their on-site report was adjusted accordingly. The level of detail in the report and its consistency with the monitoring data also increased the risk consensus value. Taking all these factors into account, the engine calculates a risk consensus value, for example, 0.8.

[0045] The system compares the calculated risk consensus value of 0.8 with the preset safety threshold of 0.75. Since the risk consensus value of 0.8 reaches or exceeds the safety threshold of 0.75, the system determines that the on-site anomaly has sufficient authenticity and urgency, and thus automatically adjusts the access permissions of operator A. The system modifies the temporary permission record for operator A in the permission management database, temporarily expanding their "Junior Maintenance Technician" permissions to include access to "Advanced Diagnostic Tools" (e.g., professional fault diagnosis software interfaces), "Detailed Technical Documentation" (e.g., electronic versions of equipment structural drawings and fault diagnosis manuals), and "Specific Operational Functions" (e.g., remotely viewing sensor data inside the cooling system).

[0046] Upon successful privilege escalation, the system immediately sends a notification to relevant supervisors via the enterprise instant messaging platform, informing operator A that their privileges have been automatically elevated, along with a risk consensus value and a summary of relevant evidence. Simultaneously, the entire privilege adjustment process is recorded in detail in the operation log. Granted temporary privileges have a preset expiration time, such as 2 hours. The system monitors the validity period of temporary privileges through scheduled tasks and alerts operator A before the privileges expire.

[0047] After gaining temporary access, Operator A immediately accessed advanced diagnostic tools and detailed technical documentation. He conducted an in-depth analysis of the oil stains at the bottom of the transformer cooling fan and, combined with auxiliary monitoring data, ultimately confirmed an initial leak in the seals. He completed the anomaly handling and submitted a report. After evaluating the report, the system determined that the anomaly had been effectively resolved and automatically restored Operator A's access permissions to their initial state.

[0048] As can be seen from the above examples, the role-based permission adaptive management method proposed in this embodiment can effectively solve the problems faced by traditional static permission management in power operation and maintenance scenarios.

[0049] Compared to existing technologies that rely on manual approval for access control, this embodiment introduces a risk consensus engine to achieve automatic access control. In the example above, after operator A discovers an oil stain, the system can quickly calculate a risk consensus value and automatically elevate access based on the description of the anomaly, auxiliary monitoring data, and the operator's professional background information, without waiting for manual approval from the supervisor. This significantly shortens the access control time and avoids the risk of escalation of the fault due to delays in manual approval. In traditional systems, operators face operational difficulties when supervisors cannot respond in a timely manner, while this embodiment ensures that operators can obtain the necessary access in a timely manner in time-sensitive anomaly situations, thereby effectively preventing further deterioration of the fault.

[0050] Furthermore, this embodiment breaks down data barriers between different independent monitoring systems. In existing technologies, high-precision vibration monitoring systems, partial discharge monitoring systems, and online oil chromatography monitoring systems may have captured weak anomaly data related to oil stains discovered by operators. However, these data lack a real-time, intelligent correlation mechanism with the facial recognition access control system, preventing the access control system from utilizing this multi-source heterogeneous auxiliary information to determine the rationality and urgency of access escalation requests. This embodiment integrates these auxiliary monitoring data through a risk consensus engine and incorporates them into the calculation of risk consensus values, making access control decisions more comprehensive and objective. In the example, the slight upward trend in acetylene content in the oil chromatography data provides strong evidence for operator A's on-site report, enabling the system to more accurately determine the authenticity and urgency of the anomaly, thereby making a more reasonable access control adjustment decision. This data fusion capability transforms the access control system from an "information blind spot" into one that can fully utilize multi-source information for intelligent decision-making.

[0051] This embodiment also considers the professional background data of operators, making permission adjustments more personalized and secure. In existing technologies, permission granting is mainly based on preset roles, failing to fully consider the actual experience and capabilities of operators. This embodiment incorporates professional background data such as operator identity information, training records, certification qualifications, cumulative number of completed tasks, number of advanced maintenance participations, experience scores in handling various types of faults, and previous permission level records into the calculation of risk consensus values. This allows the system to assess whether operators possess the qualifications to handle the current anomaly when elevating permissions. In the example, operator A's higher experience level increases the weight of their on-site report, reflecting recognition and utilization of the operator's professional capabilities and avoiding the security risks caused by blindly elevating permissions to personnel without corresponding capabilities.

[0052] In summary, this embodiment constructs an intelligent, efficient, and secure adaptive role-based access control method by employing biometric authentication, receiving on-site anomaly descriptions, acquiring and fusing multi-source data (auxiliary monitoring data and professional background data) for analysis, calculating risk consensus values, adaptively adjusting permissions, and dynamically restoring temporary permissions. This method not only overcomes the limitations of traditional static access control in responding to on-site anomalies, improving the timeliness and accuracy of anomaly handling, but also, by integrating multi-source heterogeneous data and considering the professional background of operators, makes access control more intelligent and refined, significantly improving the overall security and efficiency of power equipment operation and maintenance.

[0053] In some embodiments, the specific steps in step S4 include: S41. Perform preliminary semantic analysis on the on-site anomaly description information, and determine whether there is semantic ambiguity in the on-site anomaly description information based on the preliminary semantic analysis results; S42. When the description of an anomaly on site is semantically ambiguous, initiate a context-guided interactive protocol to refine the description of the anomaly on site by asking clarifying questions to the operator and receiving the operator's response feedback. S43. During the context-guided interactive protocol, the operator is prompted to collect multimodal on-site evidence related to the on-site anomaly and to preprocess the multimodal on-site evidence. The multimodal on-site evidence includes visual evidence and acoustic evidence. The preprocessing includes image enhancement, noise reduction, geometric correction, illumination compensation, contrast adjustment or motion blur removal for visual evidence, and background noise suppression, frequency filtering, feature extraction, transient event detection, silent segment removal or spectrum normalization for acoustic evidence. S44. Based on the refined on-site anomaly description information and the preprocessed multimodal on-site evidence, an anomaly scenario description is generated through cross-validation and fusion; S45. By integrating and analyzing the description of the abnormal situation with auxiliary monitoring data and professional background data, a risk consensus value reflecting the true extent of the on-site abnormality is calculated.

[0054] Upon receiving an on-site anomaly description from operators, the proposed solution first performs preliminary semantic analysis to quickly identify any semantic ambiguity. This preliminary semantic analysis aims to gain a basic understanding and structure the on-site anomaly description submitted by operators. Its purpose is to extract key information from unstructured text, such as the anomaly object, anomaly phenomenon, and possible causes. This analysis can be achieved using various Natural Language Processing (NLP) techniques. For example, it can utilize rule-based pattern matching algorithms to identify predefined keywords and phrases; or employ machine learning-based text classification models to categorize the description information into preset anomaly types. Another approach is to use a pre-trained language model to perform word vectorization and semantic similarity calculations on the text, thereby understanding its deeper meaning. Determining semantic ambiguity involves assessing the clarity and accuracy of the preliminary semantic analysis results. Its purpose is to identify potential ambiguities, incompleteness, or non-standardized expressions in the description information to avoid biases in subsequent analysis due to information quality issues. This determination can be achieved by calculating the matching degree between the description information and a preset standardized fault description; if the matching degree is below a certain threshold, ambiguity is considered to exist. In addition, it can also be determined by detecting whether there are a large number of vague words or non-technical terms in the description information.

[0055] When the system determines that the descriptive information is semantically ambiguous, it immediately initiates a context-guided interaction protocol. This protocol posed a series of clarifying questions to the operator and received their responses, thereby refining the original anomaly description step by step. The context-guided interaction protocol is a mechanism for dynamic and targeted dialogue between the system and the operator. Its function is to proactively guide the operator to provide more specific and accurate details when the system identifies ambiguity, thus improving the quality of the anomaly description. This protocol can be implemented based on a pre-set question-and-answer template library. The system selects appropriate questions from the template library based on the identified ambiguities. Another implementation method is to utilize a generative AI model to dynamically generate personalized clarifying questions based on the current anomaly context and existing ambiguous descriptions. Asking clarifying questions aims to specifically address the ambiguities in the descriptive information. For example, if the operator describes "the equipment is making abnormal noises," the system can ask, "Is the noise continuous or intermittent? Is it high-frequency or low-frequency?" These questions can be pre-set as a multi-turn dialogue structure to gradually obtain more information. Receiving the operator's responses means the system obtains the operator's answers to the clarifying questions. These feedbacks can be text or voice input, which the system converts into processable text data using speech-to-text technology. The system then performs secondary semantic analysis on these feedbacks and integrates them with the original descriptive information, thereby gradually refining and improving the on-site anomaly description information.

[0056] During this interaction, the system will also prompt operators to collect multimodal on-site evidence related to the anomaly, such as visual and acoustic evidence, and preprocess this multimodal evidence. Prompting operators to collect multimodal on-site evidence aims to leverage their on-site advantage to obtain more objective and comprehensive information about the anomaly beyond textual descriptions. This evidence can be a direct record of the anomaly, such as images, videos (visual evidence), or audio (acoustic evidence). The system can guide operators to collect this evidence using terminal devices through user interface prompts, voice commands, or vibration alerts. Multimodal on-site evidence includes visual and acoustic evidence. Visual evidence can be photos or videos of the anomaly point, used to record the physical appearance of the equipment, color changes, leaks, component deformation, etc. Acoustic evidence can be audio recordings near the anomaly point, used to capture abnormal noises, vibrations, and discharges during equipment operation. This evidence provides an objective description of the on-site anomaly from different dimensions. Preprocessing the multimodal on-site evidence aims to improve its quality, remove environmental interference, and make it more suitable for subsequent analysis. For visual evidence, preprocessing can include image enhancement, denoising, geometric correction, illumination compensation, contrast adjustment, or motion blur removal. These processes help improve image sharpness and analyzability. For acoustic evidence, preprocessing can include background noise suppression, frequency filtering, feature extraction, transient event detection, silence removal, or spectral normalization. These processes help highlight anomalous sound features and reduce the impact of ambient noise.

[0057] Subsequently, the system cross-validates and fuses the refined on-site anomaly description with preprocessed multimodal on-site evidence to generate an anomaly scenario description. Cross-validation aims to assess the consistency and complementarity between different modalities of information to improve the accuracy of anomaly scenario judgment. For example, if the text description states "there are oil stains on the equipment surface," and visual evidence shows an image of actual oil stains, the two corroborate each other, enhancing the reliability of the information. Cross-validation can be achieved by comparing the feature similarity extracted from different modalities of evidence or by judging whether the information conflicts through logical rules. Fusion aims to integrate the refined text description and preprocessed multimodal on-site evidence to form a more comprehensive and objective anomaly scenario description. Fusion techniques can employ various methods, such as feature-level fusion, which concatenates feature vectors from different modalities and then inputs them into a unified classifier; or decision-level fusion, which weights the analysis results of different modalities through voting or combines them based on confidence levels. Another fusion approach is based on an attention mechanism, dynamically allocating weights to different modalities of evidence to highlight key information. Generating anomaly scenario descriptions involves integrating cross-validated and fused multi-source information into a structured, high-confidence text or data structure that comprehensively reflects the true situation of the anomaly at the scene. This description is more specific and objective than the original scene anomaly description and includes supporting information from multimodal evidence, providing a solid foundation for subsequent risk assessment.

[0058] Ultimately, the system deeply integrates and analyzes this refined and multimodal evidence-supported description of the abnormal situation with auxiliary monitoring data obtained from independent monitoring systems and professional background data of operators to calculate a risk consensus value reflecting the authenticity of the on-site anomaly. The fusion analysis aims to comprehensively evaluate the abnormal situation description provided by operators, the auxiliary monitoring data automatically collected by the system, and the operators' own professional background data. Its purpose is to comprehensively consider the authenticity, severity, and operator handling capabilities of the on-site anomaly from multiple dimensions, thereby arriving at a more accurate and reliable risk assessment. This fusion analysis can employ a multi-factor weighted model, assigning different weights to different types of data and then performing a weighted sum. Another implementation method is to utilize a machine learning model, using multi-source data as input features to train the model to predict the risk consensus value. Calculating the risk consensus value reflecting the authenticity of the on-site anomaly means quantifying the result of the fusion analysis into a numerical value that intuitively represents the authenticity and potential risk of the on-site anomaly. This risk consensus value can be a floating-point number between 0 and 1, with higher values ​​indicating higher risk. This value can be calculated based on a preset risk assessment matrix, combined with factors such as anomaly type, equipment importance, monitoring data trends, and operator experience for a comprehensive score.

[0059] This solution, through the aforementioned series of steps, effectively addresses the problems of inaccurate on-site anomaly descriptions and insufficient information dimensions in traditional methods. Building upon identity verification and basic permission granting, it provides an intelligent information refinement and risk assessment mechanism, enabling the system to dynamically adjust operator permissions based on the actual on-site situation. This mechanism not only improves the accuracy of risk assessment but also provides a solid and reliable decision-making basis for subsequent adaptive permission adjustments, thereby avoiding deviations in permission adjustments due to incomplete or inaccurate information. It ensures that in emergency situations, operators can be granted timely and secure temporary operational permissions appropriate for handling on-site anomalies, effectively reducing the risk of escalation of faults.

[0060] The following is a concrete example to illustrate this. Suppose a junior maintenance technician, while inspecting a transformer, finds slight oil stains at the bottom of its cooling fan, but the system does not trigger any alarms. The technician submits a description of the anomaly via the control terminal, describing it as "oil stains at the bottom of the fan, somewhat dark in color."

[0061] First, the system performs preliminary semantic analysis on the description. The system's built-in natural language understanding module uses a pre-trained language model based on the Transformer architecture to vectorize and calculate semantic similarity for the phrase "There are oil stains on the bottom of the fan, and the color is a bit dark." Since "the color is a bit dark" is a vague description and its match with the pre-defined standardized fault dictionary is less than 0.7, the system determines that the description is semantically ambiguous.

[0062] When semantic ambiguity is detected, the system immediately initiates a context-guided interactive protocol. Through the touchscreen interface of the control terminal, the system poses clarifying questions to the operator, such as: "What exactly do you mean by 'the color is a bit dark'? Is it dark red, brown, or black?" and "Is the oil stain in droplets, flakes, or seepage?" The operator provides feedback via the touchscreen, such as: "The oil stain is dark red and seeping." The system performs secondary semantic analysis on this feedback, integrating information such as "dark red" and "seeping" into the original description, resulting in the refined description: "There is a dark red, seeping oil stain at the bottom of the transformer cooling fan."

[0063] During the interaction process, the system simultaneously prompted the operator to collect multimodal on-site evidence. The operator used the terminal's integrated camera to take close-up photos of the oil stains (visual evidence) and used a microphone to record the operating sounds near the fan (acoustic evidence). The system preprocessed this evidence: for visual evidence, image enhancement, noise reduction, and illumination compensation were performed to improve the clarity of the oil stain texture; for acoustic evidence, background noise suppression and frequency filtering were performed to ensure that there were no obvious abnormal sounds in the recording.

[0064] Subsequently, based on the refined on-site anomaly description information and preprocessed multimodal on-site evidence, the system generates an anomaly scenario description through cross-validation and fusion. The system evaluates the consistency between the text description "dark red seeping oil stains" and the dark red liquid area shown in the visual evidence, finding a high degree of agreement. Simultaneously, no abnormal sounds were detected by acoustic evidence, consistent with the characteristics of the initial leakage. Through the multimodal fusion module, the feature vectors of text, visual, and acoustic evidence are weighted and fused to generate the final anomaly scenario description: "Dark red, seeping oil stains were found at the bottom of the transformer cooling fan. Visual analysis confirmed the presence of oil stain textures, and acoustic analysis detected no abnormal sounds, highly consistent with the characteristics of the initial seal leakage."

[0065] Finally, the system integrates this anomaly description with auxiliary monitoring data (e.g., the acetylene content in the cooling oil shown by the online oil chromatography monitoring system has shown a slight upward trend over the past 30 minutes) and the operator's professional background data (e.g., the maintenance worker has a high cumulative number of completed tasks and an experience rating of above average). The system uses a multi-factor weighted model to comprehensively consider this information and calculate a risk consensus value that reflects the authenticity of the on-site anomaly. For example, if the calculated risk consensus value is 0.8, which is higher than the preset safety threshold of 0.75, it indicates that the anomaly has a high degree of authenticity and urgency, and the system will trigger the subsequent permission adjustment process accordingly.

[0066] The proposed solution first performs preliminary semantic analysis on the on-site anomaly descriptions submitted by operators, and determines whether semantic ambiguity exists based on the analysis results. This allows for quality control of input information from the source, enabling timely detection and handling of unclear descriptions. When semantic ambiguity is identified, the system initiates a context-guided interactive protocol. By posing clarifying questions to operators and receiving feedback, the system efficiently and accurately refines the anomaly descriptions, avoiding the additional burden on operators to manually compile standardized information, which is particularly suitable for emergency situations. Simultaneously, during the interaction, operators are prompted to collect multimodal on-site evidence (such as visual and acoustic evidence), and this evidence is preprocessed, greatly enriching the dimensions of the anomaly information and transforming the operator's on-site perception into analyzable objective data, effectively compensating for the shortcomings of single textual descriptions. Furthermore, based on the refined on-site anomaly descriptions and preprocessed multimodal on-site evidence, this solution generates a comprehensive and accurate anomaly scenario description through cross-validation and fusion. Cross-validation ensures the mutual verification and consistency of information from different sources, effectively eliminating contradictory or erroneous information; fusion organically integrates multi-source information, forming a more complete and objective understanding of on-site anomalies. Based on this, the generated anomaly scenario description is fused and analyzed with auxiliary monitoring data and the professional background data of operators. The calculated risk consensus value can more accurately reflect the authenticity of the on-site anomaly. Through the above technical solution, this application effectively solves the problem of inaccurate risk judgment caused by vague on-site anomaly descriptions and insufficient information dimensions in traditional methods. It ensures that the input information used for risk assessment is high-quality, multi-dimensional, and verified, thus making the calculated risk consensus value more reliable and accurate. This accurate risk assessment provides a solid foundation for the subsequent automatic adjustment of operator access permissions, enabling the system to grant operators timely and accurate temporary operating permissions matching the handling of on-site anomalies while ensuring safety. This significantly improves the response efficiency and safety of power equipment operation and maintenance, and effectively reduces the risk of potential fault escalation.

[0067] In some embodiments, the specific steps in step S44 include: S441. Evidence confidence assessment is performed on each modality of preprocessed multimodal scene evidence, specifically including the following steps S4411-S4413: S4411. For each type of modal scene evidence in the preprocessed multimodal scene evidence, identify the modal type of the modal scene evidence; S4412. Based on the modal type, extract multiple evaluation indicators from the modal field evidence; where, when the modal type is visual evidence, the multiple evaluation indicators include image sharpness, geometric distortion, and illumination consistency; when the modal type is acoustic evidence, the multiple evaluation indicators include background noise level, anomalous signal energy, and transient event density. S4413. The extracted evaluation indicators from multiple dimensions are weighted and combined to obtain the confidence level of the evidence corresponding to the modal on-site evidence; S442. Adjust the weight of each modality of on-site evidence in the fusion process based on the assessed confidence level of the evidence, specifically including the following steps S4421-S4422: S4421. When the confidence level of any modal field evidence is lower than the preset confidence threshold, reduce the weight of that modal field evidence or exclude it from the fusion process. S4422. When any modal evidence is missing, set the weight of that modal evidence to zero and redistribute the weights of the remaining modal evidence. S443. The refined on-site anomaly description information is weighted and fused with the multimodal on-site evidence after weight adjustment to generate an anomaly scenario description.

[0068] Specifically, when assessing the confidence level of each modality of preprocessed multimodal crime scene evidence, the first step is to identify the modality type of each piece of evidence. This step aims to clarify the source and nature of each piece of evidence, laying the foundation for subsequent targeted assessment. Modality type identification can be based on metadata information of the evidence, such as file extensions, data stream encoding formats, or identifiers of the acquisition devices. For example, the system can determine whether the data is image or audio based on the file header information. Another approach is to directly attach modality type labels during data acquisition; for example, data acquired by a camera is labeled "visual," and data acquired by a microphone is labeled "acoustic."

[0069] Secondly, based on the modality type, multiple evaluation metrics are extracted from the modality-specific evidence. This step quantifies and extracts key features reflecting the quality and reliability of the original evidence based on the identified modality type. For example, when the modality type is visual evidence, the multiple evaluation metrics include image sharpness metrics, geometric distortion metrics, and illumination consistency metrics. Image sharpness metrics can be calculated using image edge gradients, high-frequency components of Fourier transforms, or blind image quality assessment algorithms (such as BRISQUE, NIQE). Geometric distortion metrics can be evaluated based on the curvature of known straight lines or circles in the image, or through camera calibration parameters. Illumination consistency metrics can be analyzed by examining the image's brightness distribution, identifying overexposed or underexposed areas, or measured using the information entropy after histogram equalization. When the modality type is acoustic evidence, the multiple evaluation metrics include background noise level metrics, anomalous signal energy metrics, and transient event density metrics. Background noise level metrics can be calculated by calculating the signal-to-noise ratio (SNR) of the audio signal or obtained through noise estimation algorithms (such as spectral subtraction). Abnormal signal energy indices can analyze the energy concentration within a specific frequency range. For example, by analyzing the spectrum using Short Time Fourier Transform (STFT), energy peaks associated with known anomalous patterns can be identified. Transient event density indices can statistically analyze the frequency of short-duration, high-energy pulse events in audio. For example, they can be identified and counted using transient detection algorithms such as those based on energy envelopes or wavelet transforms.

[0070] Next, the extracted evaluation indicators from multiple dimensions are weighted and combined to obtain the confidence level of the modal on-site evidence. This step integrates the evaluation indicators extracted from different dimensions into a comprehensive confidence level value to fully reflect the reliability of individual modal evidence. The weighted combination calculation can be performed using a linear weighted summation method, that is, assigning a weight coefficient to each dimension evaluation indicator, and then summing the values ​​of each indicator after multiplying them by their corresponding weights. For example, for visual evidence, the weight of the sharpness indicator can be set to 0.5, the weight of the geometric distortion indicator to 0.3, and the weight of the illumination consistency indicator to 0.2. Another implementation method is to use a fuzzy logic inference system, taking each dimension indicator as input, and outputting a confidence level value between 0 and 1 through preset fuzzy rules and membership functions.

[0071] When adjusting the weight of each modality of on-site evidence in the fusion process based on the assessed confidence level of the evidence, the process specifically includes: reducing the weight of any modality of on-site evidence when its confidence level is lower than a preset confidence threshold, or excluding it from the fusion process. This step aims to weaken or eliminate the negative impact of low-quality evidence on the final fusion result. When the confidence level of a modality of evidence is lower than a preset threshold, the system can adopt two strategies: one is to reduce its weight in subsequent fusion, for example, by adjusting its weight coefficient from the default value to a lower value; the other is to directly exclude it from the fusion process, that is, set its weight to zero, and no longer participate in subsequent weighted fusion calculations. The preset confidence threshold can be set based on historical data analysis and expert experience to balance the availability and reliability of evidence. In addition, when any modality of on-site evidence is missing, its weight is set to zero, and the weights of the remaining modalities of on-site evidence are redistributed. This step handles the case of incomplete on-site evidence, ensuring that the fusion process can still proceed effectively even if some evidence is missing. When the system detects that on-site evidence for a certain modality has not been collected or cannot be obtained, the system will directly set its weight in the fusion to zero. In order to maintain the consistency of the overall weight, the system will redistribute the weights of the remaining available modal evidence according to the confidence level of the remaining available modal evidence or the preset priority.

[0072] Finally, the refined on-site anomaly description information is weighted and fused with the multimodal on-site evidence adjusted for weights to generate the anomaly situation description. This step is the core of multimodal information integration, aiming to organically combine the text description with visual and acoustic evidence that has undergone quality assessment and weight adjustment to form a comprehensive, accurate, and high-confidence anomaly situation description. Weighted fusion can be implemented using various techniques. For example, a multimodal fusion model can be used, taking the refined text feature vector and the weighted visual and acoustic feature vectors as input, learning the complex relationships between them, and outputting a unified anomaly situation representation. Another approach is to use a weighted average or weighted voting mechanism, combining the semantic analysis results of the text description with the classification or recognition results of each modality of evidence according to their adjusted weights, ultimately generating a structured or semi-structured anomaly situation description, which may include information such as anomaly type, location, severity, and possible causes.

[0073] This solution effectively addresses the problem of low-quality evidence interfering with the accuracy of fusion results in traditional fusion methods by introducing evidence confidence assessment and dynamic weight adjustment mechanisms before multimodal evidence fusion. In the aforementioned role-based adaptive access control method, this mechanism, combined with refined on-site anomaly description information, ensures that the quality differences and completeness of various on-site evidence are fully considered when generating anomaly scenario descriptions. This makes the subsequently calculated risk consensus values ​​more accurate, thus providing a more reliable and accurate basis for adaptive adjustment of operator access permissions. For example, when the on-site anomaly description information submitted by operators is semantically refined and combined with multimodal on-site evidence such as visual and acoustic evidence, if the visual evidence has low confidence due to poor lighting, this solution will reduce its weight; conversely, if the acoustic evidence is clear and has high confidence, it will be given a higher weight. This avoids misjudging the overall anomaly scenario due to a single low-quality piece of evidence, ensuring the rationality and security of access control decisions.

[0074] The following is a concrete example to illustrate this. In the above role-based adaptive permission management method, after the operator submits a refined description of the on-site anomaly, and the system has already collected and preprocessed multimodal on-site evidence (e.g., visual and acoustic evidence) related to the anomaly, the system will perform the following steps to generate an accurate description of the anomaly situation: First, the system assesses the confidence level of each modality of preprocessed on-site evidence. For example, for acquired visual evidence, the system identifies its modality as "visual evidence." Subsequently, the system extracts image sharpness, geometric distortion, and illumination consistency metrics from this visual evidence. The image sharpness metric can be calculated using a wavelet transform-based image sharpness evaluation method; the geometric distortion metric can be quantified using perspective correction based on preset reference points or lines in the image; and the illumination consistency metric can be evaluated based on the uniformity of the brightness histogram distribution of image pixels. These metrics are then weighted and combined, for example, using a support vector machine (SVM) model, to output a visual evidence confidence level between 0 and 1. Similarly, for acquired acoustic evidence, the system identifies its modality as "acoustic evidence" and extracts background noise level metrics (e.g., by calculating the peak signal-to-noise ratio of the audio signal), anomalous signal energy metrics (e.g., by analyzing the power spectral density within a specific frequency range), and transient event density metrics (e.g., by detecting transient events using algorithms based on short-time energy and zero-crossing rate). These indicators are also calculated by weighted combination to obtain the confidence level of acoustic evidence.

[0075] Next, the system dynamically adjusts the weight of each modality of on-site evidence in the fusion process based on the confidence levels of these assessments. For example, if the confidence level of visual evidence is 0.5 (below the preset confidence threshold of 0.7), while the confidence level of acoustic evidence is 0.8 (above the preset confidence threshold), the system will reduce the weight of visual evidence, for example, from the default 0.4 to 0.2. Simultaneously, the weight of acoustic evidence can remain the same or be slightly increased, for example, from the default 0.3 to 0.5. If, at this point, a modality of evidence is found (e.g., acoustic evidence is completely missing due to microphone malfunction), the system will set its weight directly to zero and redistribute the weights of the remaining modal evidence (such as visual evidence and refined text descriptions) to ensure that the total weight sums to 1.

[0076] Finally, the system performs a weighted fusion of the refined on-site anomaly description with the aforementioned weighted visual and acoustic evidence to generate the final anomaly situation description. For example, the refined text description might state "there is oil stain at the bottom of the transformer cooling fan," visual evidence (weight 0.2) might show a blurry image of the oil stain, while acoustic evidence (weight 0.5) might clearly capture a slight dripping sound. The system integrates this weighted information through a multimodal fusion network, ultimately generating a more accurate anomaly situation description, such as: "There is a slight oil leak at the bottom of the transformer cooling fan, accompanied by intermittent dripping sounds. The visual evidence is less clear due to insufficient lighting, but the acoustic evidence supports the leak assessment." This description is more accurate and reliable than a single modality or the fusion result without weight adjustment.

[0077] Through the above technical solution, this application effectively solves the problem of inaccurate descriptions of abnormal situations caused by uneven or missing evidence quality during multimodal on-site evidence fusion. By assessing the confidence level of each modality of on-site evidence and dynamically adjusting its weight in the fusion process based on the assessment results, this solution can effectively avoid erroneous information introduced by low-quality evidence and fully utilize the value of high-quality evidence. When some modal evidence is missing, the system can also respond flexibly by reallocating weights to ensure the robustness of the fusion process. This allows the generated abnormal situation descriptions to more accurately and objectively reflect the true situation of on-site anomalies, significantly improving the accuracy and reliability of abnormal situation perception. In the above-mentioned role-based adaptive permission management method, this highly accurate abnormal situation description serves as a key input for calculating risk consensus values, ensuring the accuracy of risk assessment. This enables the system to make more reasonable, safe, and on-site-compliant decisions when determining whether to adjust operator access permissions, avoiding permission misjudgments or delays caused by information distortion, and ensuring the efficiency and safety of power equipment operation and maintenance.

[0078] In some embodiments, the specific steps in step S45 include: S451. Identify the degree of conflict between the type of anomaly indicated in the description of the abnormal situation and the correlation changes or potential conflicts with the auxiliary monitoring data; S452. Based on the degree of conflict of the identified correlation changes or potential conflicts, and in combination with the anomaly type and the operating status of the target equipment, adjust the weight of the anomaly situation description, auxiliary monitoring data and professional background data in the fusion analysis; S453. The weighted descriptions of abnormal situations, auxiliary monitoring data, and professional background data are weighted and fused to calculate a preliminary risk consensus value; S454. When the initial risk consensus value is lower than the safety threshold, and the difference between the safety threshold and the initial risk consensus value is less than the preset calibration range, and a potential conflict is identified, the initial risk consensus value is calibrated upward to obtain the final risk consensus value.

[0079] When calculating the risk consensus value reflecting the authenticity of on-site anomalies, it is first necessary to identify the degree of conflict between the anomaly type indicated in the anomaly scenario description and the correlation changes or potential conflicts with the auxiliary monitoring data. This step aims to assess the consistency or inconsistency between the anomaly scenario description submitted by the operator and the auxiliary monitoring data automatically collected by the system. Its purpose is to discover potential differences between different data sources before data fusion, which may indicate the complexity, uncertainty, or underestimated risk of the on-site anomaly. For example, natural language processing techniques can be used to perform entity recognition and event extraction on the anomaly scenario description to extract the anomaly type. Simultaneously, pattern recognition and anomaly detection can be performed on the auxiliary monitoring data to identify anomaly patterns or trends. Then, using a pre-set rule base or machine learning model, the semantic correlation or statistical relevance between the anomaly type and the anomaly patterns in the monitoring data is compared. The degree of conflict can be quantified using a matching score or inconsistency index. Another approach is to construct a multimodal knowledge graph, using anomaly types, equipment components, monitoring data types, and their typical anomaly patterns as nodes and relationships. Upon receiving descriptions of abnormal situations and auxiliary monitoring data, these are mapped onto a knowledge graph. A graph reasoning algorithm is then used to identify the associated paths and conflicting nodes between the two. The degree of conflict can be calculated based on the number or intensity of inconsistent paths in the knowledge graph.

[0080] Based on this, according to the degree of conflict of identified correlational changes or potential conflicts, and in combination with the anomaly type and the operating status of the target equipment, the weights of the anomaly scenario description, auxiliary monitoring data, and professional background data in the fusion analysis are adjusted. This step dynamically adjusts the contribution weights of different data sources in the subsequent risk consensus value calculation based on the degree of conflict between the identified data sources. Simultaneously, by combining the anomaly type and the real-time operating status of the target equipment, the weight allocation is made more consistent with the actual situation on-site, avoiding risk assessment biases caused by data conflicts or the special nature of equipment status. For example, a rule-based weight adjustment strategy can be established. When there is a high degree of conflict between the anomaly scenario description and auxiliary monitoring data, the initial weight of the conflicting data source can be reduced, or the weight of a certain data source can be increased or decreased according to the nature of the conflict. At the same time, a preset weight adjustment table is consulted based on the anomaly type and the operating status of the target equipment. Another approach is to use a machine learning model to dynamically adjust the weights. The model can learn and optimize the weight allocation strategy for each data source based on the conflict situation, anomaly type, equipment operating status, and the final risk assessment accuracy in historical data.

[0081] Subsequently, the weighted descriptions of abnormal situations, auxiliary monitoring data, and professional background data are weighted and fused to calculate a preliminary risk consensus value. This step involves comprehensively calculating multi-source information after dynamic weight adjustment to arrive at a preliminary risk assessment result. Its purpose is to generate a more accurate and realistic risk consensus value, taking into account potential conflicts between data and equipment operating status. For example, a weighted average or weighted summation method can be used for fusion. First, the descriptions of abnormal situations, auxiliary monitoring data, and professional background data are quantified into corresponding risk indicators or confidence scores and normalized to a unified scale. Then, these quantified indicators are multiplied by the adjusted weights and summed to obtain the preliminary risk consensus value. Another approach is to utilize a multimodal fusion model, such as a deep learning-based fusion network. This network can receive preprocessed and feature-extracted descriptions of abnormal situations, auxiliary monitoring data, and professional background data as input, learn the complex relationships between them through multiple fusion layers, and guide the fusion process according to the adjusted weights, ultimately outputting a preliminary risk consensus value.

[0082] Finally, when the initial risk consensus value is lower than the safety threshold, but the difference between the safety threshold and the initial risk consensus value is less than the preset calibration range, and a potential conflict is identified, the initial risk consensus value is calibrated upwards to obtain the final risk consensus value. This step is a refined handling of critical situations in risk assessment. When the initial risk consensus value, although not reaching the safety threshold, is very close, and a potential conflict between data has been previously identified, the system will proactively adjust the initial risk consensus value upwards. The purpose is to avoid delays in permission adjustments due to an underestimated risk value, thus missing the optimal opportunity to handle potentially serious anomalies. For example, a fixed calibration increment or a calibration function based on the degree of conflict can be set. When the conditions are met, the final risk consensus value can be equal to the initial risk consensus value plus the calibration increment. The calibration increment can be a fixed value or a function proportional to the degree of potential conflict. Another approach is to use fuzzy logic or an expert system for calibration. When the calibration conditions are met, the system will adjust the initial risk consensus value according to preset fuzzy rules or rules in the expert knowledge base. The calibration magnitude can be dynamically calculated based on factors such as the type and severity of the conflict and the importance of the equipment.

[0083] This solution improves the accuracy of risk consensus value calculation by first identifying data conflicts, then adjusting fusion weights, and finally calibrating for critical risk situations. This approach more accurately reflects the actual risk level of on-site anomalies and avoids the problem of untimely permission adjustments due to missed risk assessments. The first step is to identify the degree of conflict between the anomaly type indicated in the anomaly scenario description and the correlation changes or potential conflicts with auxiliary monitoring data. This step first examines the matching degree between the anomaly information obtained from manual on-site descriptions and the monitoring data automatically collected by the equipment, providing a basis for adjustment in subsequent fusion calculations. The reason for completing conflict identification first is that inconsistencies between data from different sources indicate uncertainty or underestimation of risk in the on-site anomaly, requiring targeted adjustments to avoid calculation deviations caused by direct equal-weight fusion. Adjusting weights based on the identified correlation changes or the degree of potential conflicts, combined with the anomaly type and equipment operating status, ensures that the weight allocation is more consistent with the actual on-site scenario, avoiding calculation deviations caused by uniform weight allocation. The weighted descriptions of abnormal situations, auxiliary monitoring data, and professional background data are weighted and fused to calculate a preliminary risk consensus value. This step, based on the previously adjusted contribution of each data point, yields a preliminary risk result that more closely reflects the actual situation, resulting in higher accuracy compared to direct fusion. When the preliminary risk consensus value is lower than the safety threshold, but the difference between the safety threshold and the preliminary risk consensus value is less than a preset calibration range, and a potential conflict is identified, the preliminary risk consensus value is calibrated upwards to obtain the final risk consensus value. This situation corresponds precisely to the critical condition where there is a potential anomaly on-site but it has not yet reached the trigger threshold. The existence of a potential conflict indicates that the risk is likely underestimated. Upward calibration can avoid missing such potential real risks, ensuring timely triggering of permission adjustments and meeting the needs of emergency on-site handling of anomalies.

[0084] As a specific implementation method, in a power equipment operation and maintenance scenario, when a junior maintenance worker is inspecting a transformer, they may, based on their experience, notice a small amount of oil stains at the bottom of the transformer's cooling fan and submit a description of the anomaly: "A small amount of oil stains at the bottom of the transformer's cooling fan, suspected leakage." When calculating the dynamic risk consensus value, the system first identifies the correlation between the anomaly type indicated in the anomaly description and the degree of potential conflict with the auxiliary monitoring data. For example, the system uses a natural language processing module to parse keywords such as "small amount of oil stains" and "leakage," identifying the anomaly type as "oil leakage." Simultaneously, the system queries the auxiliary monitoring data associated with the transformer, including data on the content of characteristic gases such as acetylene and methane in the cooling oil provided by the online oil chromatography monitoring system, and vibration spectrum data of the cooling fan provided by the vibration monitoring system. If the oil chromatography data shows a slight but continuous upward trend in acetylene content over the past 24 hours, this is highly correlated with the description of "oil leakage." However, if vibration monitoring data shows that the cooling fan's vibration spectrum is within the normal range and no characteristic frequencies of bearing wear or imbalance are observed, this is not directly related to the description of "oil leakage," and may even be potentially contradictory. Based on these comparisons, the system will quantify the strong correlation between the abnormal situation description and the oil chromatography data, as well as the weak correlation or potential conflict with the vibration data.

[0085] Next, the system adjusts the weights of the anomaly description, auxiliary monitoring data, and professional background data in the fusion analysis based on the identified correlation changes or the degree of conflict of potential conflicts, combined with the anomaly type and the operating status of the target equipment. For example, because oil chromatography data is strongly correlated with "oil leakage" and the transformer is currently operating under heavy load, the system will increase the weight of oil chromatography data in the fusion analysis. Meanwhile, because vibration data is less correlated with "oil leakage," the system will appropriately decrease the weight of vibration data. The weight of the operator's professional background data (e.g., the maintenance worker has accurately reported initial leakage faults multiple times) will also be adjusted based on their experience score.

[0086] Subsequently, the system performs weighted fusion of the abnormal situation descriptions, auxiliary monitoring data, and professional background data after weight adjustment to calculate a preliminary risk consensus value. For example, the system weights and sums the quantified abnormal situation description score, the weighted oil chromatography data anomaly index, the weighted vibration data anomaly index, and the operator's professional background score according to their respective weights to obtain a preliminary risk consensus value, such as 0.72.

[0087] Finally, when the initial risk consensus value is lower than the safety threshold, but the difference between the safety threshold and the initial risk consensus value is less than the preset calibration range, and a potential conflict is identified, the initial risk consensus value is calibrated upwards to obtain the final risk consensus value. Assume the preset safety threshold is 0.75 and the preset calibration range is 0.05. In this case, the initial risk consensus value of 0.72 is lower than the safety threshold of 0.75, but the difference (0.03) is less than the calibration range of 0.05. Simultaneously, the system identifies a potential conflict between the abnormal situation description and the vibration data. In this critical situation with a potential conflict, the system triggers an upward calibration mechanism. For example, the system calibrates the initial risk consensus value of 0.72 upwards by 0.04, obtaining a final risk consensus value of 0.76. This final risk consensus value of 0.76 exceeds the safety threshold of 0.75, thus triggering a permission adjustment, granting the junior maintenance personnel temporary access to view detailed structural drawings of the transformer cooling system and advanced diagnostic tools to further confirm the source of the oil stains and assess the risk.

[0088] Through the aforementioned scheme, this application introduces mechanisms for data conflict identification, dynamic weight adjustment, and critical risk calibration on top of the basic adaptive permission management method. This enables the system to more comprehensively and intelligently consider the inherent consistency of multi-source information and external contextual factors when calculating risk consensus values. This not only improves the accuracy of risk consensus value calculation, more realistically reflecting the actual risk level of on-site anomalies and avoiding the problem of untimely permission adjustments due to missed risk assessments, but also allows for more prudent and safer decisions when facing critical risks and information uncertainty. Ultimately, this ensures that operators can promptly obtain temporary operational permissions appropriate for handling on-site anomalies when they discover potential anomalies, thereby effectively improving the safety, response speed, and efficiency of power equipment operation and maintenance, and reducing the risk of fault escalation.

[0089] Reference Appendix Figure 2 This invention provides a role-based adaptive access control system (this system adopts the role-based adaptive access control method described in the above embodiments; for details, please refer to the corresponding steps above), comprising: The identification and verification unit 100 is used to collect the operator's biometric information for identity verification and grant the operator initial access permissions corresponding to the preset role based on the verification results. The information feedback unit 200 is used to receive on-site anomaly description information submitted by the operator for the target equipment; The data acquisition unit 300 is used to acquire auxiliary monitoring data associated with the target equipment, as well as the professional background data of the operators; The data processing unit 400 is used to perform semantic parsing on the on-site anomaly description information, and calculate the risk consensus value reflecting the authenticity of the on-site anomaly by integrating the parsing results with auxiliary monitoring data and professional background data. The permission adjustment unit 500 is used to compare the risk consensus value with the preset safety threshold, and automatically adjust the operator's access permissions when the risk consensus value reaches or exceeds the safety threshold, so that the operator can obtain temporary operation permissions that match the handling of the abnormal situation on site. The permission restoration unit 600 is used to monitor the existence status of temporary operation permissions and restore the operator's access permissions to the initial access permissions when the preset revocation conditions are met.

[0090] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.

[0091] The above description is merely an embodiment of the present invention and is not intended to limit the scope of protection of the present invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A role-based access control method, characterized in that, Includes the following steps: S1. Collect the operator's biometric information for identity verification, and grant the operator initial access permissions corresponding to the preset role based on the verification results; S2. Receive the on-site anomaly description information submitted by the operator for the target equipment; S3. Obtain auxiliary monitoring data associated with the target device, as well as the professional background data of the operator; S4. Perform semantic parsing on the on-site anomaly description information, and calculate a risk consensus value that reflects the authenticity of the on-site anomaly by integrating the parsing results with the auxiliary monitoring data and the professional background data; S5. Compare the risk consensus value with the preset safety threshold, and when the risk consensus value reaches or exceeds the safety threshold, automatically adjust the access permissions of the operator so that the operator can obtain temporary operating permissions that match the handling of the on-site anomaly. S6. Monitor the duration of the temporary operation permission, and restore the operator's access permission to the initial access permission when the preset revocation conditions are met; The specific steps in step S4 include: S41. Perform preliminary semantic analysis on the on-site anomaly description information, and determine whether the on-site anomaly description information has semantic ambiguity based on the preliminary semantic analysis results; S42. When the description of the on-site anomaly is semantically ambiguous, the description of the on-site anomaly is refined by asking the operator a clarifying question and receiving the operator's response feedback. S43. Prompt the operator to collect multimodal on-site evidence related to the on-site anomaly and preprocess the multimodal on-site evidence; the multimodal on-site evidence includes visual evidence and acoustic evidence; the preprocessing includes image enhancement, noise reduction, geometric correction, illumination compensation, contrast adjustment or motion blur removal for the visual evidence, and background noise suppression, frequency filtering, feature extraction, transient event detection, silent segment removal or spectrum normalization for the acoustic evidence; S44. Generate an anomaly scenario description based on the refined on-site anomaly description information and the preprocessed multimodal on-site evidence; S45. By integrating and analyzing the abnormal situation description with the auxiliary monitoring data and the professional background data, a risk consensus value reflecting the authenticity of the on-site abnormality is calculated; The specific steps in step S44 include: S441. Assess the confidence level of each modality of scene evidence in the preprocessed multimodal scene evidence; S442. Adjust the weight of each modality of on-site evidence in the fusion process based on the assessed confidence level of the evidence; S443. The refined on-site anomaly description information is weighted and fused with the multimodal on-site evidence after weight adjustment to generate the anomaly scenario description; The specific steps in step S441 include: S4411. For each type of preprocessed multimodal scene evidence, identify the modality type of the scene evidence; S4412. Based on the modality type, extract multiple evaluation indicators from the modality scene evidence; wherein, when the modality type is visual evidence, the multiple evaluation indicators include image sharpness index, geometric distortion index, and illumination consistency index; when the modality type is acoustic evidence, the multiple evaluation indicators include background noise level index, abnormal signal energy index, and transient event density index. S4413. The extracted evaluation indicators from multiple dimensions are weighted and combined to obtain the confidence level of the evidence corresponding to the modal on-site evidence; The specific steps in step S45 include: S451. Identify the degree of conflict between the abnormality type indicated in the abnormal situation description and the correlation change or potential conflict of the auxiliary monitoring data; S452. Based on the degree of conflict of the identified correlation changes or potential conflicts, and in combination with the anomaly type and the operating status of the target device, adjust the weights of the anomaly situation description, the auxiliary monitoring data, and the professional background data in the fusion analysis; S453. The abnormal situation description, the auxiliary monitoring data, and the professional background data, after weight adjustment, are weighted and fused to calculate a preliminary risk consensus value; S454. When the preliminary risk consensus value is lower than the security threshold, and the difference between the security threshold and the preliminary risk consensus value is less than a preset calibration range, and the potential conflict is identified, the preliminary risk consensus value is calibrated upward to obtain the final risk consensus value.

2. The role-based permission adaptive management method according to claim 1, characterized in that, The auxiliary monitoring data includes at least one of the following: vibration data, partial discharge data, and oil chromatography data of the target equipment.

3. The role-based access control method according to claim 1, characterized in that, The professional background data includes the operator's identity information, training records, certification qualifications, cumulative number of tasks completed, number of times participating in advanced maintenance, experience scores for handling various types of faults, and previous permission level records.

4. The role-based adaptive permission management method according to claim 1, characterized in that, The specific steps in step S442 include: S4421. When the confidence level of any modal on-site evidence is lower than a preset confidence threshold, reduce the weight of the modal on-site evidence or exclude the modal on-site evidence from the fusion process; S4422. When any of the modal field evidences is missing, the weight of the modal field evidence is set to zero, and the weights of the remaining modal field evidences are redistributed.

5. A role-based adaptive access control system employing the role-based adaptive access control method as described in any one of claims 1-4, characterized in that, include: The identification and verification unit is used to collect the operator's biometric information for identity verification and grant the operator initial access permissions corresponding to a preset role based on the verification result. The information feedback unit is used to receive on-site anomaly description information submitted by the operator for the target equipment; The data acquisition unit is used to acquire auxiliary monitoring data associated with the target device, as well as the professional background data of the operator; The data processing unit is used to perform semantic parsing on the on-site anomaly description information, and calculate a risk consensus value that reflects the authenticity of the on-site anomaly by integrating the parsing results with the auxiliary monitoring data and the professional background data. The permission adjustment unit is used to compare the risk consensus value with a preset security threshold, and automatically adjust the access permissions of the operator when the risk consensus value reaches or exceeds the security threshold, so that the operator can obtain temporary operation permissions that match the handling of the on-site anomaly. The permission restoration unit is used to monitor the existence status of the temporary operation permission and restore the operator's access permission to the initial access permission when the preset revocation conditions are met.