Plant asset remote supervision method, device, equipment and storage medium

CN122453097BActive Publication Date: 2026-09-25STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610915384.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-06-24
Publication Date
2026-09-25
Estimated Expiration
2046-06-24

AI Technical Summary

Technical Problem

[0004]本申请的主要目的在于提供一种厂站资产远程监督方法、装置、设备及存储介质,旨在解决如何实现厂站资产自动识别和远程合规监督与闭环管理的技术问题

Benefits of technology

[0015]本申请通过调度主站与厂站运维代理建立加密通信通道,采集资产多维特征并计算置信度以完成资产识别与台账更新,基于物理链路信息生成动态拓扑,依托资产台账与拓扑构建标准化监督配置库,自动匹配并下发核查任务,通过差集运算识别不合规项并生成报告、推送告警。实现了资产自动识别、动态管理和远程监督标准化闭环,提高了监管效率与资产管控精度,降低人工下站工作量,保障厂站资产安全合规运行。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122453097B_ABST
    Figure CN122453097B_ABST
Patent Text Reader

Abstract

The application discloses a power station asset remote supervision method and device, equipment and a storage medium, relates to the technical field of data management, and comprises the following steps: an encrypted communication channel is established between a dispatching master station and a power station operation and maintenance agent, multi-dimensional features of assets are collected, confidence is calculated to complete asset identification and account updating, a dynamic topology is generated based on physical link information, a standardized supervision configuration library is constructed based on asset account and topology, verification tasks are automatically matched and issued, non-compliant items are identified through difference set operation and a report is generated, and an alarm is pushed. The standardized closed loop of asset automatic identification, dynamic management and remote supervision is realized, the supervision efficiency and asset management and control precision are improved, the workload of manual station work is reduced, and the safe and compliant operation of power station assets is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data management technology, and in particular to a method, apparatus, equipment and storage medium for remote monitoring of plant assets. Background Technology

[0002] Currently, plant asset supervision mainly relies on manual on-site inspections and manual entry of asset ledgers, followed by network topology drawing based on static ledgers by maintenance personnel. Remote technical supervision mostly adopts a decentralized, non-standardized single-point verification method, relying on manual inspection of equipment configuration, high-risk ports, password compliance, network time synchronization, and other items. After verification, a supervision report is manually compiled. Overall, it is mainly based on manual operation, static management, and offline execution.

[0003] Under current methods, asset information relies on manual entry, which is prone to errors, omissions, and delayed updates. It also fails to provide real-time monitoring of asset online status, attribute changes, and unauthorized access. Asset topology, drawn manually, struggles to accurately correlate with physical ports and cannot be dynamically updated as physical links change. Remote monitoring lacks a unified standard library, resulting in fragmented and inefficient verification processes that cannot achieve automated batch execution. Furthermore, the absence of an automated compliance assessment mechanism means that problem detection rates are heavily influenced by personnel capabilities, hindering the formation of a complete closed loop. Therefore, achieving automatic identification of plant assets and remote compliance monitoring and closed-loop management has become an urgent problem to be solved. Summary of the Invention

[0004] The main purpose of this application is to provide a method, device, equipment and storage medium for remote monitoring of plant assets, aiming to solve the technical problem of how to achieve automatic identification and remote compliance monitoring and closed-loop management of plant assets.

[0005] To achieve the above objectives, this application proposes a method for remote monitoring of plant assets, comprising: Establish an encrypted communication channel with the plant-side operation and maintenance agent and initialize remote monitoring parameters; The encrypted communication channel is used to send a collection command to the operation and maintenance agent, so that the operation and maintenance agent can obtain multi-dimensional feature data of the plant assets. The asset ownership confidence level is calculated based on the multidimensional feature data and the benchmark asset database data. The ownership of assets is determined based on the asset ownership confidence level, and an updated asset ledger is obtained, wherein the updated asset ledger includes asset object and asset type information; Based on the physical link information reported by the operation and maintenance agent, a dynamic asset topology map is generated; A standardized remote monitoring configuration library is established based on the updated asset ledger and asset dynamic topology diagram. The system matches a standardized remote monitoring configuration library based on the asset type information and sends a verification task to the operation and maintenance agent through the encrypted communication channel, and receives the set of execution results returned by the operation and maintenance agent. Non-compliant items are identified by the difference operation between the execution result set and the standard configuration set, a supervision report is generated, and a visualization display and alarm push are completed. The standard configuration set is derived from the standardized remote supervision configuration library.

[0006] In one embodiment, the step of calculating the asset ownership confidence level based on the multidimensional feature data and the benchmark asset database data includes: Extract raw feature data from the multidimensional feature data, wherein the raw feature data includes Internet Protocol address, Media Access Control address, hostname, running process identifier, and application directory path; The original feature data is cleaned and standardized to obtain standardized feature data; Based on the standardized feature data, Internet Protocol address features, Media Access Control address features, hostname features, process fingerprint features, and application directory features are constructed respectively to obtain a set of feature components; According to the preset weight configuration, feature weights are assigned to each feature in the feature component set, and the feature component set is vectorized and aggregated into a multidimensional feature vector. Convert the benchmark asset database data into benchmark asset feature vectors; Based on the multidimensional feature vector and the corresponding benchmark asset feature vector, the similarity of each feature is calculated. The asset ownership confidence score is obtained by weighted summation of the similarity scores of the aforementioned features.

[0007] In one embodiment, the step of determining asset ownership based on the asset ownership confidence level to obtain an updated asset ledger includes: Based on a preset similarity threshold, the asset ownership confidence level is used to determine asset ownership, identify asset consolidation needs, and obtain asset ownership determination results. Extract the corresponding multidimensional feature data based on the asset ownership determination results; Based on the process fingerprint features and application directory features in the multidimensional feature data, the asset type information is determined; The asset object is obtained based on the asset type information, wherein the asset object includes network device type, host type or power dedicated equipment type; Based on the asset ownership determination results, the asset attributes are checked and the change trajectory is recorded to obtain the checked asset data; An updated asset ledger is constructed based on the verified asset data.

[0008] In one embodiment, the step of generating a dynamic asset topology map based on the physical link information reported by the operation and maintenance agent includes: The encrypted communication channel is used to send a topology acquisition command to the operation and maintenance agent, so that the operation and maintenance agent can obtain the switch port forwarding table and link layer discovery protocol information to obtain the raw physical link data. Receive the raw physical link data, and parse the physical connection relationship between devices based on the raw physical link data to construct the correlation matrix data between devices; The node position coordinates are calculated using a graph layout algorithm based on the correlation matrix data to obtain an initial asset topology map; The encrypted communication channel is used to send port status monitoring instructions to the operation and maintenance agent, so that the operation and maintenance agent periodically reports port status change information, and the operation and maintenance agent reports port status change information. The initial asset topology map is redrawn in real time based on the port status change information to obtain a dynamic asset topology map.

[0009] In one embodiment, the step of redrawing the initial asset topology map in real time based on the port status change information to obtain a dynamic asset topology map includes: Based on the port status change information, the target device node and target physical port that have undergone status change are parsed to obtain the changed node information; The association matrix data is updated based on the changed node information to obtain the updated association matrix data; The layout parameters of the graphic layout algorithm are adjusted based on the updated correlation matrix data to obtain the adjusted layout parameters; The node position coordinates are recalculated based on the adjusted layout parameters to obtain the updated node position coordinates. The initial asset topology map is rendered and updated based on the updated node position coordinates to obtain a dynamic asset topology map.

[0010] In one embodiment, the step of establishing a standardized remote monitoring configuration library based on the updated asset ledger and asset dynamic topology map includes: Extract asset type information and asset attribute data from the updated asset ledger; Extract network hierarchy and physical connection data from the asset dynamic topology diagram; A basic rule layer is established based on the asset attribute data to obtain basic rule data, wherein the basic rule layer includes general port and performance collection rules; A standardized template layer is established based on the asset type information to obtain standardized template data, wherein the standardized template layer includes standardized verification items for switches, mainframes and power-specific equipment pre-set according to the industry security manual. A service customization layer is established based on the network hierarchy and physical connection relationship data to obtain service customization data, wherein the service customization layer includes custom verification items extended based on the network hierarchy. A standardized remote monitoring configuration library is constructed based on the aforementioned basic rule data, standardized template data, and business-customized data.

[0011] In one embodiment, the step of identifying non-compliant items based on the difference operation between the execution result set and the standard configuration set, generating a supervision report, and completing the visualization and alarm push includes: By performing a difference operation between the standard configuration set and the execution result set, a set of non-compliant items is obtained; By comparing the set of non-compliant items with preset security standards, detailed violation data is obtained; Risk scoring is performed based on the aforementioned violation details data to obtain the risk scoring results; A monitoring report is generated based on the detailed violation data and the risk scoring results. The supervision report is sent to the asset supervision dashboard for visualization, and the visualization results are obtained to complete the visualization display. Alarm information is pushed to the operation and maintenance alarm platform based on the set of non-compliant items.

[0012] Furthermore, to achieve the above objectives, this application also proposes a remote monitoring device for plant assets, the remote monitoring device for plant assets comprising: The communication establishment module is used to establish an encrypted communication channel with the plant-side operation and maintenance agent and initialize remote monitoring parameters; The data acquisition module is used to send acquisition instructions to the operation and maintenance agent through the encrypted communication channel, so that the operation and maintenance agent can obtain multi-dimensional feature data of the plant assets; The confidence calculation module is used to calculate the asset ownership confidence based on the multidimensional feature data and the benchmark asset database data. The asset determination module is used to determine the ownership of assets based on the asset ownership confidence level and obtain an updated asset ledger, wherein the updated asset ledger includes asset object and asset type information; The topology generation module is used to generate a dynamic asset topology map based on the physical link information reported by the operation and maintenance agent. The configuration library creation module is used to create a standardized remote monitoring configuration library based on the updated asset ledger and asset dynamic topology diagram. The task distribution module is used to match a standardized remote monitoring configuration library according to the asset type information, and distribute verification tasks to the operation and maintenance agent through the encrypted communication channel, and receive the set of execution results returned by the operation and maintenance agent; The reporting and alarm module is used to identify non-compliant items based on the difference operation between the execution result set and the standard configuration set, generate a supervision report, and complete the visualization and alarm push. The standard configuration set is derived from the standardized remote supervision configuration library.

[0013] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the remote monitoring method for plant assets as described above.

[0014] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the remote monitoring method for plant assets as described above.

[0015] This application establishes an encrypted communication channel between the main dispatch station and the plant maintenance agent, collects multi-dimensional asset features and calculates confidence levels to complete asset identification and ledger updates, generates a dynamic topology based on physical link information, constructs a standardized supervision configuration library based on the asset ledger and topology, automatically matches and issues verification tasks, identifies non-compliant items through difference set operations and generates reports and pushes alarms. This achieves a standardized closed loop of automatic asset identification, dynamic management, and remote supervision, improving regulatory efficiency and asset control accuracy, reducing manual on-site workload, and ensuring the safe and compliant operation of plant assets. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating the first embodiment of the remote monitoring method for plant assets in this application; Figure 2 This is a flowchart illustrating the second embodiment of the remote monitoring method for plant assets in this application; Figure 3 This is a schematic diagram of the module structure of the remote monitoring device for plant assets in this application; Figure 4 This is a schematic diagram of the equipment structure of the hardware operating environment involved in the remote monitoring method for plant assets in this application embodiment.

[0018] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0019] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0020] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0021] Currently, plant asset supervision mainly relies on manual on-site inspections and manual entry of asset ledgers, followed by network topology mapping by maintenance personnel based on static ledgers. Remote technical supervision often employs a decentralized, non-standardized, single-point verification method, relying on manual checks of equipment configurations, high-risk ports, password compliance, network time synchronization, and other items. After verification, a supervision report is manually compiled. Overall, it is primarily manual operation, static management, and offline execution. Under the existing methods, asset information relies on manual entry, which is prone to errors, omissions, and delayed updates, making it impossible to perceive the online status of assets, attribute changes, and unauthorized access in real time. Asset topology relies on manual mapping, making it difficult to accurately associate with physical ports and unable to dynamically update with changes in physical links. Remote supervision lacks a unified standard library, resulting in fragmented and inefficient verification processes that cannot achieve batch automated execution. At the same time, the lack of an automated compliance judgment mechanism means that the problem detection rate is greatly affected by personnel capabilities, making it difficult to form a complete closed loop. Therefore, how to achieve automatic identification of plant assets and remote compliance supervision and closed-loop management has become an urgent problem to be solved.

[0022] Based on the above, this application also provides a method for remote monitoring of plant assets, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the remote monitoring method for plant assets in this application.

[0023] In this embodiment, the remote monitoring method for plant assets includes steps S10 to S80: Step S10: Establish an encrypted communication channel with the plant-side operation and maintenance agent and initialize remote monitoring parameters.

[0024] It should be noted that the plant-side maintenance agent is a data acquisition and execution component deployed at the plant site, used to complete asset information collection and configuration verification operations according to instructions. The plant-side maintenance agent operates on the existing hardware of the plant and is responsible for maintaining communication with the dispatch master station and executing various tasks issued. The encrypted communication channel is a secure transmission path established between the dispatch master station and the plant-side maintenance agent. The encrypted communication channel is constructed using an application-layer end-to-end encryption authentication method. Remote monitoring parameters are basic configuration information used to standardize remote monitoring execution. Remote monitoring parameters include key configuration content such as communication address, data reporting cycle, task execution time period, and collection range.

[0025] Specifically, firstly, an operation and maintenance monitoring module is installed in the server cluster of the dispatch master station. This module includes an asset management submodule, a topology drawing submodule, a remote technical supervision submodule, and an operation and maintenance monitoring communication submodule. Simultaneously, existing Type II network security monitoring devices are reused at the substation side, and an operation and maintenance agent data acquisition plugin and a data forwarding module are deployed within these devices. This approach eliminates the need for additional dedicated hardware procurement, fully utilizing the existing network security monitoring devices as data acquisition nodes, reducing construction costs and deployment complexity, while ensuring compatibility between the substation's data acquisition capabilities and the existing network security management system. Next, an asymmetric encryption key pair is generated, and the public key is pre-installed in the substation operation and maintenance agent plugin. During the initial communication between the master station and the substation, identity is mutually authenticated using digital certificates, and a session key is negotiated and generated. Subsequently, all command issuance and data reporting use the session key for symmetric encryption transmission, while a transport layer integrity verification mechanism is enabled to prevent data tampering, thus establishing an encrypted communication channel. This approach is necessary because the power monitoring system belongs to... For critical information infrastructure, the data transmission for monitoring between the plant and the master station must meet the requirements of network security level protection. End-to-end encryption can prevent man-in-the-middle attacks and data eavesdropping, ensuring the secure and trustworthy foundation of the master-slave linkage architecture and preventing the malicious forgery of monitoring instructions or the tampering of execution results. Finally, communication timeout thresholds (preset duration), heartbeat detection cycles (preset cycles), and reconnection policy parameters are set. The scanning frequency, collection depth, and reporting format of the operation and maintenance agent are configured. A handshake test command is sent to the plant operation and maintenance agent to verify the bidirectional connectivity and encryption / decryption consistency of the encrypted channel. After confirming that the channel is normal, the plant is marked as online, and an initialized encrypted communication channel is obtained. This is done because there are many plants and they are widely distributed, so a reliable communication guarantee mechanism must be preset. Heartbeat detection can detect link interruptions in a timely manner, and the reconnection policy ensures business continuity during network fluctuations. Parameter initialization provides a unified execution standard for subsequent batch operations, avoiding data format chaos or task execution failure due to inconsistent configurations.

[0026] Step S20: Send a collection command to the operation and maintenance agent through an encrypted communication channel so that the operation and maintenance agent can obtain multi-dimensional feature data of the plant assets.

[0027] It should be noted that plant assets are a collective term for network equipment, host servers, and power-specific security equipment operating within a plant. Plant assets include key equipment such as switches, workstations, vertical encryption and authentication devices, and horizontal isolation devices. Multidimensional feature data is a collection of multiple types of information that can uniquely identify the asset's identity and operational status.

[0028] Specifically, firstly, a first collection command is sent to the plant-side maintenance agent through the established encrypted communication channel. This allows the maintenance agent to use the Simple Network Management Protocol (SMMP) to send port status query requests and Address Resolution Protocol (ARP) table retrieval requests to network devices. After the network devices return port status data and ARP information, the maintenance agent encrypts and sends the data back, obtaining network device asset data. This is done because SMMP is a standard protocol for network device management, allowing for batch acquisition of port status and address mapping relationships for switches and routers without requiring additional agents on each device, thus reducing deployment costs. Secondly, a second collection command is sent to the maintenance agent through the encrypted communication channel. This allows the maintenance agent to remotely log in to the host using the Secure Shell protocol, execute process status query commands and file system traversal commands, and obtain the host's performance data, running process identifiers, and application directory paths, thus obtaining host asset data. This is done because the Secure Shell protocol provides an encrypted and secure remote access channel, allowing direct reading of process signatures and directory fingerprints within the host, which are crucial for identification. Key characteristics of host service attributes cannot be obtained through network layer scanning. Next, a third collection command is sent to the maintenance agent via an encrypted communication channel, enabling the agent to actively probe devices below the station control layer using power-specific service protocols. This involves sending handshake request frames conforming to the protocol format, parsing the device type code and function code in the response frames returned by the devices, and obtaining power-specific equipment asset data. This is because devices below the station control layer, such as measurement and control devices and protection devices, use power industry-specific communication protocols and do not respond to standard network scans; the corresponding protocols must be used for identification. Finally, network device asset data, host asset data, and power-specific equipment asset data are received. These three types of data are time-stamped and format-unified, redundant fields from repeated collections are removed, and the data is aggregated and recombined according to a preset data structure to obtain multi-dimensional feature data of the plant assets. This is done because the three types of data have different sources and formats; directly mixing them would lead to chaotic feature extraction. Unified aggregation forms a complete asset profile, providing standardized input for subsequent confidence calculations.

[0029] Step S30: Calculate the asset ownership confidence level based on the multidimensional feature data and the benchmark asset database data.

[0030] It should be noted that step S30 includes: first, extracting raw feature data from the multidimensional feature data. It should be understood that the raw feature data includes Internet Protocol address, Media Access Control address, hostname, running process identifier, and application directory path.

[0031] Secondly, the original feature data is cleaned and standardized to obtain standardized feature data. Specifically, the original feature data is cleaned and standardized by converting Internet Protocol (IP) addresses into dotted decimal strings, Media Access Control (MAC) addresses into colon-separated hexadecimal strings, removing domain name suffixes from hostnames and unifying them to lowercase, extracting process identifiers into a combination of process name and version number, and standardizing application directory paths to absolute paths and removing trailing forward slashes. This is done because the formats of data from different sources vary greatly. For example, MAC addresses in the Address Resolution Protocol (ARP) table may be hyphenated, while Simple Network Management Protocol (SMMP) addresses may be unseparated. Standardization is necessary for accurate comparison.

[0032] Next, Internet Protocol address features are constructed based on the standardized feature data. Media access control address characteristics Hostname characteristics Process fingerprint characteristics and application directory features Each feature component is represented by a one-hot encoding or a hash vector to obtain a set of feature components. This is done because the original string cannot be directly used in mathematical operations and needs to be converted into a numerical vector to calculate the similarity. Next, feature weights are assigned to each feature in the feature component set according to a preset weight configuration, and the feature component set is vectorized and aggregated into a multi-dimensional feature vector. Specifically, feature weights are assigned to each feature in the feature component set according to the preset weight configuration, wherein process fingerprint features are given high weights, Internet Protocol address features and Media Access Control address features are given medium weights, and hostname features and application directory features are given basic weights, and the feature component set is vectorized and aggregated into a multi-dimensional feature vector. This is done because process fingerprints reflect the essential business attributes of a device, are difficult to forge, and have high distinguishability. In contrast, Internet Protocol addresses are prone to change due to dynamic allocation, and excessive weighting can lead to the same device being misjudged as different assets.

[0033] Subsequently, the benchmark asset database data is converted into benchmark asset feature vectors. Specifically, historical asset records in the benchmark asset database are read and processed using the same feature extraction and standardization process to convert them into benchmark asset feature vectors with dimensions consistent with the multidimensional feature vectors. This is done because similarity calculation is only meaningful if the vector space of the benchmark data and the real-time data is consistent.

[0034] Then, based on the multidimensional feature vector and the corresponding benchmark asset feature vector, cosine similarity or Euclidean distance algorithms are used to calculate the similarity of each feature dimension by dimension. This is done because different features have different dimensions and distributions, requiring the selection of a similarity measurement method that is insensitive to scale. Finally, the similarities of each feature are weighted and summed to obtain the asset ownership confidence score. The specific calculation formula is as follows: in Indicates the confidence level in asset ownership. This represents the total number of dimensions in a multidimensional feature vector. Indicates the feature dimension index. Indicates the first The weights of the feature vectors in each dimension. This represents the similarity calculation function. Indicates the number of data collected in real time. Each dimension of feature vector, Indicates the first A baseline asset feature vector is used. This is because a single feature similarity cannot fully reflect asset identity. For example, comparing only Internet Protocol (IP) addresses may miss a Media Access Control (MAC) address in scenarios with multiple IP addresses. Only by weighting and superimposing the matching degree of the five-dimensional features can the asset ownership be accurately determined, thus solving the problem of insufficient equipment identification accuracy in the power grid environment.

[0035] Step S40: Determine the ownership of assets based on the confidence level of asset ownership, and obtain the updated asset ledger.

[0036] It should be noted that step S40 includes: determining asset ownership based on a preset similarity threshold to assess the confidence level of asset ownership, identifying asset merging needs, and obtaining asset ownership determination results; extracting corresponding multi-dimensional feature data based on the asset ownership determination results; determining asset type information based on process fingerprint features and application directory features in the multi-dimensional feature data; obtaining asset objects based on asset type information; verifying asset attributes and recording change trajectories based on the asset ownership determination results to obtain verified asset data; and constructing an updated asset ledger based on the verified asset data. The updated asset ledger includes asset objects and asset type information.

[0037] It's important to understand that asset type information is identification information used to distinguish the categories of equipment in a plant or station. Asset objects are the various physical equipment actually operating within the plant or station, including network equipment types, host types, and power-specific equipment types. Asset attributes are data describing the basic information and operational status of the asset. Asset attributes include Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, port information, and configuration information. Change logs are historical records left when asset attributes are adjusted. Change logs are used to trace the asset change process, ensuring that the asset ledger is traceable and verifiable.

[0038] Specifically, the calculated asset ownership confidence score is first compared with a pre-set confidence threshold (e.g., 80%). If the confidence score is greater than or equal to the threshold, the asset ownership is considered successfully matched; if the confidence score is less than the threshold, it is considered a newly discovered asset. Simultaneously, the system checks for anomalies where the same Media Access Control (MAC) address corresponds to multiple Internet Protocol (IP) addresses. If such anomalies exist, an asset merging requirement is marked, resulting in the asset ownership determination. This is done because matching based solely on a single IP address or MAC address can easily misclassify multiple network interface card (NIC) configurations on the same device as multiple independent assets. Confidence threshold filtering and merging requirement identification accurately distinguish between device additions / removals and configuration changes. Then, based on the asset ownership determination result, corresponding records are extracted from the original multidimensional feature data. If the asset is identified as a known asset, the baseline feature data from the asset's historical ledger is extracted; if it is identified as a new asset, the currently collected complete feature data is extracted, resulting in feature data to be processed. This is done because subsequent asset type identification requires complete feature information; missing historical comparison data leads to insufficient basis for type determination. Next, the process fingerprint and application directory features in the feature data to be processed are analyzed. The process names are matched with the preset device type rule base. For example, if "switch daemon process" or "routing protocol process" appears, it is marked as a network device type. If "database service process" or "application server process" appears, it is marked as a host type. If "power protocol parsing process" or "measurement and control device dedicated process" appears, it is marked as a power dedicated equipment type. The asset type information is obtained. This is because process fingerprints and application directories directly reflect the software ecosystem and business functions of the device, and can reveal the essential attributes of the asset better than Internet Protocol address or Media Access Control address. For example, a host running vertical encryption authentication device software may have the same Internet Protocol address as an ordinary host, but the process fingerprint will reveal its identity as a power dedicated equipment. Then, the determined asset type information is bound with the corresponding Internet Protocol (IP) address, Media Access Control (MAC) address, and hostname to generate structured asset object records. These asset objects are explicitly categorized into three types: network device type, host type, and power-specific equipment type. This is done because different types of assets require different monitoring templates and verification strategies, and the type information is a key index for automatic matching in the standardized remote monitoring configuration library. Subsequently, based on the matching discrepancies in the asset ownership determination results, asset attributes are automatically verified. For example, when the real-time IP address differs from the baseline IP address, the address field is updated and marked as an address change; when the real-time process fingerprint differs from the baseline process fingerprint, it is marked as a software version upgrade. The change timestamp, the value before the change, and the value after the change are recorded to obtain the verified asset data. This is done because plant assets are in a dynamic operating state, and legitimate configuration changes need to be accurately captured rather than simply overwritten. The trajectory record supports subsequent audit tracing and anomaly detection.Finally, the verified asset data is written into the asset database according to the preset ledger structure. If the asset object already exists, an update operation is performed and the change history is appended. If the asset object does not exist, an insertion operation is performed and the lifecycle state is initialized to obtain the updated asset ledger. Each record in the updated asset ledger contains the asset object and its corresponding asset type information. This is because the asset ledger is the data foundation for subsequent topology drawing, supervision template matching, and verification task issuance. It must be synchronized with the physical objects in real time. At the same time, the embedding of asset type information enables the ledger to have self-descriptive capabilities, which can drive the subsequent process without additional queries.

[0039] Step S50: Generate a dynamic asset topology map based on the physical link information reported by the operation and maintenance agent.

[0040] It should be noted that step S50 includes: sending a topology acquisition command to the operation and maintenance agent through an encrypted communication channel, so that the operation and maintenance agent can obtain the switch port forwarding table and link layer discovery protocol information to obtain the original physical link data; receiving the original physical link data and parsing the physical connection relationship between devices based on the original physical link data to construct the correlation matrix data between devices; calculating the node position coordinates based on the correlation matrix data using a graphical layout algorithm to obtain the initial asset topology map; sending a port status monitoring command to the operation and maintenance agent through an encrypted communication channel, so that the operation and maintenance agent can periodically report port status change information, and receiving the port status change information reported by the operation and maintenance agent; and redrawing the initial asset topology map in real time based on the port status change information to obtain the asset dynamic topology map.

[0041] It's important to understand that topology acquisition commands are execution commands issued by the scheduling master station to obtain physical connection information. Topology acquisition commands drive the operation and maintenance agent to collect device link-related data, supporting topology relationship resolution. Switch port forwarding tables are data tables that record the correspondence between switch ports and media access control addresses. Switch port forwarding tables are used to locate the specific physical ports accessed by devices and clarify the link connection location. Link layer discovery protocol information is physical connection identification information automatically exchanged between devices. Link layer discovery protocol information is used to directly identify the connection relationship between adjacent devices, improving the accuracy of topology resolution. Physical connection relationships are the actual interconnection relationships formed between devices through network cables or optical fibers. Association matrix data is structured data that uses numerical form to represent the connection status between devices. Association matrix data is used to clearly express whether a physical link exists between devices. Port status monitoring commands are periodic commands used to obtain port connectivity status. Port status change information is real-time feedback information on port online / off status or link connectivity.

[0042] Specifically, firstly, a topology acquisition command is sent to the operation and maintenance agent through the established encrypted communication link. After receiving the command, the operation and maintenance agent logs into the switch and executes the port forwarding table query command to obtain the mapping relationship between the media access control address and the switch port. At the same time, the link layer discovery protocol is used to obtain the neighbor device identifiers and connection port information between switches and between switches and terminal devices. The two types of data are packaged, encrypted and sent back to obtain the original physical link data. This is done because the port forwarding table reflects the actual forwarding path of the data link layer, and the link layer discovery protocol reflects the physical connection relationship actively announced by the device. The combination of the two can cross-verify the authenticity of the connection and avoid topology misjudgment caused by a single data source. Then, the raw physical link data is received, the media access control address entries and corresponding switch port numbers in the port forwarding table are parsed, and the local port, peer device identifier and peer port in the link layer discovery protocol information are parsed. The parsed connection relationships are used to construct an association matrix with the device identifier as the row index and the device identifier as the column index. When there is a physical connection between two devices, the corresponding position in the matrix is ​​marked as 1, and when there is no connection, it is marked as 0, thus obtaining the association matrix data. This is done because the association matrix accurately describes the physical connection relationship of all devices in the network in mathematical form, which is convenient for subsequent graph theory algorithm processing. For example, it can quickly find all upstream network paths of a certain host. Next, based on the correlation matrix data, the node position coordinates are calculated using a graphical layout algorithm. Device identifiers are used as nodes, and connection relationships are used as edges. Force-directed layout or hierarchical layout algorithms are used to calculate the two-dimensional plane coordinates of each node, so that closely connected nodes are automatically clustered and nodes with clear hierarchical relationships are arranged vertically. A topology graph with port labels is rendered to obtain the initial asset topology map. This is done because graphical layout algorithms can transform abstract matrix relationships into an intuitive and readable visual presentation. Operation and maintenance personnel can understand the network structure without reading tabular data. For example, the physical simulation effect of spring connections in force-directed layout naturally conforms to human cognitive habits of network topology. Subsequently, a port status monitoring command is sent to the operation and maintenance agent via an encrypted communication link. The monitoring period is configured to a preset interval. The operation and maintenance agent continuously reads the switch port status register according to this period to detect port online or offline events. When the status changes, the changed port number, the changed status, and the change timestamp are immediately encrypted and reported. The port status change information reported by the operation and maintenance agent is received. This is done because port status changes are a direct signal of physical topology changes. For example, plugging or unplugging network cables, power failure of equipment, or fiber optic interruption will trigger port status flipping. Periodic monitoring can capture these dynamic events without continuous full scanning, reducing the performance occupation of the switch's central processing unit.Finally, based on the port status change information, the target device node and target physical port that have changed are analyzed. The connection relationship corresponding to the port is located from the association matrix data. If the port status changes from online to offline, the connection edge is deleted and marked as interrupted. If the port status changes from offline to online, a new connection edge is added and neighbor device discovery is triggered. The node layout coordinates of the affected area are recalculated, and the corresponding nodes and connections in the initial asset topology map are rendered and updated to obtain the asset dynamic topology map. This is done because the plant physical environment often undergoes topology changes due to equipment maintenance, expansion, or fault replacement. The static topology map will quickly become invalid. Real-time redrawing ensures that the topology always remains consistent with the actual physical connections. When a vertical encryption authentication device goes offline, the dynamic topology can immediately highlight the interrupted link and trace the scope of impact, helping maintenance personnel to quickly locate the source of the fault.

[0043] Furthermore, the step of redrawing the initial asset topology map in real time based on port status change information to obtain a dynamic asset topology map specifically includes: parsing the target device nodes and target physical ports that have undergone status changes based on the port status change information to obtain changed node information; updating the association matrix data based on the changed node information to obtain updated association matrix data; adjusting the layout parameters of the graphics layout algorithm based on the updated association matrix data to obtain adjusted layout parameters; recalculating the node position coordinates based on the adjusted layout parameters to obtain updated node position coordinates; and rendering and updating the initial asset topology map based on the updated node position coordinates to obtain a dynamic asset topology map.

[0044] Specifically, firstly, based on the port status change information, the target device node and target physical port whose status has changed are parsed. The switch identifier, port number, and post-change status are extracted from the port status change data. Then, combined with the node index table in the initial asset topology diagram, the row and column positions of the port in the association matrix are located to obtain the changed node information. This is done because port status changes only contain the original hardware identifier, which needs to be mapped to a logical node in the topology diagram before subsequent matrix operations can be performed. For example, port "GigabitEthernet1 / 0 / 24" needs to be resolved to port number 24 of device A. Then, the association matrix data is updated based on the changed node information. If the port status... When a device changes from online to offline, the connection marker of the corresponding device node in the association matrix is ​​set from 1 to 0, and the interruption timestamp is recorded. If a port changes from offline to online, the port forwarding table is queried to obtain the newly learned media access control address for that port. Based on the media access control address, the asset ledger is checked to determine the peer device, and a connection marker of 1 is added to the corresponding position in the association matrix to obtain the updated association matrix data. This is done because the association matrix is ​​the mathematical basis for topology calculation, and the matrix elements must be strictly synchronized with the actual physical connections. For example, when a maintenance worker unplugs the network cable of a host, the connection edge between that host and the switch in the matrix should immediately become invalid to avoid the topology map continuing to display false connectivity. Next, the layout parameters of the graph layout algorithm are adjusted based on the updated correlation matrix data. The number of newly added and deleted connection edges is counted, and the network connectivity change rate is calculated. When the change rate exceeds a preset threshold, a global re-layout is triggered. The iteration number and convergence accuracy parameters of the layout algorithm are increased to ensure the layout stability after large changes. When the change rate is lower than the preset threshold, only the changed node and its neighboring nodes are locally adjusted, reducing the iteration number to improve the response speed. The adjusted layout parameters are obtained. This is done because global re-layout is computationally intensive and time-consuming. For minor changes such as single-port plugging and unplugging, local adjustments can maintain visual continuity. However, large-scale expansion or replacement of core switches requires global recalculation to avoid node overlap and edge crossing. Subsequently, the node position coordinates are recalculated based on the adjusted layout parameters. The updated correlation matrix is ​​input into the graph layout algorithm, and the force-guided layout operation is executed according to the adjusted number of iterations and convergence accuracy. The new coordinate positions of each node on the two-dimensional plane are calculated. The newly added nodes are assigned initial coordinates and a repulsive force is applied to gradually integrate them into the existing layout. After releasing space for the neighboring nodes of the deleted nodes, the forces are rebalanced to obtain the updated node position coordinates. This is done because the node coordinates determine the visual presentation effect of the topology graph. The coordinate calculation needs to consider the reasonable insertion position of the added devices and the filling of the blanks after the deletion of devices. For example, when a new host is added, it should automatically attach to the vicinity of its own switch rather than be randomly scattered.Finally, the initial asset topology map is rendered and updated based on the updated node location coordinates. All nodes and connections are redrawn according to the new coordinates. Flashing or color-changing effects are applied to port connections with status changes to highlight them. A fade-in animation effect is applied to newly added nodes, and a fade-out animation effect is applied to deleted nodes. Port labels and status prompts are updated synchronously to obtain a dynamic asset topology map. This is done because directly switching to static images would cause visual jumps and cognitive interruptions. Smooth transition animations and status highlighting can help operations and maintenance personnel quickly capture the focus of changes. For example, when a critical business link is interrupted, the flashing red disconnected line can immediately attract attention and help operations and maintenance personnel quickly locate the fault point in a complex topology.

[0045] Step S60: Establish a standardized remote monitoring configuration library based on the updated asset ledger and asset dynamic topology map.

[0046] Specifically, firstly, asset type information and asset attribute data are extracted from the updated asset ledger. Asset type information includes network device type, host type, or power-specific equipment type. Asset attribute data includes Internet Protocol address, Media Access Control address, hostname, running process identifier, and application directory path, thus obtaining asset characteristic data. This is done because the supervision focus differs for different types of assets: network devices require attention to port open status, hosts require attention to password complexity, and power-specific equipment requires attention to business protocol compliance. Asset attributes provide specific verification object identifiers for rule matching. Secondly, network hierarchy structure and physical connection relationship data are extracted from the asset dynamic topology diagram. The network hierarchy structure includes the device distribution of the core layer, aggregation layer, and access layer, thus obtaining network structure data. This is done because core layer devices are frequently verified. The efficiency should be higher than that of edge access layer devices, and topology information enables the configuration library to have network awareness capabilities. Next, a basic rule layer is established based on asset attribute data, classifying general ports and performance collection rules. A standardized template layer is established based on asset type information, binding the verification items pre-set in the industry security manual to the asset type. A business customization layer is established based on network structure data, associating the verification items extended to specific substation levels with the network layer. Finally, the three layers of data are associated and indexed according to asset identifiers. When querying specific devices, the data is automatically aggregated to generate a complete supervision configuration sheet, resulting in a standardized remote supervision configuration library. This is done because the three-layer architecture achieves rule decoupling and reuse. Basic rules are shared globally, standard templates are reused by type, and custom rules are superimposed as needed, avoiding the need to write complete configurations for each device separately and significantly reducing maintenance workload.

[0047] Step S70: Match the standardized remote monitoring configuration library according to the asset type information, and send the verification task to the operation and maintenance agent through the encrypted communication channel, and receive the set of execution results returned by the operation and maintenance agent.

[0048] Specifically, the process begins by retrieving asset type information from the updated asset ledger. Based on this information, a standardized remote monitoring configuration library is queried. General collection rules are extracted from the basic rule layer, verification templates bound to asset types are extracted from the standardized template layer, and extended rules associated with the network layer are extracted from the business-defined layer. These three layers of rules are then aggregated into a complete verification task configuration sheet. This is done because a single rule layer cannot meet complex monitoring needs. For example, a core switch in a 220kV substation needs to simultaneously execute three types of rules: general port scanning, switch-specific template verification, and core layer traffic threshold alarms. Automatic aggregation avoids omissions caused by manual selection. Then, the verification task is sent to the operations and maintenance agent via an encrypted communication link, and the aggregated verification task is configured... The task is broken down into a sequence of independently executable subtasks, which are then encrypted and transmitted to the plant maintenance agent according to a preset priority. The maintenance agent parses the subtasks locally and executes them sequentially. For example, it first performs Internet Protocol address reachability detection, then high-risk port scanning, and finally configuration compliance comparison. The execution results of each subtask are encrypted and sent back. The maintenance agent receives the set of execution results returned by the maintenance agent. This is done because the verification task involves multiple detection contents. Packaging and distributing them in a unified manner can reduce the number of communication round trips. Local execution by the maintenance agent can avoid the exposure of sensitive configuration data during transmission. At the same time, step-by-step execution facilitates breakpoint recovery in case of abnormal interruption. For example, when high-risk port scanning consumes too much bandwidth, subsequent tasks can be automatically slowed down or postponed to ensure the continuity of power production operations.

[0049] Step S80: Identify non-compliant items based on the difference operation between the execution result set and the standard configuration set, generate a supervision report, and complete the visualization display and alarm push.

[0050] It should be noted that step S80 includes: performing a difference operation on the standard configuration set and the execution result set to obtain a set of non-compliant items; comparing the set of non-compliant items with preset security standards to obtain detailed violation data; performing risk scoring based on the detailed violation data to obtain risk scoring results; generating a supervision report based on the detailed violation data and risk scoring results; sending the supervision report to the asset supervision dashboard for visualization display to obtain visualization display results; and pushing alarm information to the operation and maintenance alarm platform based on the set of non-compliant items.

[0051] It's important to understand that the execution result set is the sum of actual device configuration data returned by the operations and maintenance agent after performing the verification task. The execution result set accurately reflects the current configuration status and operating parameters of the plant assets. The standard configuration set originates from a standardized remote monitoring configuration library. The difference operation is a numerical calculation method used to compare the differences between two sets of data. The difference operation is used to filter out content that exists in the standard configuration set but does not appear in the execution result set. The non-compliant item set is the sum of configuration items that do not meet security standards, obtained through the difference operation. The non-compliant item set contains all configuration issues and risk points that require rectification. The violation details data is a record of specific issues formed after sorting out the non-compliant items. The violation details data includes the problem location, problem content, and corresponding device information.

[0052] Specifically, firstly, a standard configuration set is extracted from the standardized remote monitoring configuration library. This set is then compared with the execution result set returned by the operations and maintenance agent using a difference operation to filter out items that exist in the standard configuration but do not meet or comply with the requirements in the execution results, resulting in a set of non-compliant items. Next, each item in the non-compliant item set is compared against preset security standards to extract the violation attribute, severity level, and applicable clause number for each non-compliant item, summarizing them into structured violation details. This is done because a simple list of non-compliant items lacks a basis for judgment; it needs to be linked to specific security standard clauses to clarify the nature of the violation. For example, even with the same issue of port opening, the nature of a business-essential port is completely different from that of a high-risk unauthorized port. Then, risk scoring is performed based on the severity level and impact scope in the violation details data. Preset risk weights are assigned to each non-compliant item, and the overall risk score is calculated by summing these weights. This is done because the severity of different violations varies significantly; for example, the risk weight of a weak password vulnerability is higher than that of a time deviation vulnerability. Quantitative scoring allows for prioritization of monitoring results, helping operations and maintenance personnel focus on key risks. Subsequently, a monitoring report is generated based on the detailed violation data and risk scoring results. The report includes a problem list, risk trend charts, and remediation suggestions, and is output after being formatted according to a preset template. This is because the monitoring report is a deliverable of the technical monitoring closed loop, and it needs to meet both the decision-making needs of management and the execution needs of operations and maintenance. The problem list facilitates rapid rectification, the risk trend facilitates long-term tracking, and the remediation suggestions provide specific operational methods. Then, the monitoring report is sent to the asset supervision dashboard for visualization. The dashboard renders risk heat maps, compliance rate dashboards, and alarm distribution topology to obtain the visualization results. This is done because the dashboard display can transform abstract data into an intuitive visual presentation, allowing dispatch center personnel to grasp the security status of all plants and stations in the jurisdiction at a glance. For example, red areas indicate areas with a high concentration of high-risk plants and stations, requiring immediate reinforcement of operations and maintenance personnel. Finally, alarm information is pushed to the operation and maintenance alarm platform based on the set of non-compliance items. High-risk non-compliance items are pushed to the mobile terminals of operation and maintenance personnel in the form of emergency alarms, medium-risk non-compliance items are dispatched to the operation and maintenance queue in the form of ordinary work orders, and low-risk non-compliance items are summarized and sent in the form of weekly report summaries. This is because different risk levels require different response times. Emergency alarms require minute-level response, while ordinary work orders can be processed in hours. Tiered push can avoid the overwhelming of critical information caused by alarm storms and ensure that major security risks are dealt with first.

[0053] This embodiment establishes an encrypted communication channel between the scheduling master station and the plant maintenance agent, collects multi-dimensional asset features and calculates confidence levels to complete asset identification and ledger updates, generates a dynamic topology based on physical link information, constructs a standardized supervision configuration library based on the asset ledger and topology, automatically matches and issues verification tasks, identifies non-compliant items through difference set operations and generates reports and pushes alarms. It achieves a standardized closed loop of automatic asset identification, dynamic management, and remote supervision, improving regulatory efficiency and asset control accuracy, reducing manual on-site workload, and ensuring the safe and compliant operation of plant assets.

[0054] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in Embodiment 1 above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2 The remote monitoring method for plant assets, step S60, further includes steps S201 to S206: Step S201: Extract asset type information and asset attribute data based on the updated asset ledger.

[0055] Specifically, the process begins by reading each asset record from the updated asset ledger, extracting asset type information and asset attribute data. Asset type information includes network device type, host type, or power-specific equipment type. Asset attribute data includes Internet Protocol address, Media Access Control address, hostname, running process identifier, and application directory path. These asset type and attribute data are then integrated to obtain asset feature data. This is done because the asset ledger, after confidence level verification, already contains accurate asset ownership and classification information; direct extraction avoids duplicate identification. For example, records marked as host type in the ledger do not require further process fingerprint matching; host class supervision rules can be directly applied. Next, the extracted asset feature data undergoes integrity verification, checking for empty values ​​or abnormal format fields. When the Internet Protocol address field is empty, it is marked as needing completion. When the media access control address format does not conform to the preset rules, a re-collection request is triggered to obtain verified asset feature data. This is done because the ledger data may be accidentally damaged during transmission or storage. Integrity verification can ensure the input quality of subsequent configuration library construction and avoid writing erroneous data into the rule binding relationship, which would cause the supervision task to fail. Finally, the verified asset feature data is grouped and indexed according to asset type. Network device types are classified into the first device group, host types into the second device group, and power special equipment types into the third device group, resulting in grouped asset feature data. This is done because assets of the same type share the same supervision template. Grouping indexing can realize batch rule matching. For example, all switches in the first device group can be bound to the port security template at once without traversing and comparing them one by one, which greatly improves the efficiency of configuration library construction.

[0056] Step S202: Extract network hierarchy and physical connection data based on the asset dynamic topology diagram.

[0057] Specifically, firstly, the node set and edge set are read from the asset dynamic topology graph. The node set contains the identifier and type of each device, and the edge set contains the connection relationships and link attributes between devices. The vertical distribution hierarchy of nodes in the topology is analyzed, marking nodes located in the core switching layer as the core layer, nodes located in the aggregation switching layer as the aggregation layer, and nodes directly connected to terminal devices as the access layer, thus obtaining the network hierarchy structure. This is done because the network hierarchy determines the importance of devices and the scope of failure impact. Core layer devices carry the entire site's traffic, and their supervision intensity should be higher than that of the access layer. The hierarchical division allows the configuration library to allocate verification resources differentially. Then, physical connection relationship data is extracted from the edge set, including the local device identifier, local port number, peer device identifier, peer port number, and link bandwidth attributes. Link redundancy is detected. When there are multiple... When there are multiple parallel edges, a link is marked as redundant; when there is only a single edge, it is marked as a single link, thus obtaining physical connection relationship data. This is because the alarm thresholds for redundant links and single links are different. For example, a single link failure should immediately trigger an emergency alarm, while a single failure in a redundant link can be downgraded to a normal alert, avoiding excessive alarms that could interfere with operational judgment. Finally, the network hierarchy structure and physical connection relationship data are associated and stored according to device identifiers. Core layer devices with redundant links are marked as high-reliability nodes, and access layer devices with single links are marked as edge-risk nodes, thus obtaining network structure data. This is because the combination of hierarchy and redundancy directly reflects the business criticality of the device. High-reliability nodes require more frequent configuration checks and stricter change control, while edge-risk nodes require a focus on link stability, providing accurate data support for subsequent rule expansion in the custom business layer.

[0058] Step S203: Establish a basic rule layer based on asset attribute data to obtain basic rule data.

[0059] It should be noted that the basic rules layer includes general port rules and performance acquisition rules. General port rules are specifications for port usage and monitoring applicable to various devices. They define the range of legal ports and the types of ports that are prohibited, ensuring compliant port usage. Performance acquisition rules are specifications for obtaining device operating status parameters. They clearly define the content, collection period, and data format to ensure effective acquisition of performance data.

[0060] Specifically, firstly, the Internet Protocol address (IPA) and Media Access Control (MAC) address fields in the asset attribute data are read to construct IPA reachability detection rules. Preset detection cycles and timeout thresholds are set. When a preset number of consecutive detection failures occur, the device is marked as offline, thus obtaining network connectivity rules. This is done because the online status of assets is a prerequisite for all monitoring operations; offline devices cannot perform subsequent checks, and early identification can avoid wasting resources by issuing invalid tasks. Secondly, the hostname and running process identifier fields in the asset attribute data are read to construct performance collection rules. CPU usage and memory usage collection thresholds are set. When real-time collected values ​​exceed the thresholds, a performance alert is triggered, thus obtaining performance monitoring rules. This is done because the operating status of host-type assets directly affects the stability of the business system, and preset thresholds can achieve early detection of anomalies, such as when CPU usage consistently exceeds 80%. The system provides early warnings to prevent reactive detection after business interruptions. Next, it reads the application directory path field from the asset attribute data, constructs file integrity verification rules, sets up a path list and hash value benchmark library for key configuration files, and periodically compares the current hash value with the benchmark value to obtain integrity verification rules. This is done because configuration files in the application directory are the carriers of device security policies; unauthorized tampering may cause security policies to fail, and hash comparison can accurately detect file-level changes. Finally, network connectivity rules, performance monitoring rules, and integrity verification rules are categorized and stored according to rule identifiers, marked as universal rules for all types, to obtain basic rule data. This is because the above three types of rules are applicable to all asset types and do not change with device type or network location. Unifying them into a globally shared basic layer avoids redundant definitions in subsequent standardized template layers, improving the reusability and consistency of the configuration library.

[0061] Step S204: Establish a standardized template layer based on asset type information to obtain standardized template data.

[0062] It should be noted that the standardized template layer includes standardized verification items pre-set in industry safety manuals for switches, mainframes, and power-specific equipment. The industry safety manual is a guidance document for equipment security configuration published in the power monitoring system field. It provides an authoritative and unified basis for remote supervision. The standardized verification items are specific inspection contents and judgment conditions set according to safety specifications. These standardized verification items are used to directly guide the execution of remote tasks and compliance judgments.

[0063] Specifically, firstly, the network device type record in the asset type information is read. Based on the switch security configuration section of the industry security manual, pre-configured port security check items are set, including closing preset high-risk ports (21 / 23) and root remote login, to obtain a standardized switch template. This is done because the exposed ports and management interfaces of network devices are attack entry points. The industry security manual clearly specifies a list of high-risk ports. Pre-configuring them as templates ensures that all switches perform a unified baseline check, avoiding omissions and version differences during manual configuration. Secondly, the host type record in the asset type information is read. Based on the host security protection section of the industry security manual, pre-configured identity authentication and access control check items are set, including password complexity verification, account lockout policy checks, and patch update status detection, to obtain a standardized host template. This is done because hosts carry business applications, and account security and system vulnerabilities are the main risk points. Insufficient password complexity makes them vulnerable to brute-force attacks, and missing patches make them vulnerable to exploitation of known vulnerabilities. Standardized templates can implement protection requirements in batches. Next, the following steps are taken: The power-specific equipment type records in the asset type information are pre-set with vertical encryption verification items and horizontal isolation verification items based on the power secondary equipment security protection chapter in the industry security manual. These include tunnel policy minimization verification and business dual-link connectivity detection, resulting in standardized templates for power-specific equipment. This is because power-specific equipment, such as vertical encryption authentication devices and horizontal isolation devices, constitute the security boundary of the power monitoring system. Overly broad tunnel policies can lead to illegal traffic penetration, and single-link operation will lose fault redundancy. Standardized templates can ensure the special security attributes of dedicated equipment. Finally, the standardized templates for switches, hosts, and power-specific equipment are indexed and bound according to asset type identifiers. When querying a device, the corresponding template is automatically called based on the type identifier to obtain standardized template data. This is because the verification items for different types of equipment differ significantly. The type index enables accurate template matching, avoiding the misdelivery of host password rules to switches for execution, which could lead to task failure and ensure the consistent implementation of supervision standards across different devices.

[0064] Step S205: Establish a service-defined layer based on the network hierarchy and physical connection relationship data to obtain service-defined data.

[0065] It should be noted that the business customization layer includes custom verification items that are extended based on the network hierarchy. Custom verification items are personalized checks added based on actual business needs. They are used to supplement requirements not covered by basic rules and standard templates.

[0066] Specifically, first, the core layer device identifiers in the network hierarchy are read. Based on the preset substation level rules, high-priority verification frequencies and strict alarm thresholds are configured for the core layer devices. For example, a core switch traffic monitoring threshold (e.g., 80%) and real-time alarms for configuration changes are set, resulting in custom rules for the core layer. This is because core layer devices carry the entire station's service traffic, and a failure would have the greatest impact. High-frequency verification can promptly identify performance bottlenecks, and strict thresholds ensure early warnings before service is compromised. Next, the aggregation layer device identifiers in the network hierarchy are read, and medium-priority verification strategies are configured, including link aggregation status detection and batch deep scanning during preset time periods (off-peak periods), resulting in custom rules for the aggregation layer. This is because the aggregation layer acts as a bridge between the core layer and the access layer, and its stability directly affects the reachability of lower-layer devices. Scanning during off-peak periods avoids the impact of deep detection on service traffic. Finally, the physical connection relationship data is read... Redundant link marking is performed, and dual-link load balancing detection and single-link degradation operation alarms are configured for redundant link devices. Link interruption emergency alarms and preset backup path switching detection are configured for single-link devices, resulting in custom rules for link redundancy. This is done because the fault tolerance of redundant links is different from that of single links. When a single redundant link is interrupted, services can still continue. The alarm level should be lower than that of a single link interruption to avoid an alarm storm overwhelming truly urgent events. Finally, the core layer custom rules, aggregation layer custom rules, access layer custom rules, and link redundancy custom rules are superimposed and bound according to the device identifier. When a device meets multiple conditions at the same time, all associated rules are executed in combination to obtain custom service data. This is done because actual devices often have multiple attributes at the same time. For example, a core layer switch with dual links needs to execute core layer rules and redundant link rules at the same time. Superimposed binding ensures comprehensive coverage of the supervision strategy and realizes the differentiated supervision intensity requirements of specific substation levels.

[0067] Step S206: Construct a standardized remote supervision configuration library based on basic rule data, standardized template data, and business-customized data.

[0068] Specifically, firstly, network connectivity rules, performance monitoring rules, and integrity verification rules are read from the basic rule data. These are then globally indexed and stored according to rule identifiers. The basic rule priority is set to the lowest level to ensure all assets inherit the common rules by default, resulting in a basic rule index library. This is done because basic rules are universal and need to be used as the default configuration to cover all assets. The low priority design allows them to be overridden by upper-layer templates or custom rules, avoiding conflicts between common rules and specific needs in special scenarios. Next, standardized templates for switches, hosts, and power-specific equipment are read from the standardized template data. A template mapping table is established according to asset type identifiers, and the standardized template priority is set to the middle level. When the asset type is clear, the corresponding template is automatically called, resulting in a standardized template index library. This is done because asset type is the core index for template matching. The middle priority allows it to inherit basic rules and overlay special verification items, while retaining the flexibility to be overridden by the business customization layer. Finally, the core layer custom rules and aggregation layer custom rules are read from the business customization data. Custom rules and link redundancy rules are established using a multi-dimensional index based on device and network layer identifiers. Business-defined rules are set to the highest priority. When a device meets specific network location or link conditions, the superimposed execution is triggered, resulting in a business-defined index library. This is done because the business-defined layer reflects the differentiated needs of specific substations, and the highest priority ensures that special rules can cover general rules. For example, the core switch of a 220kV substation needs to perform more stringent traffic monitoring than the general template. Finally, the basic rule index library, standardized template index library, and business-defined index library are associated and aggregated to generate a complete supervision configuration sheet based on the asset's unique identifier. The configuration sheet contains the complete set of rules to be executed for that asset and their priority relationships, resulting in a standardized remote supervision configuration library. This is done because the three-layer architecture achieves rule decoupling and on-demand combination. When querying specific devices, there is no need to traverse and match layer by layer; the pre-generated configuration sheet can be directly called, significantly improving the efficiency of supervision task distribution while ensuring comprehensiveness and relevance in terms of full coverage of basic rules, accurate matching of type templates, and priority fulfillment of special needs.

[0069] This embodiment extracts asset type and attribute data from the updated asset ledger, and network layer and physical connection relationship data from the dynamic asset topology diagram. It then sequentially establishes a basic rule layer containing general ports and performance collection rules, a standardized template layer with pre-set equipment verification items based on industry security manuals, and a business-customized layer extended by network layer. Finally, it integrates these three types of data to construct a standardized remote monitoring configuration library. This achieves layered adaptation of monitoring standards and precise matching of equipment types, making remote monitoring more unified and standardized to meet the actual operational needs of plants and stations.

[0070] Based on the first embodiment of this application, this application also provides a remote monitoring device for plant assets, please refer to... Figure 3The device includes: The communication establishment module 10 is used to establish an encrypted communication channel with the plant-side operation and maintenance agent and initialize remote monitoring parameters.

[0071] The data acquisition module 20 is used to send acquisition instructions to the operation and maintenance agent through an encrypted communication channel, so that the operation and maintenance agent can obtain multi-dimensional feature data of the plant assets.

[0072] The confidence calculation module 30 is used to calculate the asset ownership confidence based on multidimensional feature data and benchmark asset database data.

[0073] The asset determination module 40 is used to determine the ownership of assets based on the confidence level of asset ownership, and to obtain an updated asset ledger, which includes asset object and asset type information.

[0074] The topology generation module 50 is used to generate a dynamic asset topology map based on the physical link information reported by the operation and maintenance agent.

[0075] The configuration library creation module 60 is used to create a standardized remote monitoring configuration library based on the updated asset ledger and asset dynamic topology diagram.

[0076] The task distribution module 70 is used to match a standardized remote monitoring configuration library based on asset type information, and distribute verification tasks to the operation and maintenance agent through an encrypted communication channel, and receive the set of execution results returned by the operation and maintenance agent.

[0077] The report and alarm module 80 is used to identify non-compliant items based on the difference operation between the execution result set and the standard configuration set, generate a supervision report, and complete the visualization display and alarm push. The standard configuration set comes from the standardized remote supervision configuration library.

[0078] The remote monitoring device for plant assets provided in this application, employing the remote monitoring method for plant assets in the above embodiments, can solve the technical problem of how to achieve automatic identification and remote compliance monitoring and closed-loop management of plant assets. Compared with the prior art, the beneficial effects of the remote monitoring device for plant assets provided in this application are the same as those of the remote monitoring method for plant assets provided in the above embodiments, and other technical features in the remote monitoring device for plant assets are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0079] This application provides a remote monitoring device for plant assets, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the remote monitoring method for plant assets in the above embodiment 1.

[0080] The following is for reference. Figure 4 The diagram illustrates a structural schematic suitable for implementing the remote monitoring device for plant assets in the embodiments of this application. The remote monitoring device for plant assets in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), vehicle terminals (e.g., vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The remote monitoring equipment for plant assets shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0081] like Figure 4 As shown, the plant asset remote monitoring equipment may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the plant asset remote monitoring equipment. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following may be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the plant asset remote monitoring equipment to communicate wirelessly or wiredly with other equipment to exchange data. While various plant asset remote monitoring devices are shown in the figures, it should be understood that implementation or possession of all of them is not required. More or fewer devices may be implemented alternatively.

[0082] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0083] The remote monitoring equipment for plant assets provided in this application, employing the remote monitoring method for plant assets in the above embodiments, can solve the technical problem of how to achieve automatic identification and remote compliance monitoring and closed-loop management of plant assets. Compared with the prior art, the beneficial effects of the remote monitoring equipment for plant assets provided in this application are the same as those of the remote monitoring method for plant assets provided in the above embodiments, and other technical features in this remote monitoring equipment for plant assets are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0084] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0085] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0086] This application provides a computer-readable medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the remote monitoring method for plant assets in the above embodiments.

[0087] The computer-readable medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor devices, or any combination thereof. More specific examples of computer-readable media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable medium may be any tangible medium containing or storing a program that can be executed by instructions, used by a device, or used in conjunction with it. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0088] The aforementioned computer-readable medium may be included in the plant asset remote monitoring equipment; or it may exist independently and not be assembled into the plant asset remote monitoring equipment.

[0089] The aforementioned computer-readable medium carries one or more programs that, when executed by the plant asset remote monitoring equipment, enable the equipment to write computer program code for performing the operations of this application in one or more programming languages ​​or a combination thereof. These programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0090] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of this application. In this regard, all blocks in the flowcharts or block diagrams may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that all blocks in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using dedicated hardware-based implementations that perform the specified functions or operations, or using a combination of dedicated hardware and computer instructions.

[0091] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0092] The readable medium provided in this application is a computer-readable medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described remote monitoring method for plant assets. This solves the technical problem of how to achieve automatic identification and remote compliance monitoring and closed-loop management of plant assets. Compared with the prior art, the beneficial effects of the computer-readable medium provided in this application are the same as those of the remote monitoring method for plant assets provided in the above embodiments, and will not be elaborated upon here.

[0093] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the remote monitoring method for plant assets as described above.

[0094] The computer program product provided in this application can solve the technical problem of how to achieve automatic identification, remote compliance supervision, and closed-loop management of plant assets. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the remote supervision method for plant assets provided in the above embodiments, and will not be repeated here.

[0095] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A method for remote monitoring of plant assets, characterized in that, The method includes: Establish an encrypted communication channel with the plant-side operation and maintenance agent and initialize remote monitoring parameters; The encrypted communication channel is used to send collection instructions to the maintenance agent, enabling the maintenance agent to obtain multi-dimensional feature data of the plant assets. Specifically: a first collection instruction is sent to the plant-side maintenance agent through the established encrypted communication channel, enabling the maintenance agent to send port status query requests and address resolution protocol table retrieval requests to the network devices using Simple Network Management Protocol (SMMP). After the network devices return port status data and address resolution protocol information, the maintenance agent encrypts and sends the data back to obtain the network device asset data. A second collection instruction is sent to the maintenance agent through the encrypted communication channel, enabling the maintenance agent to remotely log in to the host using Secure Shell Protocol (SMP) and execute process status query commands and file system traversal commands. The system acquires host performance data, running process identifiers, and application directory paths to obtain host asset data. It then sends a third collection command to the maintenance agent via an encrypted communication channel, enabling the agent to actively probe devices below the station control layer using power-specific service protocols. This involves sending handshake request frames conforming to the protocol format, parsing the device type code and function code in the response frames returned by the devices, and obtaining power-specific equipment asset data. Finally, it receives network device asset data, host asset data, and power-specific equipment asset data, aligns the three types of data with timestamps and unifies their formats, removes redundant fields from repeated collections, and aggregates and reassembles them according to a preset data structure to obtain multi-dimensional feature data of the plant assets. The asset ownership confidence level is calculated based on the multidimensional feature data and the benchmark asset database data. The ownership of assets is determined based on the asset ownership confidence level, and an updated asset ledger is obtained, wherein the updated asset ledger includes asset object and asset type information; Based on the physical link information reported by the operation and maintenance agent, a dynamic asset topology map is generated; A standardized remote monitoring configuration library is established based on the updated asset ledger and asset dynamic topology diagram. The system matches a standardized remote monitoring configuration library based on the asset type information and sends a verification task to the operation and maintenance agent through the encrypted communication channel, and receives the set of execution results returned by the operation and maintenance agent. Non-compliant items are identified by the difference operation between the execution result set and the standard configuration set, a supervision report is generated, and a visual display and alarm push are completed. The standard configuration set is derived from the standardized remote supervision configuration library. The step of establishing a standardized remote monitoring configuration library based on the updated asset ledger and asset dynamic topology diagram includes: Extract asset type information and asset attribute data from the updated asset ledger; Extract network hierarchy and physical connection data from the asset dynamic topology diagram; A basic rule layer is established based on the asset attribute data to obtain basic rule data, wherein the basic rule layer includes general port and performance collection rules; A standardized template layer is established based on the asset type information to obtain standardized template data, wherein the standardized template layer includes standardized verification items for switches, mainframes and power-specific equipment pre-set according to the industry security manual. A service customization layer is established based on the network hierarchy and physical connection relationship data to obtain service customization data, wherein the service customization layer includes custom verification items extended based on the network hierarchy. A standardized remote monitoring configuration library is constructed based on the aforementioned basic rule data, standardized template data, and business-customized data.

2. The method as described in claim 1, characterized in that, The step of calculating the asset ownership confidence level based on the multidimensional feature data and the benchmark asset database data includes: Extract raw feature data from the multidimensional feature data, wherein the raw feature data includes Internet Protocol address, Media Access Control address, hostname, running process identifier, and application directory path; The original feature data is cleaned and standardized to obtain standardized feature data; Based on the standardized feature data, Internet Protocol address features, Media Access Control address features, hostname features, process fingerprint features, and application directory features are constructed respectively to obtain a set of feature components; According to the preset weight configuration, feature weights are assigned to each feature in the feature component set, and the feature component set is vectorized and aggregated into a multidimensional feature vector. Convert the benchmark asset database data into benchmark asset feature vectors; Based on the multidimensional feature vector and the corresponding benchmark asset feature vector, the similarity of each feature is calculated. The asset ownership confidence score is obtained by weighted summation of the similarity scores of the aforementioned features.

3. The method as described in claim 1, characterized in that, The step of determining asset ownership based on the asset ownership confidence level to obtain the updated asset ledger includes: Based on a preset similarity threshold, the asset ownership confidence level is used to determine asset ownership, identify asset consolidation needs, and obtain asset ownership determination results. Extract the corresponding multidimensional feature data based on the asset ownership determination results; Based on the process fingerprint features and application directory features in the multidimensional feature data, the asset type information is determined; The asset object is obtained based on the asset type information, wherein the asset object includes network device type, host type or power dedicated equipment type; Based on the asset ownership determination results, the asset attributes are checked and the change trajectory is recorded to obtain the checked asset data; An updated asset ledger is constructed based on the verified asset data.

4. The method as described in claim 1, characterized in that, The step of generating a dynamic asset topology map based on the physical link information reported by the operation and maintenance agent includes: The encrypted communication channel is used to send a topology acquisition command to the operation and maintenance agent, so that the operation and maintenance agent can obtain the switch port forwarding table and link layer discovery protocol information to obtain the raw physical link data. Receive the raw physical link data, and parse the physical connection relationship between devices based on the raw physical link data to construct the correlation matrix data between devices; The node position coordinates are calculated using a graph layout algorithm based on the correlation matrix data to obtain an initial asset topology map; The encrypted communication channel is used to send port status monitoring instructions to the operation and maintenance agent, so that the operation and maintenance agent periodically reports port status change information, and the operation and maintenance agent reports port status change information. The initial asset topology map is redrawn in real time based on the port status change information to obtain a dynamic asset topology map.

5. The method as described in claim 4, characterized in that, The step of redrawing the initial asset topology map in real time based on the port status change information to obtain a dynamic asset topology map includes: Based on the port status change information, the target device node and target physical port that have undergone status change are parsed to obtain the changed node information; The association matrix data is updated based on the changed node information to obtain the updated association matrix data; The layout parameters of the graphic layout algorithm are adjusted based on the updated correlation matrix data to obtain the adjusted layout parameters; The node position coordinates are recalculated based on the adjusted layout parameters to obtain the updated node position coordinates. The initial asset topology map is rendered and updated based on the updated node position coordinates to obtain a dynamic asset topology map.

6. The method as described in claim 1, characterized in that, The steps of identifying non-compliant items based on the difference operation between the execution result set and the standard configuration set, generating a supervision report, and completing visualization and alarm push include: By performing a difference operation between the standard configuration set and the execution result set, a set of non-compliant items is obtained; By comparing the set of non-compliant items with preset security standards, detailed violation data is obtained; Risk scoring is performed based on the aforementioned violation details data to obtain the risk scoring results; A monitoring report is generated based on the detailed violation data and the risk scoring results. The supervision report is sent to the asset supervision dashboard for visualization, and the visualization results are obtained to complete the visualization display. Alarm information is pushed to the operation and maintenance alarm platform based on the set of non-compliant items.

7. A remote monitoring device for plant assets, characterized in that, The device is applied to the remote monitoring method for plant assets as described in any one of claims 1-6, and the device comprises: The communication establishment module is used to establish an encrypted communication channel with the plant-side operation and maintenance agent and initialize remote monitoring parameters; The data acquisition module is used to send acquisition instructions to the operation and maintenance agent through the encrypted communication channel, so that the operation and maintenance agent can obtain multi-dimensional feature data of the plant assets; The confidence calculation module is used to calculate the asset ownership confidence based on the multidimensional feature data and the benchmark asset database data. The asset determination module is used to determine the ownership of assets based on the asset ownership confidence level and obtain an updated asset ledger, wherein the updated asset ledger includes asset object and asset type information; The topology generation module is used to generate a dynamic asset topology map based on the physical link information reported by the operation and maintenance agent. The configuration library creation module is used to create a standardized remote monitoring configuration library based on the updated asset ledger and asset dynamic topology diagram. The task distribution module is used to match a standardized remote monitoring configuration library according to the asset type information, and distribute verification tasks to the operation and maintenance agent through the encrypted communication channel, and receive the set of execution results returned by the operation and maintenance agent; The reporting and alarm module is used to identify non-compliant items based on the difference operation between the execution result set and the standard configuration set, generate a supervision report, and complete the visualization and alarm push. The standard configuration set is derived from the standardized remote supervision configuration library.

8. A remote monitoring device for plant assets, characterized in that, The device includes: a memory, a processor, and a plant asset remote monitoring program stored on the memory and running on the processor, the plant asset remote monitoring program being configured to implement the steps of the plant asset remote monitoring method as described in any one of claims 1-6.

9. A storage medium, characterized in that, The storage medium stores a plant asset remote monitoring program, which, when executed by a processor, implements the steps of the plant asset remote monitoring method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Method and device for identifying network hardware assets of electric power industrial control system of digital substation

    CN119520304A

  • IT asset intelligent management system and implementation method thereof

    CN121094722A