A power monitoring system peripheral safety management method and system

CN122553518APending Publication Date: 2026-08-11ANHUI LINGHUI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-15
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0004]本发明提供一种电力监控系统外设安全管控方法及系统,以解决现有技术中由于外设接入安全性难以得到有效管控,直接接入至电力监控系统,无法从技术层面杜绝非授权或不合规设备的接入,而且由于外设使用时的管控手段较为薄弱,难以完成有效地安全风险事件追溯的技术问题

Benefits of technology

[0015]The beneficial effects of this invention are as follows: The power monitoring system peripheral security management method and system proposed in this invention can ensure the reliability of each access command generated by pre-analyzing and determining the peripheral's access requirements for the expansion dock. Subsequently, by using the access requirements for connecting to the expansion dock, the system can perform expansion dock matching analysis and, based on the expansion dock's occupancy status, retrieve a matching available expansion dock for peripheral access control. Furthermore, when a peripheral is detected to be connected to an available expansion dock, access identity verification is performed first. After successful verification, the interactive data between the host and the peripheral is parsed to determine the sensitive fields to be identified as the parsing results. This allows for analysis of whether each interactive file of the interactive data truly needs to be encrypted and forwarded. If encryption and forwarding are required, the corresponding encryption mode is used to control the isolated forwarding of the interactive data. This achieves secure management of the interaction between the power monitoring system host and peripherals, ensuring not only the reliability of the expansion dock allocation for peripheral connection but also the security of isolated data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122553518A_ABST
    Figure CN122553518A_ABST
Patent Text Reader

Abstract

This invention provides a method and system for peripheral security management in a power monitoring system, relating to the field of power security technology. The method includes: obtaining a peripheral's access request command to an expansion dock; obtaining multiple compatible expansion docks based on the access request command; allocating expansion docks according to the access time information corresponding to the access request command and the occupancy status of each compatible expansion dock to obtain available expansion docks, and controlling the available expansion docks to enter the access state according to the access request command; when a peripheral is detected connecting to an available expansion dock, verifying the peripheral's access identity; after successful access identity verification, parsing the interaction data between the host and the peripheral to obtain the parsing result; and controlling the isolation and forwarding of the interaction data and event logging based on the parsing result for peripheral security management. The method and system provided by this invention ensure the reliability of the allocation of expansion docks connected to peripherals while also guaranteeing the security of isolated data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power safety technology, and in particular to a method and system for the safety management of peripheral devices in a power monitoring system. Background Technology

[0002] Power monitoring systems are the core of power grid operation and control. To defend against external network attacks, these systems generally employ physical isolation technology to build closed internal networks. However, during digital transformation, when systems undergo intelligent upgrades, equipment debugging, and routine maintenance, it is difficult to avoid operators connecting various peripheral devices such as USB drives and portable debugging terminals. Traditional peripheral device management methods mainly rely on regulations (such as "dedicated personnel for each device, affixing seals, formatting before copying") and personnel self-discipline.

[0003] However, when peripheral devices frequently connect to the power monitoring system, the security of these connections is difficult to effectively manage. Direct connection to the power monitoring system cannot technically prevent unauthorized or non-compliant devices from accessing the system. Furthermore, due to the weak management of peripheral devices during use, it is difficult to effectively trace security risk events. Summary of the Invention

[0004] This invention provides a method and system for security management of peripheral devices in a power monitoring system, in order to solve the technical problems in the prior art where the security of peripheral device access is difficult to effectively manage, direct access to the power monitoring system cannot technically prevent the access of unauthorized or non-compliant devices, and the control measures during the use of peripheral devices are relatively weak, making it difficult to effectively trace security risk events.

[0005] To achieve the above and other related objectives, this invention provides a method for peripheral security management in a power monitoring system, comprising: acquiring a peripheral's access request command to an expansion dock; performing expansion dock matching analysis based on the access request command to obtain multiple compatible expansion docks; allocating expansion docks according to the access time information corresponding to the access request command and the occupancy status of each compatible expansion dock to obtain available expansion docks, and controlling the available expansion docks to enter the access state according to the access request command; when a peripheral is detected to be connected to an available expansion dock, performing access identity verification on the peripheral; after successful access identity verification, parsing the interaction data between the host and the peripheral to obtain the parsing result; and controlling the isolation, forwarding, and event logging of the interaction data based on the parsing result for peripheral security management.

[0006] In one embodiment of the present invention, obtaining a peripheral device's access request to the expansion dock includes: obtaining an authorization document for the expansion dock, the authorization document including a work order; extracting information from the authorization document according to the instruction generation conditions to obtain multiple proof contents; the proof contents include factory area information, contact information, access reason information, access time information, access type information, and approval access information; performing a format composition integrity check on the proof contents corresponding to each instruction generation condition; when each proof content is complete, performing an access assessment on the access reason information to obtain an access acceptance rate, so that when the access acceptance rate is greater than a set threshold, the approval of the corresponding authorization document is determined, and the peripheral device's access request to the expansion dock is obtained.

[0007] In one embodiment of the present invention, an access assessment is performed on the access reason information to obtain an access acceptance level. When the access acceptance level is greater than a set threshold, the approval of the corresponding authorization certificate is determined, and the peripheral device's access request instruction for the expansion dock is obtained. This includes: extracting reason keywords from the access reason information; sequentially comparing the semantic similarity of each reason keyword with each preset keyword in the keyword library corresponding to the corresponding factory area information to obtain the target preset keyword that is semantically closest to the reason keyword; obtaining the reason matching degree based on the target semantic similarity between the target preset keyword and the reason keyword; obtaining the access risk degree based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the contribution direction of the target semantic similarity to the access risk, and the risk contribution coefficient; querying the gain intensity for the use of the expansion dock based on each reason keyword, querying the gain adjustment amount based on the semantic intensity of the auxiliary word corresponding to each reason keyword, and obtaining the reason rationality based on the gain intensity and the gain adjustment amount; and weighting the reason matching degree, the access risk degree, and the reason rationality to obtain the access acceptance level. When the access acceptance level is greater than a set threshold, the approval of the corresponding authorization certificate is determined, and the peripheral device's access request instruction for the expansion dock is obtained.

[0008] In one embodiment of the present invention, the formula for calculating the admission acceptance rate is: ;in, Indicates acceptance level. Indicates the semantic similarity of the target. Indicates the number of causal keywords. Indicates the benchmark risk value. Indicates the risk contribution coefficient. Indicates the first gain intensity. Indicates the gain adjustment amount. This represents the first weighting factor corresponding to the cause-match degree. This represents the second weighting factor corresponding to the access risk level. This represents the third weighting factor corresponding to the reasonableness of the cause.

[0009] In one embodiment of the present invention, the access risk level is obtained based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the contribution direction of the target semantic similarity to the access risk, and the risk contribution coefficient. This includes: adding a degree adverb to the target preset keyword based on the risk gain direction of the degree adverb to generate a regulating keyword; the degree adverb includes either a positive degree adverb or a negative degree adverb; comparing the semantic similarity of the cause keyword and the regulating keyword to obtain the regulating semantic similarity; and comparing the target semantic similarity with the regulating semantic similarity to obtain the contribution direction of the target semantic similarity to the access risk. The access risk level is then obtained based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the contribution direction, and the risk contribution coefficient.

[0010] In one embodiment of the present invention, based on the access request instruction, a docking station matching analysis is performed to obtain multiple compatible docking stations, including: locating and searching docking stations based on the factory area information corresponding to the access request instruction to obtain multiple matching docking stations corresponding to matching areas; obtaining the corresponding usage purpose based on the reason keywords of the access reason information corresponding to the access request instruction; searching for the baseline usage set corresponding to each matching docking station, and calculating the usage similarity between each baseline usage in the baseline usage set and the usage purpose to obtain the maximum usage similarity corresponding to each usage purpose; obtaining a comprehensive adaptation index based on the maximum usage similarity and the adaptation coefficient of the baseline usage corresponding to the maximum usage similarity; generating a ranking sequence corresponding to the matching docking stations based on the comprehensive adaptation index; and selecting a preset number of matching docking stations ranked at the top in the ranking sequence as compatible docking stations.

[0011] In one embodiment of the present invention, before finding the set of baseline uses corresponding to each matching docking station and calculating the similarity between each baseline use and the use of use to obtain the maximum similarity for each use, the method further includes: evaluating the processing capabilities of each item in the historical baseline use list of each matching docking station based on the historical access processing data corresponding to each matching docking station to obtain a processing capability index; determining whether the processing capability index is less than the index threshold of the corresponding historical baseline use in the historical baseline use list; if so, deleting the corresponding historical baseline use from the historical baseline use list to obtain the set of baseline uses corresponding to the matching docking station; if not, retaining the historical baseline use in the historical baseline use list.

[0012] In one embodiment of the present invention, after successful access identity verification, the interaction data between the host and the peripheral device is parsed to obtain the parsing result, including: after successful access identity verification, detecting the sender corresponding to the interaction data; when the sender is detected to be a peripheral device, performing data scanning on the interaction data based on different sensitive keywords in the sensitive word library to obtain multiple sensitive fields to be identified corresponding to each interaction file in the interaction data, as the parsing result.

[0013] In one embodiment of the present invention, the parsing result includes multiple sensitive fields to be identified corresponding to each interactive file in the interactive data; based on the parsing result, the interactive data is isolated and forwarded and events are logged for peripheral security management, including: extracting associated auxiliary words based on sensitive keywords for each sensitive field to be identified; combining the associated auxiliary words and sensitive keywords to obtain actual semantic words; comparing the semantic sensitivity of the actual semantic words with that of the sensitive keywords; when the first semantic sensitivity corresponding to the actual semantic words is less than the second semantic sensitivity corresponding to the sensitive keywords, obtaining the sensitivity authenticity based on the sensitivity difference between the second and first semantic sensitivity and the first authenticity coefficient; obtaining the comprehensive sensitivity authenticity based on the field length of the sensitive field to be identified, the second authenticity coefficient corresponding to the field length, and all sensitivity authenticity of the interactive file corresponding to the sensitive field to be identified; when the comprehensive sensitivity authenticity is greater than the authenticity threshold, generating a corresponding encryption mode based on the file type of the interactive file, and controlling the isolation and forwarding of the interactive data and events to be logged for peripheral security management.

[0014] To achieve the above and other related objectives, the present invention also provides a peripheral security management system for a power monitoring system, comprising: an acquisition unit for acquiring a peripheral's access request command to an expansion dock; a matching analysis unit for performing expansion dock matching analysis based on the access request command to obtain multiple compatible expansion docks; an expansion dock allocation unit for allocating expansion docks based on the access time information corresponding to the access request command and the occupancy status of each compatible expansion dock to obtain available expansion docks, thereby controlling available expansion docks to enter the access state according to the access request command; an identity verification unit for verifying the access identity of the peripheral when it is detected that the peripheral has accessed an available expansion dock; a content parsing unit for parsing the interaction data between the host and the peripheral after successful access identity verification to obtain the parsing result; and an isolation forwarding unit for controlling the isolation forwarding and event recording of the interaction data based on the parsing result to perform peripheral security management.

[0015] The beneficial effects of this invention are as follows: The power monitoring system peripheral security management method and system proposed in this invention can ensure the reliability of each access command generated by pre-analyzing and determining the peripheral's access requirements for the expansion dock. Subsequently, by using the access requirements for connecting to the expansion dock, the system can perform expansion dock matching analysis and, based on the expansion dock's occupancy status, retrieve a matching available expansion dock for peripheral access control. Furthermore, when a peripheral is detected to be connected to an available expansion dock, access identity verification is performed first. After successful verification, the interactive data between the host and the peripheral is parsed to determine the sensitive fields to be identified as the parsing results. This allows for analysis of whether each interactive file of the interactive data truly needs to be encrypted and forwarded. If encryption and forwarding are required, the corresponding encryption mode is used to control the isolated forwarding of the interactive data. This achieves secure management of the interaction between the power monitoring system host and peripherals, ensuring not only the reliability of the expansion dock allocation for peripheral connection but also the security of isolated data transmission. Attached Figure Description

[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0017] In the attached diagram: Figure 1 This is a flowchart illustrating the power monitoring system peripheral security management method provided in an embodiment of the present invention.

[0018] Figure 2 The diagram shown is a structural block diagram of a power monitoring system peripheral security management system provided in an embodiment of the present invention.

[0019] Figure 3 The diagram shown is a structural schematic of an electronic device according to an embodiment of the present invention.

[0020] The attached figures are labeled as follows: Electronic device 1; Power monitoring system peripheral security management system 11; Memory 12; Processor 13; Acquisition unit 111; Matching and analysis unit 112; Expansion dock allocation unit 113; Identity verification unit 114; Content parsing unit 115; Isolation and forwarding unit 116. Detailed Implementation

[0021] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.

[0022] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. The drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0023] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.

[0024] This invention provides a method for secure management of peripheral devices in a power monitoring system. By pre-analyzing and determining the peripheral's access requests to an expansion dock, the reliability of each access request is ensured. Subsequently, using the access requests to connect to the expansion dock, dock matching analysis is performed. Based on the expansion dock's occupancy status, a matching available expansion dock is retrieved for peripheral access control. Furthermore, when a peripheral is detected connecting to an available expansion dock, access identity verification is performed first. After successful verification, the interaction data between the host and the peripheral is parsed to identify sensitive fields as the parsing result. This allows analysis of whether each interaction file truly requires encrypted forwarding. If encrypted forwarding is required, the corresponding encryption mode is used to isolate and forward the interaction data. This achieves secure management of interactions between the power monitoring system host and peripherals, ensuring not only the reliability of expansion dock allocation for peripheral connections but also the security of isolated data transmission.

[0025] Figure 1 A flowchart of a peripheral security management method for a power monitoring system according to an exemplary embodiment of this application is shown. This method is applied to a peripheral security management system for a power monitoring system and includes steps S10-S60. The following will be combined with… Figure 1 The technical solution of this application will be described in detail below.

[0026] First, execute step S10 to obtain the peripheral device's access command for the expansion dock.

[0027] In the peripheral security management process of the power monitoring system of the present invention, it is necessary to first accurately determine the peripheral's access command for the expansion dock, and then perform expansion dock matching analysis and expansion dock allocation according to the access command to determine the available expansion docks that can be accessed.

[0028] In step S10, obtaining the peripheral device's access command to the expansion dock may further include: Obtain authorization documents for the peripheral device to the expansion dock, including the work order; Information is extracted from the authorization documents based on the instructions to obtain multiple certification contents, including factory area information, contact information, reasons for access, access time information, access type information, and approval access information. Perform a format composition integrity check on the proof content corresponding to the generation conditions of each instruction; When all the supporting documents are complete, an access assessment is performed on the access reason information to obtain the access acceptance level. If the access acceptance level is greater than a set threshold, the approval of the corresponding authorization document is determined, and the peripheral device's access command for the expansion dock is obtained.

[0029] During the process of determining the access requirements, authorization documents need to be entered first. The format information of these documents is then extracted based on the command generation conditions to obtain multiple corresponding proof contents. These authorization documents can be work tickets (electronic or paper), or other types of supporting documents. After obtaining the authorization documents, information is extracted using the command generation conditions to obtain multiple proof contents. These conditions can include factory area information, contact information, access reason conditions, access time conditions, access type conditions, and approval access conditions. Once the proof contents (factory area information, contact information, access reason information, access time information, access type information, and approval access information) are obtained, each proof content undergoes a format integrity check, such as checking for errors in factory area information or missing contact information. When all the evidence is found to be complete, an access assessment can be performed on the access reason information to quantify the acceptance of new peripherals based on the current access reason information. When the acceptance is greater than a set threshold, the authorization document can be approved. After approval, the corresponding peripheral's access request command to the expansion dock is directly generated. Based on the command information, the corresponding available expansion dock is allocated, making the expansion dock allocation process assessable. This addresses the access security risks caused by direct access without knowing whether the access reason is compliant, and improves the security of peripheral access creation to the expansion dock.

[0030] This includes conducting an access assessment based on the access reason information to obtain an access acceptance rate. If the access acceptance rate exceeds a set threshold, the approval of the corresponding authorization document is confirmed, and the peripheral device's access request to the expansion dock is obtained. This process may further include: Extract keywords from the admission reason information; Each reason keyword is compared semantically with each preset keyword in the keyword library corresponding to the factory area information to obtain the target preset keyword that is semantically closest to the reason keyword; The reason matching degree is obtained based on the target semantic similarity between the target preset keywords and the reason keywords; The access risk level is obtained based on the baseline risk value corresponding to the target preset keywords, the target semantic similarity, the direction of contribution of the target semantic similarity to the access risk, and the risk contribution coefficient. Based on each reason keyword, the gain strength of the expansion dock is obtained; based on the semantic strength of the auxiliary words corresponding to each reason keyword, the gain adjustment amount is obtained; based on the gain strength and the gain adjustment amount, the rationality of the reason is obtained. The factors of cause matching degree, access risk degree, and cause reasonableness are weighted to obtain the access acceptance degree. When the access acceptance degree is greater than a set threshold, the approval of the corresponding authorization document is confirmed, and the peripheral device's access command to the expansion dock is obtained. Preferably, the formula for calculating the access acceptance degree can be expressed as: ; in, Indicates acceptance level. Indicates the semantic similarity of the target. Indicates the number of causal keywords. Indicates the benchmark risk value. Indicates the risk contribution coefficient. Indicates the first gain intensity. Indicates the gain adjustment amount. This represents the first weighting factor corresponding to the cause-match degree. This represents the second weighting factor corresponding to the access risk level. This represents the third weighting factor corresponding to the reasonableness of the cause.

[0031] After extracting the access reason information, the access reason information can be first broken down into reason keywords to extract multiple reason keywords. Each reason keyword is then compared semantically with each preset keyword in the keyword library corresponding to the factory area information to obtain the semantic similarity between them. Based on the maximum semantic similarity, the target preset keyword that is semantically closest to the reason keyword is determined. When comparing semantic similarity, the cosine similarity between the reason keyword and each preset keyword can be used as the semantic similarity; other comparison methods are also possible. The maximum semantic similarity corresponding to the target preset keyword is taken as the target semantic similarity. Based on the target semantic similarity corresponding to all reason keywords average This serves as the cause-matching score. Then, the calculated target semantic similarity is used... The baseline risk value corresponding to the target preset keywords Combine semantic similarity with pre-set risk contribution coefficients based on empirical values To calculate the access risk level Subsequently, for each cause keyword, the correspondence between cause keywords and gain intensities can be looked up in the table to find the corresponding cause keyword's effect on the gain intensity of the docking station. Next, perform a particle search for each cause keyword, and find the corresponding gain adjustment amount by referring to the corresponding particle's mapping table. Subsequently, the reasonableness of the cause was calculated by superimposing the gain intensity and the gain adjustment amount. Finally, the first weighting factor corresponding to the cause-matching degree based on empirical presets is used. The second weighting factor corresponding to the access risk level And the third weighting factor corresponding to the reasonableness of the cause. The acceptance level of the corresponding authorization certificate is calculated, which is expressed by the formula: Furthermore, when the acceptance level is greater than the set threshold, it means that the expansion dock for the corresponding peripheral device can be set up. Therefore, the approval of the corresponding authorization certificate can be directly confirmed, thereby generating the peripheral device's access command for the expansion dock.

[0032] For example, the access reason information could be "To meet the physical isolation requirements of the 'Regulations on Security Protection of Power Monitoring Systems,' an application is made to access a dedicated encrypted authentication USB drive for one-way import of patch files from Security Zone III to Security Zone II." The extracted reason keywords could be "security protection regulations," "physical isolation," "encryption authentication," "one-way import," and "patch update." In the keyword library corresponding to the plant area information, target preset keywords such as "regulatory compliance," "network isolation," "authentication equipment," "one-way data transmission," and "system update" can be found. Then, a semantic comparison can be performed between the target preset keywords and the reason keywords to obtain the corresponding target semantic similarity, and the average is taken as the reason matching degree. Since the particle "used for" is used before "patch file," the corresponding gain adjustment amount can be obtained based on the semantic strength of this particle, and the reason's reasonableness can be determined by combining the gain strength. For cases without a particle, the reasonableness of the reason can be directly determined using the gain strength corresponding to the relevant reason keyword, such as "encryption authentication." Moreover, among the target preset keywords, "regulatory compliance", "network isolation", "authentication equipment", "one-way data transmission" and "system update" all correspond to a relatively low baseline risk value. Therefore, the access risk of the access reason information "to meet the physical isolation requirements of the 'Regulations on Security Protection of Power Monitoring Systems', apply for access to a dedicated encrypted authentication USB flash drive for one-way import of patch files from Security Zone III to Security Zone II" is also relatively low.

[0033] In addition, if the access reason information is "the relay protection device is periodically checked and a temporary access to the debugging laptop is required for data reading", for example, if the baseline risk value of the target preset keyword "temporary debugging" corresponding to the reason keyword "temporary access" is high, it will lead to a relatively high overall access risk.

[0034] Specifically, based on the baseline risk value corresponding to the target preset keywords, the target semantic similarity, the contribution direction of the target semantic similarity to the access risk, and the risk contribution coefficient, the access risk level is obtained, including: Based on the risk-gain direction of degree adverbs to target preset keywords, degree adverbs are added to target preset keywords to generate adjustment keywords. Degree adverbs include one of positive degree adverbs and negative degree adverbs. The semantic similarity between the causal keywords and the adjustment keywords is compared to obtain the adjustment semantic similarity. By comparing the target semantic similarity with the adjusted semantic similarity, the direction of the contribution of the target semantic similarity to the access risk is obtained. Based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the direction of contribution, and the risk contribution coefficient, the access risk level is obtained.

[0035] In calculating access risk, to determine the direction of risk gain, different degree adverbs can be used to influence the risk gain of the target preset keyword. For example, if the target preset keyword is "temporary debugging," combining it with the positive degree adverb "urgent" can further increase the risk level. Therefore, appropriate degree adverbs can be selected to combine with the target preset keyword to generate adjustment keywords. The semantic similarity of the cause keyword and the adjustment keyword is compared to obtain the corresponding adjustment semantic similarity. Similarly, the cosine similarity can also be calculated as the adjustment semantic similarity. By comparing the target semantic similarity and the adjustment semantic similarity, the contribution direction of the target semantic similarity to access risk can be determined. For example, if the adjustment semantic similarity after adding a degree adverb is less than the target semantic similarity, it indicates that the semantics of the target preset keyword are closer to the cause keyword, and the access risk of the cause keyword is less than that of the target preset keyword. Therefore, a risk contribution coefficient can be used. The value is negative. However, when the moderating semantic similarity after adding an adverb of degree is greater than the target semantic similarity, the risk contribution coefficient... It is a positive value.

[0036] Next, step S20 is executed, and docking analysis is performed according to the required access command to obtain multiple compatible docking stations.

[0037] After the power monitoring system peripheral security management system of the present invention obtains the access request instruction, it can first perform a preliminary screening by matching expansion docks, thereby obtaining multiple compatible expansion docks corresponding to the access request instruction, so as to further screen available expansion docks based on the occupancy status.

[0038] Next, step S30 is executed, and expansion docks are allocated according to the access time information corresponding to the access request and the occupancy status of each adapter expansion dock to obtain available expansion docks, so as to control the available expansion docks to enter the access state according to the access request.

[0039] When screening available docking stations, conflict detection can be performed based on the access time information corresponding to the access command and the occupancy status of each compatible docking station to find compatible docking stations with available access time information. After selecting the corresponding available docking station, the corresponding available docking station can be further controlled to enter the access state to wait for the corresponding peripheral device to connect at any time.

[0040] In step S30, based on the required access command, a docking station matching analysis is performed to obtain multiple compatible docking stations, which may further include: Based on the factory area information corresponding to the access command, the expansion dock is located and searched to obtain multiple matching expansion docks for matching areas. Based on the reason keywords in the access reason information corresponding to the access request, the corresponding usage purpose can be obtained; Find the set of baseline uses corresponding to each matching docking station, and calculate the similarity between each baseline use and the use of the docking station to obtain the maximum similarity between each use. A comprehensive fit index is obtained based on the maximum use similarity and the fit coefficient corresponding to the benchmark use of the maximum use similarity. Based on comprehensive compatibility metrics, a ranking sequence corresponding to the matching docking station is generated. Select the top-ranked, preset number of matching expansion docks from the ranking sequence as the compatible expansion docks.

[0041] When determining compatible expansion docks, the location information of all expansion docks can be searched based on the factory area information corresponding to the access request command to find multiple matching expansion docks. Then, based on the reason keywords in the access reason information corresponding to the access request command, the usage purpose corresponding to the reason is found. This allows for usage similarity calculation based on the baseline usage set and usage purpose of each matching expansion dock, resulting in the maximum usage similarity for each usage purpose. After determining the maximum usage similarity, the comprehensive adaptation index for each matching expansion dock can be further calculated by combining the adaptation coefficient of the baseline usage corresponding to the maximum usage similarity. Finally, based on the ranking sequence of matching expansion docks generated by the comprehensive adaptation index, a corresponding number of matching expansion docks are selected as compatible expansion docks for the corresponding peripheral device access. Through this method, the baseline usage of each matching expansion dock can be effectively determined based on the access reason information for the connection between the peripheral device and the power monitoring system to ensure that it matches the required usage of the corresponding peripheral device. This addresses the issue of expansion docks being unable to complete the interaction tasks between the peripheral device and the power monitoring system after being assigned and connected to the power monitoring system.

[0042] For example, when the access reason information is "Periodic calibration of relay protection device requires temporary access to the debugging laptop for data reading," and the key word is "periodic calibration," the usage purpose can be summarized using a large language model as "temporary access to the debugging terminal to read the settings of the protection relay protection device," which can be simplified to "temporary access to the debugging terminal." This usage purpose has a high similarity to the baseline usage "dedicated for on-site debugging" in the baseline usage set. Therefore, the usage similarity between the two can be output. By combining the usage similarity of all usage purposes with the adaptation coefficient of the corresponding baseline usage, accurate calculation of the comprehensive adaptation index can be achieved.

[0043] Specifically, the formula for calculating the comprehensive adaptation index can be expressed as: ; in, This indicates the comprehensive adaptation index. This represents the maximum usage similarity, which can be obtained by calculating the cosine similarity between the intended use and the baseline usage. This represents the adaptation coefficient corresponding to the benchmark application with the maximum application similarity. This adaptation coefficient can be preset manually based on empirical values.

[0044] As the docking station is used, its intended use may change. For example, the basic uses of a previously matched docking station might have included data transfer efficiency, etc. Before finding the set of basic uses for each matched docking station, calculating the similarity between each basic use and the intended use, and obtaining the maximum similarity for each intended use, the process also includes: Based on the historical access processing data corresponding to each matching expansion dock, the processing capacity of each item is evaluated based on the historical baseline usage list of each matching expansion dock to obtain the processing capacity index. Determine whether the processing capacity index is less than the index threshold of the corresponding historical benchmark use in the historical benchmark use list; If so, delete the corresponding historical reference usage from the historical reference usage list to obtain the reference usage set corresponding to the matching docking station; If not, the historical baseline usage will remain in the historical baseline usage list.

[0045] Before calculating the maximum usage similarity, the baseline usage set of the expansion docks needs to be updated based on their usage data. Specifically, this can be done by obtaining historical access processing data for each matching expansion dock and evaluating its processing capabilities for different historical baseline uses, resulting in multiple processing capability indicators. Then, by determining whether each processing capability indicator is less than the threshold value for the corresponding historical baseline use in the historical baseline usage list, if the indicator is less than the threshold, it means that the current matching expansion dock no longer has a historical baseline use and can be removed from the historical baseline usage list, thus obtaining the baseline usage set for the corresponding matching expansion dock. If the indicator is greater than the threshold, it means that the historical baseline use for the matching expansion dock still exists and can be retained. In this way, the baseline usage set can be dynamically updated to solve the problem of missing historical baseline uses for matching expansion docks affecting data interaction between peripherals and the power monitoring system.

[0046] In addition, based on the historical access processing data corresponding to each matched expansion dock, the processing capabilities of each item are evaluated based on the historical baseline usage list of each matched expansion dock to obtain processing capability indicators, which may further include: Select historical access processing data corresponding to the purpose of each historical baseline; The processing difference is obtained by comparing the historical access processing data with the benchmark processing data corresponding to the historical benchmark usage. The processing capacity index is obtained based on the processing difference and the capacity assessment coefficient corresponding to the historical benchmark application.

[0047] The formula for calculating the processing capacity index is: ; in, This indicates a processing capacity indicator. Indicates the amount of difference processed. This represents the ability assessment coefficient.

[0048] When calculating the difference, it can be obtained based on the curve similarity between the first curve formed by historical access processing data and the second curve formed by benchmark processing data, or it can be obtained based on the difference between the mean value of the corresponding parameter at different times in the historical access processing data and the benchmark parameter value corresponding to the benchmark processing data.

[0049] The processing difference can be obtained by selecting historical access processing data corresponding to each historical baseline application and comparing it with the baseline processing data corresponding to the historical baseline application. During the comparison, if the historical access processing data is continuous data that changes over time, such as the interface transmission speed from a peripheral device to the expansion dock, a curve similarity comparison can be performed based on the curve similarity between the first curve corresponding to the historical access processing data and the second curve formed by the baseline processing data. This curve similarity difference is used as the processing difference. The processing difference is then combined with a pre-set capability evaluation coefficient corresponding to the historical baseline application to calculate the processing capability index corresponding to the historical baseline application. This allows for the assessment of the availability of the historical baseline application and improves the reliability of selecting the appropriate expansion dock.

[0050] Next, step S40 is executed. When a peripheral device is detected connected to an available docking station, the peripheral device's access identity is verified. This verification can be performed using methods such as digital certificate authentication. For example, a unique digital certificate can be embedded in the peripheral device (e.g., a dedicated USB flash drive). The docking station verifies whether the certificate signature was issued by a trusted CA and checks whether the device serial number in the certificate is on a whitelist. If so, authentication is successful. Furthermore, various preset restrictions can be used to limit repeated unauthorized operations by directly disabling the device if authentication fails.

[0051] Next, step S50 is executed. After successful access identity verification, the interaction data between the host and the peripheral device is parsed to obtain the parsing result.

[0052] After successful access identity verification, the interaction data between the host and peripheral devices can be further parsed to determine whether there are any parsing results that require encryption. This allows the data forwarding method to be determined based on the parsing results, thereby ensuring data transmission security.

[0053] In step S50, after successful access identity verification, the interaction data between the host and the peripheral device is parsed to obtain the parsing results, including: After successful access identity verification, the sender of the interactive data is detected; When the sender is detected to be an external device, the interaction data is scanned based on different sensitive keywords in the sensitive word library to obtain multiple sensitive fields to be identified for each interaction file in the interaction data, which are used as the parsing results.

[0054] When the sender is an external device, special attention must be paid to data security when transmitting data to the power monitoring system. Therefore, by scanning the interactive data based on different sensitive keywords in a sensitive keyword library, multiple sensitive fields to be identified can be found for each interactive file. These multiple sensitive fields to be identified can then be used as the parsing results to generate corresponding encryption modes for data forwarding.

[0055] Next, step S60 is executed. Based on the parsing results, the interactive data is isolated and forwarded, and events are logged, in order to perform peripheral device security management.

[0056] Preferably, the parsing results include multiple sensitive fields to be identified for each interaction file in the interaction data.

[0057] In step S60, based on the parsing results, the system controls the isolation and forwarding of interactive data and event logging for peripheral device security management, including: For each sensitive field to be identified, extract related auxiliary words based on sensitive keywords; By combining related auxiliary words and sensitive keywords, the actual semantic vocabulary is obtained; Compare the semantic sensitivity of actual semantic words with sensitive keywords; When the first semantic sensitivity corresponding to the actual semantic words is less than the second semantic sensitivity corresponding to the sensitive keywords, the sensitivity authenticity is obtained based on the sensitivity difference between the second semantic sensitivity and the first semantic sensitivity and the first authenticity coefficient. The comprehensive sensitivity score is obtained based on the field length of the sensitive field to be identified, the second truth coefficient corresponding to the field length, and the sensitivity scores of all interactive files corresponding to the sensitive field to be identified. When the overall sensitivity level exceeds the sensitivity threshold, a corresponding encryption mode is generated based on the file type of the interactive files. This controls the isolated forwarding of interactive data and event logging for peripheral device security management. The formula for calculating the overall sensitivity level can be expressed as: ; Indicates the overall sensitivity and authenticity. Indicates second semantic sensitivity, Indicates primary semantic sensitivity. Represents the first true coefficient. Indicates the field length. This represents the second true coefficient. This represents the first weighting factor corresponding to the sensitivity difference. This represents the second weighting factor corresponding to the field length, and the first true coefficient. Second semantic sensitivity First weighting factor Second weighting factor All of these can be pre-calibrated based on empirical values.

[0058] After obtaining the parsing results, auxiliary words based on sensitive keywords can be extracted for each sensitive field to be identified. Then, the auxiliary words and sensitive keywords are combined to generate actual semantic vocabulary. The first semantic sensitivity of the actual semantic vocabulary is then compared with the second semantic sensitivity of the sensitive keywords. When the first semantic sensitivity of the actual semantic vocabulary is less than the second semantic sensitivity of the sensitive keywords, the second semantic sensitivity can be used as the basis for identification. With first semantic sensitivity The difference in sensitivity between Combined with the first true coefficient This is to achieve the sensitivity level of each sensitive field to be identified. Calculations are then performed. Subsequently, the field length of the sensitive field to be identified is considered. The second true coefficient corresponding to the field length The sensitivity of all interactive files corresponding to the sensitive fields to be identified is used to achieve a comprehensive sensitivity assessment. Calculation. Finally, when the overall sensitivity level exceeds the sensitivity threshold, the corresponding encryption mode in the encryption mode library can be retrieved based on the file type of the interactive file. This allows for the isolated forwarding of the interactive data, while simultaneously recording the corresponding forwarding time as an event, thus completing the security control between the peripheral device and the power monitoring system.

[0059] For example, in the sensitive field to be identified, "modify the protection setting of line A to xxx," the sensitive keyword is "protection setting." "Protection setting" is relatively common under normal circumstances and has a low encryption level. However, adding the related auxiliary word "modify" significantly increases the semantic sensitivity of this sensitive field, thus increasing its sensitivity accuracy. Similarly, in the sensitive field to be identified, "switch xxx changes from closed to open," if the semantic sensitivity of the sensitive keyword "closed" is high, while the semantic sensitivity of the open state "changes from closed to open" is low, then the corresponding sensitivity accuracy will be lower compared to the sensitive keyword, resulting in a lower sensitivity accuracy. Of course, other sensitive fields to be identified can also be considered.

[0060] Please see Figure 2 The present invention also provides a peripheral security management system 11 for a power monitoring system, comprising: an acquisition unit 111 for acquiring a peripheral's access request command to an expansion dock; a matching analysis unit 112 for performing expansion dock matching analysis based on the access request command to obtain multiple compatible expansion docks; an expansion dock allocation unit 113 for allocating expansion docks based on the access time information corresponding to the access request command and the occupancy status of each compatible expansion dock to obtain available expansion docks, so as to control the available expansion docks to enter the access state according to the access request command; an identity verification unit 114 for performing access identity verification on the peripheral when it is detected that the peripheral has accessed an available expansion dock; a content parsing unit 115 for parsing the interaction data between the host and the peripheral after successful access identity verification to obtain the parsing result; and an isolation forwarding unit 116 for controlling the isolation forwarding and event recording of the interaction data based on the parsing result to perform peripheral security management.

[0061] It should be noted that the power monitoring system peripheral security management system 11 provided in the above embodiments and the power monitoring system peripheral security management method provided in the above embodiments belong to the same concept. The specific operation methods of each module and unit have been described in detail in the method embodiments and will not be repeated here. In practical applications, the power monitoring system peripheral security management system 11 provided in the above embodiments can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. This is not a limitation here.

[0062] Please see Figure 3 The electronic device 1 may include a memory 12, a processor 13 and a bus, and may also include a computer program stored in the memory 12 and capable of running on the processor 13, such as a power monitoring system peripheral security management program.

[0063] The memory 12 includes at least one type of readable storage medium, such as flash memory, portable hard drive, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 12 can be an internal storage unit of the electronic device 1, such as a portable hard drive. In other embodiments, the memory 12 can be an external storage device of the electronic device 1, such as a plug-in portable hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the electronic device 1. Furthermore, the memory 12 can include both internal and external storage units of the electronic device 1. The memory 12 can be used not only to store application software and various types of data installed on the electronic device 1, such as code for security control of peripheral devices in a power monitoring system, but also to temporarily store data that has been output or will be output.

[0064] In some embodiments, the processor 13 may be composed of integrated circuits, such as a single packaged integrated circuit or multiple integrated circuits with the same or different functions, including combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 13 is the control unit of the electronic device 1, connecting various components of the electronic device 1 through various interfaces and lines. It executes programs or modules stored in the memory 12 (such as peripheral security management programs for power monitoring systems) and calls data stored in the memory 12 to perform various functions and process data of the electronic device 1.

[0065] The processor 13 executes the operating system of the electronic device 1 and various installed applications. The processor 13 executes the applications to implement the steps in the above-described power monitoring system peripheral security management method.

[0066] For example, the computer program may be divided into one or more modules, which are stored in the memory 12 and executed by the processor 13 to complete this application. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the electronic device 1. For example, the computer program may be divided into units within a power monitoring system peripheral security management system.

[0067] The integrated unit implemented as a software functional module can be stored in a computer-readable storage medium, which can be non-volatile or volatile. The software functional module, stored in the storage medium, includes several instructions to cause a computer device (which may be a personal computer, computer equipment, or network device, etc.) or processor to execute some functions of the power monitoring system peripheral security management method described in the various embodiments of this application.

[0068] In summary, the power monitoring system peripheral security management method and system disclosed in this invention, by pre-analyzing and determining the peripheral's access command to the expansion dock, ensures the reliability of each access command generation. Subsequently, by utilizing the access command to connect to the expansion dock, expansion dock matching analysis can be performed, and based on the expansion dock's occupancy status, a matching available expansion dock can be retrieved for peripheral access control. Furthermore, when a peripheral is detected to be connected to an available expansion dock, access identity verification is first performed. After successful verification, the interaction data between the host and the peripheral is parsed to determine the sensitive fields to be identified as the parsing result. This allows analysis of whether each interaction file in the interaction data truly requires encrypted forwarding. If encrypted forwarding is required, the corresponding encryption mode is used to control the isolated forwarding of the interaction data, thereby achieving secure management of the interaction between the power monitoring system host and peripherals. This not only ensures the reliability of the expansion dock allocation for peripheral connection but also guarantees the security of isolated data transmission. Therefore, this invention effectively overcomes the various shortcomings of the prior art and has high industrial application value.

[0069] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.

Claims

1. A method for security control of peripheral devices in a power monitoring system, characterized in that, include: Obtain the peripheral device's access command to the expansion dock; Based on the access command, a docking station matching analysis is performed to obtain multiple compatible docking stations; Based on the access time information corresponding to the access request and the occupancy status of each of the adapted expansion docks, expansion docks are allocated to obtain available expansion docks, so as to control the available expansion docks to enter the access state according to the access request. When a peripheral device is detected to be connected to the available expansion dock, the peripheral device's access identity is verified. After successful access identity verification, the interaction data between the host and the peripheral device is parsed to obtain the parsing result; Based on the parsing results, the system will isolate and forward the interactive data and record events to manage peripheral device security.

2. The power monitoring system peripheral security control method according to claim 1, characterized in that, Obtain the peripheral device's access command to the expansion dock, including: Obtain the authorization certificate for the peripheral device to the expansion dock, the authorization certificate including the work order; Based on the instructions generated, information is extracted from the authorization certificate to obtain multiple certificate contents; the certificate contents include factory area information, contact information, access reason information, access time information, access type information, and approval access information. Perform a format composition integrity check on the proof content corresponding to each of the aforementioned instruction generation conditions; When all the aforementioned proof contents are complete, an access assessment is performed on the access reason information to obtain the access acceptance level. When the access acceptance level is greater than a set threshold, the approval of the corresponding authorization proof document is determined, and the peripheral device's access command for the expansion dock is obtained.

3. The power monitoring system peripheral security control method according to claim 2, characterized in that, An access assessment is performed on the access reason information to obtain an access acceptance rate. When the access acceptance rate is greater than a set threshold, the approval of the corresponding authorization certificate is determined, and the peripheral device's access request command to the expansion dock is obtained, including: Extract reason keywords from the admission reason information; Each of the stated cause keywords is sequentially compared with each preset keyword in the keyword library corresponding to the factory area information to obtain the target preset keyword that is semantically closest to the stated cause keyword; The cause matching degree is obtained based on the target semantic similarity between the target preset keywords and the cause keywords; The access risk level is obtained based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the direction of the target semantic similarity's contribution to the access risk, and the risk contribution coefficient. Based on each of the stated cause keywords, the gain intensity of the expansion dock is obtained by querying; based on the semantic intensity of the auxiliary word corresponding to each of the stated cause keywords, the gain adjustment amount is obtained by querying; and based on the gain intensity and the gain adjustment amount, the rationality of the cause is obtained. The matching degree of the cause, the access risk degree, and the reasonableness of the cause are weighted to obtain the access acceptance degree. When the access acceptance degree is greater than a set threshold, the approval of the corresponding authorization certificate is determined, and the peripheral device's access instruction to the expansion dock is obtained.

4. The method of claim 3, wherein, The formula for calculating the admission acceptance rate is as follows: ; in, Indicates acceptance level. Indicates the semantic similarity of the target. Indicates the number of causal keywords. Indicates the benchmark risk value. Indicates the risk contribution coefficient. Indicates the first gain intensity. Indicates the gain adjustment amount. This represents the first weighting factor corresponding to the cause-match degree. This represents the second weighting factor corresponding to the access risk level. This represents the third weighting factor corresponding to the reasonableness of the cause.

5. The method of claim 3, wherein the method further comprises: Based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the contribution direction of the target semantic similarity to the access risk, and the risk contribution coefficient, the access risk level is obtained, including: Based on the risk-gain direction of the degree adverb to the target preset keyword, degree adverbs are added to the target preset keyword to generate adjustment keywords. The degree adverb includes one of positive degree adverbs and negative degree adverbs. The semantic similarity between the causal keywords and the adjustment keywords is compared to obtain the adjustment semantic similarity. The target semantic similarity is compared with the adjusted semantic similarity to obtain the contribution direction of the target semantic similarity to the access risk. Based on the baseline risk value corresponding to the target preset keyword, the target semantic similarity, the contribution direction, and the risk contribution coefficient, the access risk level is obtained.

6. The method of claim 1, wherein, Based on the access command, a docking station matching analysis is performed to obtain multiple compatible docking stations, including: Based on the factory area information corresponding to the access command, the expansion dock is located and searched to obtain multiple matching expansion docks corresponding to matching areas. Based on the reason keywords of the access reason information corresponding to the access request, the corresponding usage purpose can be obtained; Find the baseline usage set corresponding to each of the matching expansion docks, and calculate the usage similarity between each baseline usage set and the usage, to obtain the maximum usage similarity corresponding to each usage. A comprehensive fit index is obtained based on the maximum use similarity and the fit coefficient of the benchmark use corresponding to the maximum use similarity. Based on the comprehensive adaptation index, a ranking sequence corresponding to the matching dock is generated; Select a preset number of matching expansion docks that rank high in the ranking sequence as the adaptive expansion docks.

7. The method of claim 6, wherein, Before finding the baseline usage set corresponding to each of the matching docks, and calculating the usage similarity between each baseline usage in the baseline usage set and the usage, and obtaining the maximum usage similarity corresponding to each usage, the method further includes: Based on the historical access processing data corresponding to each of the matching expansion docks, the processing capabilities of each item are evaluated based on the historical baseline usage list of each of the matching expansion docks to obtain processing capability indicators. Determine whether the processing capacity index is less than the index threshold of the corresponding historical benchmark use in the historical benchmark use list; If so, delete the corresponding historical reference use from the historical reference use list to obtain the reference use set corresponding to the matching docking station; If not, the historical baseline usage will remain in the historical baseline usage list.

8. The method of claim 1, wherein the method further comprises: After successful access identity verification, the interaction data between the host and the peripheral device is parsed to obtain the parsing results, including: After successful access identity verification, the sender corresponding to the interactive data is detected; When the sender is detected to be the peripheral device, the interaction data is scanned based on different sensitive keywords in the sensitive word library to obtain multiple sensitive fields to be identified for each interaction file in the interaction data, which are used as the parsing results.

9. The method of claim 1, wherein the method further comprises: The parsing results include multiple sensitive fields to be identified for each interactive file in the interactive data; Based on the parsing results, the interaction data is isolated, forwarded, and logged for event management to control peripheral security, including: For each of the sensitive fields to be identified, auxiliary words related to sensitive keywords are extracted; The associated auxiliary words and the sensitive keywords are combined to obtain the actual semantic vocabulary; Compare the semantic sensitivity of the actual semantic words with the sensitive keywords; When the first semantic sensitivity corresponding to the actual semantic word is less than the second semantic sensitivity corresponding to the sensitive keyword, the sensitivity authenticity is obtained based on the sensitivity difference between the second semantic sensitivity and the first semantic sensitivity and the first authenticity coefficient. The comprehensive sensitivity score is obtained based on the field length of the sensitive field to be identified, the second truth coefficient corresponding to the field length, and the sensitivity scores of all interactive files corresponding to the sensitive field to be identified. When the overall sensitivity level is greater than the sensitivity threshold, a corresponding encryption mode is generated based on the file type of the interactive file, and the interactive data is isolated, forwarded, and recorded for peripheral security management.

10. A power monitoring system peripheral security management system, characterized in that, include: The acquisition unit is used to acquire the access command of the peripheral device to the expansion dock; The matching analysis unit is used to perform dock matching analysis according to the access command requirements to obtain multiple compatible docks. The expansion dock allocation unit is used to allocate expansion docks according to the access time information corresponding to the access request and the occupancy status of each of the adapted expansion docks, so as to obtain available expansion docks and control the available expansion docks to enter the access state according to the access request. An identity verification unit is used to verify the access identity of a peripheral device when it is detected that the peripheral device is connected to the available expansion dock. The content parsing unit is used to parse the interaction data between the host and the peripheral device after successful access identity verification, and obtain the parsing result; as well as The isolation forwarding unit is used to control the isolation forwarding and event recording of the interactive data based on the parsing results, so as to perform peripheral device security management.