Hydropower plant equipment operation authorization control method and system based on dynamic task token
Patent Information
- Application Number
- CN202611003328.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-09-22
AI Technical Summary
现有钥匙与锁的两方验证模式使得权限一旦从中心系统发出,其使用过程便不可控,中心系统无法知晓权限是否正在被使用、使用条件是否仍然满足,更无法在紧急情况下远程干预或撤回已发出的权限
1、本发明提供的基于动态任务令牌的水电站设备操作授权控制方法,通过中心决策平台响应合法操作任务后,首先启动多源数据融合模块集成实时水文数据、设备数据、电气数据及环境数据构建电站全景运行数字孪生模型,并由动态风险评估引擎基于该数字孪生模型对操作任务进行实时安全风险评估,仅在风险评估通过时才由动态令牌生成模块创建一个与操作任务唯一对应的动态数字令牌,并将该令牌安全下发至操作人员持有的授权终端。该令牌内编码有最小化操作权限、安全约束条件及有效期。在现场操作时,设备控制器执行包含本地令牌真伪验证、安全约束条件与设备实时状态比对、以及向中心决策平台查询任务实时状态的三方协同验证,仅在三项验证均通过时才解锁操作。本发明将操作权限从传统的基于人员或角色的静态属性转变为与具体任务实例强绑定的动态临时凭证,实现了授权决策与基于多源数据融合的实时安全风险评估的深度结合,避免了有权限的人员在不恰当的时间或条件下操作的系统性风险,解决了现有技术中授权静态化、与实时运行状态脱节的技术问题,达到了从逻辑防误升级为系统安全防误的效果。
Smart Images

Figure CN122802163A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of safety control technology, and more specifically, to a method and system for authorizing the operation of hydropower station equipment based on dynamic task tokens. Background Technology
[0002] Hydropower station equipment operation is characterized by high risk, strong coupling, and multiple constraints. Its operational safety is directly related to the stable operation of the power system and the safety of personnel and equipment. Currently, hydropower stations widely adopt the traditional authorization management model of operation tickets plus mechanical keys or electrical interlocks. Before operating the equipment, operators must fill out a paper or electronic operation ticket, obtain approval, and then receive the corresponding mechanical key or smart key before going to the equipment site to perform the operation. Another more advanced solution is the microcomputer-based five-prevention system plus smart key model. This system performs a logical pre-run based on a static rule base before operation. After the pre-run is successful, the operation procedure is downloaded to the smart key. The operator carries the smart key to the site and performs the operation by interfacing with the locks on the equipment. The above-mentioned existing technical solutions standardize the operation process to a certain extent, but their core authorization logic is still to statically bind permissions to the operator's identity or job role. That is, personnel holding specific keys or authorization cards are considered to have the right to operate a certain type of equipment.
[0003] However, the aforementioned existing technical solutions have the following fundamental flaws. First, authorization is static and role-based, rather than task-based. The smart key or access card held by the operator represents their identity or fixed job authority, not the specific operational task at hand. This leads to the systemic risk that authorized personnel can perform operations at inappropriate times or under inappropriate conditions. For example, a person holding general access to switch station operations could theoretically operate at any time and at any interval, without being able to correlate it with the dynamic condition of whether there is a relevant operational task at hand. Second, authorization decisions are decoupled from real-time risks. Existing microcomputer-based five-prevention systems mainly perform logical pre-operations based on a static rule base before operation. Once the pre-operation results are downloaded into the key, they become detached from the real-time operating status of the power station. During authorization execution, the system cannot perceive and respond to changes in the on-site environment and equipment status at the moment of operation, creating a blind spot where the pre-operation is safe but the actual execution is unsafe. Furthermore, the authorization execution process lacks feedback and control. The existing two-party verification model of keys and locks makes the use of permissions uncontrollable once they are issued from the central system. The central system cannot know whether the permissions are being used or whether the conditions for use are still met, and it is even more impossible to remotely intervene or revoke the issued permissions in an emergency.
[0004] Therefore, researching and designing a dynamic task token-based hydropower station equipment operation authorization control method and system that can overcome the above-mentioned defects is an urgent problem to be solved. Summary of the Invention
[0005] To address the shortcomings of existing technologies, the present invention aims to provide a method and system for authorizing and controlling the operation of hydropower station equipment based on dynamic task tokens. This method transforms operation permissions from static attributes based on personnel or roles to dynamic temporary credentials strongly bound to specific task instances. It achieves a deep integration of authorization decisions with real-time security risk assessment based on multi-source data fusion, avoiding systemic risks caused by authorized personnel operating at inappropriate times or under inappropriate conditions. This solves the technical problems of static authorization and disconnection from real-time operating status in existing technologies, achieving an upgrade from logical error prevention to system security error prevention.
[0006] The above-mentioned technical objective of the present invention is achieved through the following technical solution: Firstly, a method for authorizing and controlling the operation of hydropower station equipment based on dynamic task tokens is provided, including the following steps: In response to a legitimate operational task, the central decision-making platform activates the multi-source data fusion module to integrate real-time hydrological data, equipment data, electrical data, and environmental data, constructs a panoramic digital twin model of the power station's operation, and the dynamic risk assessment engine performs a real-time safety risk assessment of the operational task based on the digital twin model. If the risk assessment is successful, the dynamic token generation module creates a dynamic digital token that uniquely corresponds to the operation task and securely distributes the dynamic digital token to the authorized terminal held by the operator performing the operation task; the dynamic digital token encodes the minimum operation permissions, security constraints, and validity period. After the operator brings the authorized terminal to the equipment site, the authorized terminal establishes communication with the equipment controller on site and presents the dynamic digital token to the equipment controller; The device controller performs a three-party collaborative verification: First verification, locally verifying the authenticity and format validity of the dynamic digital token; Second verification, comparing the security constraints encoded in the dynamic digital token with the real-time operating status of the device; Third verification, sending a query request to the central decision-making platform to confirm whether the real-time status of the task corresponding to the dynamic digital token is active and has not been terminated. The device controller is only unlocked and allowed to perform the corresponding operation if the first verification, the second verification, and the third verification are all passed.
[0007] Furthermore, after the device controller is unlocked and the corresponding operation is permitted, the following is also included: The device controller continuously monitors the real-time operating status of the device. When the real-time operating status of the device is detected to have changed beyond the preset change range, the device controller automatically re-executes the three-party collaborative verification. If the re-verification fails, the device controller immediately suspends the current operation and returns to a safe state.
[0008] Furthermore, during the task cycle of the operation, the central decision-making platform continuously monitors the real-time risk assessment results; When the risk assessment value output by the dynamic risk assessment engine exceeds the preset risk upper limit threshold, the central decision-making platform will proactively intervene in at least one of the following ways: The collaborative verification service module returns an authorization rejection signal to the corresponding dynamic digital token during subsequent status queries of all device controllers. Alternatively, an emergency invalidation command can be sent directly to the authorized terminal to invalidate the dynamic digital token locally on the terminal.
[0009] Furthermore, the operation task is one or more operation steps in the electronic operation ticket; The dynamic digital token is bound to the specific operation steps in the electronic operation ticket, and the activation and deactivation of the dynamic digital token are synchronized with the task status of the electronic operation ticket.
[0010] Furthermore, when the electronic operation ticket contains multiple operation steps that need to be executed in a preset order, the dynamic token generation module generates a corresponding sub-token for each operation step. The device controller activates the sub-token for the next step only after the sub-token verification of the current step is successful and the operation is completed.
[0011] Furthermore, during the execution of the third verification by the device controller, if a communication timeout occurs between the device controller and the central decision-making platform, the device controller shall perform one of the following operations according to a preset strategy: Deny the operation and log it. Alternatively, it allows the execution of preset limited security degradation operations and logging; The preset strategy is pre-configured according to the security level of the operation type.
[0012] Furthermore, the data structure of the dynamic digital token includes: a token identifier, an associated task identifier, an authorized operation field, a security constraint field, a valid time period field, and a digital signature field; The authorized operation field records the device identifier and action type of the authorized operation; The security constraint field records one or more device state conditions that must be met before the operation is performed.
[0013] Secondly, a hydropower station equipment operation authorization control system based on dynamic task tokens is provided. This system is used to implement the hydropower station equipment operation authorization control method based on dynamic task tokens as described in any one of the first aspects, including: The central decision-making platform is deployed in the power plant's central control room to respond to legitimate operational tasks and perform real-time safety risk assessments. The central decision-making platform includes a multi-source data fusion module, a dynamic risk assessment engine, a dynamic token generation module, and a collaborative verification service module. At least one dynamic authorization terminal, held by an operator, is used to receive and display dynamic digital tokens issued by the central decision-making platform and to communicate with field device controllers; Multiple device controllers are respectively set at the site of each controlled device to perform three-party collaborative verification. Each device controller includes a local verification unit, a security constraint check unit, a collaborative verification agent unit, and a control execution unit. The central decision-making platform communicates with the dynamic authorization terminal and the equipment controller through the power plant industrial network.
[0014] Furthermore, the multi-source data fusion module is used to integrate real-time hydrological data, equipment data, electrical data, and environmental data to construct a digital twin model of the power station's panoramic operation. The dynamic risk assessment engine performs real-time security risk assessments on operational tasks based on the digital twin model. The dynamic token generation module is used to generate a dynamic digital token that uniquely corresponds to the operation task. The dynamic digital token encodes the minimum operation permissions, security constraints, and validity period. The collaborative verification service module is used to respond to the status query request of the device controller and return an authorization confirmation signal or an authorization rejection signal based on the real-time risk assessment results.
[0015] Furthermore, the local verification unit is used to verify the authenticity and format validity of the dynamic digital token; The security constraint checking unit is used to compare the security constraints encoded in the dynamic digital token with the real-time operating status of the device. The collaborative verification agent unit is used to send query requests to the central decision-making platform and receive responses. The control execution unit is used to unlock and allow the operation to be performed after the verification by the local verification unit, the security constraint check unit, and the collaborative verification agent unit have all passed.
[0016] Compared with the prior art, the present invention has the following beneficial effects: 1. The hydropower station equipment operation authorization control method based on dynamic task tokens provided by this invention, after responding to a legitimate operation task through the central decision-making platform, first activates the multi-source data fusion module to integrate real-time hydrological data, equipment data, electrical data, and environmental data to construct a panoramic digital twin model of the power station operation. Then, the dynamic risk assessment engine performs a real-time safety risk assessment of the operation task based on this digital twin model. Only when the risk assessment passes is the dynamic token generation module create a dynamic digital token uniquely corresponding to the operation task and securely issue this token to the authorized terminal held by the operator. This token encodes minimal operation permissions, security constraints, and an expiration date. During on-site operation, the equipment controller performs a three-way collaborative verification process, including local token authenticity verification, comparison of security constraints with the real-time equipment status, and querying the central decision-making platform for the real-time task status. Operation is only unlocked when all three verifications pass. This invention transforms operation permissions from traditional static attributes based on personnel or roles into dynamic temporary credentials strongly bound to specific task instances. It achieves a deep integration of authorization decisions and real-time security risk assessment based on multi-source data fusion, avoiding systemic risks of authorized personnel operating at inappropriate times or under inappropriate conditions. It solves the technical problems of static authorization and disconnection from real-time operation status in existing technologies, achieving the effect of upgrading from logical error prevention to system security error prevention.
[0017] 2. After the device controller is unlocked and allowed to execute operations, the device controller continuously monitors the real-time operating status of the device. When a change in the real-time operating status exceeding a preset change range is detected, the device controller automatically re-executes the three-party collaborative verification. If the re-verification fails, the operation is immediately stopped and the device returns to a safe state. Simultaneously, throughout the entire task cycle, the central decision-making platform continuously monitors the real-time risk assessment results. When the risk assessment value output by the dynamic risk assessment engine exceeds a preset risk upper limit threshold, the central decision-making platform returns an authorization rejection signal during subsequent status queries of all device controllers through the collaborative verification service module, or directly sends an emergency invalidation command to the authorized terminal, invalidating the token locally on the terminal. This invention constructs a dual dynamic security protection mechanism. On the one hand, re-verification is triggered by status changes at the device site; on the other hand, remote circuit breaking is triggered by risk exceeding the limit at the central decision-making platform. This ensures that authorization is no longer a static, one-time action, but rather maintains real-time responsiveness to risks and status changes throughout the entire operation execution process. This solves the technical problems of lack of feedback and control in the authorization execution process in existing technologies, and the inability of the central system to remotely intervene or revoke issued permissions in emergency situations. It achieves full controllability of the authorization lifecycle and inherent process security.
[0018] 3. This invention sets the operation task as one or more operation steps in an electronic operation ticket. A dynamic digital token is bound to the specific operation step in the electronic operation ticket, and the token's activation and deactivation are synchronized with the task status of the electronic operation ticket. When the electronic operation ticket contains multiple operation steps that need to be executed in a preset order, the dynamic token generation module generates a corresponding sub-token for each operation step. The device controller only activates the sub-token for the next step after the sub-token for the current step has been verified and the operation is completed. This invention decomposes complex multi-step operation tasks into a series of ordered atomic operations. Each atomic operation has an independent dynamic digital token as an authorization credential. The sub-tokens are linked by a sequential chain to form a strict timing control logic, preventing operators from skipping preceding steps and directly executing subsequent steps, and also preventing the reversal of the operation order. This solves the technical problems in existing technologies where multiple devices and multiple specialties collaborate, lacking timing control and status synchronization mechanisms, and easily experiencing skipped operations or reversed order leading to safety accidents. It achieves the effects of reducing communication costs, preventing sequential errors, and improving the safety and efficiency of complex collaborative operations.
[0019] 4. In the process of the device controller performing the third verification, if the communication between the device controller and the central decision-making platform times out, the device controller will either execute a rejection operation and log it according to a preset strategy, or allow the execution of a preset limited security degradation operation and log it. The preset strategy is pre-configured according to the security level of the operation type. This invention addresses the unavoidable communication interruption scenarios in industrial control networks by introducing a differentiated processing strategy based on the operation's security level. For operations with the highest security level, a strict rejection operation is executed during communication interruption to ensure security priority; for operations with lower security levels, limited degradation operations are allowed to maintain a certain level of availability. Simultaneously, all operations are logged in detail for post-event auditing. This solves the technical problem of existing technologies either indiscriminately rejecting all operations in abnormal situations such as communication interruptions, leading to system stagnation, or indiscriminately allowing operations, leading to security risks. It achieves a dynamic balance between security and availability, improving system robustness. Attached Figure Description
[0020] The accompanying drawings, which are included to provide a further understanding of embodiments of the invention and form part of this application, do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart from Embodiment 1 of the present invention; Figure 2 This is a system block diagram in Embodiment 2 of the present invention. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention.
[0022] Example 1: A hydropower station equipment operation authorization control method based on dynamic task tokens, such as... Figure 1 As shown, it includes the following steps: S1: In response to a legitimate operational task, the central decision-making platform activates the multi-source data fusion module to integrate real-time hydrological data, equipment data, electrical data, and environmental data, constructs a panoramic digital twin model of the power station's operation, and the dynamic risk assessment engine conducts a real-time safety risk assessment of the operational task based on the digital twin model. S2: If the risk assessment is successful, the dynamic token generation module creates a dynamic digital token that uniquely corresponds to the operation task and securely distributes the dynamic digital token to the authorized terminal held by the operator performing the operation task; the dynamic digital token contains the minimum operation permissions, security constraints and validity period. S3: After the operator brings the authorized terminal to the equipment site, the authorized terminal establishes communication with the equipment controller on site and presents a dynamic digital token to the equipment controller; S4: The device controller performs three-party collaborative verification: First verification, locally verifying the authenticity and format validity of the dynamic digital token; Second verification, comparing the security constraints encoded in the dynamic digital token with the real-time operating status of the device; Third verification, sending a query request to the central decision-making platform to confirm whether the real-time status of the task corresponding to the dynamic digital token is active and has not been terminated. S5: The device controller will only unlock and allow the corresponding operation to be performed if the first, second and third verifications are all passed.
[0023] In step S1, when a hydropower station needs to perform a certain equipment operation, the person in charge of the work creates or invokes a valid operation task through the human-machine interface of the central decision-making platform. This operation task is specifically represented by an electronic operation ticket, which clearly records information such as the equipment to be operated, the operation type, the expected operation sequence, and safety precautions.
[0024] Upon receiving the task, the central decision-making platform immediately activated the multi-source data fusion module. This module collects and integrates four types of data in real time through the power plant's industrial network: First, real-time hydrological data, including upstream reservoir water level, downstream tailrace water level, inflow and outflow; second, equipment data, including unit speed, bearing temperature, vibration amplitude, circuit breaker open / closed status, disconnector position, and valve opening; third, electrical data, including generator active power, reactive power, bus voltage, line current, and frequency; and fourth, environmental data, including wind speed, rainfall intensity, and lightning activity. These four types of data are then aggregated into the central decision-making platform in a unified time-series database format.
[0025] Based on the aforementioned multi-source real-time data, the central decision-making platform constructs a digital twin model of the power plant's panoramic operation. This model is an object-oriented, high-fidelity virtual mirror system that contains mathematical and physical models of all key equipment in the power plant, as well as their topological connections. The update cycle of the digital twin model is set at the millisecond level to ensure a high degree of synchronization between the model's state and the actual physical equipment's state.
[0026] Subsequently, the dynamic risk assessment engine performs real-time security risk assessments of the operational tasks based on a digital twin model. In some optional examples, the engine employs a comprehensive assessment method based on weighted risk indicators, the core calculation formula of which is as follows: ; in, This represents the overall risk assessment value of the current operational task. It is a dimensionless real number ranging from 0 to 1, with a higher value indicating a higher risk. 'n' represents the total number of risk factors involved in the risk assessment, specifically including equipment health factors, operational disturbance factors, environmental risk factors, and scheduling urgency factors. This represents the weight coefficient of the i-th risk factor. The sum of all weight coefficients is 1. The value of the weight coefficient is pre-calibrated based on the power plant's historical accident statistics and expert experience. This represents the original observed value of the i-th risk factor, such as the unit vibration amplitude, reservoir water level deviation, or measured wind speed. Let represent the normalized risk function of the i-th risk factor, which maps the original observations of different dimensions and magnitudes to a risk score range of 0 to 1.
[0027] The dynamic risk assessment engine will calculate the comprehensive risk assessment value. With preset risk upper limit threshold Compare. Preset risk upper limit threshold. This is a constant preset by the power plant's safety management department according to operating procedures, typically with a value of 0.7. If If the risk of the current operation is deemed acceptable, the risk assessment is passed, and the subsequent dynamic token generation and issuance process continues. If the risk of the current task is deemed too high, the risk assessment fails, the generation of a dynamic digital token is refused, and a risk warning is issued to the person in charge of the task.
[0028] In some preferred examples, the central decision-making platform continuously monitors real-time risk assessment results throughout the task cycle. This means that even after the dynamic digital token has been issued to the authorized terminal, the multi-source data fusion module of the central decision-making platform continues to collect and update various real-time data at a fixed sampling period, and the dynamic risk assessment engine repeatedly calculates the aforementioned comprehensive risk assessment value based on the latest digital twin model. Once the dynamic risk assessment engine outputs the risk assessment value... Exceeding the preset risk upper limit threshold This indicates that the current operating environment of the power plant has deteriorated to an unsafe state, and the central decision-making platform immediately activates the proactive intervention mechanism.
[0029] The proactive intervention mechanism is implemented in at least one of the following ways: First, the central decision-making platform, through its internal collaborative verification service module, uniformly returns an authorization rejection signal for the dynamic digital token associated with the high-risk task in all subsequent status query requests from all device controllers. Since the device controller must confirm the token status with the central decision-making platform before executing an operation, this mechanism can effectively prevent operations that have not yet begun. Second, the central decision-making platform directly sends an emergency invalidation command to the authorized terminal holding the dynamic digital token. Upon receiving the command, the authorized terminal immediately marks the dynamic digital token as invalid locally. Even if the terminal subsequently attempts to communicate with the device controller, it will be unable to pass the local verification process. These two methods can be used individually or in combination to achieve rapid circuit breaking for high-risk operations.
[0030] In step S2, when the dynamic risk assessment engine determines that the comprehensive risk evaluation value is lower than the preset risk upper limit threshold, i.e., the risk assessment is passed, the dynamic token generation module inside the central decision-making platform immediately starts to create a dynamic digital token uniquely corresponding to the current operation task. This dynamic digital token is an encrypted digital credential, and its core design concept is to transform operation permissions from static attributes of operators to temporary attributes of specific tasks, achieving the goal of one task, one authorization, and expiration.
[0031] The dynamic digital token encodes three core types of information: The first type is the minimal operation permission, which grants only the most concise set of operation instructions necessary to complete the current operation task. For example, for the operation of closing valve V201, the token only encodes the closing instruction and does not include the opening or adjustment instructions. The second type is the safety constraints, which are a set of physical state conditions that the equipment must meet before the operation is performed. For example, the unit speed is less than 0.5 revolutions per minute, the circuit breaker is in the open position, or the pressure difference across the valve is within the allowable range. The third type is the validity period, which is the time window from the time the token is generated to the time it expires. After the time window expires, the token is automatically invalidated and cannot pass any verification.
[0032] The dynamic digital token's data structure consists of six fields. The first field is the token identifier, a globally unique string generated by the central decision-making platform to uniquely identify the token within the system. The second field is the associated task identifier, which records the task number of the electronic operation ticket corresponding to the token, establishing a binding relationship between the token and the task. The third field is the authorized operation field, recording the device identifier and action type of the authorized operation. The device identifier uses a unique device number from the power plant asset coding system, and the action type uses standardized operation verbs such as close, open, start, or shut. The fourth field is the security constraint field, recording one or more device state conditions that must be met before executing the operation. Each condition consists of a device identifier, a state parameter name, a comparison operator, and a target value. The fifth field is the validity period field, recording the token's effective and expiration timestamps, accurate to the millisecond level. The sixth field is the digital signature field, generated by the central decision-making platform using a private key to sign the hash values of the aforementioned five fields, used to prevent the token from being tampered with or forged.
[0033] After the dynamic digital token is generated, the central decision-making platform distributes it to the authorized terminal held by the operator performing the task via a secure encrypted channel. The secure encrypted channel is protected using a transport layer security protocol to ensure the token is not eavesdropped on or tampered with during transmission. Upon receiving the dynamic digital token, the authorized terminal stores it in its encrypted secure storage area and displays the token's basic information to the operator in a visual manner, including the authorized operation content, validity period, and current status.
[0034] The dynamic digital token is bound to the specific operational steps in the electronic operation ticket. An electronic operation ticket may contain one or more operational steps. When the electronic operation ticket contains only a single operational step, the dynamic token generation module generates a dynamic digital token corresponding one-to-one with that step. When the electronic operation ticket contains multiple operational steps, the activation and deactivation of the dynamic digital token are synchronized with the task status of the electronic operation ticket. Specifically, the token's lifecycle begins the moment the electronic operation ticket is approved for execution and ends the moment all steps of the electronic operation ticket are executed or it is manually terminated. During task execution, the token is active and can be used for on-site verification; after the task is completed, the token automatically enters an deactivated state and cannot be used again.
[0035] When an electronic operation ticket contains multiple operation steps that must be executed in a preset order, the dynamic token generation module generates a corresponding sub-token for each operation step. Each sub-token independently encodes the minimum operation permissions, security constraints, and validity period for the corresponding step. Sub-tokens are linked through a sequential chain, with the completion status of the previous sub-token serving as the activation condition for the next sub-token. The device controller activates the sub-token for the next step only after the sub-token for the current step has been verified and the operation has been completed. This sequential control mechanism ensures that the execution order of complex multi-step operations is inviolable, fundamentally preventing safety accidents caused by skipping steps or reversing the order. For example, for an operation sequence that requires disconnecting the isolating switch before closing the grounding switch, a sub-token for disconnecting the isolating switch is generated first. After this step is completed and feedback is received, the sub-token for closing the grounding switch is activated, thus ensuring strict compliance with the operation sequence.
[0036] In step S3, after the operator arrives at the target equipment location with the authorized terminal, on-site communication establishment and token presentation are performed. The authorized terminal is a portable handheld device specifically designed for the harsh industrial environment of hydropower stations, integrating a wireless communication module, encrypted secure storage area, touch screen, and biometric module. Upon arrival at the equipment site, the operator first authenticates their identity through the authorized terminal's biometric module, such as fingerprint or facial recognition, to confirm that the current holder is indeed the authorized operator for this task.
[0037] After successful authentication, the authorized terminal actively scans the identification markers on-site. Each controlled device has a near-field communication tag or QR code label installed nearby, which encodes the device's unique asset number. The authorized terminal obtains the device identifier through near-field communication reading or camera scanning and compares it with the device identifier recorded in the authorized operation field of the dynamic digital token stored in the authorized terminal. If the two match, it confirms that the operator has reached the correct device location; if they do not match, the authorized terminal immediately issues an audible and visual alarm, prompting the operator that the current location does not match the target device, thereby preventing accidental operation due to going to the wrong interval.
[0038] After the location is confirmed, the authorized terminal establishes a communication link with the on-site equipment controller. The equipment controller is an embedded intelligent device installed on or near the controlled equipment, responsible for receiving operating commands and driving actuators to complete the opening / closing or starting / stopping actions of the equipment. Communication between the authorized terminal and the equipment controller uses a short-range wireless communication protocol, such as Bluetooth Low Energy or Near Field Communication (NFC). During communication establishment, both parties perform two-way authentication: the authorized terminal presents its digital certificate to the equipment controller, and the equipment controller presents its digital certificate to the authorized terminal; each party verifies the validity and legitimacy of the other's certificate. After successful two-way authentication, the communication link is successfully established, and a session key is negotiated and generated for encryption protection of subsequent data transmission.
[0039] After the communication link is established, the authorized terminal presents a dynamic digital token to the device controller. This presentation process is not a simple data transmission but follows a strict security protocol. The authorized terminal first encrypts all fields of the dynamic digital token using a session key, and then sends the encrypted token data packet to the device controller. Upon receiving the encrypted data packet, the device controller decrypts it using the session key to obtain the original plaintext data of the dynamic digital token. At this point, the token presentation step is complete, and the device controller obtains all the information of the dynamic digital token required for subsequent three-party collaborative verification, including the token identifier, associated task identifier, authorized operation field, security constraint field, validity period field, and digital signature field.
[0040] Throughout the entire process, the authorized terminal's display screen presents the operator with real-time operation progress information, including communication connection status, token presentation status, and prompts for the next step. If communication fails to establish or token presentation is abnormal, the authorized terminal displays specific error codes and troubleshooting suggestions to help the operator quickly locate and resolve the problem. Simultaneously, the authorized terminal records a complete log of this communication and token presentation in local storage and reports it during subsequent communications with the central decision-making platform, thus forming a complete operation audit chain.
[0041] In step S4, after receiving the dynamic digital token presented by the authorized terminal, the device controller immediately initiates a three-party collaborative verification process. This verification process consists of three independent verification steps connected in series: the first verification, the second verification, and the third verification. All three must pass before the device controller unlocks and allows the operation to be performed.
[0042] The first verification is a local verification performed by the local verification unit of the device controller. This unit first checks whether the data format of the dynamic digital token conforms to predetermined specifications, including whether the token identifier is a valid UUID format, whether the associated task identifier is not empty, whether the authorized operation field contains a valid device identifier and action type, whether the security constraint field contains at least one conditional expression, whether the effective timestamp of the valid time period field is earlier than the expiration timestamp, and whether the length of the digital signature field is correct. After the format check passes, the local verification unit uses the public key of the central decision-making platform to verify the digital signature field. The verification process first concatenates the first five fields of the token into a continuous byte stream, then calculates the hash value of this byte stream, then uses the public key of the central decision-making platform to decrypt the digital signature field to obtain the original hash value, and finally compares whether the calculated hash value matches the decrypted hash value. If they match, it proves that the token was indeed issued by the central decision-making platform and has not been tampered with; if they do not match, it is determined that the token is counterfeit or has been tampered with, the first verification fails, the device controller directly refuses the operation and issues an alarm.
[0043] After the first verification passes, the second verification stage begins, executed by the equipment controller's safety constraint check unit. This unit extracts each safety constraint from the dynamic digital token's safety constraint field, with each constraint consisting of four parts: equipment identifier, status parameter name, comparison operator, and target value. The safety constraint check unit reads the real-time operating status data of the corresponding equipment through the equipment controller's sensor interface or industrial bus, and then compares the read real-time value with the target value in the constraint. For example, for a constraint stating that the unit speed is below 0.5 revolutions per minute, the safety constraint check unit reads the current real-time speed value from the unit speed sensor and then determines whether this real-time value is less than 0.5 revolutions per minute. If the comparison results of all constraints are true, the second verification passes; if any constraint comparison result is false, the second verification fails, the equipment controller immediately refuses to operate and reports the safety condition not being met to the central decision-making platform.
[0044] After the second verification is passed, the third verification stage begins, executed by the collaborative verification agent unit of the device controller. This unit sends a query request to the collaborative verification service module of the central decision platform, carrying the token identifier of the dynamic digital token and the associated task identifier. Upon receiving the query request, the collaborative verification service module of the central decision platform performs the following checks: First, it searches the task database for the task record corresponding to the associated task identifier to confirm whether the task is currently in progress; second, it checks whether the dynamic risk assessment engine has ever output a risk assessment value exceeding the preset risk upper limit threshold since the token was issued, i.e., whether a risk exceeding the limit event has occurred; third, it checks whether the token has ever been marked as invalid by the central decision platform. If all three checks are normal, i.e., the task is in progress, no risk exceeding the limit event has occurred, and the token has not been invalidated, the collaborative verification service module returns an authorization confirmation signal to the device controller. If any check result is abnormal, the collaborative verification service module returns an authorization rejection signal to the device controller.
[0045] During the execution of the third verification, communication timeouts may occur between the equipment controller and the central decision-making platform. A communication timeout occurs when the equipment controller sends a query request but does not receive any response from the central decision-making platform within a preset timeout period. In response to this communication timeout anomaly, the equipment controller executes corresponding processing operations according to a preset policy. The preset policy is a set of rules pre-configured in the equipment controller's non-volatile memory, categorized according to the security level of the operation type. The security level is determined based on the severity of the potential consequences of the operation; for example, operations involving the opening and closing of high-voltage electrical equipment are classified as the highest security level, while inspection operations involving auxiliary equipment are classified as lower security levels. For operations of the highest security level, the preset policy stipulates that the operation must be rejected and logged upon communication timeout to ensure safety priority. For operations of lower security levels, the preset policy allows the execution of preset limited security degradation operations and logging, such as allowing inspection operations that only involve status readings and do not involve equipment switching. Regardless of the strategy employed, the device controller will record the communication timeout event and the corresponding countermeasures in detail in the local log, and report it to the central decision-making platform after communication is restored, so as to conduct post-event analysis and auditing.
[0046] After completing the three verification stages, the equipment controller makes a final decision based on the verification results. Only if the first, second, and third verifications are all passed will the equipment controller unlock operating permissions through its control execution unit, allowing the operator to perform the corresponding operations via the authorized terminal or the equipment controller panel. If any verification stage fails, the equipment controller remains locked and refuses to perform any operations. Simultaneously, it feeds back detailed information about the verification failure to the operator via the authorized terminal and reports an alarm to the central decision-making platform via the industrial network.
[0047] In step S5, after the equipment controller completes the first, second, and third verifications and all three verifications pass, it enters the operation unlocking execution phase. Upon receiving confirmation signals that all three verification steps have passed, the control execution unit of the equipment controller releases the electrical or mechanical lock on the controlled equipment's operating mechanism. For electric operating mechanisms, the control execution unit connects the operating power circuit, enabling the operating mechanism to operate under power; for hydraulic or pneumatic operating mechanisms, the control execution unit opens the corresponding solenoid valve, providing the operating mechanism with a power source for movement. Simultaneously, the control execution unit sends an operation ready signal to the authorized terminal, and the authorized terminal's display shows a prompt indicating that the operation is ready, informing the operator that they can perform the specific operation.
[0048] Operators execute actions via the operating interface on the authorized terminal or the operating buttons on the equipment controller panel. For remote control operation, the operator clicks the execute button on the touchscreen of the authorized terminal. The authorized terminal encrypts the operation command and sends it to the equipment controller. The equipment controller decrypts the command and drives the actuator to complete the opening / closing or starting / stopping action of the equipment. For local manual operation, the operator directly operates the buttons or handles on the equipment controller panel. The equipment controller detects the operation input and drives the actuator to complete the action. Regardless of the operation method used, after the operation is completed, the equipment controller feeds back the latest status data of the controlled equipment to the central decision-making platform through the industrial network. Based on this, the central decision-making platform updates the status parameters of the corresponding equipment in the digital twin model and simultaneously updates the execution status of the corresponding steps in the electronic operation ticket.
[0049] After the equipment controller is unlocked and authorized to perform the corresponding operations, it enters a dynamic monitoring and re-verification mode. The core purpose of this mode is to continuously monitor changes in the equipment's operating status during operation, promptly detect and respond to any abnormal conditions, and prevent the operation from continuing under dangerous conditions.
[0050] The equipment controller's safety constraint check unit continuously monitors the equipment's real-time operating status during operation. The set of monitored parameters is consistent with the set of parameters contained in the safety constraint field of the dynamic digital token, including but not limited to key state quantities such as unit speed, bearing temperature, vibration amplitude, circuit breaker position, and valve opening. The safety constraint check unit reads the real-time measurement values of each sensor at a fixed sampling period, set to the millisecond level, to ensure rapid response to changes in equipment status.
[0051] The device controller calculates the difference between the real-time status data obtained from each sampling and the status data from the previous sampling to obtain the change in each status parameter. When the change in any status parameter exceeds the preset change range, the device controller determines that the real-time operating status of the device has changed significantly. The preset change range is a threshold vector independently configured for each status parameter, and its mathematical representation is as follows: ; Where m represents the total number of monitored state parameters. This represents the maximum permissible variation range of the m-th state parameter. For example, for the unit speed parameter, the maximum permissible variation range is set to 0.1 revolutions per minute; for the bearing temperature parameter, the maximum permissible variation range is set to 1 degree Celsius; and for the vibration amplitude parameter, the maximum permissible variation range is set to 0.02 millimeters. When the equipment controller monitors the real-time change of the m-th state parameter... satisfy When the change in the state parameter exceeds the preset state change range, it is determined that the change is significant.
[0052] Once the device controller determines that the real-time operating status of the device has changed beyond the preset range, the device controller immediately and automatically re-executes the three-party collaborative verification process. The re-executed three-party collaborative verification is completely consistent with the initial three-party collaborative verification in terms of process, including the first verification, which is to verify the authenticity and format validity of the dynamic digital token locally; the second verification, which is to compare the security constraints encoded in the dynamic digital token with the current real-time operating status of the device; and the third verification, which is to send a query request to the central decision-making platform to confirm whether the real-time status of the task corresponding to the dynamic digital token is active and has not been terminated.
[0053] If the re-execution of the three-way collaborative verification fails—that is, if any one of the first, second, or third verifications fails—the equipment controller immediately suspends the current operation and restores to a safe state. Specific measures for suspending operation include: for ongoing equipment actions, the equipment controller immediately cuts off the power source to the operating mechanism, stopping the action at its current intermediate position or automatically resetting it to the initial safe position; for actions not yet started, the equipment controller keeps the operating mechanism locked, prohibiting any new operational input. Specific measures for restoring to a safe state include: the equipment controller restores all controllable parameters related to the controlled equipment to safe preset values, such as restoring the opening of a regulating valve to zero or the open / closed state of a circuit breaker to its initial safe position; simultaneously, the equipment controller sends an operation suspension notification to the authorized terminal, informing the operator that the current operation has been suspended and the reason for the suspension; the authorized terminal displays an operation suspension alarm message on its screen and issues an audible and visual warning. The equipment controller also records the triggering reason, verification result, and complete log of the operation suspension in local storage and immediately reports it to the central decision-making platform via the industrial network, so that safety management personnel can promptly understand the abnormal situation on site and take subsequent measures.
[0054] Example 2: A hydropower station equipment operation authorization control system based on dynamic task tokens. This system is used to implement the hydropower station equipment operation authorization control method based on dynamic task tokens described in Example 1, such as... Figure 2 As shown, it includes a central decision-making platform, at least one dynamic authorization terminal, and multiple equipment controllers. The central decision-making platform communicates with the dynamic authorization terminal and equipment controllers through the power plant industrial network, forming a distributed control system with a star topology.
[0055] The central decision-making platform, deployed in the power plant's central control room, is the core decision-making and control node of the entire system. The central decision-making platform consists of one or more high-performance industrial servers running a specially developed authorization management software system. It responds to legitimate operational tasks and performs real-time security risk assessments. Internally, it comprises four key functional modules: a multi-source data fusion module, a dynamic risk assessment engine, a dynamic token generation module, and a collaborative verification service module.
[0056] The multi-source data fusion module is the data acquisition and integration unit of the central decision-making platform. This module establishes data interfaces with the power plant's existing monitoring system, hydrological forecasting system, equipment status monitoring system, and environmental meteorological station through the power plant's industrial network, collecting four types of data in real time. The first type is real-time hydrological data, including upstream reservoir water level, downstream tailrace water level, inflow and outflow, with a sampling period of seconds. The second type is equipment data, including unit speed, bearing temperature, vibration amplitude, circuit breaker open / close status, disconnector position, and valve opening, with a sampling period of milliseconds. The third type is electrical data, including generator active power, reactive power, bus voltage, line current, and frequency, with a sampling period of milliseconds. The fourth type is environmental data, including wind speed, rainfall intensity, and lightning activity, with a sampling period of minutes. The multi-source data fusion module processes this heterogeneous data from different data sources, sampling frequencies, and data formats, performing preprocessing operations such as timestamp alignment, unit conversion, and outlier removal, before converting it into a standardized time-series data format and storing it in a real-time database. Based on this real-time data, a multi-source data fusion module constructs a digital twin model of the power plant's overall operation. This digital twin model is an object-oriented, high-fidelity virtual mirror system that contains mathematical and physical models of all key equipment in the power plant, as well as their topological connections. The update cycle of the digital twin model is set at the millisecond level to ensure a high degree of synchronization between the model's state and the actual physical equipment's state. The digital twin model provides an accurate real-time data foundation for subsequent risk assessment.
[0057] The dynamic risk assessment engine is the risk quantification and decision-making unit of the central decision-making platform. Based on a digital twin model built from multi-source data fusion modules, this engine performs real-time security risk assessments for each operational task.
[0058] The dynamic token generation module is the authorization credential generation unit of the central decision-making platform. Once the dynamic risk assessment engine determines that the risk assessment is passed, the dynamic token generation module immediately starts, creating a dynamic digital token uniquely corresponding to the current operation task. The dynamic digital token is an encrypted digital credential, and its data structure consists of six fields. The first field is the token identifier, which is a globally unique string generated by the central decision-making platform. The second field is the associated task identifier, which records the task number of the electronic operation ticket corresponding to the token. The third field is the authorized operation field, which records the device identifier and action type of the authorized operation. The fourth field is the security constraint field, which records one or more device state conditions that must be met before executing the operation; each condition consists of a device identifier, a state parameter name, a comparison operator, and a target value. The fifth field is the validity period field, which records the token's effective and expiration timestamps. The sixth field is the digital signature field, which is generated by the central decision-making platform using its private key to sign the hash values of the aforementioned five fields. The dynamic digital token encodes the minimum operation permissions, security constraints, and validity period. For electronic operation tickets containing multiple operation steps that need to be executed in a preset order, the dynamic token generation module generates a corresponding sub-token for each operation step. The sub-tokens are linked by a sequential chain, and the completion status of the previous sub-token serves as the activation condition for the next sub-token.
[0059] The Collaborative Verification Service Module is the remote verification response unit of the central decision-making platform. This module responds to status query requests from device controllers and returns an authorization confirmation signal or an authorization rejection signal based on real-time risk assessment results. Upon receiving a query request from a device controller, the Collaborative Verification Service Module performs the following checks: First, it searches the task database for the task record corresponding to the associated task identifier to confirm whether the task is currently in progress. Second, it checks whether the dynamic risk assessment engine has ever output a risk assessment value exceeding a preset risk upper limit since the token was issued. Third, it checks whether the token has ever been marked as invalid by the central decision-making platform. If all three checks are normal, the Collaborative Verification Service Module returns an authorization confirmation signal to the device controller; if any check is abnormal, it returns an authorization rejection signal. Furthermore, the Collaborative Verification Service Module is also responsible for uniformly returning an authorization rejection signal to all subsequent status query requests from all device controllers when the dynamic risk assessment engine triggers proactive intervention, thus achieving remote circuit breaking for high-risk operations.
[0060] The dynamic authorization terminal is a portable handheld device designed specifically for the harsh industrial environment of hydropower stations. It receives and displays dynamic digital tokens issued by the central decision-making platform and communicates with field equipment controllers. The terminal integrates a wireless communication module, a secure encrypted storage area, a touchscreen display, and a biometric module. The wireless communication module supports Bluetooth Low Energy and Near Field Communication (NFC) technologies to establish short-range wireless communication links with the equipment controllers. The secure encrypted storage area is protected by a hardware encryption chip and securely stores dynamic digital tokens and other sensitive data. The touchscreen display shows operators token information, operation prompts, and alarm messages. The biometric module supports fingerprint and facial recognition to verify operator identity.
[0061] After receiving the dynamic digital token from the central decision-making platform, the dynamic authorization terminal stores it in an encrypted secure storage area and displays the token's basic information, including the authorized operation content, validity period, and current status, on a touch screen. When an operator arrives at the equipment site with the dynamic authorization terminal, the terminal first verifies the operator's identity through a biometric module, then scans the near-field communication tag or QR code nameplate at the equipment site to obtain the equipment identifier, and compares it with the equipment identifier recorded in the authorization operation field of the token to confirm that the operator has arrived at the correct equipment location. After the location is confirmed, the dynamic authorization terminal establishes a communication link with the on-site equipment controller, performs two-way authentication, and uses the negotiated session key to encrypt and transmit the dynamic digital token, presenting the token to the equipment controller.
[0062] Each device controller is located at the site of the controlled device and is an embedded intelligent device installed on or near the control cabinet of the controlled device. The device controller is used to perform three-way collaborative verification and contains four key functional units: a local verification unit, a security constraint check unit, a collaborative verification agent unit, and a control execution unit.
[0063] The local verification unit is the first line of defense for the device controller. This unit verifies the authenticity and format validity of the dynamic digital token. First, the local verification unit checks whether the data format of the dynamic digital token conforms to predetermined specifications, including the length, type, and value range of each field. After the format check passes, the local verification unit uses the public key of the central decision-making platform to verify the digital signature field, confirming that the token was issued by the central decision-making platform and has not been tampered with. If both the format check and signature verification pass, the first verification is successful; otherwise, the first verification fails, the device controller directly rejects the operation and issues an alarm.
[0064] The security constraint check unit is the second verification checkpoint for the equipment controller. This unit compares the security constraints encoded within the dynamic digital token with the real-time operating status of the equipment. The security constraint check unit extracts each security constraint from the security constraint field of the dynamic digital token, reads the corresponding real-time operating status data of the equipment through the sensor interface or industrial bus of the equipment controller, and then compares the read real-time value with the target value in the constraint. If the comparison result of all constraints is true, the second verification passes; if the comparison result of any constraint is false, the second verification fails, the equipment controller immediately refuses operation and reports the security condition not being met to the central decision-making platform. During operation execution, the security constraint check unit continuously monitors the real-time operating status of the equipment. When it detects a change in the real-time operating status of the equipment exceeding a preset change range, it triggers the re-execution of the three-party collaborative verification.
[0065] The collaborative verification agent unit is the third verification checkpoint for the device controller. This unit sends query requests to the central decision-making platform and receives responses. After the second verification passes, the collaborative verification agent unit sends a query request to the collaborative verification service module of the central decision-making platform, carrying the token identifier of the dynamic digital token and the associated task identifier. The collaborative verification agent unit waits for a response from the central decision-making platform and determines whether the third verification passes based on the received response. If an authorization confirmation signal is received, the third verification passes; if an authorization rejection signal is received or a communication timeout occurs, the third verification fails. In the event of a communication timeout, the collaborative verification agent unit executes corresponding processing operations according to a preset policy, which is pre-configured based on the security level of the operation type.
[0066] The control execution unit is the final actuator of the equipment controller. This unit unlocks and allows operation after successful verification by the local verification unit, safety constraint check unit, and collaborative verification agent unit. Upon receiving confirmation signals that all three verification stages have passed, the control execution unit releases the electrical or mechanical lock on the controlled equipment's operating mechanism, enabling it to move. After operation execution, the control execution unit feeds back the latest status data of the controlled equipment to the central decision-making platform via the industrial network. If re-verification fails during operation, the control execution unit immediately suspends the current operation and returns to a safe state, cutting off the power source to the operating mechanism and restoring relevant parameters to safe preset values.
[0067] Working Principle: After responding to a legitimate operational task through the central decision-making platform, this invention first activates the multi-source data fusion module to integrate real-time hydrological data, equipment data, electrical data, and environmental data to construct a panoramic digital twin model of the power station's operation. The dynamic risk assessment engine then performs a real-time safety risk assessment of the operational task based on this digital twin model. Only when the risk assessment passes is a dynamic token generation module created a unique dynamic digital token corresponding to the operational task and securely issued to the authorized terminal held by the operator. This token encodes minimal operational permissions, security constraints, and an expiration date. During on-site operation, the equipment controller performs a three-way collaborative verification process, including verifying the authenticity of the local token, comparing the security constraints with the real-time equipment status, and querying the central decision-making platform for the real-time status of the task. Operation is only unlocked when all three verifications pass. This invention transforms operation permissions from traditional static attributes based on personnel or roles into dynamic temporary credentials strongly bound to specific task instances. It achieves a deep integration of authorization decisions and real-time security risk assessment based on multi-source data fusion, avoiding systemic risks of authorized personnel operating at inappropriate times or under inappropriate conditions. It solves the technical problems of static authorization and disconnection from real-time operation status in existing technologies, achieving the effect of upgrading from logical error prevention to system security error prevention.
[0068] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0069] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0070] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0071] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0072] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A hydropower station equipment operation authorization control method based on dynamic task tokens, characterized in that, Includes the following steps: In response to a legitimate operational task, the central decision-making platform activates the multi-source data fusion module to integrate real-time hydrological data, equipment data, electrical data, and environmental data, constructs a panoramic digital twin model of the power station's operation, and the dynamic risk assessment engine performs a real-time safety risk assessment of the operational task based on the digital twin model. If the risk assessment is successful, the dynamic token generation module creates a dynamic digital token that uniquely corresponds to the operation task and securely distributes the dynamic digital token to the authorized terminal held by the operator performing the operation task; the dynamic digital token encodes the minimum operation permissions, security constraints, and validity period. After the operator brings the authorized terminal to the equipment site, the authorized terminal establishes communication with the equipment controller on site and presents the dynamic digital token to the equipment controller; The device controller performs a three-party collaborative verification: First verification, locally verifying the authenticity and format validity of the dynamic digital token; Second verification, comparing the security constraints encoded in the dynamic digital token with the real-time operating status of the device; Third verification, sending a query request to the central decision-making platform to confirm whether the real-time status of the task corresponding to the dynamic digital token is active and has not been terminated. The device controller is only unlocked and allowed to perform the corresponding operation if the first verification, the second verification, and the third verification are all passed.
2. The hydropower station equipment operation authorization control method based on dynamic task tokens according to claim 1, characterized in that, After the device controller is unlocked and the corresponding operation is permitted, the following is also included: The device controller continuously monitors the real-time operating status of the device. When the real-time operating status of the device is detected to have changed beyond the preset change range, the device controller automatically re-executes the three-party collaborative verification. If the re-verification fails, the device controller immediately suspends the current operation and returns to a safe state.
3. The hydropower station equipment operation authorization control method based on dynamic task tokens according to claim 1, characterized in that, During the task cycle of the operation, the central decision-making platform continuously monitors the real-time risk assessment results; When the risk assessment value output by the dynamic risk assessment engine exceeds the preset risk upper limit threshold, the central decision-making platform will proactively intervene in at least one of the following ways: The collaborative verification service module returns an authorization rejection signal to the corresponding dynamic digital token during subsequent status queries of all device controllers. Alternatively, an emergency invalidation command can be sent directly to the authorized terminal to invalidate the dynamic digital token locally on the terminal.
4. The hydropower station equipment operation authorization control method based on dynamic task tokens according to claim 1, characterized in that, The operation task is one or more operation steps in the electronic operation ticket; The dynamic digital token is bound to the specific operation steps in the electronic operation ticket, and the activation and deactivation of the dynamic digital token are synchronized with the task status of the electronic operation ticket.
5. The hydropower station equipment operation authorization control method based on dynamic task tokens according to claim 4, characterized in that, When the electronic operation ticket contains multiple operation steps that need to be executed in a preset order, the dynamic token generation module generates a corresponding sub-token for each operation step. The device controller activates the sub-token for the next step only after the sub-token verification of the current step is successful and the operation is completed.
6. The hydropower station equipment operation authorization control method based on dynamic task tokens according to claim 1, characterized in that, If a communication timeout occurs between the device controller and the central decision-making platform during the execution of the third verification by the device controller, the device controller shall perform one of the following operations according to a preset strategy: Deny the operation and log it. Alternatively, it allows the execution of preset limited security degradation operations and logging; The preset strategy is pre-configured according to the security level of the operation type.
7. The hydropower station equipment operation authorization control method based on dynamic task tokens according to claim 1, characterized in that, The data structure of the dynamic digital token includes: token identifier, associated task identifier, authorized operation field, security constraint field, valid time period field, and digital signature field; The authorized operation field records the device identifier and action type of the authorized operation; The security constraint field records one or more device state conditions that must be met before the operation is performed.
8. A hydropower station equipment operation authorization control system based on dynamic task tokens, characterized in that, This system is used to implement the hydropower station equipment operation authorization control method based on dynamic task tokens as described in any one of claims 1-7, comprising: The central decision-making platform is deployed in the power plant's central control room to respond to legitimate operational tasks and perform real-time safety risk assessments. The central decision-making platform includes a multi-source data fusion module, a dynamic risk assessment engine, a dynamic token generation module, and a collaborative verification service module. At least one dynamic authorization terminal, held by an operator, is used to receive and display dynamic digital tokens issued by the central decision-making platform and to communicate with field device controllers; Multiple device controllers are respectively set at the site of each controlled device to perform three-party collaborative verification. Each device controller includes a local verification unit, a security constraint check unit, a collaborative verification agent unit, and a control execution unit. The central decision-making platform communicates with the dynamic authorization terminal and the equipment controller through the power plant industrial network.
9. The hydropower station equipment operation authorization control system based on dynamic task tokens according to claim 8, characterized in that, The multi-source data fusion module is used to integrate real-time hydrological data, equipment data, electrical data and environmental data to construct a digital twin model of the power station's panoramic operation. The dynamic risk assessment engine performs real-time security risk assessments on operational tasks based on the digital twin model. The dynamic token generation module is used to generate a dynamic digital token that uniquely corresponds to the operation task. The dynamic digital token encodes the minimum operation permissions, security constraints, and validity period. The collaborative verification service module is used to respond to the status query request of the device controller and return an authorization confirmation signal or an authorization rejection signal based on the real-time risk assessment results.
10. The hydropower station equipment operation authorization control system based on dynamic task tokens according to claim 8, characterized in that, The local verification unit is used to verify the authenticity and format validity of the dynamic digital token; The security constraint checking unit is used to compare the security constraints encoded in the dynamic digital token with the real-time operating status of the device. The collaborative verification agent unit is used to send query requests to the central decision-making platform and receive responses. The control execution unit is used to unlock and allow the operation to be performed after the verification by the local verification unit, the security constraint check unit, and the collaborative verification agent unit have all passed.