A smart electric energy metering box management method with remote state monitoring
Patent Information
- Application Number
- CN202610648002.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-12
- Publication Date
- 2026-09-25
AI Technical Summary
[0003]针对现有技术的不足,本发明提供了一种具备远程状态监测的智能电能计量箱管理方法,解决了传统方法中存在的对目标计量箱真实电气异常与环境扰动、合法运维操作、邻近设备影响以及传感链路漂移之间缺少有效区分的问题
1.本发明,通过先与目标电能计量箱建立一致的状态辨识会话,再对电压、电流、磁场、温湿度、箱门视频等多源的监测数据进行对象一致核验、链路有效校验和时间对齐,最后再按照自然环境扰动、正常运维操作、邻近设备影响、传感链路漂移先排除复核,再根据时序关联判断、持续确认对异常进行区分、确认,从而可以避免因正常检修、外部干扰和采集偏差误判为箱体异常的现象发生,减少真实异常误判为环境变化或链路波动的情况发生,提高目标电能计量箱真实异常的识别、异常定位、异常分级判断的准确率,将远程状态监测结果与异常状态进行有效对应。
Smart Images

Figure CN122823744A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electricity metering and monitoring technology, specifically to a management method for an intelligent electricity metering box with remote status monitoring. Background Technology
[0002] Electricity metering boxes are crucial metering devices at the end of low-voltage power distribution lines. Their operational status directly impacts the accuracy of electricity metering, power safety, and the effectiveness of on-site operation and maintenance management. Existing technologies already include remote status monitoring and intelligent protection solutions for electricity metering boxes. For example, authorized invention patent application CN208126141U discloses a system for intelligent protection of metering boxes. This system can monitor the operating status data of the metering box online and, combined with high-frequency magnetic fields, temperature and humidity, incoming line current, image acquisition, and a remote master station, achieve abnormal event reporting and remote safety control. Another example is authorized invention patent application CN201518040U, which discloses an electricity monitoring device that can determine the legality of opening the box by combining the door opening status, key reading information, image acquisition information, and backend communication results. Therefore, existing technologies can already achieve remote monitoring and anomaly identification of electricity metering boxes to a certain extent, and improve the security protection capabilities of the metering boxes. However, the existing technologies mainly collect, upload, or compare multi-source status information such as voltage, current, magnetic field, temperature and humidity, door status, and image information, focusing on the discovery of abnormal phenomena but lacking an effective mechanism for distinguishing the source of anomalies. Since factors such as actual electrical anomalies of the target metering box, environmental disturbances, legitimate maintenance operations, the influence of nearby equipment, and sensor link drift may exhibit similar characteristics in the monitoring results, existing technologies struggle to accurately determine whether an anomaly truly originates from the target metering box itself. This easily leads to misjudging normal maintenance, external interference, or acquisition deviations as box anomalies, or misjudging actual anomalies as environmental changes, resulting in a high false alarm rate, inaccurate anomaly location, distorted anomaly level assessment, and insufficient reliability of subsequent handling. Therefore, a smart energy metering box management method is needed to achieve effective analysis of multi-source monitoring results and differentiation of anomaly sources, improving the accuracy of identifying the true abnormal state of the target metering box and the reliability of remote management. Summary of the Invention
[0003] To address the shortcomings of existing technologies, this invention provides a management method for intelligent power metering boxes with remote status monitoring, which solves the problem in traditional methods of lacking effective differentiation between actual electrical anomalies of the target metering box and environmental disturbances, legitimate operation and maintenance, influence of nearby equipment, and sensor link drift.
[0004] To achieve the above objectives, the present invention provides the following technical solution: A management method for a smart electricity metering box with remote status monitoring includes: Establish a status identification session based on the remote monitoring trigger information of the target energy metering box to determine the object identifier, time caliber, parameter version, authorization status and relationship with neighboring devices of the target energy metering box; The voltage, current, magnetic field, temperature and humidity, door and video monitoring information collected during the session period are verified for object consistency, link validity and time alignment to obtain the session time sequence record corresponding to the target power metering box; Based on the session timing records, the elimination and verification are carried out in the order of natural environmental disturbance, legitimate operation and maintenance, influence of nearby equipment and sensor link drift, and the timing correlation judgment and continuity confirmation are performed on the abnormal changes that have not been eliminated. Based on the results of exclusion review and continuous confirmation, the source, type and level of the anomaly of the target power meter box are determined, and anomaly handling information and recovery observation information are generated.
[0005] Preferably, a status identification session is established based on the remote monitoring trigger information of the target energy metering box, including: Remote monitoring trigger information is uniformly recorded to form a trigger record containing trigger type, trigger time, target box number, trigger source number, trigger summary, trigger priority and original event index; Within the preset merging time window, multiple trigger records corresponding to the same target box are merged and compared, and the trigger record with the highest priority is determined as the main trigger, while the remaining trigger records are written into the auxiliary trigger list. When trigger summaries of multiple trigger records conflict, a trigger conflict record is generated, and the current session state is set to pending review. Configure the session start time, session end time, and current state according to the main trigger type to form a state-identifying session record.
[0006] Preferably, the object identifier, time caliber, parameter version, authorization status, and proximity relationship of the target energy metering box are determined, including: Extract the enclosure number, meter number, substation number, installation location number, incoming and outgoing line circuit number, and valid data collection point list number from the current valid basic files to form an object identification snapshot, and perform conflict verification on the installation location number and valid data collection point list number; Combine the main trigger type to set the total session time window and core time slice length, and record the acquisition time, reception time and mapping time; Write the current valid parameter version and generate a parameter snapshot record; Determine authorization status by retrieving authorization records based on session time windows; Read the relationships between neighboring devices according to the time range corresponding to the main trigger, and record the neighboring device number, device type, relative location, distance level, readable operation status marker, and missing neighboring relationship marker.
[0007] Preferably, the voltage, current, magnetic field, temperature and humidity, door and video monitoring information collected during the session period are subject to object consistency verification, link validity verification and time alignment, including: The raw acquisition messages received during the session are written into the session data buffer, and messages lacking key fields are written into the abnormal message registration record. Based on the target enclosure number, the list of valid acquisition points, the range of incoming and outgoing line circuits, and the message sequence number, the message consistency is checked, and conflicting messages are either blocked or not blocked. When the verification is passed or the non-blocking conditions are met, the message is checked for sampling continuity, timing rationality, status bit consistency, value retention abnormality, repeated transmission, and local buffer status according to the type of collection item. The message is then merged into the core time slice according to the collection time, and a time slice compensation record is generated for the retransmitted message.
[0008] Preferably, the session timing record corresponding to the target energy metering box is obtained, including: The merged monitoring data is organized according to time slices and written into voltage, current, magnetic field, temperature, humidity, door lock, box door and video entries. The link status, connection status, connection duration, additional record mark, compensation record mark and real-time upload mark of each entry are recorded. At the same time, object conflict mark, pending mark and suspicious mark are written. Generate a link status summary record based on the type of collection item or the collection point number, recording the number of valid records, the number of suspicious records, the number of records to be supplemented, the number of failed records, continuous interruption flags, value retention abnormal flags, clock rollback flags, duplicate upload flags, core link missing flags, and session core judgment impact flags.
[0009] Preferably, based on the session timing records, the exclusion and verification are performed in the following order: natural environmental disturbances, legitimate operation and maintenance, influence of nearby devices, and sensor link drift, including: First, extract abnormal segment records according to time slice intervals, and form electrical side abnormal segments, local thermal abnormal segments, entry-related abnormal segments, and video-assisted abnormal segments according to the change pattern of the collected items; Then, in the order of natural environmental disturbance, legitimate operation and maintenance, influence of nearby equipment and sensor link drift, each abnormal segment is compared in turn. For abnormal segments that were not explained in the previous round, the next round of comparison is carried out, and all or part of the explainable time segments are excluded and recorded. Write the abnormal segments that are inconsistent with the authorization record and behavior trajectory into the authorization conflict candidate, and write the sessions that explain all the remaining abnormal segments by the link state abnormality into the link abnormality description record.
[0010] Preferably, for any unexcluded abnormal changes, time-series correlation analysis and persistence confirmation are performed, including: For abnormal segments that remain unexplained after rounds of comparison, they are sorted by the time of their first appearance, and the correspondence between abnormal segments is identified according to a preset succession pattern. Exception segments that satisfy the succession relationship are grouped into associated exception chains, and exception segments that do not form a succession relationship are recorded as isolated exceptions; Then, according to the continuous judgment rules corresponding to the anomaly type, the anomaly fragments or associated anomaly chains are continuously confirmed. Those that pass the continuous confirmation are written into the confirmed candidate record, those that fail but still have continuous changes are written into the observation candidate record, and the anomaly fragments supported by the failure entries are written into the low confidence anomaly list.
[0011] Preferably, based on the results of exclusion review and continuous confirmation, the source, type, and level of anomaly of the target energy metering box are determined, including: Read the exclusion review record, abnormal candidate record, session timing record, link status summary record and parameter snapshot record, and establish a session conclusion record; The main and secondary anomaly chains are determined based on the time slices covered by the anomaly segments, the associated anomaly chains, the persistence status, and the level of evidence. The source of the anomaly is determined based on the proportion of sources and the relationship between the main anomaly chain. The anomaly type is determined based on the composition, order of collection, and type proportion of the main anomaly chain. The anomaly level is determined based on the clarity of the anomaly source, the combination of anomaly types, the persistence status, and the risk status. The relevant results are then written into the session conclusion record.
[0012] Preferably, the generation of anomaly handling information and recovery observation information includes: Anomaly handling information and recovery observation information are generated based on the session conclusion records; Based on the source, type and level of the anomaly, match the suggested processing path and review time limit, and write the session number, target box number, main reference items, excluded factors, suggested processing path and review mark; Based on the original criteria for establishing the anomaly, the observation duration, key observation items, and recovery judgment conditions are set to generate recovery observation information. During the recovery observation period, when a corresponding abnormal candidate appears, the current session state is written as recovery failed and a new associated session is triggered. When the recovery judgment condition is met, the current session state is written as closed loop, and the processing record and recovery record are written to the status history.
[0013] Compared with the prior art, the present invention provides a management method for intelligent power metering boxes with remote status monitoring, which has the following beneficial effects: 1. This invention establishes a consistent status identification session with the target energy metering box first, then performs object consistency verification, link validity verification, and time alignment on monitoring data from multiple sources such as voltage, current, magnetic field, temperature and humidity, and door video. Finally, it first excludes and reviews data based on natural environmental disturbances, normal operation and maintenance, influence of nearby equipment, and sensor link drift, and then distinguishes and confirms anomalies based on time-series correlation judgment and continuous confirmation. This can avoid the phenomenon of misjudging box anomalies due to normal maintenance, external interference, and acquisition deviation, reduce the occurrence of misjudging real anomalies as environmental changes or link fluctuations, improve the accuracy of identifying real anomalies of the target energy metering box, anomaly location, and anomaly classification judgment, and effectively correspond remote status monitoring results with abnormal states.
[0014] 2. This invention, after determining the source, type, and level of the anomaly, further generates anomaly handling information and recovery observation information corresponding to the current session conclusion, and uniformly records the handling path, review time limit, recovery judgment conditions, and status history. Therefore, the remote monitoring results are no longer limited to a single alarm, but form a continuous anomaly handling record, reducing the inconsistency between anomaly discovery, manual review, and recovery confirmation, and avoiding inconsistencies in judgment criteria or handling basis for the same anomaly at different processing stages. This improves the continuity and traceability of anomaly handling and recovery confirmation for the target energy metering box. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of a management method for an intelligent power metering box with remote status monitoring according to the present invention. Figure 2 A schematic diagram showing the relationship between the target energy metering box and the data acquisition data. Figure 3 This is a diagram illustrating the association between session timing records and exceptions. Figure 4 This is a schematic diagram of the closed loop for anomaly detection, handling, and recovery. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] Example 1: As Figures 1-4A management method for intelligent power metering boxes with remote status monitoring is presented, including: Establish a status identification session based on the remote monitoring trigger information of the target energy metering box to determine the object identifier, time caliber, parameter version, authorization status and relationship with neighboring devices of the target energy metering box; The voltage, current, magnetic field, temperature and humidity, door and video monitoring information collected during the session period are verified for object consistency, link validity and time alignment to obtain the session time sequence record corresponding to the target power metering box; Based on the session timing records, the elimination and verification are carried out in the order of natural environmental disturbance, legitimate operation and maintenance, influence of nearby equipment and sensor link drift. For the abnormal changes that have not been eliminated, the timing correlation judgment and persistence confirmation are carried out. Based on the results of exclusion review and continuous confirmation, the source, type, and level of anomalies in the target electricity metering box are determined, and anomaly handling information and recovery observation information are generated. Specifically, such as Figure 2 As shown: A status identification session is established based on the remote monitoring trigger information of the target energy metering box to determine the target energy metering box object, time caliber, parameter version, authorization status, and relationship with neighboring devices. The status identification session can determine the current processing object, session time, judgment parameters, authorization background, and external influence range before data verification and anomaly source differentiation. Voltage, current, magnetic field, temperature and humidity, box door, and video monitoring information are interpreted and compared under the same object, time caliber, and parameter version, reducing the impact of mixing data from different objects, times, and parameter calibers on the judgment results, and preparing for the next step of object consistency verification, link validity verification, and time alignment. The system receives remote monitoring trigger information from the target energy metering box. This information uses a unified input record structure, including at least the following fields: trigger type, trigger time, target box number, trigger source number, trigger summary, trigger priority, and original event index. The trigger type distinguishes between proactive anomaly reporting, scheduled inspections, authorized maintenance, changes in nearby equipment operation, communication recovery, and manual verification. The trigger time determines the start time of the current session. The target box number establishes a correspondence with the target energy metering box's basic file. The trigger source number identifies the trigger source. The trigger summary records the trigger overview. The trigger priority is used to... When multiple triggers occur simultaneously within a short period of time, the primary trigger is determined; the original event index is used for subsequent tracing; the trigger priority can be divided into five levels, with level one being the highest priority; proactive anomaly reporting and communication recovery can be set to level one, authorized maintenance can be set to level two, changes in the operation of adjacent equipment can be set to level three, manual review can be set to level four, and scheduled inspection can be set to level five; the above priority settings mainly consider the timeliness requirements corresponding to different trigger types, among which proactive anomaly reporting and communication recovery are usually directly related to anomaly confirmation or post-recovery review, and have high processing timeliness requirements, while scheduled inspection is mainly used for periodic checks and has a relatively lower urgency; When more than two trigger records appear for the same target energy meter box within a preset merging window, trigger merging is performed first. The trigger merging window can be selected as 30 seconds, with a range of 10 to 60 seconds. This time range is set based on the fact that proactive anomaly reporting, communication recovery and retransmission, and platform verification triggers usually occur within a few seconds to tens of seconds. When the merging window is less than 10 seconds, it is easy to split the same event into multiple sessions. When the merging window is greater than 60 seconds, it is easy to merge independent events. If multiple trigger records have different priorities, the trigger record with the highest priority is determined as the main trigger, and the remaining trigger records are written into the auxiliary trigger list. If multiple trigger records have the same priority but conflicting trigger summaries, a trigger conflict record is generated, and the current session status is set to the initialization pending verification state. The trigger conflict record includes at least the conflict trigger number, conflict field, conflict value, discovery time, and pending verification mark. Through the above trigger merging process, the situation of the same target energy meter box repeatedly establishing parallel sessions in a short period of time can be reduced, thereby avoiding the overlap of object boundaries and time boundaries. After trigger reception and trigger merging are completed, a status identification session is established. The status identification session adopts a unified session record structure, which includes at least the following fields: session number, target box number, main trigger, auxiliary trigger, session start time, session end time, current status, and parameter version number. The session number can be generated using a date plus serial number method to ensure uniqueness within the same day. The current status can include initialization status, pending data collection and verification status, object pending verification status, initialization pending verification status, and terminated status. The session time window is determined according to the main trigger type. When the main trigger is active anomaly reporting, the session duration can be 20 minutes, with a range of 10 to 30 minutes. When the main trigger is timed inspection, the session duration can be 10 minutes, with a range of 5 to 15 minutes. The aforementioned time settings are mainly determined based on the characteristic that abnormal changes in energy metering boxes usually have a leading, continuous, and stabilizing process. Too short a time is not conducive to covering changes before and after, while too long a time is easy to mix in irrelevant operating conditions. When the main trigger is authorized maintenance, the session time window can be from 5 minutes before the authorization starts to 20 minutes after the authorization ends. The pre-authorization period is used to identify anomalies that existed before the authorization, and the post-authorization period is used to observe the state stabilization and residual anomalies after the operation ends. When the main trigger is communication recovery, the session time window can be from the last 5 minutes before the interruption to 20 minutes after the recovery, in order to retain the last valid state before the interruption and the compensation and verification state after the recovery. When the main trigger is changes in the operation of nearby equipment, the session duration can be 15 minutes, with a range of 10 to 25 minutes. The above time settings are mainly determined based on the fact that the thermal, magnetic, or vibration effects of nearby equipment on the target enclosure usually have a transmission and decay process. Too short a time is not conducive to the formation and fallback of the coverage effect, while too long a time may introduce irrelevant external states. After the session is established, the object identifier of the target energy metering box is first determined. The object identifier is a combined identifier, not based on a single box number. It includes at least the box number, meter number, transformer substation number, installation location number, incoming and outgoing line circuit number, and valid data collection point list number. Among these, the box number is used for the physical carrier, the meter number for the metering entity, the transformer substation number for establishing regional association, the installation location number for relocation or replacement, the incoming and outgoing line circuit number for representing the electrical connection boundary, and the valid data collection point list number for representing the range of data sources acceptable for this session. The basic file of the target energy metering box can be updated when the equipment is put into operation, the meter is replaced, the data collection point is adjusted, the installation location is relocated, or the circuit is changed. The most recently effective file is used as the current valid basic file. When the session is established, the above information is extracted from the valid basic file. The fields form an object identifier snapshot and are written to the session record. If the same box number has multiple installation location numbers, or the same valid collection point list number is bound to another box, an object conflict record is generated and set to the object pending review status. Object conflicts include at least the conflict field, conflict value, first discovery time, conflict source index, and manual verification mark. If only a single abnormal point appears and the verification results are consistent, it is treated as a non-blocking object abnormality and will not be subject to subsequent data verification. It is only used as a record and will not be directly used as the basis for subsequent consistency judgment. If a stable conflict occurs, such as the same box number corresponding to multiple installation location numbers for a long time, or multiple boxes sharing the same collection point list number, it is treated as a blocking object conflict and will not be subject to subsequent data verification. Object confirmation is completed during the session establishment phase to reduce the impact of object misalignment from the source. The time caliber is used to standardize the comparison of data from different sampling periods, and includes at least the fields of total session time window, core time slice length, acquisition time, reception time, and mapping time. The total session time window is determined based on the main trigger type. The core time slice is used to uniformly merge monitoring data such as voltage, current, door locks, cabinet doors, door magnets, temperature, and humidity. The core time slice length can be selected from 1 to 5 seconds, preferably 2 seconds. This is because fast variables such as voltage, current, door locks, and cabinet doors typically exhibit second-level changes; a time slice that is too short will increase the proportion of empty slices for low-frequency data and the processing burden. If the time slice is too long, it will be difficult to preserve the sequential relationship between door lock action, current change and video trigger. When the target power metering box mainly collects fast variables such as voltage, current, door lock and door magnet, the core time slice is preferably 2 seconds. When the main collection items are slow variables such as temperature and humidity, the core time slice can be selected from 3 to 5 seconds. The acquisition time represents the actual sampling time of the terminal, the reception time represents the reception time of the remote end, and the mapping time represents the corresponding time after the data is merged into the current session time slice. By recording the above time fields in parallel, real-time data, delayed data and retransmission data can be distinguished. After determining the time caliber, the parameter version is further determined. The parameter version specifies the key parameters used in the current state identification session and remains consistent within the current session. The parameter version corresponds at least to environmental screening parameters, authorized observation parameters, nearby device impact parameters, link verification parameters, and anomaly retention parameters. Among them, the environmental screening parameters include at least the environmental type code, the allowable range of temperature rise in the same environment, and the allowable range of humidity fluctuation. The authorized observation parameters include at least the pre-authorization observation duration, the post-authorization observation duration, and the door lock associated observation window. The nearby device impact parameters include at least the nearby synchronization observation window, the distance classification threshold, and the impact decay observation duration. The link verification parameters include at least the allowed... Fields such as allowable interruption duration, data latency limit, and repeated upload judgment window; anomaly retention parameters should include at least the following fields: local thermal anomaly retention duration, electrical anomaly repeated observation cycle, and anomaly associated observation window; parameter version can be an integer version number, such as 1001 or 1002; the current valid parameter version is written when the session is established, and a parameter snapshot record is generated synchronously. The parameter snapshot record should include at least the following fields: core time slice length, session duration, door lock associated observation window, image effective latency limit, nearby device synchronous observation window, local thermal anomaly retention duration, and electrical anomaly repeated observation cycle; the above parameters are not changed within the current session; when parameters are adjusted, they are distinguished by the new parameter version number; The optimal viewing window for the door lock association is 10 seconds before and after, with a selectable range of 5 to 20 seconds. This setting is because there are usually several-second response differences between door lock actions, door opening / closing, and image triggering. Too short a time is insufficient to cover the complete action process, while too long a time can easily include irrelevant behaviors. The optimal upper limit for effective image delay is 30 seconds, with a selectable range of 10 to 60 seconds. This setting is because image capture typically involves significant latency after local caching, compression, and network transmission. A delay below 10 seconds can easily misjudge normal latency as invalid, while a delay exceeding 60 seconds weakens the correspondence with the current session sequence. The optimal viewing window for nearby device synchronization is 60 seconds before and after, with a selectable range of 30 seconds before and 120 seconds after. This setting is due to the presence of nearby heat sources, high-voltage equipment, and... The impact of mechanical equipment on the target power metering box typically exhibits transmission and dissipation lags. The optimal duration for localized thermal anomalies is 3 minutes, with a selectable range of 1 to 5 minutes. This setting is because localized poor contact or terminal heating usually has a continuous accumulation characteristic; durations shorter than 1 minute may easily misjudge instantaneous thermal disturbances as anomalies, while durations longer than 5 minutes may delay the identification of the true overheating state. The optimal period for repeated observation of electrical anomalies is 10 minutes, with a selectable range of 5 to 30 minutes. This setting is because minute-level repetitive fluctuations are more conducive to distinguishing between occasional disturbances and continuous repetitive anomalies. The above parameters can be adjusted within the appropriate range according to the installation environment, sampling cycle, communication method, and maintenance scenario of the target power metering box, and can be uniformly managed through parameter versions. After determining the parameter version, the authorization status is determined. The authorization status indicates whether the target energy metering box has legitimate operation and maintenance within the current session time window. The authorization status is: no authorization, valid authorization, authorization timeout, authorization revoked, and authorization pending verification. The authorization record must contain at least the following fields: authorization number, authorization type, authorization start time, authorization end time, authorized personnel ID, and permitted operation scope. When constructing a session, the authorization record related to the target box number is searched based on the current session time window. If a valid authorization exists and the authorization time window overlaps with the current session time window, the authorization status is determined as valid authorization and an authorization summary is written. If an authorization record exists and the current session time window exceeds the authorization end time, the authorization status is determined as timeout. If the current session trigger information, door lock pilot record, box door pilot record, or manual review record shows that manual operation has occurred, but no corresponding authorization record is detected, the authorization status is determined as authorization pending verification. If it has been revoked, the authorization status is determined as authorization revoked. Subsequent processing is based on this authorization status to ensure that anomaly interpretation always stays within the same authorization boundary. After confirming the authorization status, the process continues to determine the relationships with neighboring devices. These relationships characterize the set of devices surrounding the target energy metering box that may affect its thermal, magnetic, vibration, or visual state. They include at least the following fields: neighboring device number, device type, relative orientation, distance level, readable operating status marker, and typical impact type. The distance level can be categorized into three levels: nearest neighbor, second nearest neighbor, and far neighbor. 0 to 1 meter can be selected as nearest neighbor, 1 to 3 meters as second nearest neighbor, and 3 to 5 meters as far neighbor. This grading is used for filtering and prioritizing neighboring influence relationships and does not imply that there is no impact beyond the corresponding distance. The basis for this setting is that the effects of thermal radiation, magnetic induction, and mechanical vibration on the metering box typically decrease gradually with increasing distance, with the 0 to 3 meter range being the most affected. The impact within the range is more direct; if the neighboring device is a high-voltage device, heat source device, vibration device, or door movement device, it will be preferentially included in the nearest or second nearest neighbor range; when the session is established, only the neighboring device relationship corresponding to the current session time window is read, and the unrelated devices are not fully read to reduce resource consumption; if the general neighboring device relationship is missing, an unknown neighboring relationship mark is written in the session record, and a conservative judgment criterion is adopted in subsequent processing; if the current main trigger type is triggered by the operation change of the neighboring device, and the corresponding nearest or second nearest neighbor relationship record is missing, it is treated as a critical neighboring relationship missing, and the current state is set to the initialization pending review state; critical neighboring relationships can be selected as neighboring device relationships that are directly related to the main trigger and whose distance level is nearest or second nearest neighbor; After determining the object identifier, time caliber, parameter version, authorization status, and neighboring device relationships, an initial status identification session record is generated. This initial record must include fields such as session number, target enclosure number, main trigger type, session start time, session end time, object identifier summary, time caliber summary, parameter version number, parameter snapshot index, authorization status summary, neighboring device relationship summary, and current status. After a successful session establishment, the current status can be selected as the pending data collection and verification status, proceeding to subsequent data verification and time processing. If trigger conflicts, blocking object conflicts, missing time fields, no valid parameter version, authorization status conflicts, or missing key neighboring relationships occur, an initial anomaly record is generated, and the current status is selected as the initial pending verification status. This initial anomaly record must include fields such as anomaly type, discovery time, involved fields, original record index, and whether subsequent processing is blocked. Blocking anomalies are not processed further; data corresponding to both blocking and non-blocking anomalies are only retained as auxiliary records and are not the sole basis for object consistency approval or anomaly exclusion. State constraints are imposed. During session establishment, the target energy metering box is set to a pending trigger state, a trigger receiving state, a session establishment state, a boundary determination state, and a data collection and verification state. When trigger conflicts, blocking object conflicts, or invalid parameter versions occur, it enters the initialization pending verification state. After the abnormal fields are completed, conflicts are eliminated, and the parameter versions are restored to validity, it enters the session establishment state or the boundary determination state. When the authorization state is valid or pending verification, an authorization background marker is added to the session summary. When the proximity relationship is unknown, the current session continues to flow in a non-blocking state. In subsequent processing, the current session initialization state and boundary integrity state are identified based on the session summary. Regarding time and resource control, the trigger merging process can be completed within 3 seconds of receiving the trigger record, and session establishment and boundary determination can be completed within 10 seconds. When the processing time exceeds 10 seconds but does not exceed 30 seconds, the session is allowed to continue forming, and an initialization delay flag is written. When the processing time exceeds 30 seconds, the current session value is set to the initialization pending review state, and it does not directly enter the normal anomaly identification process. The basis for the above time settings is that trigger merging is a pre-processing deduplication process, which usually only requires a short processing time. After session establishment and boundary determination exceed 10 seconds, the correspondence with the real-time state begins to weaken; after exceeding 30 seconds, the initial state and the real-time state become incompatible. The temporal correspondence between time changes is further reduced; the proximity relationship reading range can optionally cover the nearest and second nearest neighbor devices, and the distant neighbor devices are only included in the current session when the main trigger is a change in the operation of the neighbor device; the parameter snapshot record includes at least the core time slice length, session duration, door lock associated observation window, image effective delay limit, neighbor device synchronization observation window, local thermal anomaly retention duration, electrical anomaly repeated observation cycle, etc., and only saves the key parameters actually used in the current session to reduce storage and transmission burden, forming the initial record of state identification session, which can be called later for object consistency verification, link validity verification and time alignment.
[0018] Specifically, such as Figure 3As shown: Data entering the current session is received using a consistent original acquisition message structure. The original acquisition message includes at least the enclosure number, acquisition point number, acquisition item type, acquisition time, reception time, current value, status bit, validity bit, local cache bit, and message sequence number. The enclosure number is compared with the target enclosure number in the current session, and the acquisition point number is compared with the list of valid acquisition points for the target enclosure. The acquisition item type corresponds to voltage, current, magnetic field, temperature, humidity, door lock status, enclosure door status, video capture index, and manual recording. The acquisition time corresponds to the actual sampling time of the terminal, the reception time corresponds to the remote side reception time, the current value corresponds to the measured value for numerical acquisition items, the status code for status acquisition items, and the capture index identifier and clarity status for video acquisition items. The status bit corresponds to the current working status of the acquisition point, and the validity bit... For the availability judgment of the corresponding message on the terminal side, the local cache distinguishes between real-time transmission and delayed retransmission; the message sequence number corresponds to the order of messages at the same collection point; the status code includes encoding states such as available on, off, normal, abnormal, alarm maintenance, and recovery; different collection items share the same field structure, distinguished only by the collection item type and the representation of the current value; if the message lacks any key field in the box number, collection time, or collection item type, it will not enter the core timing construction of the current session, but will be written to the abnormal message registration record; the abnormal message registration record includes at least the abnormal message number, missing field type, discovery time, original message index, and supplementation status; after the key fields are completed, the abnormal message can re-enter the object consistency verification; if not completed, it is only recorded as abnormal input and does not participate in the current session judgment; After the initial data acquisition message is received, a session data buffer is first established. The session data buffer includes at least the following fields: session number, target enclosure number, session time window, and message index. The session number and target enclosure number are used as the primary indexes, and the session time window is used as the primary time boundary. Only messages falling within the session time window and its adjacent acceptance time window are accepted. To avoid truncating critical state changes at the start and end of the session, a pre-acceptance time window and a post-acceptance time window are set. The pre-acceptance time window can be selected as 30 seconds, with a range of 10 to 60 seconds. The reason for this setting is that door lock actions, current changes, and magnetic field fluctuations may have a lead time of several seconds to tens of seconds before triggering. Leading changes; when the value is less than 10 seconds, it is not conducive to retaining leading changes; when the value is greater than 60 seconds, it is easy to introduce historical states that have no direct correspondence with the current session; the post-acceptance time window can be selected as 60 seconds, with an selectable range of 30 seconds to 120 seconds. The reason for this setting is that there are usually delays of tens of seconds in image capture, wireless link uploading, and local buffer retransmission; when the value is less than 30 seconds, it is not conducive to accepting normal delayed messages; when the value is greater than 120 seconds, it will reduce the temporal correspondence between messages and the current session; after the session data buffer is established, object consistency verification is performed first, followed by link validity verification and time alignment, in order to avoid data from different objects being mixed into the same temporal record; Object consistency verification revolves around the object identifiers already identified in the current session. It confirms that data entering the session corresponds to the target energy metering box, and not originates from other boxes, other locations, or old locations with outdated records. Object consistency verification includes at least box number consistency verification, collection point attribution consistency verification, message sequence number continuity verification, and loop attribution consistency verification. When performing box number consistency verification, the box numbers in the original collection messages are compared line by line with the target box numbers; discrepancies are recorded as object conflict messages. When performing collection point attribution consistency verification, the collection point numbers are matched line by line with the current list of valid collection points; those not in the list are recorded as point out-of-bounds messages. Message sequence number continuity verification... During continuous verification, the message sequence number is checked at the same collection point to see if it maintains a unidirectional increase or jumps within a tolerable range. Continuous regression or repeated playback is considered an abnormal sequence. When performing loop attribution consistency verification, for collection items with loop attributes such as voltage and current, it is checked whether their loop number is within the range of the incoming and outgoing loops corresponding to the object identifier. The object consistency verification window can be set to 20 consecutive messages, with a range of 10 to 30 messages. The reason for this setting is that 20 consecutive messages can cover the basic upload stability of the same collection point in a short period of time. Less than 10 messages are not conducive to identifying persistent object conflicts, and more than 30 messages will increase verification delay and introduce unnecessary data volume. When all container numbers in the verification window are consistent, all collection points can be found in the list of valid collection points, message sequence numbers do not show consecutive backwards, and loop ownership does not exceed the boundary, the object consistency is deemed successful. When any message comes from a different container number, or when the collection point number of three or more consecutive messages is not in the list of valid collection points, or when the message sequence number of the same collection point shows consecutive backwards, the object consistency is deemed unsuccessful. The reason for using three or more consecutive out-of-bounds points as a failure condition is that a single abnormal point may be caused by a momentary mapping error or cache misalignment, while three or more consecutive out-of-bounds points better reflect stable object anomalies. Messages that fail object consistency are not directly deleted, but are written into the object's context. The list of conflicting messages should include at least the conflict type, time of occurrence, corresponding collection point, original sequence number, conflict value, and whether the current session is blocked. If the conflict is only a single, occasional message and does not reappear in subsequent verification windows, the current session is allowed to continue, and the message is retained only as supplementary evidence. If the conflict occurs continuously or the blocking condition is met, the current session status will be changed to the object pending review status, and normal timing construction will no longer continue. Object conflicts, missing key fields, or stable mismatch of core collection items can be treated as blocking conditions. Single abnormal messages, short-term link jitter, or partial pending supplementation can be treated as non-blocking conditions and retained only as supplementary evidence. After the object consistency verification passes or the non-blocking fault tolerance condition is met, a link validity check is performed. This check distinguishes between real state changes and abnormal data collection links, ensuring that each data entry in subsequent session timing records carries a callable credibility marker. The link validity check does not rely solely on the validity bits in the message; instead, it comprehensively assesses the validity based on sampling period, continuity, timing rationality, state bit changes, duplicate uploads, local cache characteristics, and value retention characteristics. The link validity check rules include at least the sampling period, allowed interruption duration, maximum latency tolerance, value retention anomaly detection window, and duplicate upload detection window. The sampling period for voltage and current can be selected as 2 seconds, ranging from 1 to 5 seconds, with an allowable interruption duration of 15 seconds, ranging from 5 to 30 seconds; the sampling period for magnetic field can be selected as 2 seconds, with an allowable interruption duration of 10 seconds; the sampling period for temperature and humidity can be selected as 10 seconds, ranging from 5 to 30 seconds, with an allowable interruption duration of 60 seconds, ranging from 20 to 120 seconds; the sampling period for door lock status and cabinet door status can be selected as 1 second, with an allowable interruption duration of 5 seconds; video capture uses an event-triggered method, with a maximum latency tolerance of 30 seconds, ranging from 10 to 60 seconds. The above values are based on the following: voltage and current are fast variables; excessively long interruptions weaken the ability to represent continuous electrical states, while excessively short interruptions can easily misjudge short-term communication jitter as link anomalies. Magnetic field disturbances typically have short-term continuity; after an interruption of more than 10 seconds, the correlation between segments before and after will significantly decrease. Temperature and humidity change relatively slowly; 10-second sampling can cover general environmental change trends, and allowing an interruption of 60 seconds is beneficial for maintaining the continuity of slow variables under conditions of slight communication fluctuations. Door lock status and cabinet door status are fast variables of action type; second-level sampling is beneficial for preserving the opening and closing sequence, and allowing an interruption of 5 seconds is used to accommodate short-term link jitter. Video capture usually involves buffering, compression, and uploading, resulting in significant latency; if the latency is too long, it will weaken the correspondence with the current session time slice. The above link verification thresholds are written into the parameter snapshot or link verification rules corresponding to the current session and remain unchanged in this round of the session. During link validity verification, the collection point number and collection item type are used as grouping units. Each group of messages undergoes sequential checks for continuity, timing rationality, status bit consistency, and value retention anomaly. If a collection group does not receive a new message within the allowed interruption period, the current link status is marked as pending. If a collection group experiences a significant value jump within a short period, and the status bit changes from normal to abnormal or the validity bit mismatches, the current link status is marked as suspicious. If the same collection point continuously experiences clock rollback, message sequence number reversal, the same value remaining unchanged for a long time, repeated uploading of the same message, or the local buffer bit remaining open for a long time, the collection group is marked as a link drift candidate. For example, for temperature acquisition, if the same temperature point has completely consistent values within three consecutive sampling periods, while other related temperature points in the same enclosure, the ambient temperature background, or the enclosure door status have changed, the temperature point is adjusted from valid to acceptable. The reason for using three consecutive sampling periods is that while one or two periods remaining unchanged may indicate a natural stable state, three consecutive periods remaining unchanged are more likely to reflect probe jamming or upload stagnation. For example, in door lock or door magnetic sensor acquisition, if three consecutive flips (open, close, open) occur within one second, and there is no reasonable transition between the door lock state and the door state, the record is recorded as a jitter candidate. This time and number condition is used because normal door movements typically do not result in three valid state transitions within such a short time. Furthermore, for video capture, if the capture time is more than 30 seconds later than the trigger time, or the clarity status is severely blurred, the video entry is only used as supplementary evidence and not as the sole basis for the core judgment of the current session. The 30-second time limit is used because video capture usually involves buffering, compression, and upload delays, but excessive delays weaken its correspondence with the current time sequence. Link status can be divided into four categories: valid, suspicious, pending, and invalid. Valid indicates that it can be directly used for subsequent core judgments; suspicious indicates that it is reserved as an auxiliary basis; pending indicates that the current data is temporarily missing or delayed, and will be compensated after subsequent retransmission; invalid indicates that the data is no longer used in the current session. If a collection group changes from valid to suspicious and then to pending twice in a row during the current session without recovery, it can be directly downgraded to invalid. Data that can be used as the core basis includes at least data formed by valid link status entries that do not have object conflicts, timing misalignments, or exceed the capacity limit; the remaining data is reserved as an auxiliary basis. After verifying the link validity, time alignment is performed. Time alignment is based on the core time slice determined by the current session, mapping packets with different sampling periods, delay characteristics, and event granularities to a unified time axis. During time alignment, the acquisition time is used as the merging criterion; the reception time is only used to identify delay attributes and is not used as the primary sorting criterion to avoid local buffer retransmissions or network jitter altering the original timing. The core time slice length can be selected as 2 seconds. When the current session has determined other time slice lengths, the current session's criteria are used. For high-frequency acquisition items such as voltage, current, door lock, and cabinet door status, when multiple valid packets exist within the same time slice, the packet with the acquisition time closest to the end time of that time slice is taken as the master record, and the remaining packets are treated as master records. As an additional record, it is retained to record whether there is duplicate transmission; if there is no valid message but there is a suspicious message in the same time slice, the suspicious message is retained and a suspicious mark is written; if there is neither a valid message nor a suspicious message in the same time slice, but there is a valid value in the previous time slice and the acceptance time does not exceed the acceptance limit, the valid value of the previous time slice is used for acceptance; the acceptance limit for high-frequency acquisition items can be selected from 1 to 3 sampling periods. For example, the acceptance limit for voltage and current can be 6 seconds. The reason is that after more than 3 typical sampling periods, the old value’s ability to represent the current electrical state will be significantly reduced; the acceptance limit for door lock and cabinet door status can be 3 seconds. The reason is that action-type status changes quickly, and a long acceptance time will mask the actual opening and closing switching; For low-frequency data collection items such as temperature and humidity, if no new message is available in the current time slice, the most recent valid value can be used to carry over the data, and the carrying over duration and source should be recorded. The carrying over limit for low-frequency data collection items can be 90 seconds, with a selectable range of 30 to 180 seconds. The rationale is that slow variables such as temperature and humidity have a certain inertia, and moderate carrying over helps maintain the integrity of the time sequence. However, carrying over for too long will cause the old value to lose its current reference significance. When the carrying over duration exceeds the carrying over limit, the corresponding entry in that time slice will no longer use the old value and will be put into a pending state. For video capture and other event-type messages, the capture time is mapped to the corresponding time slice, and additional information corresponding to the message is written, including at least the capture index, clarity status, delay status, and whether it is used as an auxiliary basis. Through the above processing, a unified time slice record for subsequent judgment can be formed without changing the original time sequence relationship. For retransmission messages with local cache enabled, time-slice compensation records are used. When the acquisition time of a retransmission message falls within the original time slice, the original time slice result is not directly rewritten, but written into the time-slice compensation record. The time-slice compensation record includes at least the original time slice number, retransmission message index, retransmission acquisition time, retransmission reception time, and impact judgment flag field. If the retransmission message completes the original missing item, the time-slice link status is corrected during the session end compensation review. If the retransmission message does not match the original time-slice master record, the original record is retained, and the retransmission content is reviewed first during subsequent recovery observation, ensuring the original timing is stable. After time alignment, the session timing records are recorded. The session timing records are organized by time slices. Each time slice includes at least the following fields: time slice number, time slice start time, time slice end time, voltage entry, current entry, magnetic field entry, temperature entry, humidity entry, door lock entry, cabinet door entry, video entry, object conflict marker, pending supplement marker, suspicious marker, and link status summary entry. Each acquisition item entry, in addition to the current value, includes at least the acquisition item type, link status, whether it is accepted, acceptance duration, whether it is attached, whether it is compensated, and whether it is real-time transmission. Voltage and current entries may also include voltage loops or phases, and video entries may include image index, clarity status, delay status, and auxiliary evidence markers. The session timing records are directly used for subsequent anomaly source verification, retaining the credibility, acceptance relationship, and compensation relationship corresponding to each time slice to distinguish between core evidence and auxiliary evidence. Generate a link status summary record. The link status summary record is organized by collection item type or collection point number, including the number of valid records, the number of suspicious records, the number of records to be supplemented, the number of failed records, the longest continuous interruption duration, the value retention anomaly flag, the clock rollback flag, the duplicate upload flag, and whether it affects the core judgment field of the current session. If a core collection item is missing throughout the entire session, such as the door lock being missing for the entire time or the cabinet door being continuously abnormal, the core link missing flag will be written into the link status summary record. During subsequent review, the core collection item will be handled conservatively, without excluding the anomaly of the collection item. If video collection is missing, the video entry will not be directly used as the basis for judging whether the entry behavior is valid or invalid. Instead, it will be compared in combination with the door lock, cabinet door, and magnetic field entries. The link status summary record indicates the availability status of each collection item in the current session. In the boundary conditions, if a certain data acquisition item suddenly becomes missing during a session, and the missing time does not exceed the allowed interruption duration, the time slice is marked as pending and the current session continues. The link status of this data acquisition item in the remaining sessions is suspicious or failed. If a large number of duplicate uploads occur at the same data acquisition point and the message sequence number remains unchanged, only the first message is retained as the master record, and the remaining duplicate upload records are written into the duplicate upload record. If a large batch of buffered retransmissions spans several processed time slices, the current session remains unchanged, and a compensation pending review mark is written. These are reviewed uniformly after the session ends or processed first during the recovery observation period. If two or more core data acquisition items fail in the same time slice, the time slice is marked as low confidence. The core data acquisition items can be any two or more of voltage, current, door lock status, cabinet door status, and temperature. The basis for using the failure of two or more core data acquisition items as a judgment condition is that the failure of a single data acquisition item may only reflect a local link anomaly, while the simultaneous failure of multiple core data acquisition items indicates a decrease in the overall confidence level of the current time slice. The low confidence time slice is only used as an auxiliary basis and is not used as the basis for the establishment of an anomaly. Regarding real-time performance and resource control, the processing time for object consistency verification can be selected to be within 5 seconds, the processing time for link validity verification can be selected to be within 10 seconds, and the processing time for time alignment and session timing record generation can be selected to be within 15 seconds, with the overall processing time set to be within 30 seconds. The basis for these time settings is as follows: object consistency verification needs to complete object filtering as quickly as possible to prevent abnormal object data from entering subsequent processing; link validity verification needs to cover short-term data accumulation intervals to form a continuity judgment; time alignment and session timing record generation need to ensure that key time slices are formed in a timely manner; when the overall processing time exceeds 30 seconds, the correspondence between the current timing result and the real-time state will be significantly weakened.
[0019] After the session timing record is formed, abnormal segments are extracted first, and then excluded and reviewed according to natural disturbance, legitimate operation and maintenance, nearby devices, and sensor link drift. Then, the abnormal changes that were not excluded after the exclusion and review are judged by timing association and confirmed by continuity. The current session input should include at least the session number, target enclosure number, session timing record, link status summary record, parameter snapshot record, authorized status summary record, and neighboring device relationship summary record. The session timing record is arranged according to time slices, and each time slice should include voltage, current, magnetic field, temperature, humidity, door lock, enclosure door, video, and link status, acceptance status, and compensation status fields. The parameter snapshot should include at least environmental screening parameters, authorized observation parameters, neighboring influence parameters, link drift judgment parameters, and anomaly retention parameters. The exclusion review order can be set as natural environmental disturbance, legitimate operation and maintenance, neighboring device influence, and sensor link drift. The main reason for this order is that natural environmental disturbance generally has a large impact range and fluctuates, legitimate operation and maintenance has clear authorized boundaries and time boundaries, neighboring device influence has external coupling, and sensor link drift has already been marked with link status in the previous sequence, so placing it last is more conducive to combining with anomaly segments for separation. Using a fixed order for session processing can ensure that the exclusion order of sessions under the same parameter version can be kept consistent, avoiding inconsistencies in results due to changes in the exclusion order. First, abnormal changes are extracted from the session time sequence records. Using time slice intervals as the basic unit of expression, abnormal segment records are constructed by combining the type of collected items, the direction of change, the duration, and the link status. Each abnormal segment record includes at least the segment number, start time slice, end time slice, collected item, evidence level, and link credibility. Evidence levels are divided into three levels: high, medium, and low. A high level indicates that the abnormal segment is mainly composed of valid items, forming a chain of related abnormalities. A medium level indicates that the abnormal segment is supported by valid and suspicious items. A low level indicates that the abnormal segment is supported by suspicious items, items to be supplemented, or low-credibility time slices. Link credibility is also divided into three levels: high, medium, and low. A high level indicates that the time slice is mainly composed of valid items. A medium level indicates that a certain proportion of suspicious and items to be supplemented exist within the time slice. A low level indicates that the time slice is mainly composed of items to be supplemented, invalid items, or low-credibility time slices. The revised statements are more concise, and the terminology is closer to the common writing style in manuals, without affecting the sufficiency of disclosure. Anomaly segments can be categorized by anomaly type. Electrical anomaly segments can be formed by a continuous deviation of voltage, current, or phase relationship from the current operating parameters within a continuous time frame. Phase relationship anomalies are changes in phase sequence, phase correspondence, or circuit correspondence that are inconsistent with the session object identifier. Local thermal anomaly segments can be formed by a continuous increase in local temperature relative to other measuring points in the same enclosure or the current environmental parameters. Entry-related anomaly segments can be formed by at least two types of changes in door locks, enclosure doors, video, or magnetic fields forming a corresponding relationship within a short time window. Video-assisted anomaly segments can be formed by changes in personnel approaching or obstruction in the video, or changes in enclosure door opening and closing. Anomaly segments supported by all failure entries are written into the low-confidence anomaly list and are not included in the core exclusion. Anomaly segments that have not passed continuous confirmation but are still changing are written into the observation candidate list. Anomaly segments that have passed continuous confirmation are written into the confirmed candidate list. After anomaly segment records are formed, subsequent processing revolves around the continuous anomaly interval. Natural environmental disturbance elimination verification is prioritized. This verification is based on the environmental type of the target power metering box, the temperature and humidity change patterns in the session timeline, the consistency of multiple temperature points, the box door status, the door lock status, and the concurrent voltage and current changes. The environmental type can be selected as outdoor sunny, outdoor shady, semi-enclosed passage, underground distribution room, indoor equipment floor, and high humidity location. Different environmental types correspond to different environmental judgment criteria. The environmental temperature rise criterion can be determined based on the sunlight intensity, ventilation conditions, and heat dissipation conditions of the installation location. For outdoor sunny environments, a temperature rise of 3°C to 8°C within 15 minutes during midday is acceptable. For indoor equipment floors, a temperature rise of no more than 1°C is acceptable. Temperatures exceeding 3°C are acceptable, but for underground electrical distribution rooms, the temperature increase should not exceed 2°C. This temperature range is used as the criterion for excluding environmental disturbances in the current session and is recorded via parameter snapshots. The reason for using this range is that outdoor sunny environments are significantly affected by solar radiation, and their overall temperature rise is typically higher than that of indoor equipment floors and underground electrical distribution rooms. Underground electrical distribution rooms have relatively stable ventilation, and environmental fluctuations are usually small. The humidity range can be determined based on the degree of environmental enclosure, air exchange conditions, and external weather changes. For example, a 5% to 15% increase in humidity within ten minutes in a high-humidity environment can be considered a short-term environmental humidity disturbance range. This humidity range is used for excluding environmental disturbances and is not considered an absolute upper limit for humidity changes. When verifying the elimination of natural environmental disturbances, not only are the amplitudes of the changes compared, but also their distribution and rhythm. If multiple temperature points show a similar direction, similar amplitude, and a gentle slope of increase in a continuous time slice, and the door lock, cabinet door, current, and magnetic field do not show synchronous abnormal changes, then the corresponding temperature rise segment is recorded as a candidate for environmental disturbance. If the increase in humidity is consistent with rainy days, high humidity backgrounds, or ventilation changes, and is not accompanied by local electrical or thermal anomalies, then the corresponding humidity change is recorded as a candidate for environmental disturbance. If the temperature rise is concentrated at a single local measuring point, or if the temperature rise is consistent with local current changes... If the environmental disturbance is insufficient to explain the anomaly, the environmental exclusion observation window is preferably 15 minutes, with a selectable range of 5 to 20 minutes. The reason for using this time range is that a time frame shorter than 5 minutes is not conducive to observing the formation and stabilization process of environmental disturbances, while a time frame longer than 20 minutes is prone to introducing background states that are not directly related to the current anomaly. If an anomaly segment can be explained by environmental factors within the observation window, it is marked as environmental exclusion. If only a portion of the time slice can be explained by environmental factors, only that portion is excluded, and the remaining unexplained portions are retained. After eliminating natural environmental disturbances, a legitimate operation and maintenance check is performed. This check is based on the authorized status summary record, authorized time window, authorized type, allowed operation range, and door lock, cabinet door, video, and electrical change entries in the session sequence record. The pre-authorization observation duration follows the authorized observation parameters in the current session and can be set to 5 minutes. The post-authorization observation duration follows the authorized observation parameters in the current session and can be set to 20 minutes. The door lock and cabinet door action association observation window follows the door lock association observation window in the current session and can be set to 10 seconds before and after. The upper limit of video effective delay follows the upper limit of image effective delay in the current session and can be set to 30 seconds. The above time settings are based on the following: the pre-authorization observation duration is used to cover the operation preparation stage and identify anomalies that existed before authorization; the post-authorization observation duration is used to cover the state stabilization stage after the operation is completed; the door lock and cabinet door action association observation window is used to cover the short-term response difference between door lock action and cabinet door opening and closing; and the upper limit of video effective delay is used to cover the normal delay generated during image capture, buffering, transmission, and reception. When an authorization is valid in a session, the authorization time window is first mapped to the session time slice, and then a consistency comparison is performed on door lock actions, cabinet door changes, video indicators, and electrical changes. For example, if the authorization type is meter reading verification, short-term door opening, personnel approach, and slight obstruction are allowed, but the duration of local thermal anomalies still follows the duration of local thermal anomalies in the current session and is not changed due to the existence of authorization. If the authorization type is meter replacement, longer door opening, short-term current fluctuations, and multiple door lock actions are allowed, but stability should be gradually restored after the operation is completed. If the door lock actions, cabinet door changes, and video indicators all fall within the authorized range... If the time window is specified and the electrical change matches the authorized operation type, the corresponding abnormal segment is classified as a legitimate maintenance impact candidate. If an authorization record exists, but the door lock action occurs after authorization has ended, or the authorization type does not match the actual behavior, it is recorded as an authorization conflict candidate and is not eliminated. Authorization conflict candidates are retained as background conditions in subsequent time-series correlation judgments and are not directly used as the basis for elimination, but can be used as auxiliary conditions for the absence of valid authorization background in subsequent abnormality source and abnormality type judgments. If the current session authorization status is no authorization, authorization revoked, or authorization pending verification, the abnormality is not eliminated using the legitimate maintenance approach. After completing the legitimate maintenance operation and troubleshooting, a review of the impact of neighboring devices is performed. This review focuses on the summary of neighboring device relationships identified in the current session, and compares them synchronously with temperature changes, magnetic field changes, video background changes, and neighboring device operation changes recorded in the session's timeline. The neighboring device synchronous observation window can be set to 60 seconds before and after, with a range of 30 seconds before and 120 seconds after. The basis for this time frame is that the thermal, magnetic, or vibration effects of neighboring heat sources, high-voltage equipment, and mechanical equipment on the target enclosure typically have transmission and dissipation lags. A window shorter than 30 seconds is not conducive to covering the influence transmission process, while a window longer than 120 seconds will reduce the correspondence with the current anomaly. The impact dissipation observation time can be set to 2 minutes, with a range of 30 seconds to 5 minutes. The basis for this time setting is that after neighboring devices stop, there is usually a short-term residual heat, magnetic, or vibration. The impact of the change is considered. If the change persists for more than 2 minutes after recovery, it indicates that the anomaly has exceeded the short-term residual range of the neighboring influence. If the target enclosure experiences temperature rise, magnetic field enhancement, or other externally induced changes, and the nearest or second-nearest neighboring devices are starting up, stopping, switching loads, increasing heat dissipation, or mechanically moving within the synchronous observation window, while the voltage, current, door lock, and door status of the target enclosure itself do not show corresponding changes, then the anomaly segment is recorded as a candidate for influence from neighboring devices. For example, starting an air conditioner outdoor unit can cause a temperature rise on the enclosure surface, and putting an inverter into operation can cause local magnetic field fluctuations. After a candidate for influence from neighboring devices is formed, the observation of the impact fading continues. If the corresponding anomaly segment of the target enclosure weakens or disappears synchronously after the neighboring devices stabilize, then the exclusion is determined. If the anomaly segment persists after the neighboring devices stabilize, then the neighboring devices are deemed insufficient to explain the anomaly. After eliminating natural environmental disturbances, legitimate operation and maintenance, and the influence of nearby equipment, a sensor link drift exclusion review is conducted. The exclusion review is based on at least the link status summary record and the link status distribution within the corresponding time slice of the abnormal segment. If an abnormal segment consists only of suspicious items, items to be supplemented, or low-confidence time slices, and there are no other valid acquisition items constituting the corresponding changes within the same time slice, then the abnormal segment is excluded as a link drift candidate. If the magnetic field probe shows an isolated spike, and the door lock, cabinet door, current, and video are all stable, and the link status summary record shows that the corresponding magnetic field acquisition point has repeated abnormal status bits and repeated uploads, then the abnormal segment is excluded as magnetic field link drift. If the door magnet flips continuously and rapidly, and the door lock status remains unchanged, and the door does not move in the video, then the abnormal segment is excluded as door magnet jitter. If the link drift can explain all the remaining abnormal segments, then the current session takes the dominant link abnormality state, generates a link abnormality description record, and does not write it into the main body abnormality candidate record. If only some abnormal segments can be explained, then only the explainable abnormal segments are excluded, and the unexplained parts are left for judgment. After four rounds of elimination and review, time-series correlation judgment is performed on the anomaly segments that were not eliminated. This judgment identifies whether there is a sequential relationship between the anomaly segments that conforms to the anomaly evolution pattern of the target energy metering box. The anomaly correlation observation window can be set to 120 seconds before and after, with a selectable range of 30 to 300 seconds. This time frame is based on the fact that entry behavior, electrical changes, and local thermal changes typically form a connection within tens of seconds to several minutes. A time frame shorter than 30 seconds is not conducive to covering the response differences between adjacent anomaly segments, while a time frame longer than 300 seconds easily merges changes without direct correlation into the same anomaly chain. The connection mode is based on the common anomaly evolution patterns of the target energy metering box. The sequence is pre-defined, including at least the following patterns: entry behavior precedes electrical changes, electrical changes precede local thermal anomalies, and magnetic field anomalies occur simultaneously with door lock actions, followed by changes in the cabinet door or video approach. During judgment, the remaining anomaly segments are first sorted by their first occurrence time, and then it is checked whether different anomaly segments meet the pre-defined succession pattern. If two or more anomaly segments correspond to each other within the associated observation window, and their sequential relationship conforms to actual physical and operational logic, they are merged into an associated anomaly chain and assigned an associated anomaly chain number. If an anomaly segment has no corresponding anomaly segment within the associated observation window, it is recorded as an isolated anomaly. The evidentiary weight of associated anomaly chains is higher than that of isolated anomalies. After the timing correlation judgment is completed, a persistence confirmation is performed to distinguish between short-term, occasional fluctuations and valid abnormal changes. Different types of anomalies use different persistence criteria. Electrical-side anomalies can be selected as those that maintain the same direction of anomaly for at least 7 out of 10 consecutive core time slices, or those that repeat more than 3 times within 10 minutes. The rationale for setting the above criteria is that this ratio can balance continuous identification and transient noise suppression. Below this ratio, short-term fluctuations are more likely to be misjudged as persistent anomalies. Local thermal anomalies can be selected as those that last for more than 3 minutes, with a selectable range of 1 to 5 minutes. This time length is used to distinguish between transient thermal disturbances and persistent local heating, and the current session is used. The duration of localized thermal anomalies; enclosure entry anomalies can be selected as at least two types of changes in door locks, enclosure doors, video, or magnetic fields that occur within 30 seconds; the reason for setting the 30-second acceptance window is that this time range can cover common short-term response differences between door lock actions, enclosure door opening and closing, video proximity, and magnetic field changes; if anomalies related to proximity effects continue to persist for more than 2 minutes after the proximity device has recovered and stabilized, they are no longer attributed to the proximity device; continuously confirmed anomaly segments or associated anomaly chains are written into the confirmed candidate list, while those that fail to pass but still have continuing changes are written into the observation candidate list, in order to avoid short-term noise or instantaneous fluctuations directly entering the final anomaly judgment; The current session output includes excluded review records and abnormal candidate records; excluded review records include at least the abnormal segment number, excluded factors, time slice interval, parameter version used, exclusion range, and explanation of the unexcluded parts; abnormal candidate records include at least the abnormal segment number, first occurrence time, duration, associated abnormal chain number, persistence status, evidence level, and priority for subsequent judgment.
[0020] Specifically, such as Figure 4 As shown: After excluding the review record, anomaly candidate record, session timing record and link state summary record in the current session, the anomaly candidates that have been excluded but passed continuous confirmation are finally judged, and anomaly handling information and recovery observation information are generated. The minimum inputs required to enter the current session include the session number, target enclosure number, exclusion review record, anomaly candidate record, session timing record, link status summary record, parameter snapshot record, authorization status summary record, and neighboring device relationship summary record. The exclusion review record indicates what factors explain each anomaly segment, which time slices are excluded, and which parts are still unexplained. The anomaly candidate record indicates the first occurrence time, end time, associated anomaly chain number, persistence status, and current evidence level of the unexcluded anomaly segment. To facilitate handling, recovery, and confirmation, a conclusion record needs to be established. The session conclusion record should include at least the session number, target container number, anomaly source, anomaly type, anomaly level, main anomaly chain, secondary anomaly chain, initial confirmation time, current session status, main basis, excluded factors, suggested processing path, recovery observation information, session end information, and history write-back information. The secondary anomaly chain can be any other related anomaly chain that is not identified as the main anomaly chain but still has an independent anomaly succession relationship. The current session status can be pending judgment, judged, pending recovery observation, recovery failed, or closed loop. The session end information can be judged and ended, pending recovery observation ended, interrupted and ended, recovery failed and ended, or closed loop ended. The history write-back information should include at least the write-back time, write-back type, associated session number, and associated anomaly chain number. After the session conclusion record is established, it should be processed in the order of anomaly source determination, anomaly type determination, anomaly level determination, anomaly processing information generation, recovery observation information generation, and history write-back, and written into the same session conclusion record. First, determine the source of the anomaly. The source can be selected from anomalies in the target enclosure itself, environmental disturbances, legitimate maintenance impacts, impacts from nearby devices, sensor link anomalies, or a combination of these. If all anomaly segments in the current session have been explained by the natural environment, legitimate maintenance, nearby devices, and sensor links, the anomaly source belongs to the corresponding category. If there are still anomaly candidates that have not been ruled out and have been continuously confirmed, first determine the main anomaly chain. The main anomaly chain is the anomaly chain in the current session that covers the most time slices, has the most associated anomaly segments, the highest degree of continuous confirmation, and the highest level of evidence. When multiple anomaly chains have similar numbers of time slices covered, prioritize the anomaly chain with the highest degree of continuous confirmation as the main anomaly chain. When the degree of confirmation is the same, the anomaly chain that was first formed earlier is selected as the main anomaly chain; if the main anomaly chain points to an electrical state anomaly, local thermal anomaly, or an anomaly inherited change after unauthorized entry, then the source of the anomaly is an anomaly of the target enclosure itself; if some anomaly segments have been explained by external factors, but a persistent high-level anomaly chain is still retained, then the source of the anomaly is a composite source; if the anomaly chain is not retained, but the time slice covered by a certain external source is significantly higher than that of other external sources, then that external source is taken as the main source; sensor link anomalies indicate that the current session is mainly dominated by the acquisition link, upload link, or sensor anomalies; acquisition reliability anomalies indicate that there are signs of anomalies, but the existing evidence is insufficient to directly confirm the type of anomaly; To ensure the reproducibility of anomaly source identification, a source coverage ratio is set. The source coverage ratio is the proportion of the number of time slices corresponding to a certain source to the total number of anomaly time slices. If the coverage ratio of a certain source reaches 70% or more, then the source is directly identified as the primary source. If the coverage ratios of two sources each exceed 30%, and both have anomaly segments of medium or higher level, then they are identified as a composite source. If no external source reaches 30%, but there is a continuously confirmed ontological anomaly chain, then it is still identified as a target container ontological anomaly. The basis for setting the above ratio is: 70% is used to ensure that the primary source has a clear dominant role in the anomaly time slices in the current session, and 30% is used to ensure that each source in the composite source has a stable supporting role, thereby avoiding misjudging scattered interference as independent sources. After identifying the source of the anomaly, the anomaly type is determined. The anomaly type reflects the specific manifestation of the current anomaly at the target energy metering box's status level and can be categorized into five types: electrical status anomaly, local thermal anomaly, box entry anomaly, data acquisition reliability anomaly, and composite anomaly. Electrical status anomalies can indicate continuous anomalies in voltage, current, phase relationships, circuit relationships, or load changes, and this anomaly has ruled out environmental disturbances, authorized operations, the influence of nearby equipment, and link drift. Local thermal anomalies can indicate a continuous increase in a local temperature point or adjacent temperature zone inside the box, and this increase is unrelated to overall environmental changes, nearby heat sources, and legitimate maintenance. Box entry anomalies can indicate changes in access caused by monitoring items such as door locks, box doors, video, and magnetic fields without valid authorization, with authorization timeouts, or authorization conflicts. Data acquisition reliability anomalies can indicate the existence of anomaly signs, but the core items supporting these signs mainly come from suspicious items and items awaiting supplementation. A single item or a low-confidence time slice is insufficient to directly identify an ontological anomaly; a composite anomaly can be used to indicate that two or more anomaly types form a chain of related anomalies with a sequential relationship within the same session; when determining the anomaly type, first read the composition of the acquisition items involved in the main anomaly chain and their sequential order; if the main anomaly chain is mainly composed of changes in current, voltage, or phase, accompanied by a small amount of thermal changes, but the thermal changes do not meet the conditions for independent maintenance, it can be preferentially identified as an electrical state anomaly; if the main anomaly chain is mainly composed of local temperature rise, and the temperature rise time slice accounts for more than 60% of the main anomaly chain time slice, it can be preferentially identified as a local thermal anomaly; if the main anomaly chain is composed of changes in door locks, cabinet doors, video, and magnetic fields, and the authorization status is unauthorized, authorized revoked, or authorized conflict, it can be preferentially identified as a cabinet entry anomaly; if the main anomaly chain exists, but its key segments are mainly supported by suspicious items, items to be supplemented, or low-confidence time slices, it can be preferentially identified as an acquisition confidence anomaly; To ensure the reproducibility of anomaly type identification, a type proportion rule is established. The type proportion is based on the time slices of the main anomaly chain. If the number of valid time slices corresponding to a certain type accounts for more than 60% of the total number of time slices in the main anomaly chain, then that type is identified as the main type. If two types each account for more than 35% and have a clear temporal sequence, then they are identified as composite anomalies. If no single type reaches 35%, but the data collection reliability anomaly has the highest proportion, then it is prioritized as a data collection reliability anomaly. If electrical anomalies and local thermal anomalies in the same main anomaly chain both meet their respective persistence conditions, and the two are temporally correlated (e.g., a continuous current anomaly occurs first, followed by a local temperature rise that persists), then they are uniformly identified as composite anomalies. The 60% threshold for main type identification is used because this proportion ensures that the main type forms a stable dominant position in the main anomaly chain. The 35% threshold for composite anomaly identification is used because both types of anomalies involved in the composite identification should have independent supporting significance and should not be formed by piecing together fragmented pieces. After determining the source and type of the anomaly, the anomaly level is then determined. The anomaly level is used to map established anomaly conclusions to different priority and urgency entry points, rather than simply ranking them based on a single numerical value. Anomaly levels can be categorized as Attention, Review, Handling, and Emergency. Attention level indicates situations where there are only observational candidates, insufficient data collection reliability, limited impact, or weak persistence. Review level indicates situations where the anomaly source is relatively clear, the anomaly type is basically identified, but further confirmation is still needed. Handling level indicates situations where the anomaly source is clear, the main anomaly chain is complete, persistence is sufficiently confirmed, and there is a clear on-site handling direction. Emergency level indicates situations where there is a security risk, unauthorized entry... Anomalies are classified as follows: Anomalies caused by risks such as entry into the enclosure, continued deterioration of localized temperature rise, or significant impact on measurement accuracy and operational safety. The anomaly level is determined primarily by the urgency of the current risk, combined with the clarity of the anomaly source, the combination of anomaly types, and the results of continuous confirmation. If the anomaly source is primarily environmental disturbance, legal maintenance impact, impact from nearby equipment, or sensor link anomaly, the anomaly level is generally no higher than the review level. If the anomaly source is an anomaly in the target enclosure itself, and the anomaly type is an electrical anomaly or a localized thermal anomaly, and continuous confirmation is sufficient, the anomaly level can be no lower than the handling level. If the anomaly type is an anomaly entering the enclosure, accompanied by electrical changes or localized thermal anomalies, the anomaly level can be upgraded to the emergency level. To ensure consistent grading standards, it can be stipulated that if a localized thermal anomaly persists for more than 5 minutes and is accompanied by a continuous abnormal current, the anomaly level will be directly upgraded to the handling level. If there are also signs of unauthorized access, authorization conflicts, or video intrusion, the level will be further upgraded to the emergency level. If there are only link drift candidates or abnormal data acquisition reliability, the anomaly level will not exceed the attention level. The basis for using a localized thermal anomaly persisting for 5 minutes as the threshold for upgrading is that a localized temperature rise lasting more than 5 minutes usually indicates that the temperature has moved beyond the short-term surface heating range and is closer to a sustained risk state. To prevent repeated fluctuations in the anomaly level due to the entry of secondary information during a session, a level freezing rule can be set. Once the anomaly level is determined, it will not be downgraded within the same session due to subsequent low-priority information, unless the recovery observation is completed and the original anomaly is confirmed to have been eliminated. If a new high-risk anomaly segment appears in the same session and can be merged into the main anomaly chain or form a higher-risk secondary anomaly chain, the level can be upgraded. The level freezing result will be written into the session conclusion record and used as the unified grading standard for subsequent processing of the current session. After determining the source, type, and level of the anomaly, anomaly handling information is generated. This information is output in a structured format for subsequent maintenance, review, or automatic dispatch. The information includes at least the session number, target enclosure number, anomaly source, anomaly type, anomaly level, initial confirmation time, main anomaly chain number, key reference items, excluded factors, suggested handling path, review time limit, and whether immediate review is required. Key reference items consist of critical anomaly segments and key time slices supporting the current anomaly source, type, and level. Key time slices can be selected as the time slice of the first occurrence of the anomaly, the time slice of the most stable anomaly duration, the time slice triggering an anomaly level increase, and the time slice of the recovery observation start. Related content may include local temperature rise time slice intervals, current anomaly time slice intervals, door lock action time slice intervals, and video capture indexes. The excluded factors field records environmental disturbances, legitimate maintenance, influence from nearby equipment, and link drift types and their exclusion scope that have been excluded in previous processing. The suggested handling path is automatically matched based on the combination of the anomaly source, type, and level, and written into the session conclusion record. If the anomaly is primarily caused by environmental disturbances, it is recommended to maintain observation, supplement environmental boundary records, or correct the environmental baseline. If the anomaly is caused by legitimate maintenance, it is recommended to archive authorization records and end the current anomaly handling. If the anomaly is caused by nearby equipment, it is recommended to check the operating status of nearby equipment, correct the nearby impact boundary, or adjust installation isolation conditions. If the anomaly type is an anomaly in data acquisition reliability, it is recommended to prioritize checking the probe status, communication link, message sequence, and buffer retransmission logic. If the anomaly type is an electrical status anomaly or a localized thermal anomaly, it is recommended to conduct on-site wiring, terminal, load, and insulation verification. If the anomaly type is an anomaly in enclosure entry, it is recommended to prioritize verifying the authorization status and door lock. Record and document the on-site safety status; the review timeframe is determined based on the level of abnormality. For the "Attention" level, this can be completed before the next cycle session; for the "Review" level, it can be completed within 2 hours; for the "Handling" level, it can be completed within 30 minutes; and for the "Emergency" level, it can be triggered immediately. The above timeframes are based on the following: the "Attention" level corresponds to low-urgency observation situations and can be completed before the next cycle session; the "Review" level corresponds to situations with a relatively clear source but still requiring further confirmation, and completion within 2 hours helps maintain consistency with the current status; the "Handling" level corresponds to situations with a clear on-site handling direction, and completion within 30 minutes helps control the escalation of risks; and the "Emergency" level corresponds to situations with security risks or unauthorized entry risks, and should be triggered immediately. After generating anomaly handling information, recovery observation information is generated. This recovery observation information is used to verify whether the target energy metering box has returned to a stable state after anomaly handling is completed or the anomaly naturally subsides, and to form a closed-loop session record. The recovery observation information includes at least the following fields: recovery observation number, session number, target box number, observation start time, observation duration, key observation items, recovery judgment conditions, observation end method, and recovery failure restart conditions. The observation end method can be natural end, manual termination, recovery failure termination, or interruption termination. The observation duration is set according to the anomaly type. The recovery observation duration for electrical state anomalies and localized thermal anomalies can be selected from 10 minutes to 30 minutes, with a selectable value of 2. 0 minutes; This time setting is based on the fact that after electrical or localized thermal anomalies are dealt with, there is usually a stabilization process and short-term recurrence. 20 minutes can balance the timeliness of recovery confirmation and the completeness of observation. The recovery observation time for enclosure entry anomalies can be selected to cover 20 minutes after the enclosure door is closed, with an optional range of 10 to 30 minutes. This time setting is based on the fact that there may still be residual state fluctuations and the risk of short-term re-entry after the entry behavior ends. The recovery observation time for data acquisition reliability anomalies can be selected to cover 20 minutes after the link is restored. This time setting is based on the fact that after the link is restored, a certain continuous observation interval needs to be maintained to confirm that the communication, data acquisition, and upload status have been stably restored, rather than being interrupted again after a short-term recovery. The recovery criteria correspond item by item to the original anomaly criteria. If the original anomaly was a local thermal anomaly, the key recovery observation items should include at least whether the relevant temperature point has fallen back to within the allowable range of the same environment and remained there for more than 5 minutes, and whether the corresponding current item is no longer abnormal in the same direction. The basis for using a continuous 5-minute duration as the recovery confirmation criterion is that the recovery holding time is longer than the minimum duration for the establishment of a local thermal anomaly, which can improve the robustness of the recovery confirmation and avoid short-term declines being mistakenly judged as recovery completion. If the original anomaly was an electrical state anomaly, the recovery criteria can be that the corresponding voltage and current remain within the normal operating range for 10 consecutive core time slices. The basis for this condition is that 10 consecutive core time slices... The time slice can eliminate short-term recovery artifacts; if the original anomaly was a cabinet entry anomaly, the recovery judgment condition can be that the door lock, cabinet door, video, and authorization status are consistently consistent within the observation window and no new entry segments appear; if the original anomaly was a collection reliability anomaly, the recovery judgment condition can be that the core collection items have no suspicious or pending markers for 20 consecutive time slices; the basis for this condition is that 20 consecutive time slices can confirm that the link recovery is continuous, rather than a short-term recovery followed by fluctuations; when the source of the anomaly is determined to be dominated by environmental disturbances, legitimate operation and maintenance, or the influence of nearby equipment, and no ontological anomaly candidates are retained in the current session, recovery observation can be not started, and only the session end record can be written; If an anomaly that is identical to or very similar to the original anomaly reappears during the recovery observation period, the recovery status is "recovery failed" and a new status identification session is triggered. The main trigger of the session can be "recovery failed" and the source is associated with the main anomaly chain number of the previous session. If the recovery observation is successful, the current session status is recorded as "closed loop" and information such as the recovery confirmation time, recovery observation number, recovery success conditions, and recovery key items are added to the status history. The current session sets exception boundary handling rules. When multiple exceptions occur in the same session and there is no temporal correlation between the exception types, exception handling information is generated for each exception. The highest exception level is the main level for this session, and other exception types will be written into the same session result as auxiliary exception records. If subsequent retransmissions change the original partial time slice facts, the original result will not be overwritten, and supplementary review records will be generated. If necessary, the recovery observation will be restarted. When recovery observation is performed after communication interruption, the currently confirmed exception level will still be retained, and the session termination method will be changed to interruption termination. It will continue when communication is restored. When the main exception chain is split into multiple independent exception chains during recovery observation, the earliest formed exception chain with the highest evidence level will be used as the main exception chain, and other exception chains will be written into the auxiliary exception chain record. This can ensure that the session result remains stable under retransmission, loss of contact, and multiple exceptions coexisting simultaneously. Regarding time and resource control, the determination time for anomaly source, anomaly type, and anomaly level can be selected to be within 5 seconds, the generation time for anomaly handling information and recovery observation information can be selected to be within 10 seconds, and the processing time for the entire final determination process is set to be within 15 seconds. The basis for the above time settings is that the current session has completed source elimination and anomaly candidate convergence before entering the final determination, and the determination of anomaly source, anomaly type, and anomaly level no longer involves the original message processing, so it can be completed in a short time. The anomaly handling information and recovery observation information adopt a structured output method, and the generation process mainly involves field organization and result writing, so it can be completed within 10 seconds. The overall processing time is controlled within 15 seconds, which is conducive to maintaining the real-time correspondence between the final conclusion and the current session state. If there are a large number of anomaly fragments in the current session, the results can be generated in batches according to the order of priority of the main anomaly chain and subsequent secondary anomaly chain, and the anomaly handling information corresponding to the main anomaly chain is output first. The processing results are written into the session conclusion record and status history.
[0021] Example 2: Taking an outdoor, sunny electricity metering box in a residential power distribution area as the target electricity metering box, the overall operation process of a smart electricity metering box management method with remote status monitoring is described. The target electricity metering box is numbered A-102, the meter number is M-102, the distribution area number is T-08, the installation location number is P-08-17, and the incoming and outgoing line circuit number is L1. The current list of valid data collection points includes at least voltage data collection points, current data collection points, magnetic field data collection points, temperature data collection point 1, temperature data collection point 2, humidity data collection points, door lock status data collection points, box door status data collection points, and video capture index points. There is an air conditioner outdoor unit within 1 meter of the target electricity metering box and a frequency converter within 2 meters. Both of them have been registered in the proximity device relationship table. At 14:23:18 on a certain day, the remote master station received an active anomaly report from the target power metering box. The trigger summary was a local temperature rise anomaly accompanied by current fluctuation. After receiving the remote monitoring trigger information, the system first organized it into a unified trigger record. The trigger record includes at least the trigger type, trigger time, target box number, trigger source number, trigger summary, trigger priority, and original event index. The trigger type in this case was an active anomaly report, and the trigger priority was level one. Subsequently, the system checked whether there were other trigger information within the 30-second merging window. After checking, at 14:23:31, another communication recovery retransmission prompt was received. Since this prompt corresponds to the same target box as the active anomaly report and belongs to the same anomaly event chain, the active anomaly report was taken as the main trigger, and the communication recovery retransmission prompt was merged into the auxiliary trigger list, without establishing a parallel session again. Upon receiving the trigger information, a status identification session is established. The session number can be 20260101-001, and the session time window is determined according to the active anomaly reporting standard, which can be from 14:13:18 to 14:43:18. The session duration is 20 minutes. When establishing the session, the object boundary, time boundary, parameter boundary, authorization boundary, and adjacent influence boundary are frozen first. The object identification adopts a combined identification method, including at least the box number A-102, meter number M-102, the substation number T-08, the installation location number P-08-17, the incoming and outgoing line circuit number L1, and the effective data collection point list number C-102. In the time caliber, the core time slice length is 2 seconds, and the acquisition time, reception time, and mapping time are recorded simultaneously to distinguish real-time data, delayed data, and supplementary data. The parameter version is... 1003, and freeze its use within this session; the parameter snapshot includes at least the door lock associated observation window, the upper limit of the effective image delay, the synchronous observation window of the nearby devices, the duration of local thermal anomaly retention, and the repeated observation cycle of electrical anomalies. Among them, the door lock associated observation window takes 10 seconds before and after, the upper limit of the effective image delay takes 30 seconds, the synchronous observation window of the nearby devices takes 60 seconds before and after, the duration of local thermal anomaly retention takes 3 minutes, and the repeated observation cycle of electrical anomalies takes 10 minutes; the authorization status retrieval results show that there is no valid authorization work order for the target energy metering box within the session time window, so the authorization status is determined to be unauthorized; the nearby device relationship reading results show that the nearest device includes the air conditioner outdoor unit E-21, and the next nearest device includes the inverter device E-22, and the operating status of both can be read; after completing the above processing, the initial record of the status identification session is formed; After the session is established, the original acquisition messages within the session time window are received. Each original acquisition message includes at least the cabinet number, acquisition point number, acquisition item type, acquisition time, reception time, current value, status bit, validity bit, local buffer bit, and message sequence number. Subsequently, object consistency verification is performed. The object consistency verification uses 20 consecutive messages as the verification window to check the cabinet number, acquisition point affiliation, message sequence number, and loop affiliation. The verification results show that, except for one delayed video index message with a lagging reception time, the cabinet numbers of the remaining messages are consistent with A-102, the acquisition points all belong to the current valid acquisition point list, the loop affiliation is within the L1 range, and the message sequence number does not show consecutive backwards. Therefore, the object consistency verification is passed. For delayed transmission messages, only the compensation record is retained and is not used as a basis for judging the current session subject. Subsequently, the system performed a link validity check. The sampling period for voltage and current was 2 seconds, with an allowable interruption duration of 15 seconds; the sampling period for temperature and humidity was 10 seconds, with an allowable interruption duration of 60 seconds; the sampling period for door lock status and cabinet door status was 1 second, with an allowable interruption duration of 5 seconds; video capture adopted an event-triggered method, with a maximum latency tolerance of 30 seconds. The check results showed that voltage, current, temperature, door lock, cabinet door, and video items were all valid. The magnetic field acquisition point only showed slight fluctuations in a few time slices, with no repeated abnormal status bits and no link drift candidates. Therefore, it was retained as a valid item or auxiliary basis. After completing the link validity check, the system performed time alignment according to the 2-second core time slice, merged high-frequency acquisition items into a unified time series, adopted the most recent valid value for temperature and humidity items, and mapped the video capture index to the corresponding time slice according to the acquisition time to form a session time sequence record. After the session timeline was generated, abnormal segments were extracted first. Between 14:22:54 and 14:31:08, the current entry continuously deviated from the normal operating range, which can be identified as electrical abnormal segment P1. Between 14:24:10 and 14:32:40, temperature sampling point one was consistently higher than temperature sampling point two and the current environmental range, which can be identified as local thermal abnormal segment P2. Within the session time window, there were no changes in the opening of the door lock and cabinet door entries, and no personnel were seen approaching in the video, so no entry-related abnormal segment was formed. Since P1 and P2 are mainly supported by valid entries, their evidence level can be determined as medium to high, and the link credibility can be determined as high. After extracting the abnormal segments, a natural environmental disturbance elimination verification was performed first. Since the current installation environment is outdoors and facing the sun, the system used the ambient temperature rise caliber from the parameter snapshot to compare the temperature rise changes within the 15-minute observation window. The session timing log showed that the temperature rise at temperature sampling point one was significantly higher than that at temperature sampling point two, and it exhibited a localized, concentrated temperature increase, rather than a simultaneous, similar-amplitude, and gradual increase across multiple temperature points. Furthermore, there was a clear continuity between the localized temperature increase and the current anomaly time slice; therefore, this anomaly did not meet the characteristics of an overall temperature rise caused by environmental disturbance and could not be eliminated as an environmental disturbance. Subsequently, a legitimate maintenance operation elimination verification was performed. Since the authorization status was unauthorized, and the door lock, cabinet door, and video... None of the frequency entries showed any legitimate maintenance activity, thus ruling out the impact of legitimate operation and maintenance. Next, the impact of adjacent equipment was checked. The system retrieved the operation change records of air conditioner outdoor unit E-21 and inverter equipment E-22. It was found that although there were start-up records of the air conditioner outdoor unit around 14:23, its operation change did not correspond to the local temperature rise of the target enclosure. Moreover, after the air conditioner outdoor unit stabilized at 14:27, the local temperature rise continued to exist. Therefore, the impact of adjacent equipment was insufficient to explain the anomaly. Finally, the sensor link drift was checked. Since the key time slices supporting P1 and P2 are mainly composed of valid entries, and there are no large areas of unfilled, suspicious, or low-confidence time slices, the impact of sensor link drift can be ruled out. After four rounds of elimination and review, the time-series correlation judgment was performed on the abnormal segments that were not eliminated. The electrical abnormal segment P1 appeared before the local thermal abnormal segment P2. The two formed a sequential relationship within the 120-second abnormal correlation observation window. Therefore, P1 and P2 were merged into the same associated abnormal chain L-01. Then, continuous confirmation was performed. P1 maintained the same direction of abnormality in 8 out of 10 consecutive core time slices and repeated more than 3 times within 10 minutes. P2 lasted for more than 3 minutes. Therefore, P1 and P2 were added to the confirmed candidate list. Based on this, the final judgment is made. Since the current session does not retain the dominant sources of environmental disturbance, legitimate maintenance impact, impact from nearby devices, and sensor link anomalies, and the main anomaly chain L-01 represents the continuous evolution of electrical anomalies and local thermal anomalies, the source of the anomaly is determined to be an anomaly in the target enclosure itself. Both the electrical anomaly and the local thermal anomaly in the main anomaly chain L-01 have met their corresponding retention conditions, and there is a clear sequential relationship between the two, so the anomaly type is determined to be a composite anomaly. The local thermal anomaly lasts for more than 5 minutes and is accompanied by a continuous current anomaly, so the anomaly level is determined to be the handling level. If there are signs of unauthorized entry or video intrusion at the same time, the anomaly level can be upgraded to the emergency level. No entry-related anomalies were found in this session, so the final level remains the handling level. After the source, type, and level of the anomaly are determined, anomaly handling information is generated. The anomaly handling information includes at least the session number, target enclosure number, anomaly source, anomaly type, anomaly level, initial confirmation time, main anomaly chain number, main basis items, excluded factors, suggested handling path, review time limit, and whether immediate review is required. In this session, the anomaly source is determined to be an anomaly in the target enclosure itself, the anomaly type is determined to be a composite anomaly, the anomaly level is determined to be a handling level, the main basis items include the current anomaly time interval and the local temperature rise time interval, excluded factors include environmental disturbance, legal operation and maintenance impact, impact of nearby equipment, and sensor link anomaly, the suggested handling path is on-site wiring, terminal, load, and insulation review, and the review time limit is to be completed within 30 minutes. Subsequently, recovery observation information is generated. Since the current anomaly is a composite anomaly formed by electrical state anomaly and local thermal anomaly, the recovery observation duration is set at 20 minutes. The key observation items include at least whether the temperature at the first temperature acquisition point has fallen back to the allowable range for the same environment and remained there for more than 5 minutes, and whether the current item has recovered to the normal operating range for 10 consecutive core time slices. If a current anomaly or local temperature rise consistent with the original anomaly reappears during the recovery observation period, the current session status is recorded as recovery failure, and a new round of status identification session is triggered. If the recovery observation is successful, the current session status is recorded as closed loop, and the recovery confirmation time, recovery observation number, key recovery items, and recovery success conditions are written into the status history. As can be seen from the above operation process, it is not a simple collection and superposition of voltage, current, magnetic field, temperature and humidity, door and video information. Instead, within the scope of a unified session conclusion, it first completes object consistency verification, link validity verification, and time alignment. Then, it performs source elimination, time sequence correlation and continuity verification on abnormal segments. Finally, it fixes the abnormal candidates into session conclusions with clear abnormal sources, abnormal types and abnormal levels, and generates consistent abnormal handling information and recovery observation information. It performs closed-loop management of the remote status monitoring results of the target power metering box, so as to distinguish between abnormalities of the target box body and environmental disturbances, legitimate operation and maintenance, influence of nearby equipment and sensor link drift, thereby improving the accuracy of abnormal source judgment, the pertinence of subsequent handling and the continuity of status management.
[0022] It should be noted that this invention can be deployed on the device itself to realize embedded applications, or it can run on a PC or other terminal with a user interface, thereby meeting various hardware environments and usage requirements.
[0023] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented in software, the above embodiments can be implemented in whole or in part by a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions of the embodiments of this application are implemented in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted wirelessly or wiredly from one website, computer, server, or data center to another website, computer, server, or data center. Wired methods include optical fiber, twisted pair, coaxial cable, etc. Wireless methods include infrared, microwave, etc. Available media include any available media that can be accessed by a computer or data storage devices such as servers and data centers that contain one or more sets of available media. Available media can be magnetic media (floppy disks, hard disks, magnetic tapes), optical media (DVDs), or semiconductor media. Semiconductor media can be solid-state drives.
[0024] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0025] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A management method for an intelligent electricity metering box with remote status monitoring, characterized in that, include: Establish a status identification session based on the remote monitoring trigger information of the target energy metering box to determine the object identifier, time caliber, parameter version, authorization status and relationship with neighboring devices of the target energy metering box; The voltage, current, magnetic field, temperature and humidity, door and video monitoring information collected during the session period are verified for object consistency, link validity and time alignment to obtain the session time sequence record corresponding to the target power metering box; Based on the session timing records, the elimination and verification are carried out in the order of natural environmental disturbance, legitimate operation and maintenance, influence of nearby equipment and sensor link drift, and the timing correlation judgment and continuity confirmation are performed on the abnormal changes that have not been eliminated. Based on the results of exclusion review and continuous confirmation, the source, type and level of the anomaly of the target power meter box are determined, and anomaly handling information and recovery observation information are generated.
2. The intelligent power metering box management method with remote status monitoring according to claim 1, characterized in that, Establish a status identification session based on the remote monitoring trigger information of the target power metering box, including: Remote monitoring trigger information is uniformly recorded to form a trigger record containing trigger type, trigger time, target box number, trigger source number, trigger summary, trigger priority and original event index; Within the preset merging time window, multiple trigger records corresponding to the same target box are merged and compared, and the trigger record with the highest priority is determined as the main trigger, while the remaining trigger records are written into the auxiliary trigger list. When trigger summaries of multiple trigger records conflict, a trigger conflict record is generated, and the current session state is set to pending review. Configure the session start time, session end time, and current state according to the main trigger type to form a state-identifying session record.
3. The intelligent power metering box management method with remote status monitoring according to claim 1, characterized in that, Determine the target energy meter box's object identifier, time caliber, parameter version, authorization status, and proximity to other devices, including: Extract the enclosure number, meter number, substation number, installation location number, incoming and outgoing line circuit number, and valid data collection point list number from the current valid basic files to form an object identification snapshot, and perform conflict verification on the installation location number and valid data collection point list number; Combine the main trigger type to set the total session time window and core time slice length, and record the acquisition time, reception time and mapping time; Write the current valid parameter version and generate a parameter snapshot record; Determine authorization status by retrieving authorization records based on session time windows; Read the relationships between neighboring devices according to the time range corresponding to the main trigger, and record the neighboring device number, device type, relative location, distance level, readable operation status marker, and missing neighboring relationship marker.
4. The intelligent energy metering box management method with remote status monitoring according to claim 1, characterized in that, The voltage, current, magnetic field, temperature and humidity, door and video monitoring information collected during the session period are subject to object consistency verification, link validity verification and time alignment, including: The raw acquisition messages received during the session are written into the session data buffer, and messages lacking key fields are written into the abnormal message registration record. Based on the target enclosure number, the list of valid acquisition points, the range of incoming and outgoing line circuits, and the message sequence number, the message consistency is checked, and conflicting messages are either blocked or not blocked. When the verification is passed or the non-blocking conditions are met, the message is checked for sampling continuity, timing rationality, status bit consistency, value retention abnormality, repeated transmission, and local buffer status according to the type of collection item. The message is then merged into the core time slice according to the collection time, and a time slice compensation record is generated for the retransmitted message.
5. The intelligent power metering box management method with remote status monitoring according to claim 1, characterized in that, Obtain the session timing record corresponding to the target power meter box, including: The merged monitoring data is organized according to time slices and written into voltage, current, magnetic field, temperature, humidity, door lock, box door and video entries. The link status, connection status, connection duration, additional record mark, compensation record mark and real-time upload mark of each entry are recorded. At the same time, object conflict mark, pending mark and suspicious mark are written. Generate a link status summary record based on the type of collection item or the collection point number, recording the number of valid records, the number of suspicious records, the number of records to be supplemented, the number of failed records, continuous interruption flags, value retention abnormal flags, clock rollback flags, duplicate upload flags, core link missing flags, and session core judgment impact flags.
6. A method for managing an intelligent energy metering box with remote status monitoring according to claim 1, characterized in that, Based on the session sequence records, the elimination and review process was conducted in the following order: natural environmental disturbances, legitimate maintenance operations, impact from nearby devices, and sensor link drift. This included: First, extract abnormal segment records according to time slice intervals, and form electrical side abnormal segments, local thermal abnormal segments, entry-related abnormal segments, and video-assisted abnormal segments according to the change pattern of the collected items; Then, in the order of natural environmental disturbance, legitimate operation and maintenance, influence of nearby equipment and sensor link drift, each abnormal segment is compared in turn. For abnormal segments that were not explained in the previous round, the next round of comparison is carried out, and all or part of the explainable time segments are excluded and recorded. Write the abnormal segments that are inconsistent with the authorization record and behavior trajectory into the authorization conflict candidate, and write the sessions that explain all the remaining abnormal segments by the link state abnormality into the link abnormality description record.
7. A method for managing an intelligent energy metering box with remote status monitoring according to claim 1, characterized in that, For any unresolved abnormal changes, perform time-series correlation analysis and persistence confirmation, including: For abnormal segments that remain unexplained after rounds of comparison, they are sorted by the time of their first appearance, and the correspondence between abnormal segments is identified according to a preset succession pattern. Exception segments that satisfy the succession relationship are grouped into associated exception chains, and exception segments that do not form a succession relationship are recorded as isolated exceptions; Then, according to the continuous judgment rules corresponding to the anomaly type, the anomaly fragments or associated anomaly chains are continuously confirmed. Those that pass the continuous confirmation are written into the confirmed candidate record, those that fail but still have continuous changes are written into the observation candidate record, and the anomaly fragments supported by the failure entries are written into the low confidence anomaly list.
8. A method for managing an intelligent power metering box with remote status monitoring according to claim 1, characterized in that, Based on the results of exclusion review and continuous confirmation, the source, type, and level of anomalies in the target energy metering box are determined, including: Read the exclusion review record, abnormal candidate record, session timing record, link status summary record and parameter snapshot record, and establish a session conclusion record; The main and secondary anomaly chains are determined based on the time slices covered by the anomaly segments, the associated anomaly chains, the persistence status, and the level of evidence. The source of the anomaly is determined based on the proportion of sources and the relationship between the main anomaly chain. The anomaly type is determined based on the composition, order of collection, and type proportion of the main anomaly chain. The anomaly level is determined based on the clarity of the anomaly source, the combination of anomaly types, the persistence status, and the risk status. The relevant results are then written into the session conclusion record.
9. A method for managing an intelligent energy metering box with remote status monitoring according to claim 1, characterized in that, Generate anomaly handling information and recovery observation information, including: Anomaly handling information and recovery observation information are generated based on the session conclusion records; Based on the source, type and level of the anomaly, match the suggested processing path and review time limit, and write the session number, target box number, main reference items, excluded factors, suggested processing path and review mark; Based on the original criteria for establishing the anomaly, the observation duration, key observation items, and recovery judgment conditions are set to generate recovery observation information. During the recovery observation period, when a corresponding abnormal candidate appears, the current session state is written as recovery failed and a new associated session is triggered. When the recovery judgment condition is met, the current session state is written as closed loop, and the processing record and recovery record are written to the status history.
Citation Information
Patent Citations
Electricity monitoring apparatus
CN201518040U
System for be used for carrying out intelligence protection to batch meter
CN208126141U