Substation screen cabinet anti-misoperation unlocking system and method

CN122888694APending Publication Date: 2026-10-09GUANGDONG POWER GRID CO LTD DONGGUAN POWER SUPPLY BUREAU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611117001.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-24
Publication Date
2026-10-09

AI Technical Summary

Technical Problem

但存在因误开、错开屏柜而引发非计划停运和安全事故的问题

Benefits of technology

[0025]本申请提供的变电站屏柜防误开锁系统及方法,其中的系统包括:工作票解析模块,用于响应于接收到工作票文本,对工作票文本进行语义分析,提取目标屏柜标识,并基于目标屏柜标识生成操作白名单;动态权限分配模块,用于将操作白名单与作业人员身份信息及作业时间窗口关联,生成加密且带有数字签名的授权数据包;授权数据包用于限定:持有作业人员身份信息的作业人员,仅在作业时间窗口内具备开启操作白名单中屏柜的权限;且授权数据包与智能终端的唯一设备标识绑定,以限定授权数据包仅在绑定的智能终端上有效;智能终端,用于安全存储授权数据包,并作为开锁现场的交互载体;智能锁具,部署于屏柜,用于读取智能终端中的授权数据包,验证授权数据包的有效性,并验证授权数据包中绑定的唯一设备标识与智能终端的唯一设备标识是否匹配,在验证通过且操作白名单包含智能锁具的屏柜标识时执行解锁,并生成对应的操作记录。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122888694A_ABST
    Figure CN122888694A_ABST
Patent Text Reader

Abstract

The application provides a transformer substation screen cabinet anti-misoperation unlocking system and method, and relates to the technical field of power system operation and maintenance management and intelligent lock control. The system comprises a work ticket analysis module, a dynamic permission allocation module, an intelligent terminal and an intelligent lock. The work ticket analysis module performs semantic analysis on the work ticket text to generate an operation whitelist; the dynamic permission allocation module associates the operation whitelist with the work personnel identity information and the work time window to generate an authorized data package; the intelligent terminal stores the authorized data package; the intelligent lock verifies the validity of the authorized data package, and verifies whether the device identification bound to the intelligent lock matches the device identification of the intelligent terminal, and when the verification is passed and the operation whitelist contains the screen cabinet identification of the intelligent lock, the intelligent lock executes unlocking and generates an operation record, thereby effectively reducing the unplanned shutdown and safety hazards caused by human error, extensive permissions and lack of closed-loop verification, and significantly improving the safety, standardization and intelligent level of the operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system operation and maintenance management and intelligent lock control technology, specifically to a substation cabinet anti-misoperation lock system and method. Background Technology

[0002] With the continuous expansion of the power grid and the constant improvement of its intelligence level, the requirements for safety and accuracy in substation operation and maintenance are becoming increasingly stringent. The number of various cabinets in the substation relay protection room is enormous, and the numbering system is complex. The secondary equipment installed inside, such as protection and measurement and control devices, directly affects the stable operation of the power grid. Routine equipment maintenance, parameter modification, and functional testing all require opening designated cabinets. Against this backdrop, ensuring the accuracy of every unlocking operation and fundamentally preventing unplanned outages or even safety accidents caused by mistakenly opening or incorrectly opening cabinets has become a prominent challenge and a major safety management requirement in the field of power system operation and maintenance.

[0003] In related technologies, when performing inspection, debugging, or maintenance tasks, operators typically verify the target cabinet number based on paper or electronic work orders and manually perform the unlocking operation. However, there is a risk of unplanned downtime and safety accidents caused by mistakenly opening or incorrectly opening cabinets. Summary of the Invention

[0004] This application provides a substation cabinet anti-misoperation lockout system and method to improve the problem of unplanned shutdowns and safety accidents caused by accidental or incorrect opening of cabinets in related technologies.

[0005] In a first aspect, this application provides a substation cabinet anti-misoperation unlocking system, including a work order parsing module, a dynamic permission allocation module, an intelligent terminal, and an intelligent lock, wherein:

[0006] The work order parsing module is used to respond to the received work order text, perform semantic analysis on the work order text, extract the target cabinet identifier, and generate an operation whitelist based on the target cabinet identifier;

[0007] The dynamic permission allocation module is used to associate the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. The authorization data packet is used to limit the operator holding the operator's identity information to having the permission to open the cabinets in the operation whitelist only within the operation time window. The authorization data packet is also bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal.

[0008] The intelligent terminal is used to securely store authorized data packets and serves as an interactive medium at the unlocking site;

[0009] The smart lock, deployed in the cabinet, is used to read the authorization data packet in the smart terminal, verify the validity of the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal. When the verification is successful and the cabinet identifier of the smart lock is included in the operation whitelist, the lock is unlocked and a corresponding operation record is generated.

[0010] In one possible implementation, the work order parsing module performs semantic analysis on the work order text, extracts the target cabinet identifier, and generates an operation whitelist based on the target cabinet identifier. Specifically, this includes: using a pre-trained semantic parsing model to perform deep semantic analysis on the work order text to extract the initial identifier information of the target cabinet specified in the work order text; associating and verifying the initial identifier information with a pre-built substation equipment knowledge graph to verify and determine the accurate target cabinet identifier; and generating an operation whitelist based on the verified target cabinet identifier.

[0011] In one possible implementation, the pre-trained semantic parsing model is a natural language processing model based on the Transformer architecture.

[0012] In one possible implementation, the dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. This includes: associating and encapsulating the operation whitelist, operator's identity information, and operation time window; encrypting the encapsulated data; digitally signing the encrypted data using the private key of the digital certificate to generate the authorization data packet; and sending the authorization data packet to the bound smart terminal through a secure communication link.

[0013] In one possible implementation, the encryption process employs a symmetric encryption algorithm; and / or, the secure communication link is a Transport Layer Security (TLS) encrypted channel.

[0014] In one possible implementation, the smart terminal is a smart key card with a built-in security chip or a mobile terminal with an authorization management application installed. The secure storage area of ​​the security chip or the authorization management application is used to securely store authorization data packets.

[0015] In one possible implementation, the smart lock is specifically used to: read the authorization data packet in the smart terminal via near-field communication; verify the validity of the digital signature of the authorization data packet, and verify whether the current time is within the operation time window contained in the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal; if the signature verification, time verification, and terminal identifier matching verification all pass, then verify whether the cabinet identifier stored in itself exists in the operation whitelist, and if the verification passes, perform the unlocking operation and generate an operation record; if any of the signature verification, time verification, terminal identifier matching verification, or cabinet identifier verification fails, then refuse to unlock and trigger a local alarm.

[0016] In one possible implementation, the substation cabinet anti-misoperation unlocking system also includes a management platform, which is used to receive and store operation records and alarm records uploaded by smart locks.

[0017] In one possible implementation, the substation cabinet anti-misoperation unlocking system also includes a blockchain evidence storage module, which is used to write summary information of operation records and / or alarm records into the blockchain network for evidence storage.

[0018] Secondly, this application provides a method for preventing accidental unlocking of substation cabinets, applicable to a substation cabinet anti-accidental unlocking system as described in any of the first aspects, the method comprising:

[0019] The work order parsing module responds to the received work order text by performing semantic analysis on the work order text, extracting the target cabinet identifier, and generating an operation whitelist based on the target cabinet identifier;

[0020] The dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. The authorization data packet is used to limit the operator holding the operator's identity information to having the permission to open the cabinets in the operation whitelist only within the operation time window. The authorization data packet is also bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal.

[0021] The smart terminal securely stores authorized data packets and serves as the interaction medium at the unlocking site;

[0022] The smart lock reads the authorization data packet from the smart terminal, verifies the validity of the authorization data packet, and verifies whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal. If the verification is successful and the operation whitelist includes the smart lock's cabinet identifier, the lock is unlocked, and a corresponding operation record is generated.

[0023] Thirdly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed, are used to implement the method of the second aspect.

[0024] Fourthly, this application provides a computer program product, including a computer program that, when executed, implements the method of the second aspect.

[0025] The substation cabinet anti-misoperation unlocking system and method provided in this application includes: a work order parsing module, used to respond to received work order text, perform semantic analysis on the work order text, extract the target cabinet identifier, and generate an operation whitelist based on the target cabinet identifier; a dynamic permission allocation module, used to associate the operation whitelist with the operator's identity information and the operation time window, and generate an encrypted authorization data packet with a digital signature; the authorization data packet is used to limit: the operator holding the operator's identity information only has the permission to open the cabinets in the operation whitelist within the operation time window; and the authorization data packet is bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal; the smart terminal is used to securely store the authorization data packet and serve as the interaction carrier at the unlocking site; a smart lock, deployed in the cabinet, is used to read the authorization data packet in the smart terminal, verify the validity of the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal. When the verification is successful and the operation whitelist contains the cabinet identifier of the smart lock, the lock is unlocked and a corresponding operation record is generated.

[0026] This application automatically generates a precise operation whitelist through semantic analysis of the work order parsing module, effectively eliminating errors and omissions that may be caused by manual identification and verification of work orders. The dynamic permission allocation module generates dynamically authorized encrypted data packets based on the operation whitelist, personnel identity, time window, and unique device identifier of the smart terminal, realizing a strong binding between permissions and designated terminals, further improving the fine-grained and timely control of permissions, and effectively preventing unauthorized operations. By forcibly verifying the validity of the authorization data packet and the matching of terminal identifier with the current cabinet identifier through smart locks, the possibility of accidentally opening non-target cabinets is reduced from the physical execution level. Combined with operation records, the entire process is traceable, thereby comprehensively improving the unplanned shutdowns and safety hazards caused by human error, loose permissions, and lack of closed-loop verification in traditional operations, and significantly improving the safety, standardization, and intelligence level of substation operation and maintenance. Attached Figure Description

[0027] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0028] Figure 1 A schematic diagram of a substation cabinet anti-misoperation unlocking system provided as an exemplary embodiment of this application;

[0029] Figure 2 Another structural schematic diagram of a substation cabinet anti-misoperation unlocking system provided as an exemplary embodiment of this application;

[0030] Figure 3 A flowchart illustrating a method for preventing accidental unlocking of substation cabinets, provided as an exemplary embodiment of this application;

[0031] Figure 4 Another flowchart illustrating the method for preventing accidental unlocking of substation cabinets provided as an exemplary embodiment of this application.

[0032] In the diagram, 10—Substation cabinet anti-misoperation unlocking system; 11—Work order parsing module; 12—Dynamic permission allocation module; 13—Smart terminal; 14—Smart lock; 15—Management platform; 16—Blockchain evidence storage module.

[0033] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0034] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0035] The terms "first," "second," etc., used in this application's specification and some aspects are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, products, or apparatus.

[0036] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0037] In related technologies, when performing inspection, debugging, or maintenance tasks, operators typically manually verify the target cabinet number based on paper or electronic work orders and then perform the unlocking operation. However, this method has the following core drawbacks:

[0038] First, manual verification relies on the subjective judgment and on-site identification of operators. Given the large number of substation cabinets (hundreds per station), the complex numbering system (often containing multiple layers of information such as numbers, letters, and interval codes), and the interference of the on-site environment, misreading, omissions, or misidentifications are very likely to occur, leading to the wrong opening of non-target cabinets, which can directly cause unplanned shutdowns or even safety accidents.

[0039] Secondly, existing technical solutions lack the ability to intelligently parse work order texts, essentially remaining in the primitive mode of "human reading of tickets and human finding cabinets," unable to automatically and accurately convert unstructured work requirements into executable equipment operation instructions. This results in the persistent high-risk error link of "human eye recognition and human brain conversion," failing to achieve automated and accurate conversion of work instructions from the information source.

[0040] Furthermore, access control often remains at a static and rudimentary management level. Specifically, authorizations are typically issued in batches to a specific area or type of equipment, rather than precisely to individual cabinets; validity periods are often set to working days or even longer, rather than being strictly tied to the actual time window of the task; and there is a lack of effective mechanisms for dynamically linking authorizations to specific personnel. These deficiencies lead to authorizations being decoupled from specific personnel, precise time windows, and minimal equipment lists. It is difficult to promptly revoke permissions after the task is completed, and the long-term validity or ubiquitous authorization of permissions creates hidden dangers for unauthorized operations and abuse of power.

[0041] Finally, operation logs generally lack completeness, traceability, and tamper resistance. In common scenarios, unlocking records may be stored locally as logs scattered across various locks or keys, lacking a centralized and standardized management mechanism. Log information often lacks key fields such as operator and authorization source. The coexistence of paper records and simple spreadsheets makes it difficult to guarantee the authenticity and integrity of the data. These deficiencies make it difficult to meet the high standards of the power system for rigorous auditing and accountability of the operation and maintenance process.

[0042] To address the aforementioned issues, this application provides a solution for preventing accidental unlocking of substation cabinets, specifically constructing a closed-loop anti-misoperation system encompassing intelligent work order recognition and precise on-site execution. Specifically, a work order parsing module performs semantic understanding on work orders described in natural language, automatically extracting and verifying them to form a structured operation whitelist, eliminating human error at the source. Furthermore, a dynamic permission allocation module dynamically binds and encrypts the whitelist with the specific operator's identity, time window, and the unique device identifier of the smart terminal, achieving refined and time-sensitive permission control. Further, smart locks enforce verification of the matching between the authorized data packet and the current cabinet identifier, ensuring that only devices on the whitelist can be opened within the authorized time limit, and automatically generating a reliable operation record during execution. This collaborative mechanism of "intelligent parsing - dynamic authorization - on-site verification - full traceability" effectively reduces unplanned shutdowns and safety accidents caused by accidental or incorrect cabinet opening, as well as issues of unauthorized access and difficulty in traceability.

[0043] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0044] Figure 1 A schematic diagram of a substation cabinet anti-misoperation unlocking system provided as an exemplary embodiment of this application. Figure 1 As shown, the substation cabinet anti-misoperation unlocking system 10 includes: a work order parsing module 11, a dynamic permission allocation module 12, an intelligent terminal 13, and an intelligent lock 14, wherein:

[0045] The work order parsing module 11 is used to respond to the received work order text, perform semantic analysis on the work order text, extract the target cabinet identifier, and generate an operation whitelist based on the target cabinet identifier;

[0046] The dynamic permission allocation module 12 is used to associate the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. The authorization data packet is used to limit that the operator holding the operator's identity information only has the permission to open the cabinets in the operation whitelist within the operation time window. The authorization data packet is also bound to the unique device identifier of the smart terminal 13 to limit the authorization data packet to be valid only on the bound smart terminal.

[0047] The intelligent terminal 13 is used to securely store authorized data packets and serves as an interactive carrier at the unlocking site;

[0048] The smart lock 14, deployed in the cabinet, is used to read the authorization data packet in the smart terminal 13, verify the validity of the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal 13. When the verification is successful and the cabinet identifier of the smart lock 14 is included in the operation whitelist, the lock is unlocked and a corresponding operation record is generated.

[0049] For example, the work order parsing module 11 receives a work order text described in natural language from the operation and maintenance management system, and performs intelligent semantic analysis on the work order text to understand the work intent and operation targets. It automatically and accurately extracts the identification information of one or more target cabinets involved in the current operation. For instance, from the text "Please perform scheduled inspection on protection panels A and B of #1 main transformer," the cabinet numbers "A-101" and "A-102" to be operated are parsed out. Based on these precisely extracted target cabinet identifiers, the work order parsing module 11 generates a structured, machine-readable "operation whitelist." This operation whitelist is essentially a list containing only the cabinets allowed to be operated in this operation. It serves as the sole and accurate basis for subsequent permission allocation, fundamentally replacing the manual identification and verification process of operators in the traditional method, effectively eliminating the risk of oversight.

[0050] The dynamic permission allocation module 12 serves as the system's permission management center and security hub. It receives the "operation whitelist" from the work order parsing module 11 and dynamically associates and binds it with the specific operator's identity information (e.g., employee ID, name, position) and the work time window specified in the work task (i.e., the allowed start and end times). This module 12 is responsible for packaging the operation whitelist, operator identity information, work time window, and the unique device identifier of the smart terminal 13 into a four-dimensional association. It then uses encryption and digital signature technologies to generate an encrypted and digitally signed authorization data packet. This authorization data packet restricts the operator holding the operator's identity information to having permission to open the cabinets on the operation whitelist only within the specified work time window. Furthermore, the authorization data packet is bound to the unique device identifier of the smart terminal 13, limiting its validity to the bound smart terminal. Encryption ensures the confidentiality of the data packet content, preventing sensitive information leakage; the digital signature guarantees the integrity and trustworthiness of the data packet's source. Finally, the authorization data packet is distributed to the smart terminal 13 held by the operator. By dynamically binding permissions to specific personnel, precise time, designated terminals, and minimum device sets, this method achieves refined management and automatic revocation of permissions, effectively preventing the transfer and reuse of authorized data packets between different terminals and eliminating the abuse and retention of permissions.

[0051] The smart terminal 13 serves as the carrier of authorized data and the medium for interaction with the site. In some embodiments, the smart terminal 13 is a smart key card with a built-in security chip or a mobile terminal with an authorization management application installed. The secure storage area of ​​the security chip or the authorization management application is used to securely store the authorized data packets. The main responsibility of the smart terminal 13 is to securely store the authorized data packets received from the backend and, upon the arrival of the operator at the substation site, use them as electronic credentials of identity and authorization to interact with the smart lock 14 on the control panel. The built-in security chip is a security element with the ability to resist physical attacks and side-channel attacks. It has a key pair embedded inside for encryption and decryption and is equipped with a hardware-protected isolated storage area specifically for securely storing the authorized data packets and their decryption keys. When verifying the legitimacy of the authorized data packets, the security chip performs critical calculations directly within itself, ensuring that sensitive information is not exposed to the external environment. Thus, this terminal serves as the operator's sole authorization credential on site, ensuring end-to-end security of authorized data from receipt to use through a hardware-level security mechanism.

[0052] The smart lock 14 serves as the final execution unit and physical defense line for the system's anti-misoperation function. Deployed on each control cabinet requiring monitoring, each smart lock 14 internally stores or has a unique cabinet identifier corresponding to that cabinet. Accordingly, when an operator approaches the target cabinet with a smart terminal 13, the smart lock 14 reads the authorization data packet from the smart terminal 13 and executes a triple verification logic: 1) Verifying the validity of the authorization data packet itself, confirming its legitimate origin, lack of tampering, and expiration; 2) Verifying whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal 13, ensuring that the authorization packet is used only by the designated terminal; 3) Verifying whether its own cabinet identifier is included in the "operation whitelist" contained in the authorization data packet. Correspondingly, the smart lock 14 will only trigger its internal mechanism to unlock if all verifications pass; if any verification fails, unlocking is refused. Regardless of whether unlocking is successful or not, the smart lock 14 will generate a corresponding operation record, detailing the operation time, personnel, cabinet, and result, providing an immutable data foundation for operation auditing and event tracing.

[0053] The substation cabinet anti-misoperation unlocking system provided in this application automatically generates an accurate operation whitelist through semantic analysis of the work order parsing module, effectively eliminating errors and omissions that may be caused by manual identification and verification of work orders. The dynamic permission allocation module generates dynamically authorized encrypted data packets based on the operation whitelist, personnel identity, time window, and unique device identifier of the smart terminal, realizing a strong binding between permissions and designated terminals, further improving the fine-grained and timely control of permissions, and effectively preventing unauthorized operations. By forcibly verifying the validity of the authorization data packet and the matching of terminal identifier with the current cabinet identifier through smart locks, the possibility of accidentally opening non-target cabinets is reduced from the physical execution level. Combined with operation records, the entire process is traceable, thereby comprehensively improving the unplanned shutdowns and safety hazards caused by human error, loose permissions, and lack of closed-loop verification in traditional operations, and significantly improving the safety, standardization, and intelligence level of substation operation and maintenance.

[0054] In some embodiments, the work order parsing module performs semantic analysis on the work order text, extracts the target cabinet identifier, and generates an operation whitelist based on the target cabinet identifier. Specifically, this includes: using a pre-trained semantic parsing model to perform deep semantic analysis on the work order text, extracting the initial identifier information of the target cabinet specified in the work order text; associating and verifying the initial identifier information with a pre-built substation equipment knowledge graph to verify and determine the accurate target cabinet identifier; and generating an operation whitelist based on the verified target cabinet identifier.

[0055] For example, after receiving the work order text, the work order parsing module invokes a pre-trained semantic parsing model to perform deep semantic analysis on the text content. This semantic parsing model is based on an advanced natural language processing architecture and can understand the complex business language and instruction logic in the work order. Specifically, during the analysis process, the semantic parsing model first performs word segmentation, named entity recognition, and syntactic analysis, and then uses an attention mechanism to identify the explicitly specified cabinet information in the work order. For example, from text such as "perform routine inspection of protection A and B panels for #1 main transformer, and inspect synchronization panel C cabinet," the semantic parsing model initially extracts the initial identification information of the target cabinets, such as descriptive text like "protection A panel for #1 main transformer," "B panel," and "synchronization panel C cabinet." This initial identification information may contain various forms of expression, such as synonyms, abbreviations, or non-standard naming. Accordingly, the work order parsing module performs association matching and cross-validation of this information with a pre-built substation equipment knowledge graph. Among them, the substation equipment knowledge graph is constructed based on the substation design drawings, equipment ledgers, operation and maintenance history records and standard procedures, etc., structured and unstructured data; through information extraction technology, the equipment entities, attributes and relationships are automatically extracted, and supplemented by manual review, forming a structured knowledge base that includes, for example: standard cabinet number (such as "PB-A-101"), equipment official name (such as "#1 main transformer protection A panel"), equipment alias or common name (such as "main transformer A panel"), physical and logical relationships between cabinets, electrical bays and functional categories to which the equipment belongs, etc.; the verification process includes the following steps: (1) Existence verification: confirm whether the extracted cabinet identifier has a corresponding entity in the substation equipment knowledge graph, for example, verify whether "B panel" can be found in the current substation cabinet record; (2) Consistency verification: through the relationship network of the substation equipment knowledge graph, verify the logical consistency between the initially extracted cabinet identifiers, for example, when the work order mentions "main transformer protection A panel and the corresponding control panel", the substation equipment knowledge graph can verify that the two cabinets do have a corresponding relationship of protection and control functions. (3) Ambiguity Removal: When the initial identification information is ambiguous (e.g., multiple "synchronous panels" may exist in the same substation), the contextual information (such as equipment location and associated bay) in the substation equipment knowledge graph is used to remove ambiguity and determine the specific panel. Further, after verification by the substation equipment knowledge graph, the work order parsing module converts the verified target panel identifier into a structured format and generates a final operation whitelist. This whitelist contains the unique identification information of all target panels that have been confirmed as permissible for operation.

[0056] In this embodiment, a pre-trained semantic parsing model is used to perform deep parsing and automated information extraction of work order text, replacing the traditional work mode that relies on manual identification and conversion. This fundamentally reduces the risk of errors and omissions in cabinet identification caused by human negligence, complex text descriptions, or ambiguous numbering. Furthermore, by associating and verifying the initially extracted identification information with the substation equipment knowledge graph, the accuracy, standardization, and business logic rationality of the target cabinet identification are further ensured. This effectively overcomes the misjudgments or limitations that may exist in a single model, and significantly improves the accuracy, automation level, and overall security of operation and maintenance.

[0057] In some embodiments, the pre-trained semantic parsing model is a natural language processing model based on the Transformer architecture.

[0058] Among them, the Transformer architecture is an advanced neural network architecture that abandons the sequence dependency relationship of traditional recurrent neural networks (RNNs). Its core technology lies in the self-attention mechanism, which allows the model to calculate the association weight between each word and all other words in the text when processing each word, thereby achieving global modeling and deep understanding of contextual information.

[0059] Specifically, the model can include, but is not limited to, the original Transformer model with an encoder-decoder architecture, the BERT (Bidirectional Encoder Representations from Transformers) model with an encoder-only architecture, the GPT (Generative Pre-trained Transformer) series models with a decoder-only architecture, or customized variants optimized for the power industry. Among them, the BERT model employs a bidirectional encoding mechanism, enabling it to understand the context of words simultaneously from both left and right directions, making it particularly adept at named entity recognition and information extraction tasks; the GPT model employs a unidirectional autoregressive generation mechanism, excelling at handling long text sequences and understanding instruction logic. All of these models are based on a self-attention mechanism and are pre-trained on large amounts of text corpora, possessing powerful language understanding and sequence modeling capabilities.

[0060] In practical applications, the appropriate model can be selected based on the actual application scenario and resource constraints. For example, when focusing on deep semantic understanding and accurate information extraction of work order text, a BERT-type bidirectional encoding model can be chosen; when processing longer texts containing complex operation steps or considering the logical generation of instructions, a GPT-type autoregressive model can be used; or the advantages of both can be combined to build a hybrid architecture. In addition, based on the above general models, domain-specific corpora in the power industry (such as historical work orders, equipment ledgers, and on-site operating procedures of substations) can be used for further fine-tuning to build a domain-specific model that is more in line with the substation operation and maintenance scenario, thereby improving the parsing accuracy and robustness of power industry professional terms, non-standard expressions, and complex referential relationships.

[0061] This application's embodiment employs a Transformer-based natural language processing model. Its core self-attention mechanism enables a global understanding of the text context, accurately capturing complex technical terms, non-standard expressions, and long-distance semantic dependencies in work orders, effectively overcoming the reliance on rules and fixed templates inherent in traditional methods. Furthermore, this architecture, through a "pre-training + domain fine-tuning" paradigm, can quickly adapt to the terminology habits of different substations, demonstrating excellent domain adaptability. Simultaneously, the model's parallel computing capabilities ensure efficient parsing, better meeting real-time operational needs and laying a solid technical foundation for building a highly reliable and intelligent substation cabinet anti-misoperation unlocking system.

[0062] Based on the above embodiments, in some embodiments, the dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature, including: associating and encapsulating the operation whitelist, operator's identity information and operation time window; encrypting the encapsulated data; digitally signing the encrypted data using the private key of the digital certificate to generate an authorization data packet; and sending the authorization data packet to the bound smart terminal through a secure communication link.

[0063] For example, upon receiving the structured operation whitelist from the work order parsing module, the dynamic permission allocation module logically associates and encapsulates this operation whitelist with the operator's identity information (such as employee ID, name, and work group) obtained from, for example, the enterprise identity management system, and the precise operation time window (start and end times accurate to the second) synchronized from the work order system, forming an original authorization instruction package containing four complete elements: "who, what equipment can be operated, when to operate, and with which terminal".

[0064] Accordingly, to ensure the confidentiality of the data content and prevent sensitive information from being stolen or leaked during transmission or storage, the encapsulated data is encrypted. In some embodiments, the encryption process employs a symmetric encryption algorithm. For example, a symmetric encryption algorithm such as AES-256 (Advanced Encryption Standard with a 256-bit key) is used to perform high-strength encryption on the original authorization instruction packet. This algorithm has the advantages of fast encryption and decryption speed and relatively low computational resource consumption, making it suitable for the rapid encryption needs of processing batch authorization data.

[0065] In addition, to ensure data integrity, reliable source, and tamper-proof protection, the dynamic permission allocation module calls the private key of the digital certificate deployed in the security hardware to calculate the digest of the encrypted data and perform digital signature.

[0066] Furthermore, the encrypted data and digital signature are combined according to a predetermined format to generate the final authorization data packet. This authorization data packet is then transmitted via a secure communication link to the smart terminal held by the operator associated with it, such as a smart key card or a mobile terminal with an authorization management application installed. By binding the authorization data packet to the unique device identifier of the smart terminal, it is ensured that the authorization data packet can only be used on the designated terminal, effectively preventing the authorization data packet from being transferred, copied, and reused between different terminals.

[0067] This application embodiment achieves a four-dimensional, refined, and time-sensitive binding of "who, when, with which terminal, and which cabinet can be opened" by dynamically associating and encapsulating the operation whitelist, personnel identity, time window, and unique device identifier of the smart terminal. This effectively prevents the transfer and reuse of authorized data packets between different terminals, eliminating abuse of permissions and operations beyond their scope. Furthermore, core authorized data is encrypted to ensure the confidentiality of sensitive information and reduce the risk of theft or leakage during transmission and storage. In addition, digital signatures using digital certificate private keys endow data packets with immutability and source credibility. Finally, secure communication links are used to direct the data packets to the bound smart terminal, constructing a secure transmission channel from the server to the designated terminal. This series of measures constitutes a multi-layered, in-depth security protection system from permission generation to terminal binding. It not only ensures the accuracy and security of single authorized operations but also establishes a solid and reliable security trust foundation for the entire substation cabinet anti-misoperation unlocking system, significantly improving the system's overall anti-attack and anti-tampering capabilities.

[0068] In some embodiments, the secure communication link is a TLS encrypted channel.

[0069] For example, the transmission of authorization data packets between the dynamic permission allocation module and the smart terminal is completed through a TLS encrypted channel. The TLS protocol is a standardized secure communication protocol widely used in the Internet and industrial control fields, which can provide end-to-end encrypted transmission protection for upper-layer applications.

[0070] Specifically, during the establishment of a communication connection, the server side (i.e., the backend system where the dynamic permission allocation module resides) and the client side (i.e., the smart terminal, such as a smart key card or mobile terminal application) perform a standard TLS handshake protocol. This handshake process includes the following key steps:

[0071] Negotiated Encryption Suite: Both parties exchange lists of their supported encryption algorithms, key exchange algorithms, and hash algorithms, and jointly select a set of mutually supported encryption suites with the highest security.

[0072] Identity authentication: The server presents its digital certificate issued by a trusted Certificate Authority (CA) to the client. The client verifies the signature validity, validity period and domain name information of the certificate to confirm the authenticity of the connected server. Optionally, the client can also present its device certificate to the server to achieve two-way identity authentication.

[0073] Key Negotiation: Both parties negotiate and generate a temporary session key for this session only, using a secure key exchange algorithm such as Elliptic Curve Diffie-Hellman Ephemeral (ECDHE), without directly transmitting the key. This key employs a "forward secrecy" mechanism, ensuring that even if the server's long-term private key is later leaked, the previously recorded encrypted communication content cannot be deciphered.

[0074] Encrypted channel establishment: After the handshake is completed, both parties use the agreed session key to encrypt all data transmitted subsequently using a symmetric encryption algorithm (such as AES-256). At the same time, they use a Message Authentication Code (MAC) to calculate an integrity check value for each piece of data to ensure the confidentiality and integrity of the data during transmission.

[0075] Subsequently, all authorized data packets transmitted over the network (including their content and signature information) are securely transmitted in this TLS encrypted channel, achieving multiple layers of security without the need for additional application-layer encryption.

[0076] The core security guarantees provided by the TLS protocol include: 1) Confidentiality: All transmitted data is encrypted with a session key. Even if network packets are intercepted by a third party, the specific content of the authorized data packets cannot be decrypted without knowing the session key, preventing data from being eavesdropped on during transmission. 2) Integrity: Through the message authentication code mechanism, the receiver can verify whether each piece of data has been accidentally or maliciously modified during transmission, preventing data from being tampered with by a man-in-the-middle attack. 3) Identity authentication: The identities of both communicating parties are verified through a digital certificate chain, effectively preventing attackers from impersonating legitimate dynamic permission allocation modules or smart terminals to conduct man-in-the-middle attacks (MITM), avoiding the interception or replacement of authorized data packets. In addition, the TLS protocol also has the following advantages: 1) Wide compatibility: TLS is a standardized security protocol, widely supported by various operating systems, smart terminal devices, and embedded systems, facilitating cross-platform deployment and integration of systems. 2) Scalability: It supports protocol version upgrades and flexible configuration of encryption algorithm suites, enabling it to adapt to the evolution of higher security standards in the future. 3) Performance optimization: TLS version 1.3 further simplifies the handshake process, reducing the handshake latency from two round trips to one, significantly improving communication efficiency and making it more suitable for field operation scenarios with certain requirements for response speed.

[0077] In this embodiment of the application, the TLS encryption channel mechanism effectively ensures the security and reliability of the entire transmission process of authorized data packets from the dynamic permission allocation module to the smart terminal, building a solid security barrier at the network communication level. This better meets the requirements of power industry standards such as the security protection regulations for power monitoring systems regarding the confidentiality, integrity, and authenticity of sensitive data transmissions.

[0078] In some embodiments, the smart lock is specifically used to: read the authorization data packet in the smart terminal via near-field communication; verify the validity of the digital signature of the authorization data packet, and verify whether the current time is within the operation time window contained in the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal; if the signature verification, time verification, and terminal identifier matching verification all pass, then verify whether the cabinet identifier stored in itself exists in the operation whitelist, and if the verification passes, perform the unlocking operation and generate an operation record; if any of the signature verification, time verification, terminal identifier matching verification, or cabinet identifier verification fails, then refuse to unlock and trigger a local alarm.

[0079] For example, when an operator approaches the target cabinet with an authorized smart terminal (such as a smart key card or mobile terminal), the smart lock deployed on the cabinet interacts with the smart terminal via Near Field Communication (NFC) or Bluetooth. The smart lock initiates a secure communication session with the smart terminal, reads the authorization data packet stored in the smart terminal, and performs critical security verification. Specifically, the smart lock first decrypts the authorization data packet and verifies the validity of the digital signature in the authorization data packet to confirm that the data has not been tampered with. After the signature verification is successful, the smart lock parses the operation time window (i.e., the allowed start and end times of the operation) from the decrypted data packet and compares it with the real-time clock (RTC) built into the smart lock to verify whether the current time is within the authorized time window. This verification mechanism ensures the timeliness of the authorization and reduces the possibility of exceeding the time limit or starting the operation early. If the current time is earlier than the start time or later than the end time, the verification fails.

[0080] After both signature verification and time verification pass, the smart lock also verifies whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal, to ensure that the authorization data packet is used only by the designated smart terminal and to prevent the authorization packet from being transferred, copied and reused between different terminals.

[0081] Furthermore, after the signature verification, time verification, and terminal identifier matching verification are all passed, the cabinet identifier verification is performed: the smart lock reads its own unique cabinet identifier (such as "PS-A-101"), which is bound to the current physical cabinet, from its tamper-proof secure storage area; at the same time, it extracts the operation whitelist (i.e., the list of cabinet identifiers allowed to be operated) signed by the backend from the authorized data packet; the smart lock compares its own cabinet identifier with the operation whitelist one by one, and performs a "whether it contains" logical judgment; the verification is deemed to be passed only if its own cabinet identifier is clearly present in the operation whitelist. The smart lock's logic control unit sends a command to the actuator (such as the motor drive circuit) to retract the bolt and perform the unlocking operation only when all the above-mentioned signature verification, time verification, terminal identifier matching verification, and cabinet identifier verification pass. If any of the above verification steps fail (including but not limited to: invalid signature, expired certificate, current time not within the window, mismatched terminal identifier, or cabinet identifier not in the operation whitelist), the smart lock will refuse to perform the unlocking action and immediately trigger a local alarm device upon verification failure or detection of anomalies such as forced unlocking or multiple verification failures. For example, the alarm is divided into two levels: for routine verification failures (such as invalid signature, mismatched time, or mismatched cabinet identifier), a level one alarm is triggered, which is manifested by a continuous buzzing prompt; if the smart lock detects anomalies such as multiple consecutive verification failures, external damage, or illegal disassembly, a level two alarm is triggered, which is manifested by a high-frequency buzzing and a red warning light flashing simultaneously. This hierarchical early warning mechanism helps on-site personnel quickly identify the urgency of the event.

[0082] Simultaneously, if the verification is successful and unlocking is achieved, the smart lock will record a detailed operation log, including but not limited to the operator's identity information, the unlocked cabinet identifier, the specific unlocking time, and the authorized data packet number used. If the cabinet identifier verification fails, the smart lock will record an abnormal operation log, including but not limited to the operator's identity information, cabinet identifier, reason for failure, and time.

[0083] This application embodiment achieves comprehensive security and automated error prevention for on-site unlocking operations by implementing a strict "four-fold verification" closed loop through smart locks. Specifically, by verifying digital signatures, the source of authorization commands is ensured to be trustworthy and the data integrity is guaranteed, reducing attacks that forge or tamper with permissions at the source. Secondly, by verifying the operation time window in real time, permissions are forcibly bound to a precise time period, effectively preventing unauthorized operations during timeouts, delays, or unplanned times. Thirdly, by verifying whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal, it is ensured that the authorization packet is only valid on the designated terminal, effectively preventing the transfer, copying, and reuse of the authorization packet between different terminals. Finally, by forcibly comparing the current cabinet identifier with the authorization whitelist, a "one cabinet, one verification" physical error prevention mechanism is formed, effectively reducing the possibility of accidentally opening or opening the wrong non-target cabinet. In addition, failure in any step will result in refusal to unlock and a real-time alarm, forming an immediate feedback and proactive protection capability. At the same time, the automatically generated trusted operation records provide an immutable basis for event tracing and responsibility determination. By transforming static authorization in the background into dynamic and mandatory safety enforcement on-site, this mechanism achieves a leap from "human-based" to "technology-based" security, significantly improving operational safety and management reliability.

[0084] In some embodiments, the substation cabinet anti-misoperation unlocking system also includes a management platform, which is used to receive and store operation records and alarm records uploaded by smart locks.

[0085] For example, the substation panel locker anti-misoperation system also includes a management platform. This management platform serves as the system's data aggregation center and operation and maintenance management portal. It maintains communication with each smart lock via the substation's communication network, enabling centralized management of the numerous smart locks deployed in a dispersed manner. Smart locks can access the substation's communication network via an intra-station wireless network (such as Wi-Fi) or a Low-Power Wide-Area Network (LPWAN), or via wired connections such as industrial Ethernet, to adapt to the different network environments of various substations.

[0086] Accordingly, when the smart lock performs an unlocking operation or triggers an alarm, it will encapsulate and encrypt the generated operation record or alarm record according to a preset strategy (such as real-time upload or batch reporting) and immediately upload it to the management platform. Specifically, the operation record includes, but is not limited to, the following key fields: operator identification information (such as employee ID, name), the identifier of the operated cabinet, the precise timestamp of unlocking, the unique number of the authorized data packet, and the operation result (such as "success" or "failure"). The alarm record includes, but is not limited to, the following key fields: alarm trigger time, the identifier of the cabinet that triggered the alarm, the reason for failure (such as "digital signature verification failed", "operation time window timeout", "operation whitelist mismatch", etc.), and the associated authorized data packet number (if available).

[0087] Correspondingly, upon receiving these records, the management platform first performs data parsing and source legitimacy verification to confirm that the records indeed originate from legitimate smart locks. Then, it categorizes and stores these records in a highly reliable and secure database, encrypting sensitive information (such as personnel identification and locker identifiers) to protect data privacy. Simultaneously, the platform provides a visual monitoring dashboard that displays the real-time status of all online smart locks (such as "online / offline," "locked / unlocked"), the latest operation events, and alarm events.

[0088] In addition, the management platform also provides the following core functions:

[0089] 1) Historical Inquiry and Audit: Operation and maintenance personnel or safety auditors can use the platform to flexibly query historical operation records and alarm records by combining multiple dimensions such as time range, substation area, cabinet identification, and operator, so as to quickly locate specific events and better meet the audit and traceability requirements of power operation and maintenance.

[0090] 2) Statistical analysis and report generation: The platform supports the generation of standardized reports by day, week, month or custom period, such as operation statistics reports, alarm analysis reports, equipment utilization reports, etc., to provide data support for operation and maintenance management decisions.

[0091] 3) Anomaly monitoring and alarm notification: The platform can automatically identify and mark high-frequency alarms, consecutive failed attempts in a short period of time, and abnormal operation modes of specific cabinets, and issue real-time monitoring notifications to operation and maintenance personnel through color highlighting, pop-up reminders or sound and light prompts, so as to facilitate timely intervention and handling.

[0092] 4) Hierarchical permission management: The platform supports account management with multiple roles and levels of permissions. Different roles, such as system administrators, security auditors, and general maintenance personnel, are granted different data access and operation permissions, which complies with the "separation of powers" security management standard in the power industry.

[0093] In this embodiment of the application, the integration of the aforementioned management platform enables closed-loop management from decentralized on-site execution to centralized back-end monitoring. This not only ensures that all operational behaviors are "traceable and verifiable," meeting the power industry's requirements for full-process traceability and auditability of operation and maintenance, but also provides a solid data foundation and decision support for continuous optimization of operation and maintenance processes and prevention of potential safety risks through data statistical analysis and anomaly monitoring capabilities.

[0094] In some embodiments, the substation cabinet anti-misoperation unlocking system also includes a blockchain evidence storage module, which is used to write summary information of operation records and / or alarm records into the blockchain network for evidence storage.

[0095] For example, Figure 2 Another structural schematic diagram of a substation cabinet anti-misoperation unlocking system provided as an exemplary embodiment of this application. (See diagram below.) Figure 2 As shown, the substation cabinet anti-misoperation unlocking system 10 also includes a management platform 15 and a blockchain evidence storage module 16.

[0096] Accordingly, when the management platform 15 receives the operation records or alarm records uploaded by the smart lock 14, the blockchain evidence storage module 16 extracts and standardizes the key fields of these records (such as operation time, cabinet identification, personnel identity, operation result, etc.) or the calculated data digests (hash values) to form a data packet to be stored. Then, the blockchain evidence storage module 16 submits the data packet to be stored to a blockchain network in the power industry, for example, built on consortium blockchain technology, through an encrypted secure interface. This blockchain network is jointly maintained by multiple trusted nodes (such as power grid companies, operation and maintenance units, and regulatory agencies).

[0097] Correspondingly, after the data packet to be stored is verified by the blockchain network consensus mechanism, it is timestamped and written into a new block, forming an irreversible chain of evidence storage with the previous and subsequent blockchains, thus forming an immutable, traceable, and time-stamped permanent record.

[0098] This application embodiment introduces a blockchain evidence storage module, writing the summary information of key records into a distributed, tamper-proof blockchain network. This effectively reduces the possibility of data being privately modified, deleted, or forged, ensuring the integrity and credibility of audit evidence and greatly enhancing the traceability and transparency of the operation process. This mechanism not only meets the stringent requirements of the power industry for "full-process traceability and non-repudiation" in operation and maintenance operations, but also provides a reliable data foundation for accident analysis, responsibility determination, and safety auditing, significantly improving the data credibility and security management effectiveness of the entire substation cabinet anti-misoperation system.

[0099] The above embodiments illustrate the implementation of the substation panel cabinet anti-misoperation unlocking system. Next, specific embodiments will be used to introduce the application of this system.

[0100] Figure 3 This is a flowchart illustrating a method for preventing accidental unlocking of substation cabinets, provided as an exemplary embodiment of this application. The method for preventing accidental unlocking of substation cabinets provided in this application is applied to a substation cabinet accidental unlocking system as described in any of the above embodiments. Figure 3 As shown, the method for preventing accidental unlocking of the substation cabinet includes:

[0101] S301. Upon receiving the work order text, the work order parsing module performs semantic analysis on the work order text, extracts the target cabinet identifier, and generates an operation whitelist based on the target cabinet identifier.

[0102] For example, when a new substation work assignment arrives, the input work order information is received by the work order parsing module. This module utilizes a pre-trained Transformer model, combined with a pre-built substation equipment knowledge graph, to perform deep semantic analysis on the work order text. This process aims to automatically identify and extract the precise identifiers of all target cabinets related to the current work, such as their numbers and names, thereby forming a precise operation whitelist and effectively reducing potential oversights that may occur during manual verification.

[0103] S302 The dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. The authorization data packet is used to limit the operator holding the operator's identity information to having the permission to open the cabinets in the operation whitelist only within the operation time window. The authorization data packet is also bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal.

[0104] For example, the parsed list of target cabinets is then passed to the dynamic permission allocation module. This module integrates the operation whitelist, the operator's identity information (such as employee ID, permission level, etc.), and the allowed time window for this operation (start and end time). Based on this, an authorization data packet containing this key information is generated. This authorization data packet restricts the operator holding the operator's identity information to having the permission to open cabinets in the operation whitelist only within the specified operation time window. Furthermore, this authorization data packet is bound to the unique device identifier of the smart terminal, limiting its validity to the bound smart terminal. To ensure data security, the authorization data packet is first symmetrically encrypted to protect sensitive content, and then digitally signed using the private key of the digital certificate in the digital certificate system to ensure data integrity and immutability. Finally, the encrypted and signed authorization data packet is securely transmitted through an established TLS secure encrypted channel to the smart key card used by the operator bound to it or to a mobile terminal with the authorization management application installed.

[0105] S303, the intelligent terminal securely stores the authorized data packet and serves as the interaction carrier at the unlocking site.

[0106] S304. The smart lock reads the authorization data packet from the smart terminal, verifies the validity of the authorization data packet, and verifies whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal. If the verification is successful and the operation whitelist includes the smart lock's cabinet identifier, the lock is unlocked, and a corresponding operation record is generated.

[0107] For example, when an operator arrives at the target cabinet with their smart key card or a mobile terminal with an authorized management application installed, and is about to unlock it, the smart lock (which has a cabinet identifier uniquely corresponding to the cabinet burned into or stored inside) will read the authorized data packet from the operator's smart key card or mobile terminal through near field communication (such as NFC) or other wireless communication methods.

[0108] Correspondingly, after receiving the authorization data packet, the smart lock will perform key verification steps, specifically including: decrypting the authorization data packet; verifying the validity of the digital signature in the authorization data packet to confirm that the data has not been tampered with; verifying whether the current time is within the operation time window contained in the authorization data packet to ensure that the permission has not expired; and verifying whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal to ensure that the authorization packet is only used by the designated terminal and to prevent it from being transferred, copied, and reused between different terminals. Furthermore, it compares whether the operation whitelist listed in the authorization data packet includes the cabinet identifier associated with the current lock.

[0109] Accordingly, if signature verification, time verification, terminal identifier matching verification, and cabinet identifier verification all pass (meaning the cabinet identifier is on the authorized operation whitelist), the smart lock will drive its internal motor to perform the unlocking action. After unlocking, the smart lock will record the operation details, including the operator's identity information, the successfully unlocked cabinet identifier, the precise operation time, and the unique number of the authorized data packet used. This information is encrypted and uploaded to the backend management platform in real time via the network. If, during the verification process, an invalid signature, time outside the window, mismatched terminal identifier, or cabinet identifier not on the authorized list is found, or if the signature is invalid, the smart lock will immediately refuse to perform the unlocking action. In addition, to promptly alert operators and security personnel, the lock will trigger a local alarm. Simultaneously, records of this abnormal operation (such as the person attempting to unlock, the target cabinet identifier, the reason for failure, and the operation time) will also be encrypted and uploaded to the management platform in real time for subsequent security audits and incident investigations.

[0110] In this embodiment, the semantic analysis of the work order parsing module automatically generates an accurate operation whitelist, effectively eliminating errors and omissions that may be caused by manual identification and verification of work orders. The dynamic permission allocation module generates dynamically authorized encrypted data packets based on the operation whitelist, personnel identity, time window, and unique device identifier of the smart terminal, realizing a strong binding between permissions and designated terminals, further improving the fine-grained and timely control of permissions, and effectively preventing unauthorized operations. By forcibly verifying the validity of the authorization data packet and the matching of terminal identifier with the current cabinet identifier through smart locks, the possibility of mistakenly opening non-target cabinets is reduced from the physical execution level. Combined with operation records, the entire process is traceable, thereby comprehensively improving the unplanned shutdowns and safety hazards caused by human error, loose permissions, and lack of closed-loop verification in traditional operations, and significantly improving the safety, standardization, and intelligence level of substation operation and maintenance.

[0111] Figure 4 Another flowchart illustrating the method for preventing accidental unlocking of substation cabinets provided as an exemplary embodiment of this application. Figure 4 As shown, the method for preventing accidental unlocking of the substation cabinet includes:

[0112] S401. Upon receiving the work order text, the work order parsing module performs semantic analysis on the work order text, extracts the target cabinet identifier, and generates an operation whitelist based on the target cabinet identifier.

[0113] For example, the work order parsing module receives a work order text described in natural language from the operation and maintenance management system. It performs intelligent semantic analysis on the work order text to understand the work intent and the target devices, automatically and accurately extracting the identification information of one or more target cabinets involved in the current operation. For instance, from the text "Please perform scheduled inspection on protection panels A and B of #1 main transformer," the cabinet numbers "A-101" and "A-102" to be operated are parsed out. Based on these precisely extracted target cabinet identifiers, the work order parsing module 11 generates a structured, machine-readable "operation whitelist." This operation whitelist is essentially a list containing only the cabinets allowed to be operated in this operation. It serves as the sole and accurate basis for subsequent permission allocation, fundamentally replacing the traditional manual identification and verification process by operators, effectively eliminating the risk of oversight.

[0114] In some embodiments, the work order parsing module performs semantic analysis on the work order text, extracts the target cabinet identifier, and generates an operation whitelist based on the target cabinet identifier. Specifically, this includes: using a pre-trained semantic parsing model to perform deep semantic analysis on the work order text, extracting the initial identifier information of the target cabinet specified in the work order text; associating and verifying the initial identifier information with a pre-built substation equipment knowledge graph to verify and determine the accurate target cabinet identifier; and generating an operation whitelist based on the verified target cabinet identifier.

[0115] In some embodiments, the pre-trained semantic parsing model is a natural language processing model based on the Transformer architecture.

[0116] Specifically, the model can include, but is not limited to, the original Transformer model with an encoder-decoder architecture, the BERT model with an encoder-only architecture, the GPT series models with a decoder-only architecture, or customized variants optimized for the power industry. Among them, the BERT model employs a bidirectional encoding mechanism, enabling it to understand the context of words simultaneously from both left and right directions, making it particularly adept at named entity recognition and information extraction tasks; the GPT model employs a unidirectional autoregressive generation mechanism, excelling at handling long text sequences and understanding instruction logic. All of these models are based on a self-attention mechanism and are pre-trained on large amounts of text corpora, possessing powerful language understanding and sequence modeling capabilities.

[0117] In practical applications, the appropriate model can be selected based on the actual application scenario and resource constraints. For example, when focusing on deep semantic understanding and accurate information extraction of work order text, a BERT-type bidirectional encoding model can be chosen; when processing longer texts containing complex operation steps or considering the logical generation of instructions, a GPT-type autoregressive model can be used; or the advantages of both can be combined to build a hybrid architecture. In addition, based on the above general models, domain-specific corpora in the power industry (such as historical work orders, equipment ledgers, and on-site operating procedures of substations) can be used for further fine-tuning to build a domain-specific model that is more in line with the substation operation and maintenance scenario, thereby improving the parsing accuracy and robustness of power industry professional terms, non-standard expressions, and complex referential relationships.

[0118] S402 The dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature.

[0119] The authorization data packet is used to limit the permissions of operators who possess the operator's identity information to only have the authority to open the whitelisted cabinets within the operation time window; and the authorization data packet is bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal.

[0120] For example, the dynamic permission allocation module serves as the system's permission management center and security hub. It receives the "operation whitelist" from the work order parsing module and dynamically associates and binds it with the specific operator's identity information (e.g., employee ID, name, and position) and the work time window specified for the task (i.e., the allowed start and end times). Based on this, an authorization data packet containing this key information is generated. This authorization data packet restricts the operator holding the operator's identity information to having permission to open the cabinets on the operation whitelist only within the specified work time window. Furthermore, this authorization data packet is bound to the unique device identifier of the smart terminal, limiting its validity to the bound smart terminal. To ensure data security, the authorization data packet is first symmetrically encrypted to protect sensitive content, and then digitally signed using the private key of a digital certificate in a digital certificate system, ensuring data integrity and immutability. By binding the authorization data packet to the unique device identifier of the smart terminal, the transfer, copying, and reuse of the authorization data packet between different terminals are effectively prevented. Furthermore, the encrypted and signed authorization data packets are then distributed via an established TLS secure encrypted channel to the smart key cards used by the personnel associated with them or to mobile terminals with authorization management applications installed.

[0121] In some embodiments, the encryption process employs a symmetric encryption algorithm. For example, a symmetric encryption algorithm such as AES-256 is used to perform high-strength encryption on the original authorization data packet. This algorithm has the advantages of fast encryption and decryption speed and relatively low computational resource consumption, making it suitable for the rapid encryption needs of processing batches of authorization data.

[0122] S403, the intelligent terminal securely stores the authorized data packet and serves as the interaction carrier at the unlocking site.

[0123] Accordingly, the smart terminal serves as the carrier of authorized data and the medium for interaction with the site. In some embodiments, the smart terminal is a smart key card with a built-in security chip or a mobile terminal with an authorization management application installed. The secure storage area of ​​the security chip or the authorization management application is used to securely store the authorized data packets. The main responsibility of this smart terminal is to securely store the authorized data packets received from the backend and, upon the arrival of the operator at the substation site, use them as electronic credentials of identity and authority to interact with the smart locks on the control panel. The built-in security chip is a security element with the capability to resist physical attacks and side-channel attacks. It has a built-in key pair for encryption and decryption and a hardware-protected isolated storage area specifically for securely storing the authorized data packets and their decryption keys. When verifying the legitimacy of the authorized data packets, the security chip performs critical calculations directly within itself, ensuring that sensitive information is not exposed to the external environment. Thus, this terminal, as the operator's sole authorization credential on site, ensures end-to-end security of authorized data from receipt to use through a hardware-level security mechanism.

[0124] S404. The smart lock reads the authorization data packet in the smart terminal, verifies the validity of the authorization data packet, and verifies whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal.

[0125] Among them, smart locks are the final execution unit and physical defense line of the system's anti-misoperation function. They are deployed on every control cabinet that needs to be managed, and each smart lock has a unique cabinet identifier that is fixed or stored inside. Accordingly, when an operator approaches the target cabinet with a smart terminal, the smart lock reads the authorization data packet in the smart terminal and executes the verification logic.

[0126] S405. If the authorized data packet is valid and the terminal identifier matches, verify whether the current time is within the job time window contained in the authorized data packet.

[0127] If so, execute S406;

[0128] If not, proceed with S410.

[0129] S406. Verify whether the whitelist includes the smart lock cabinet identifier.

[0130] Specifically, the verification logic includes: 1) verifying the validity of the authorization data packet itself, including digital signature verification, to confirm that it has not been tampered with and that its source is legitimate; 2) verifying whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal; 3) verifying whether the current time is within the operation time window contained in the authorization data packet; 4) verifying whether its own cabinet identifier is included in the "operation whitelist" contained in the authorization data packet.

[0131] If so, execute S407;

[0132] If not, proceed with S410.

[0133] S407, the smart lock drives its internal motor to perform the unlocking action.

[0134] Correspondingly, the smart lock will only activate its internal mechanism to unlock if all verifications pass; if any verification fails, it will refuse to unlock.

[0135] S408. Record the operation log for this operation, including the identity information of the operator who performed the operation, the identifier of the cabinet that was successfully unlocked, the precise operation time, and the unique number of the authorized data packet used.

[0136] Specifically, regardless of whether the unlocking is successful or not, the smart lock will generate a corresponding operation record, which will record the operation time, personnel, reasons for failure and results of the cabinet in detail, so as to provide an immutable data foundation for operation auditing and event tracing.

[0137] S409. Upload the encrypted operation records to the management platform.

[0138] S410, the smart lock refuses to perform the unlocking action.

[0139] S411, Trigger the local alarm device.

[0140] Specifically, upon verification failure or detection of anomalies such as forced unlocking or multiple verification failures, a local alarm device is immediately triggered to issue a warning. For example, the alarm is divided into two levels: a level one alarm is triggered for routine verification failures (such as invalid signatures, inconsistent times, or mismatched cabinet identifiers), characterized by a continuous beeping sound; if the smart lock detects anomalies such as multiple consecutive verification failures, external damage, or unauthorized disassembly, a level two alarm is triggered, characterized by a high-frequency beeping sound and a flashing red warning light. This tiered warning mechanism helps on-site personnel quickly identify the urgency of the incident.

[0141] S412. Upload abnormal operation records to the management platform.

[0142] In summary, this application has at least the following advantages:

[0143] First, by using natural language semantic parsing technology to perform deep intelligent analysis on work order text, it can automatically and accurately extract target cabinet information and generate a structured operation whitelist, effectively replacing the traditional operation mode that relies on manual identification and verification. This fundamentally reduces the risk of identification omissions and misreadings caused by the large number of cabinets on site, complex numbering, and human negligence, and significantly improves the accuracy and automation of the operation preparation process.

[0144] Second, by dynamically associating the operation whitelist with the specific operator's identity, precise operation time window, and the unique device identifier of the smart terminal, a time-sensitive authorization data packet bound to the designated terminal is generated. This allows permissions to automatically take effect and expire according to the preset time window, and are only valid on the bound smart terminal. This effectively prevents the transfer, copying, and reuse of authorization data packets between different terminals, and achieves refined permission control of "who, when, with which terminal, and which cabinet can be opened". This effectively reduces security risks such as overuse of permissions, key retention, or misuse under the traditional static authorization mode.

[0145] Third, during the unlocking process, the smart lock forcibly verifies the legality of the authorization data packet, the matching of the terminal identifier, the validity of the time window, and whether the current cabinet identifier exists in the operation whitelist, forming a quadruple guarantee of "digital authorization verification + terminal identity authentication + time window verification + physical identifier matching". This mechanism effectively prevents the possibility of accidentally opening non-target cabinets and the authorization data packet being used by non-designated terminals, transforming "not opening the wrong cabinet" from a management requirement into an insurmountable technical rule.

[0146] Fourth, sensitive information storage is protected through security chips, data transmission security is ensured through TLS encryption, authorized data integrity and trustworthiness are guaranteed based on digital signatures, and blockchain technology is introduced to prevent tampering and preserve operation records. These measures together achieve end-to-end security protection and trustworthy traceability from data generation, transmission, storage to auditing, effectively meeting the highest level of security compliance requirements for operation and maintenance in the power industry.

[0147] Based on the above-mentioned technical advantages, this application not only significantly reduces the risk of unplanned outages and safety accidents caused by misoperation, but also reduces work preparation time through process automation and simplifies management and auditing work through electronic records. While improving the safety of on-site operations, it significantly improves the standardization and overall efficiency of operation and maintenance work, providing reliable technical support for the intelligent and lean operation and maintenance management of substations.

[0148] This application also provides a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are executed, they are used to implement the method steps as described in the above method embodiments. The specific implementation methods and technical effects are similar and will not be repeated here.

[0149] The aforementioned computer-readable storage media can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0150] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Alternatively, the readable storage medium can be an integral part of the processor. The processor and the readable storage medium can reside within an application-specific integrated circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in a substation panel lockout anti-misoperation system.

[0151] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0152] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0153] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0154] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0155] This application also provides a computer program product, including a computer program, which, when executed, implements the method steps as described in the above method embodiments. The specific implementation and technical effects are similar and will not be repeated here.

[0156] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0157] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0158] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.

Claims

1. A substation panel cabinet anti-misoperation unlocking system, characterized in that, It includes a work order parsing module, a dynamic permission allocation module, a smart terminal, and a smart lock, among which: The work order parsing module is used to respond to the received work order text, perform semantic analysis on the work order text, extract the target cabinet identifier, and generate an operation whitelist based on the target cabinet identifier; The dynamic permission allocation module is used to associate the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. The authorization data packet is used to limit that the operator holding the operator's identity information only has the permission to open the cabinets in the operation whitelist within the operation time window. The authorization data packet is also bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal. The smart terminal is used to securely store the authorized data packet and serve as an interactive carrier at the unlocking site; The smart lock, deployed in the cabinet, is used to read the authorization data packet in the smart terminal, verify the validity of the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal. When the verification is successful and the operation whitelist contains the cabinet identifier of the smart lock, the lock is unlocked and a corresponding operation record is generated.

2. The substation cabinet anti-misoperation unlocking system according to claim 1, characterized in that, The work order parsing module performs semantic analysis on the work order text, extracts the target cabinet identifier, and generates an operation whitelist based on the target cabinet identifier, specifically including: The work order text is subjected to deep semantic analysis using a pre-trained semantic parsing model to extract the initial identification information of the target cabinet specified in the work order text; The initial identification information is associated with and verified with the pre-constructed substation equipment knowledge graph to verify and determine the accurate target cabinet identification. Based on the verified target cabinet identifier, the operation whitelist is generated.

3. The substation panel cabinet anti-misoperation unlocking system according to claim 2, characterized in that, The pre-trained semantic parsing model is a natural language processing model based on the Transformer architecture.

4. The substation cabinet anti-misoperation unlocking system according to any one of claims 1 to 3, characterized in that, The dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window, generating an encrypted authorization data packet with a digital signature, including: The operation whitelist, the operator's identity information, and the operation time window are associated and encapsulated. The encapsulated data is then encrypted. The encrypted data is digitally signed using the private key of the digital certificate to generate the authorized data packet; The authorized data packet is sent to the bound smart terminal via a secure communication link.

5. The substation panel cabinet anti-misoperation unlocking system according to claim 4, characterized in that, The encryption process employs a symmetric encryption algorithm; and / or, the secure communication link is a Transport Layer Security (TLS) encrypted channel.

6. The substation panel cabinet anti-misoperation unlocking system according to any one of claims 1 to 3, characterized in that, The smart terminal is a smart key card with a built-in security chip or a mobile terminal with an authorization management application installed. The security chip or the secure storage area of ​​the authorization management application is used to securely store the authorization data packet.

7. The substation cabinet anti-misoperation unlocking system according to any one of claims 1 to 3, characterized in that, The smart lock is specifically used for: The authorized data packets in the smart terminal are read via near-field communication. Verify the validity of the digital signature of the authorization data packet, check whether the current time is within the job time window contained in the authorization data packet, and verify whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal; If the signature verification, time verification, and terminal identifier matching verification all pass, then verify whether the cabinet identifier stored in itself exists in the operation whitelist. If the verification passes, perform the unlocking operation and generate the operation record. If any of the signature verification, time verification, terminal identifier matching verification, or cabinet identifier verification fails, unlocking will be refused and a local alarm will be triggered.

8. The substation panel cabinet anti-misoperation unlocking system according to claim 7, characterized in that, The substation cabinet anti-misoperation unlocking system also includes a management platform, which is used to receive and store the operation records and alarm records uploaded by the smart lock.

9. The substation panel cabinet anti-misoperation unlocking system according to claim 8, characterized in that, It also includes a blockchain evidence storage module, which is used to write the summary information of the operation record and / or the alarm record into the blockchain network for evidence storage.

10. A method for preventing accidental unlocking of substation cabinets, characterized in that, The substation panel cabinet anti-misoperation unlocking system, applied to any one of claims 1 to 9, comprises the following methods: The work order parsing module responds to the received work order text by performing semantic analysis on the work order text, extracting the target cabinet identifier, and generating an operation whitelist based on the target cabinet identifier; The dynamic permission allocation module associates the operation whitelist with the operator's identity information and the operation time window to generate an encrypted authorization data packet with a digital signature. The authorization data packet is used to limit that the operator holding the operator's identity information only has the permission to open the cabinets in the operation whitelist within the operation time window. The authorization data packet is also bound to the unique device identifier of the smart terminal to limit the authorization data packet to be valid only on the bound smart terminal. The smart terminal securely stores the authorized data packet and serves as the interaction medium at the unlocking site; The smart lock reads the authorization data packet from the smart terminal, verifies the validity of the authorization data packet, and verifies whether the unique device identifier bound in the authorization data packet matches the unique device identifier of the smart terminal. If the verification is successful and the operation whitelist contains the cabinet identifier of the smart lock, the lock is unlocked and a corresponding operation record is generated.