A method for trusted component partitioning and automated deployment of a trusted DCS controller

By dividing the components of the trusted DCS controller into the trust_module underlying management trusted security component and the agent agent management communication trusted security component, and adopting automated deployment tools, the problems of component installation complexity and non-scalability in the existing technology are solved, and fast, stable and secure component deployment is achieved.

CN119861940BActive Publication Date: 2025-10-10XIAN THERMAL POWER RES INST CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510077553.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-10-10
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

The existing trusted component installation and deployment methods of trusted DCS controllers are complex, resulting in the inability to independently install and uninstall components, affecting system stability and security. They also lack flexibility and scalability, making it difficult to cope with changes in technological development and business needs.

Method used

The components of the trusted DCS controller are divided into the trust_module bottom-level management trusted security component and the agent agent management communication trusted security component, and corresponding automated deployment tools are provided. The independent installation and configuration of the components are achieved through modular design, and automated deployment is carried out in the form of compressed packages.

Benefits of technology

It achieves rapid deployment and simplified process of trusted components, improves system stability and security, reduces maintenance costs, and enhances system scalability and compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119861940B_ABST
    Figure CN119861940B_ABST
Patent Text Reader

Abstract

The application provides a method for dividing and automatically deploying trusted components of a trusted DCS controller, comprising: dividing components in the trusted DCS controller into trust_module bottom management trusted security components and agent proxy management communication trusted security components according to the functional characteristics and security requirements of the components in the trusted DCS controller; and simultaneously or separately installing the trust_module bottom management trusted security components and the agent proxy management communication trusted security components by using a trust_module trusted security component automatic deployment tool and an agent proxy trusted security component automatic deployment tool. The application realizes modular design of trusted components, and the required trusted security components can be separately installed and configured, so that the deployment process of the trusted components is greatly simplified and the deployment efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of industrial control systems and relates to a trusted component partitioning and automated deployment method for a trusted DCS controller. Background Art

[0002] With the deep integration of industrialization and informatization, intelligent manufacturing and the Industrial Internet are rapidly developing. Industrial control systems are widely used in energy, transportation, advanced manufacturing, public utilities, and other fields. However, compared with traditional information systems, which are already relatively secure, industrial control systems are particularly vulnerable in terms of information security. Therefore, ensuring the overall security of industrial control systems has become particularly important.

[0003] As a core component of industrial control systems, DCS (distributed control systems) play an increasingly important role, making their security particularly critical. However, with the widespread adoption of network technology, DCS systems face increasingly severe security challenges. Trusted DCS controllers, equipped with trusted computing capabilities, can verify the trustworthiness of the bootloader, operating system kernel, applications, configuration files, and processes, ensuring the reliability of the controller's hardware and software environment.

[0004] The installation and deployment of trusted components in current trusted DCS controllers is complex. This is primarily reflected in the following aspects: These factors lead to the inability to independently install and uninstall components, and the inefficiency of requiring comprehensive adjustments when problems arise:

[0005] First, existing installation and deployment methods often use an integrated design, which means that each trusted component is tightly coupled and lacks independence. When a component encounters a problem or requires an update, the entire system often needs to be shut down for maintenance, which not only affects the normal operation of the DCS controller but also increases maintenance costs and time.

[0006] Secondly, due to the high interdependence between components, compatibility and interoperability with other components must be considered when deploying new components or uninstalling old ones. This requires engineers to have high technical skills and extensive experience to ensure that the overall stability and security of the system are not compromised during operation. However, this highly interdependent design also increases operational risks and uncertainties.

[0007] Finally, existing installation and deployment methods lack flexibility and scalability. With the continuous advancement of technology and evolving business needs, DCS controllers may need to add new trusted components or upgrade existing ones. However, the complexity of existing methods makes adding new components and upgrading old ones very difficult, and may even require the reconstruction of the entire system. This not only affects the scalability of the system but also limits the application of DCS controllers in new technologies and business areas.

[0008] In summary, existing methods for installing and deploying trusted components in trusted DCS controllers are complex and cannot independently install and uninstall each component. When a trusted component fails, a comprehensive adjustment is required, which is not only inefficient but also severely impacts the normal operation of the DCS controller. Therefore, it is necessary to improve and optimize existing installation and deployment methods to enhance system stability, security, and scalability. Summary of the Invention

[0009] To address the aforementioned problems of the prior art, the present invention provides a method for partitioning and automating the deployment of trusted components for a trusted DCS controller. This method implements a modular design of trusted components and facilitates the rapid deployment of trusted DSC controllers through automated installation, configuration, and management of each trusted security component. Required trusted security components can be installed and configured individually, significantly simplifying the trusted component deployment process and improving deployment efficiency.

[0010] The present invention is achieved through the following technical solutions:

[0011] In a first aspect, the present invention provides a method for partitioning and automatically deploying trusted components of a trusted DCS controller, comprising:

[0012] According to the functional characteristics and security requirements of the components in the trusted DCS controller, the components in the trusted DCS controller are divided into trust_module bottom-level management trusted security components and agent agent management communication trusted security components, wherein the trust_module bottom-level management trusted security components are used for bottom-level security management functions, and the agent agent management communication trusted security components are used for security control during the communication process. The trust_module bottom-level management trusted security components are correspondingly provided with a trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security components are correspondingly provided with an agent agent trusted security component automatic deployment tool;

[0013] The trust_module underlying management trusted security component and the agent agent management communication trusted security component are installed simultaneously through a compressed package containing the trust_module trusted security component automatic deployment tool and the agent agent trusted security component automatic deployment tool; or, the trust_module underlying management trusted security component is installed through a compressed package containing the trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security component is installed through a compressed package containing the agent agent trusted security component automatic deployment tool.

[0014] Optionally, simultaneously installing the trust_module underlying management trusted security component and the agent agent management communication trusted security component through a compressed package containing the trust_module trusted security component automated deployment tool and the agent agent trusted security component automated deployment tool includes:

[0015] Decompress the compressed package containing the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool to a specified directory to obtain the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool;

[0016] Run the trust_module trusted security component automated deployment tool, install the trust_module underlying management trusted security component, and configure the trust_module underlying management trusted security component;

[0017] Running the agent agent trusted security component automated deployment tool, installing the agent agent management communication trusted security component, and configuring the agent agent management communication trusted security component;

[0018] Start the trust_module bottom management trusted security component and the agent agent management communication trusted security component.

[0019] Optionally, the compressed package containing the trust_module trusted security component automatic deployment tool and the agent trusted security component automatic deployment tool exists in the form of a tar file compressed package.

[0020] Optionally, the trust_module trusted security component automatic deployment tool exists in the form of a Linux self-extracting bin executable file.

[0021] Optionally, the agent agent trusted security component automated deployment tool adopts an automated deployment script; the automated deployment script exists in the form of a Linux shell script, and the automated deployment script contains instructions and configuration information required to deploy the agent agent management communication trusted security component.

[0022] Optionally, the configuration content of configuring the trust_module underlying management trusted security component includes: setting a monitoring frequency and defining a trusted state determination rule.

[0023] Optionally, the configuration content of the agent management communication trusted security component includes: setting a communication protocol and defining task execution rules.

[0024] Optionally, the compressed package containing the trust_module trusted security component automated deployment tool exists in the form of a self-extracting bin file compressed package.

[0025] Optionally, the step of installing the trust_module underlying management trusted security component through a compressed package containing the trust_module trusted security component automated deployment tool, and configuring the agent agent management communication trusted security component, includes:

[0026] Logging into the operating system of the trusted DCS controller;

[0027] Open a shell terminal;

[0028] Locate the directory storing the bin file compressed package of the trust_module trusted security component automated deployment tool in the shell terminal;

[0029] In the directory where the bin file compressed package of the trust_module trusted security component automated deployment tool is located, execute the bin file compressed package of the trust_module trusted security component automated deployment tool to start the installation process of the trust_module underlying management trusted security component, the installation process includes decompressing the compressed package, copying files, and setting permissions;

[0030] At the same time as or after installing the trust_module underlying management trusted security component, the agent agent management communication trusted security component is configured according to the instructions or configuration file in the bin file compression package of the trust_module trusted security component automated deployment tool, so that the agent agent management communication trusted security component and the trust_module underlying management trusted security component work together to achieve security control during the communication process.

[0031] Optionally, when the trust_module underlying management trusted security component has been installed on the trusted DCS controller, the following method is used to replace the trust_module underlying management trusted security component:

[0032] Logging into the operating system of the trusted DCS controller;

[0033] Open a shell terminal;

[0034] Locate the directory storing the bin file compressed package of the new trust_module underlying management trusted security component in the shell terminal;

[0035] Uninstall the installed trust_module underlying management trusted security component based on the bin file compression package of the new trust_module underlying management trusted security component;

[0036] Decompress the bin file compressed package of the new trust_module underlying management trusted security component, and install the new trust_module underlying management trusted security component based on the decompressed bin file of the new trust_module underlying management trusted security component;

[0037] According to the configuration file or instructions carried in the bin file compressed package of the new trust_module underlying management trusted security component, the new trust_module underlying management trusted security component is configured so that the new trust_module underlying management trusted security component runs correctly and works in conjunction with other components in the system.

[0038] In a second aspect, the present invention provides a trusted component partitioning and automated deployment device for a trusted DCS controller, the device comprising:

[0039] A division module is used to divide the components in the trusted DCS controller into a trust_module bottom-level management trusted security component and an agent agent management communication trusted security component according to the functional characteristics and security requirements of the components in the trusted DCS controller, wherein the trust_module bottom-level management trusted security component is used for bottom-level security management functions, and the agent agent management communication trusted security component is used for security control during the communication process. The trust_module bottom-level management trusted security component is correspondingly provided with a trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security component is correspondingly provided with an agent agent trusted security component automatic deployment tool;

[0040] An installation module is used to simultaneously install the trust_module underlying management trusted security component and the agent agent management communication trusted security component through a compressed package containing the trust_module trusted security component automatic deployment tool and the agent agent trusted security component automatic deployment tool; or, to install the trust_module underlying management trusted security component through a compressed package containing the trust_module trusted security component automatic deployment tool, and to install the agent agent management communication trusted security component through a compressed package containing the agent agent trusted security component automatic deployment tool.

[0041] In a third aspect, the present invention provides an electronic device comprising: a memory, a processor, and a computer program stored in the memory and running on the processor; the processor is configured to read the computer program in the memory to implement the steps of the method for partitioning and automatically deploying trusted components of a trusted DCS controller as described in the first aspect.

[0042] In a fourth aspect, the present invention provides a computer-readable storage medium storing a program or instruction. When the program or instruction is executed by a processor, the steps of the method for partitioning and automatically deploying trusted components of a trusted DCS controller according to the first aspect are implemented.

[0043] The present invention has the following beneficial effects:

[0044] The present invention's method for rapidly deploying trusted components for a trusted DCS controller divides the trusted components into multiple trusted security components, including a trust_module underlying management trusted security component and an agent communication management trusted security component, thereby achieving a modular design for the trusted components. This modular design facilitates rapid deployment of the trusted DCS controller, as only the required trusted security components need to be installed and configured. This significantly simplifies the deployment process, improves deployment efficiency, enhances DCS system stability, reduces production losses due to system crashes or failures, and lowers maintenance costs, reducing the frequent repairs and updates caused by system security issues. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0046] Figure 1A flow chart of a method for partitioning and automatically deploying trusted components of a trusted DCS controller provided by an embodiment of the present invention;

[0047] Figure 2a Flowchart of the method for dividing and automatically deploying trusted components of a trusted DCS controller in Example 1 of the present invention;

[0048] Figure 2b Flowchart of the trusted component partitioning and automated deployment method of a trusted DCS controller according to embodiments 2 and 3 of the present invention;

[0049] Figure 3 It is a structural diagram of a trusted component division and automatic deployment device of a trusted DCS controller provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0050] The following describes the embodiments of the present invention through specific examples. Those skilled in the art will readily understand the other advantages and benefits of the present invention from the disclosure herein. The present invention may also be implemented or applied through various other specific embodiments, and the details in this specification may be modified or altered based on different viewpoints and applications without departing from the spirit of the present invention.

[0051] It should be noted that the process equipment or devices not specifically specified in the following embodiments are all conventional equipment or devices in the art.

[0052] It should be noted that the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products, or apparatuses. Furthermore, unless otherwise specified, the numbering of each method step is merely a convenient tool for identifying each method step, and is not intended to limit the order of arrangement of each method step or to define the scope of the invention. Changes or adjustments to their relative relationships, without substantially changing the technical content, should also be considered within the scope of the invention.

[0053] In order to facilitate understanding of the technical solution of this application, the nouns or terms mentioned in the embodiments of this application are first explained:

[0054] 1. Division of trusted components:

[0055] The trusted components of the trusted DCS controller are divided into two categories: trust_module underlying management trusted security components and agent agent management communication trusted security components.

[0056] This division is based on the functional characteristics and security requirements of the components, where the trust_module is responsible for the underlying security management tasks such as encryption, decryption, identity verification, etc., while the agent is responsible for the security control in the communication process, such as the establishment of a secure channel, encrypted transmission of data, etc.

[0057] ‌2. The division of logic and ideas:

[0058] The division follows the principles of modularity, hierarchy, and security isolation, aiming to improve the maintainability, scalability, and security of the system.

[0059] By separating security components with different functions, it is easier to conduct independent security audits and updates for each component, reducing the overall security risk of the system.

[0060] ‌3. The benefits of division:

[0061] It improves the security of the system, as each component can be independently secured and protected.

[0062] It enhances the scalability of the system, making it easier to add new security components or functions in the future.

[0063] It simplifies the maintenance and management of the system, as the responsibilities of each component are clear and well-defined.

[0064] ‌4. Component features:

[0065] The trust_module manages the underlying trusted security components with high security and stability, usually running in the kernel layer or a trusted execution environment of the system.

[0066] The agent manages the communication trusted security components, which are more flexible and can dynamically adjust security policies according to communication needs.

[0067] ‌5. Setting up automated deployment tools:

[0068] For the trust_module that manages the underlying trusted security components, one or more trust_module trusted security component automated deployment tools are set up, each responsible for the deployment and configuration of specific security components.

[0069] For the agent that manages the communication trusted security components, an agent trusted security component automated deployment tool is also set up, responsible for the deployment, configuration, and update of the component.

[0070] ‌6. Automated deployment in multiple security component scenarios:

[0071] When the trust_module contains multiple security components, each security component corresponds to a dedicated automated deployment tool, or a general deployment tool is used to deploy different security components through different configuration parameters.

[0072] Automated deployment tools communicate with security components through pre-defined interfaces or protocols to achieve automated and intelligent deployment and configuration processes.

[0073] The present invention divides the trusted components of a trusted DSC controller into multiple trusted security components, enabling modular design of the system's trusted components. These trusted security components include a trust_module underlying management trusted security component and an agent communication trusted security component. The trust_module underlying management trusted security component provides protection for files and processes configured with trusted policies, while the agent communication trusted security component facilitates communication between the host computer management terminal and the underlying rust_module underlying management trusted security component.

[0074] Furthermore, the modular design of trusted components makes it easier to quickly replace trusted components in the DCS system. This is because all that is needed is to automatically run the bin file compression package to uninstall, install, configure policies, and other related content. This greatly simplifies the replacement process of the DCS system and improves the efficiency of rapid replacement. It also quickly restores the stability and security of the DCS system and reduces production losses caused by module failures. It improves the simplicity and efficiency of replacement operations and reduces maintenance costs. It ensures the continuous operation of the system and data integrity during the replacement process.

[0075] For these trusted security components, there are separate automated deployment tools, namely the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool. Each automated deployment tool can realize automated installation, configuration and management. Through their own automated installation, configuration and management, the rapid deployment of trusted DSC controllers is easier.

[0076] The trust_module bottom management trusted security component and the agent agent management communication trusted security component of the present invention can be installed in combination or independently, depending on actual needs.

[0077] Specifically, such as Figure 1 As shown, the method for rapidly deploying trusted components of a trusted DCS controller of the present invention includes the following steps:

[0078] Step S1: Based on the functional characteristics and security requirements of the components in the trusted DCS controller, the components in the trusted DCS controller are divided into a trust_module bottom-level management trusted security component and an agent agent management communication trusted security component, wherein the trust_module bottom-level management trusted security component is used for bottom-level security management functions, and the agent agent management communication trusted security component is used for security control during the communication process. The trust_module bottom-level management trusted security component is correspondingly provided with a trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security component is correspondingly provided with an agent agent trusted security component automatic deployment tool;

[0079] Step S2: simultaneously install the trust_module underlying management trusted security component and the agent agent management communication trusted security component through a compressed package containing the trust_module trusted security component automated deployment tool and the agent agent trusted security component automated deployment tool; or, install the trust_module underlying management trusted security component through a compressed package containing the trust_module trusted security component automated deployment tool, and install the agent agent management communication trusted security component through a compressed package containing the agent agent trusted security component automated deployment tool.

[0080] When both the trust_module underlying management trusted security component and the agent communication trusted security component need to be installed simultaneously, installing them using a compressed package containing automated deployment tools for both is an efficient and integrated deployment method. This technical solution not only simplifies the installation process but also ensures compatibility and collaboration between components. Specifically, it includes the following steps:

[0081] Unzip the compressed package: First, unzip the compressed package containing the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool to the specified directory to obtain the two automated deployment tools.

[0082] Install and configure the trust_module underlying management trusted security component: Next, run the trust_module trusted security component automated deployment tool. This tool automatically installs the trust_module underlying management trusted security component and configures it according to preset configuration files or parameters to ensure the component runs correctly and manages the system's trusted security.

[0083] Install and configure the agent management communication trusted security component: Then, run the agent management trusted security component automated deployment tool. This tool will also install and configure the agent management communication trusted security component, ensuring that it can effectively communicate with other components in the system (including the trust_module underlying management trusted security component) and jointly maintain system security.

[0084] Start components: Finally, start the installed and configured trust_module underlying management trusted security component and agent agent management communication trusted security component, so that they can start working together to provide comprehensive trusted security protection for the system.

[0085] The beneficial effects of this technical solution are mainly reflected in the following aspects:

[0086] Improve installation efficiency: Automated deployment tools can greatly shorten component installation and configuration time and improve deployment efficiency.

[0087] ‌Ensuring component compatibility‌: Because the compressed package contains automated deployment tools for both components, compatibility between the two components during installation and configuration can be ensured, avoiding problems caused by version mismatches or configuration errors.

[0088] Improve system security: The collaborative work of the trust_module underlying management trusted security component and the agent agent management communication trusted security component can provide the system with multi-level, comprehensive trusted security protection, effectively preventing various security threats.

[0089] In addition, the trusted component division and automated deployment method of the trusted DCS controller provided in the embodiment of the present application can also adopt the following parallel solution: in addition to installing through a compressed package containing two automated deployment tools, it is also possible to adopt a method of downloading and installing the trust_module underlying management trusted security component and the agent agent management communication trusted security component separately. Specifically, the user can first download the installation package of the trust_module underlying management trusted security component from the official channel, and install and configure it according to the installation guide; then download the installation package of the agent agent management communication trusted security component, and also install and configure it according to the installation guide. Finally, start the two components manually or automatically so that they begin to work together. Although this solution is relatively complex, it provides higher flexibility and customizability to meet the different needs of users.

[0090] If you need to independently install the trust_module underlying management trusted security component, use the compressed package that contains the trust_module trusted security component automated deployment tool to install the trust_module underlying management trusted security component.

[0091] Example 1

[0092] In the method for partitioning and automating the deployment of trusted security components for a trusted DSC controller provided in this embodiment, the trust_module underlying management trusted security component and the agent communication management trusted security component are installed together. This method provides an installation program, which is stored as a compressed .tar file. After decompression, it is divided into the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool.

[0093] The trust_module automated deployment tool exists as a Linux self-extracting bin executable file. The agent automated deployment tool contains the executable program and related dependency files of the agent management communication trusted security component. The installation tool exists in the form of a Linux shell script.

[0094] Before deploying trusted security components, ensure that the following conditions are met:

[0095] (1) The hardware and software installation of the DCS system is complete and the system is operating normally.

[0096] (2) The DCS system has sufficient permissions to install and configure the trust_module underlying management trusted security component and the agent agent management communication trusted security component.

[0097] (3) The network environment is stable to ensure that data transmission is not disturbed during the installation process.

[0098] In some embodiments of the present invention, the trust_module underlying management trusted security component and the agent agent management communication trusted security component are simultaneously installed using a compressed package containing the trust_module trusted security component automated deployment tool and the agent agent trusted security component automated deployment tool, including:

[0099] Decompress the compressed package containing the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool to a specified directory to obtain the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool;

[0100] Run the trust_module trusted security component automated deployment tool, install the trust_module underlying management trusted security component, and configure the trust_module underlying management trusted security component;

[0101] Running the agent agent trusted security component automated deployment tool, installing the agent agent management communication trusted security component, and configuring the agent agent management communication trusted security component;

[0102] Start the trust_module bottom management trusted security component and the agent agent management communication trusted security component.

[0103] like Figure 2a As shown, the trusted security component division and automatic deployment method of the trusted DCS controller of the present invention includes the following steps:

[0104] (1) Unzip the installation program;

[0105] Decompress the tar file to the specified directory to obtain the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool.

[0106] (2) Install the trust_module underlying management trusted security component;

[0107] Run the trust_module trusted security component automated deployment tool and follow the prompts to complete the installation. The tool automatically detects the system environment and configuration to ensure that the trust_module underlying management trusted security component is installed and running correctly. During the installation process, you may need to enter some necessary configuration information, such as the controller's IP address and port number.

[0108] (3) Configure the trust_module underlying management trusted security component;

[0109] After installation is complete, you need to configure the trust_module underlying management trusted security component to ensure it can correctly monitor the trusted status of the trusted DCS controller. Configuration content includes but is not limited to: setting the monitoring frequency and defining the trusted status determination rules.

[0110] (4) Install the agent management communication trusted security component;

[0111] Run the agent trusted security component automated deployment tool and follow the prompts to complete the installation. The tool automatically detects the system environment and configuration to ensure that the agent management communication trusted security component is installed and running correctly. During the installation process, you may also need to enter some necessary configuration information.

[0112] (5) Configure the agent to manage communication trust and security components;

[0113] After installation is complete, you need to configure the agent management communication trusted security component to ensure it can communicate with the trust_module underlying management trusted security component and correctly execute related tasks. Configuration content includes but is not limited to: setting the communication protocol and defining task execution rules.

[0114] (6) Start the trust_module underlying management trusted security component and the agent agent management communication trusted security component.

[0115] After completing the configuration, start the trust_module underlying management trusted safety component and the agent agent management communication trusted safety component to start working. At this point, the trust_module underlying management trusted safety component will begin to periodically monitor the trusted status of the trusted DCS controller, and the agent agent management communication trusted safety component will execute tasks according to the configuration.

[0116] In some embodiments of the present invention, the compressed package containing at least one of the trust_module trusted security component automated deployment tool and the agent agent trusted security component automated deployment tool can exist in the form of a tar file compressed package, or in the form of a Linux self-extracting bin executable file, which is not specifically limited here.

[0117] In some implementations, the automated deployment tool is in the form of a tar file compression package, which has the following benefits:

[0118] Wide compatibility: Tar file compression is a widely used archiving format in Unix / Linux systems and has good cross-platform compatibility. This means that users can easily decompress and use the compressed package on any Unix / Linux distribution, reducing compatibility issues during deployment.

[0119] Efficient compression: Tar file compression packages typically have a good compression ratio, effectively reducing file size and saving storage space. When transmitting or distributing automated deployment tools for trusted security components, smaller file sizes can significantly reduce transmission time and bandwidth consumption.

[0120] ‌Easy to manage‌: tar file compression packages can package multiple files and directories into a single file, making it easier for deployment tools to manage. Users can easily backup, copy and move the entire compression package without worrying about file loss or path errors;

[0121] ‌Standardized format‌: tar file compression packages follow a standard archive format, which makes it easy for various Unix / Linux tools to handle it. Users can use standard tar commands to decompress, view and operate the contents of the compression package without additional learning costs.

[0122] In other embodiments, the automated deployment tool takes the form of a Linux self-extracting bin executable file, which has the following benefits:

[0123] ‌One-click deployment‌: Linux self-extracting bin executable files integrate the decompression and installation processes together, and users only need to run one command to automatically complete the entire deployment process. This one-click deployment greatly simplifies the deployment process and improves user convenience;

[0124] ‌No need for additional tools‌: Unlike traditional compression packages, self-extracting bin files do not require users to install or rely on other decompression tools. This reduces the dependency and complexity of the deployment process, allowing users to easily deploy trusted and secure component automation deployment tools in any Linux-supported environment;

[0125] ‌Reduce human error‌: Self-extracting bin files perform decompression and installation processes automatically, reducing the opportunity for human operation and potential errors. This helps ensure the consistency and reliability of the deployment process, reducing the risk of deployment failure due to human operation errors;

[0126] ‌High integration‌: Self-extracting bin files can integrate all necessary components and configurations of the deployment tool into a single executable file. This makes the deployment process more compact and efficient, without the need for users to manually configure or install additional dependencies.

[0127] In summary, the use of tar file compression packages or Linux self-extracting bin executable files has different benefits. In actual application, the most suitable compression package form can be selected according to specific needs and scenarios to meet the efficient, convenient and reliable deployment of deployment tools.

[0128] In some embodiments of the present application, the agent proxy trusted security component automatic deployment tool adopts an automatic deployment script; the automatic deployment script exists in the form of a Linux shell script, and the automatic deployment script contains instructions and configuration information required for deploying the agent proxy management communication trusted security component.

[0129] ‌The present embodiment has the following beneficial effects‌:

[0130] ‌Improving deployment efficiency‌: The automatic deployment script can automatically execute a series of preset instructions and configurations, thereby greatly reducing the time for manual intervention and significantly improving the deployment efficiency. In particular, in scenarios where agent proxies need to be deployed on a large scale, this automation can save a lot of manpower and time costs;

[0131] ‌Ensuring deployment consistency‌: Since the automatic deployment script contains all necessary instructions and configuration information, each deployment will follow the same process, ensuring the consistency and reliability of the deployment results. This avoids inconsistent deployment caused by human operation differences, improving the stability and security of the system;

[0132] ‌Simplifying the deployment process‌: Linux shell script is a widely used scripting language with the characteristics of simplicity and ease of use. The use of this form of automatic deployment script makes the deployment process more intuitive and easy to understand, even for non-professional users can quickly get started and deploy;

[0133] ‌Facilitating version management and updates‌: The automatic deployment script exists in the form of a file, which facilitates version management and updates. When upgrading or modifying the deployment process, you only need to update the corresponding script file, without the need for manual operation on each deployment node, greatly improving the convenience of management;

[0134] ‌Enhancing scalability and flexibility‌: The automatic deployment script can be customized and extended according to actual needs. By modifying or adding instructions and configuration information in the script, deployment requirements in different scenarios can be easily implemented, enhancing the scalability and flexibility of the system.

[0135] In summary, the use of automatic deployment scripts in the form of Linux shell scripts brings many benefits to the deployment of agent proxy trusted security components, including improving deployment efficiency, ensuring deployment consistency, simplifying the deployment process, facilitating version management and updates, and enhancing scalability and flexibility. These advantages provide strong guarantees for the rapid, stable, and secure deployment of the system.

[0136] In some embodiments of the present invention, the configuration content of configuring the trust_module underlying management trusted security component includes: setting monitoring frequency and defining trusted status determination rules.

[0137] This embodiment has the following beneficial effects:

[0138] Improve monitoring efficiency: By setting the monitoring frequency, users can adjust the frequency of the trust_module underlying management trusted security component monitoring the system or application according to actual needs. By setting a reasonable frequency, we can ensure timely detection of security threats while avoiding the waste of system resources caused by overly frequent monitoring. This helps improve monitoring efficiency and ensure a balance between system performance and security.

[0139] Enhanced Determination Accuracy: By defining trusted status determination rules, users can customize trusted status determination rules based on specific security policies and business requirements. This means that the trust_module underlying management trusted security component can accurately determine whether a system or application is in a trusted state based on user-defined standards, thereby promptly identifying and responding to potential security risks. This enhances determination accuracy and improves the effectiveness of security responses.

[0140] Improved Flexibility: By configuring monitoring frequency and trusted status determination rules, users can flexibly adjust the working mode and behavior of the trust_module underlying management trusted security component according to different application scenarios and security requirements. This flexibility enables the trust_module underlying management trusted security component to better adapt to various complex environments and scenarios, providing more accurate and effective security protection.

[0141] Simplified Management: Centralized configuration management allows users to easily adjust the working parameters of the trust_module underlying trusted security management components by modifying configuration files or interface settings, without having to delve into the code or perform complex operations. This simplifies the management process, reduces management costs, and makes it easier for users to maintain and manage system security.

[0142] Enhanced Scalability: As business development and security requirements evolve, users may need to adjust or expand the functionality of the trust_module's underlying management components. By configuring monitoring frequency and trusted status determination rules, users can easily adjust the behavior of the trust_module's underlying management components without changing the core code, thereby enhancing system scalability and maintainability.

[0143] In summary, configuring the trust_module underlying management trusted security component, including setting the monitoring frequency and defining trusted status determination rules, can significantly improve monitoring efficiency, enhance determination accuracy, increase flexibility, simplify management, and enhance scalability, providing more powerful and flexible support for system security protection.

[0144] In some embodiments of the present invention, the configuration content of the agent management communication trusted security component includes: setting a communication protocol and defining task execution rules.

[0145] In some embodiments of the present invention, detailed configuration of the agent management communication trust and security component, including setting the communication protocol and defining the task execution rules, can achieve the following beneficial effects:

[0146] Ensuring communication security: By setting up communication protocols, you can establish secure and reliable channels for communication between the agent management trusted security component and other trusted security components. This helps prevent data from being stolen or tampered with during transmission, thereby ensuring the confidentiality and integrity of communications and providing a solid foundation for the secure operation of the system.

[0147] Improved task execution efficiency: Clearly defined task execution rules enable the agent-managed communication trusted security component to efficiently execute various security tasks according to established logic and sequence. This not only reduces confusion and delays during task execution, but also improves the overall security management efficiency of the system.

[0148] Enhanced system compatibility: The use of standardized communication protocols and task execution rules helps improve the system's compatibility with other security components or systems. This makes it easier to integrate the invention into existing security architectures and achieve seamless integration with various security components.

[0149] Ease of management and maintenance: By configuring and managing the trusted and secure communication component, we can more easily monitor and manage the behavior of the agent. This not only simplifies the system's daily operations and maintenance, but also allows for quick problem location and resolution, reducing system maintenance costs.

[0150] Improved System Flexibility: Flexible configuration of communication protocols and task execution rules allows the system to adapt to varying security requirements and actual environments. This flexibility enables the invention to address evolving security threats and provide strong assurance for the long-term safe operation of the system.

[0151] In summary, carefully configuring the trusted security components of agent-managed communication not only ensures communication security and efficient task execution, but also enhances system compatibility, facilitates management and maintenance, and improves system flexibility. These benefits together provide strong support for building a more secure, reliable, and efficient communication system environment.

[0152] In some embodiments of the present invention, the compressed package containing the trust_module trusted security component automatic deployment tool exists in the form of a self-extracting bin file compressed package.

[0153] This embodiment can achieve the following beneficial effects:

[0154] ‌Simplified deployment process‌: The self-extracting bin file format makes the installation and configuration of the deployment tool much simpler. Users no longer need to manually decompress and install multiple files. Simply run a single self-extracting file to automatically complete all deployment steps, significantly reducing deployment complexity and error rates.

[0155] Improved deployment efficiency: Since self-extracting files automatically complete the decompression and installation process, deployment time can be significantly shortened. This is particularly important for environments that need to quickly deploy a large number of trust_module agents to manage communication trusted security components, greatly improving work efficiency.

[0156] ‌Ensuring deployment consistency‌: The self-extracting bin file package ensures the consistency and integrity of the deployment tool. All users download the same compressed package, and the decompression and installation process is also automated, thus avoiding deployment inconsistencies caused by manual operation differences;

[0157] Easy to distribute and transfer: Self-extracting files are usually smaller in size, making them easier to distribute and transfer over the network. This can save significant bandwidth and time costs for remote deployments or environments where trust_module agents need to be installed on multiple nodes to manage communication with trusted security components.

[0158] Enhanced Security: Self-extracting files can be digitally signed and verified during the decompression and installation process, ensuring file integrity and non-tampering. This is particularly important for security components such as the trust_module agent that manages communication with trusted security components, effectively preventing malware intrusion and damage.

[0159] In summary, the trust_module trusted security component automated deployment tool, which exists in the form of a self-extracting bin file compressed package, can simplify the deployment process, improve deployment efficiency, ensure deployment consistency, facilitate distribution and transmission, and enhance security. It provides strong support for the widespread application of the trust_module agent management communication trusted security component.

[0160] Below, reference Figure 2b As shown, Example 2 and Example 3 are explained:

[0161] Example 2

[0162] In some embodiments of the present invention, the steps of installing the trust_module underlying management trusted security component through a compressed package containing the trust_module trusted security component automated deployment tool and configuring the agent agent management communication trusted security component include:

[0163] Logging into the operating system of the trusted DCS controller;

[0164] Open a shell terminal;

[0165] Locate the directory storing the bin file compressed package of the trust_module trusted security component automated deployment tool in the shell terminal;

[0166] In the directory where the bin file compressed package of the trust_module trusted security component automated deployment tool is located, execute the bin file compressed package of the trust_module trusted security component automated deployment tool to start the installation process of the trust_module underlying management trusted security component, the installation process includes decompressing the compressed package, copying files, and setting permissions;

[0167] At the same time as or after installing the trust_module underlying management trusted security component, the agent agent management communication trusted security component is configured according to the instructions or configuration file in the bin file compression package of the trust_module trusted security component automated deployment tool, so that the agent agent management communication trusted security component and the trust_module underlying management trusted security component work together to achieve security control during the communication process.

[0168] Technical solution description and beneficial effect analysis:

[0169] ‌1. Technical Solution Description‌

[0170] This embodiment is aimed at the trusted security component of the trusted DSC controller, especially the trust_module underlying management of the trusted security component, and provides a method of independent and fast installation and deployment. The method realizes the whole process of independent uninstallation, installation and configuration of the component through the provided trust_module trusted security component automatic deployment tool in the form of self-decompression bin file compression package. The specific steps are as follows:

[0171] ‌1. Design and prepare DCS controller operating system: select appropriate hardware platform and compatible Linux operating system.

[0172] 2. Prepare necessary components, such as trust_module bin file compression package, driver, dependent library, etc.

[0173] 3. Create a special directory in the operating system for managing installation files.

[0174] 4. Log in to the operating system of the trusted DCS controller: log in to the DCS controller using credentials and ensure the authority to perform installation and configuration tasks.

[0175] 5. Open the shell terminal for subsequent operations.

[0176] 6. Install the trust_module underlying management of the trusted security component:

[0177] 7. Navigate to the directory where the bin file compression package is located in the shell terminal.

[0178] 8. Execute the bin file compression package to start installation, usually by entering the. / trust_module.bin command.

[0179] 9. Complete the configuration according to the installation program prompts, such as selecting the installation location, setting the environment variables, configuring the network parameters, etc.

[0180] 10. The installation program automatically processes decompression, file copying, permission setting, etc. to ensure that the component is correctly installed and running.

[0181] ‌II. Analysis of beneficial effects

[0182] ‌1. Improve installation efficiency: the automatic deployment tool simplifies the installation process, reduces manual intervention, and significantly improves installation efficiency. The design of self-decompression bin file compression package makes the installation process more convenient without additional decompression steps.

[0183] 2. Ensure installation accuracy: Automated deployment tools can perform installations according to preset steps and parameters, eliminating human error. The installer automatically handles details such as file copying and permission settings to ensure the correct and complete installation of components.

[0184] ‌3. Enhanced system flexibility‌: The independent installation design allows the trust_module underlying management of trusted security components to be separated from other components, facilitating management and maintenance. Users can choose to install or uninstall components based on actual needs without affecting the normal operation of other systems.

[0185] 4. Improve system security: The independent installation and configuration of the trust_module underlying management trusted security components helps build a more secure and reliable system environment. Installation through automated deployment tools can reduce security risks introduced by improper human operation.

[0186] ‌III. Parallel Plan Description‌

[0187] The trusted component division and automated deployment method of the trusted DCS controller provided in the embodiment of the present invention can also adopt the following installation method:

[0188] ‌1. Script-based installation method‌:

[0189] In addition to providing a self-extracting bin file, a script-based installation method is also available. Users can download a script file containing installation instructions and configuration parameters and execute it through a shell terminal to complete the installation of the trust_module underlying management trusted security component. The script file can include detailed installation steps, dependency checks, and environment variable settings to ensure the accuracy and completeness of the installation process. This script-based installation method provides users with greater flexibility and customization, allowing them to modify the script file to meet specific installation requirements.

[0190] The description of the above parallel solutions further enriches the connotation of the technical solution and enhances the comprehensiveness and feasibility of the trusted component partitioning and automated deployment method for a trusted DCS controller provided in the embodiments of this application. It also demonstrates that the installation method provided in this embodiment is not the only option and can be flexibly adjusted and expanded according to actual needs.

[0191] Example 3

[0192] In some embodiments of the present invention, when the trust_module underlying management trusted security component has been installed on the trusted DCS controller, the following method is used to replace the trust_module underlying management trusted security component:

[0193] Logging into the operating system of the trusted DCS controller;

[0194] Open a shell terminal;

[0195] Locate the directory storing the bin file compressed package of the new trust_module underlying management trusted security component in the shell terminal;

[0196] Uninstall the installed trust_module underlying management trusted security component based on the bin file compression package of the new trust_module underlying management trusted security component;

[0197] Decompress the bin file compressed package of the new trust_module underlying management trusted security component, and install the new trust_module underlying management trusted security component based on the decompressed bin file of the new trust_module underlying management trusted security component;

[0198] According to the configuration file or instructions carried in the bin file compressed package of the new trust_module underlying management trusted security component, the new trust_module underlying management trusted security component is configured so that the new trust_module underlying management trusted security component runs correctly and works in conjunction with other components in the system.

[0199] Technical solution description and beneficial effect analysis:

[0200] ‌1. Technical Solution Description‌

[0201] This embodiment provides a method for quickly replacing the trust_module underlying management trusted security component already installed on a trusted DCS controller. This method uses the provided trust_module trusted security component automated deployment tool in the form of a self-extracting bin file compressed package to complete the entire process of uninstalling the old component and installing and configuring the new component, thereby quickly restoring the normal functionality of the DCS controller. The specific steps are as follows:

[0202] 1. Clarify requirements and prepare the replacement environment: Clearly define and understand the functions and features of the trust_module underlying management trusted security component to be replaced, ensuring that the replacement process does not introduce incompatible or non-compliant features. Prepare a stable replacement environment, including selecting the appropriate hardware platform, installing the appropriate Linux operating system version, and ensuring that all necessary dependencies and tools are installed and configured properly.

[0203] 2. Log in to the DCS controller and access the shell terminal: Log in to the DCS controller's operating system by entering the correct username and password. Ensure that you have sufficient permissions to perform the replacement operation. After successfully logging in, open a shell terminal session to interact with the system through the command line.

[0204] 3. Perform a quick replacement of the trust_module underlying management trusted security component: Navigate to the directory containing the .bin file compressed package containing the new trust_module underlying management trusted security component in a shell terminal. Execute the .bin file compressed package. The tool will automatically uninstall the old trust_module underlying management trusted security component (if it exists), then install the new trust_module underlying management trusted security component and configure the necessary system settings or environment variables.

[0205] ‌ 2. Analysis of Beneficial Effects‌

[0206] 1. Improved replacement efficiency: Automated deployment tools simplify the replacement process, reduce manual intervention, and significantly improve replacement efficiency. The self-extracting bin file compression package design makes the replacement process more convenient, eliminating the need for additional decompression and manual operation steps.

[0207] 2. Ensure replacement accuracy: Automated deployment tools can perform replacements according to preset steps and parameters, eliminating human error. The tools automatically handle the details of uninstallation, installation, and configuration, ensuring the correct installation of new components and the complete uninstallation of old components.

[0208] 3. Enhanced System Stability: Rapid replacement methods can quickly restore normal functionality of DCS controllers, reducing system downtime caused by component failures. New components are verified and tested to ensure compatibility and stability, helping to improve overall system stability.

[0209] 4. Improved system security: Automated deployment tools can reduce security risks introduced by improper human operation. The installation and configuration of new components adhere to strict security standards, helping to build a more secure and reliable system environment.

[0210] ‌III. Parallel Plan Description‌

[0211] The trusted component division and automated deployment method of the trusted DCS controller provided in the embodiment of the present application may also adopt the following alternative methods:

[0212] ‌Script-based replacement method‌: In addition to providing a self-extracting bin file compressed package, a script-based replacement method is also available. Users can download a script file containing replacement instructions and configuration parameters, and execute the script file through a shell terminal to complete the replacement of the trust_module underlying management trusted security component. The script file can include detailed replacement steps, dependency checks, environment variable settings, and other content to ensure the accuracy and completeness of the replacement process. Before executing the script, users can modify the parameters and instructions in the script file according to actual needs to meet specific replacement requirements. This script-based replacement method provides users with more flexibility and customizability, and is suitable for scenarios that require complex replacement logic or special configuration.

[0213] The description of the above parallel solutions further enriches the connotation of the technical solution and enhances the comprehensiveness and feasibility of the trusted component partitioning and automated deployment method for a trusted DCS controller provided in the embodiments of this application. It also demonstrates that the replacement method provided in this embodiment is not the only option and can be flexibly adjusted and expanded according to actual needs.

[0214] like Figure 3 As shown, the embodiment of the present application further provides a trusted component division and automatic deployment device 300 of a trusted DCS controller, and the trusted component division and automatic deployment device 300 of a trusted DCS controller includes:

[0215] A division module 301 is configured to divide the components in the trusted DCS controller into a trust_module underlying management trusted security component and an agent agent management communication trusted security component based on the functional characteristics and security requirements of the components in the trusted DCS controller, wherein the trust_module underlying management trusted security component is used for underlying security management functions, and the agent agent management communication trusted security component is used for security control during the communication process. The trust_module underlying management trusted security component is correspondingly provided with a trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security component is correspondingly provided with an agent agent trusted security component automatic deployment tool;

[0216] The installation module 302 is used to simultaneously install the trust_module underlying management trusted security component and the agent agent management communication trusted security component through a compressed package containing the trust_module trusted security component automatic deployment tool and the agent agent trusted security component automatic deployment tool; or, to install the trust_module underlying management trusted security component through a compressed package containing the trust_module trusted security component automatic deployment tool, and to install the agent agent management communication trusted security component through a compressed package containing the agent agent trusted security component automatic deployment tool.

[0217] Optionally, the installation module 302 is specifically configured to:

[0218] Decompress the compressed package containing the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool to a specified directory to obtain the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool;

[0219] Run the trust_module trusted security component automated deployment tool, install the trust_module underlying management trusted security component, and configure the trust_module underlying management trusted security component;

[0220] Running the agent agent trusted security component automated deployment tool, installing the agent agent management communication trusted security component, and configuring the agent agent management communication trusted security component;

[0221] Start the trust_module bottom management trusted security component and the agent agent management communication trusted security component.

[0222] Optionally, the compressed package containing the trust_module trusted security component automatic deployment tool and the agent trusted security component automatic deployment tool exists in the form of a tar file compressed package.

[0223] Optionally, the trust_module trusted security component automatic deployment tool exists in the form of a Linux self-extracting bin executable file.

[0224] Optionally, the agent agent trusted security component automated deployment tool adopts an automated deployment script; the automated deployment script exists in the form of a Linux shell script, and the automated deployment script contains instructions and configuration information required to deploy the agent agent management communication trusted security component.

[0225] Optionally, the configuration content of configuring the trust_module underlying management trusted security component includes: setting a monitoring frequency and defining a trusted state determination rule.

[0226] Optionally, the configuration content of the agent management communication trusted security component includes: setting a communication protocol and defining task execution rules.

[0227] Optionally, the compressed package containing the trust_module trusted security component automated deployment tool exists in the form of a self-extracting bin file compressed package.

[0228] Optionally, the installation module 302 is specifically configured to:

[0229] Logging into the operating system of the trusted DCS controller;

[0230] Open a shell terminal;

[0231] Locate the directory storing the bin file compressed package of the trust_module trusted security component automated deployment tool in the shell terminal;

[0232] In the directory where the bin file compressed package of the trust_module trusted security component automated deployment tool is located, execute the bin file compressed package of the trust_module trusted security component automated deployment tool to start the installation process of the trust_module underlying management trusted security component, the installation process includes decompressing the compressed package, copying files, and setting permissions;

[0233] At the same time as or after installing the trust_module underlying management trusted security component, the agent agent management communication trusted security component is configured according to the instructions or configuration file in the bin file compression package of the trust_module trusted security component automated deployment tool, so that the agent agent management communication trusted security component and the trust_module underlying management trusted security component work together to achieve security control during the communication process.

[0234] Optionally, the trusted component division and automated deployment device 300 of the trusted DCS controller further includes:

[0235] The replacement module is used to replace the trust_module underlying management trusted security component by the following method when the trust_module underlying management trusted security component has been installed on the trusted DCS controller:

[0236] Logging into the operating system of the trusted DCS controller;

[0237] Open a shell terminal;

[0238] Locate the directory storing the bin file compressed package of the new trust_module underlying management trusted security component in the shell terminal;

[0239] Uninstall the installed trust_module underlying management trusted security component based on the bin file compression package of the new trust_module underlying management trusted security component;

[0240] Decompress the bin file compressed package of the new trust_module underlying management trusted security component, and install the new trust_module underlying management trusted security component based on the decompressed bin file of the new trust_module underlying management trusted security component;

[0241] According to the configuration file or instructions carried in the bin file compressed package of the new trust_module underlying management trusted security component, the new trust_module underlying management trusted security component is configured so that the new trust_module underlying management trusted security component runs correctly and works in conjunction with other components in the system.

[0242] The trusted component division and automated deployment device of the trusted DCS controller provided in the embodiment of the present application can perform the following operations: Figure 1 The various steps in the method embodiment shown can achieve the same beneficial effects, and will not be described again here to avoid repetition.

[0243] Optionally, an embodiment of the present application further provides an electronic device, including a processor, a memory, and a program or instruction stored in the memory and executable on the processor. When the program or instruction is executed by the processor, each process of the embodiment of the method for partitioning and automatically deploying trusted components of the trusted DCS controller described above is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be described here.

[0244] It should be noted that the electronic devices in the embodiments of the present application include the mobile electronic devices and non-mobile electronic devices mentioned above.

[0245] The embodiment of the present application further provides a computer-readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the embodiment of the method for partitioning and automatically deploying trusted components of a trusted DCS controller is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0246] The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0247] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to run programs or instructions to implement the various processes of the embodiment of the method for partitioning and automatically deploying trusted components of the trusted DCS controller described above, and can achieve the same technical effects. To avoid repetition, these are not described here.

[0248] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0249] While various embodiments of the present disclosure have been described above, the foregoing description is intended to be illustrative, non-exhaustive, and not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or technical improvements to existing technologies, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A method for partitioning and automatically deploying trusted components of a trusted DCS controller, characterized in that: include: According to the functional characteristics and security requirements of the components in the trusted DCS controller, the components in the trusted DCS controller are divided into trust_module bottom-level management trusted security components and agent agent management communication trusted security components, wherein the trust_module bottom-level management trusted security components are used for bottom-level security management functions, and the agent agent management communication trusted security components are used for security control during the communication process. The trust_module bottom-level management trusted security components are correspondingly provided with a trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security components are correspondingly provided with an agent agent trusted security component automatic deployment tool; The trust_module underlying management trusted security component and the agent agent management communication trusted security component are installed simultaneously through a compressed package containing the trust_module trusted security component automatic deployment tool and the agent agent trusted security component automatic deployment tool; or, the trust_module underlying management trusted security component is installed through a compressed package containing the trust_module trusted security component automatic deployment tool, and the agent agent management communication trusted security component is installed through a compressed package containing the agent agent trusted security component automatic deployment tool.

2. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 1, characterized in that: The trust_module underlying management trusted security component and the agent agent management communication trusted security component are installed simultaneously using a compressed package containing the trust_module trusted security component automation deployment tool and the agent agent trusted security component automation deployment tool, including: Decompress the compressed package containing the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool to a specified directory to obtain the trust_module trusted security component automated deployment tool and the agent trusted security component automated deployment tool; Run the trust_module trusted security component automated deployment tool, install the trust_module underlying management trusted security component, and configure the trust_module underlying management trusted security component; Running the agent agent trusted security component automated deployment tool, installing the agent agent management communication trusted security component, and configuring the agent agent management communication trusted security component; Start the trust_module bottom management trusted security component and the agent agent management communication trusted security component.

3. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 2, characterized in that: The compressed package containing the trust_module trusted security component automatic deployment tool and the agent trusted security component automatic deployment tool exists in the form of a tar file compressed package.

4. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 2, wherein: The trust_module trusted security component automated deployment tool exists in the form of a Linux self-extracting bin executable file.

5. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 2, characterized in that: The agent agent trusted security component automated deployment tool adopts an automated deployment script; the automated deployment script exists in the form of a Linux shell script, and the automated deployment script contains the instructions and configuration information required to deploy the agent agent management communication trusted security component.

6. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 2, characterized in that: The configuration content of configuring the trust_module bottom layer management trusted security component includes: setting the monitoring frequency and defining the trusted status determination rules.

7. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 2, characterized in that: The configuration content of configuring the agent agent management communication trusted security component includes: setting the communication protocol and defining the task execution rules.

8. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 1, characterized in that: The compressed package containing the trust_module trusted security component automated deployment tool exists in the form of a self-extracting bin file compressed package.

9. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 8, characterized in that: The step of installing the trust_module underlying management trusted security component through a compressed package containing the trust_module trusted security component automated deployment tool and configuring the agent agent management communication trusted security component includes: Logging into the operating system of the trusted DCS controller; Open a shell terminal; Locate the directory storing the bin file compressed package of the trust_module trusted security component automated deployment tool in the shell terminal; In the directory where the bin file compressed package of the trust_module trusted security component automated deployment tool is located, execute the bin file compressed package of the trust_module trusted security component automated deployment tool to start the installation process of the trust_module underlying management trusted security component, the installation process includes decompressing the compressed package, copying files, and setting permissions; At the same time as or after installing the trust_module underlying management trusted security component, the agent agent management communication trusted security component is configured according to the instructions or configuration file in the bin file compression package of the trust_module trusted security component automated deployment tool, so that the agent agent management communication trusted security component and the trust_module underlying management trusted security component work together to achieve security control during the communication process.

10. The method for dividing and automatically deploying trusted components of a trusted DCS controller according to claim 8, characterized in that: In the case where the trust_module underlying management trusted security component has been installed on the trusted DCS controller, the following method is used to replace the trust_module underlying management trusted security component: Logging into the operating system of the trusted DCS controller; Open a shell terminal; Locate the directory storing the bin file compressed package of the new trust_module underlying management trusted security component in the shell terminal; Uninstall the installed trust_module underlying management trusted security component based on the bin file compression package of the new trust_module underlying management trusted security component; Decompress the bin file compressed package of the new trust_module underlying management trusted security component, and install the new trust_module underlying management trusted security component based on the decompressed bin file of the new trust_module underlying management trusted security component; According to the configuration file or instructions carried in the bin file compressed package of the new trust_module underlying management trusted security component, the new trust_module underlying management trusted security component is configured so that the new trust_module underlying management trusted security component runs correctly and works in conjunction with other components in the system.

Citation Information

Patent Citations

  • Trusted DCS (Distributed Control System) trusted function installation method and related device

    CN119396421A