WAPI electric power communication security access method and system based on zero trust, and storage medium

By introducing a zero-trust architecture and dynamic permission adjustment into power communication networks, combined with biometric authentication and the RAdAC model, the problems of rigid authentication and static permissions in traditional WAPI security systems in power communication networks are solved, achieving fine-grained access control and high reliability, and preventing unauthorized access and attacks.

CN121310135APending Publication Date: 2026-01-09ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID SHANDONG ELECTRIC POWER COMPANY +2
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511251215.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-03
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

Traditional WAPI security systems based on fixed boundaries are ill-suited for addressing security vulnerabilities in power communication networks, such as rigid authentication and static permissions, which arise from ubiquitous wireless terminal access and diversified business scenarios. Unauthorized devices may access the network, posing potential security risks.

Method used

The WAPI power communication security access method based on zero trust is adopted. By performing certificate authentication and biometric authentication (such as fingerprint authentication) on terminal devices, the identity authentication and access process is monitored in real time, access permissions are dynamically adjusted, and risk assessment is performed in real time. A biometric database is built and updated regularly. The Rabin-Karp algorithm and Winnow algorithm are used to optimize features, and the RAdAC model is combined for fine-grained access control.

Benefits of technology

It enables fine-grained access control over power communication networks, improving system reliability and business continuity, effectively preventing unauthorized access and potential network attacks, and enhancing the ability to combat advanced persistent threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121310135A_ABST
    Figure CN121310135A_ABST
Patent Text Reader

Abstract

The invention discloses a zero-trust-based WAPI electric power communication security access method and system and a storage medium, and the method comprises the steps: carrying out the identity authentication of a terminal device, the identity authentication comprising certificate authentication and biological feature authentication, and the biological feature authentication comprising fingerprint authentication; if the identity authentication is passed, starting a dynamic access strategy for the network based on the trust level; monitoring an identity authentication process and a dynamic access process in real time, and continuously performing risk assessment to obtain a risk assessment result; and granting dynamic access authority or directly terminating access based on an evaluation result. According to the invention, through dynamic fingerprint authentication and dynamic granting of the access authority, fine-grained access control is carried out on resources while the security is ensured, the reliability and service continuity of the system can be improved, and unauthorized access and potential network attacks can be effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of electronic data processing, and particularly relates to a WAPI power communication security access method based on zero trust, an electronic device and a storage medium. BACKGROUND

[0002] The power communication network based on the WAPI protocol needs to process a large amount of real-time data transmission, including key information such as power grid monitoring and dispatching instructions. The transmission of these information requires high security and high reliability. However, the traditional security model has many limitations in dealing with security threats in the new power system. For example, in the power network, the access of a large number of terminal devices makes it difficult for traditional security measures to guarantee the safe and controllable operation of the system and the terminal. Unauthorized devices may access the network, thereby causing potential security risks.

[0003] In related technologies, the traditional WAPI security system based on fixed boundaries faces security risks such as authentication rigidity and permission staticity caused by the ubiquitous access of wireless terminals and the diversification of business scenarios. SUMMARY

[0004] The purpose of the present application is to deeply integrate the zero trust security architecture and the WAPI power communication, adopt a dynamic monitoring and dynamic permission adjustment strategy, and realize the transition from network boundary protection to endogenous security, which can effectively improve the ability of the power communication network to resist advanced persistent threats.

[0005] In order to achieve the above purpose, the present application proposes a WAPI power communication security access method based on zero trust, comprising: performing identity authentication on a terminal device, the identity authentication comprising certificate authentication and biometric authentication, the biometric authentication comprising fingerprint authentication; if the identity authentication is passed, starting a dynamic access strategy based on trust level; monitoring the identity authentication process and the dynamic access process in real time, continuously performing risk assessment to obtain a risk assessment result; and granting dynamic access permission or directly terminating access based on the assessment result.

[0006] In an optional embodiment, identity authentication is performed on a terminal device, the identity authentication comprising biometric authentication, specifically comprising: constructing a biometric database, the biometric database comprising a fingerprint template; acquiring a fingerprint image; generating a fingerprint feature code to be verified based on the fingerprint image; generating an identity authentication data document fingerprint based on the fingerprint feature code; calculating a similarity based on the identity authentication data document fingerprint and the fingerprint template; and if the similarity exceeds a preset threshold, determining that the identity authentication is passed.

[0007] In an alternative embodiment, the method for secure access of WAPI power communication based on zero trust, the construction of the biometric database further comprises: periodically updating the biometric database, including deleting expired fingerprint records and adding new authorized information.

[0008] In an alternative embodiment, the construction of the biometric database specifically comprises: collecting a set of fingerprint minutiae and performing grayscale value binary conversion to obtain conversion data; using a line tracing algorithm to exclude false feature points from the conversion data to obtain accurate feature data; extracting the coordinates, direction angles and topological structures of fingerprint endpoints and bifurcation points based on the accurate feature data to obtain a fingerprint document; performing block operation on the fingerprint document based on the Rabin-Karp algorithm to obtain fingerprint features; adjusting the weights and screening the fingerprint features based on the Winnow algorithm to obtain an optimized feature set; and using the MD5 algorithm to obtain a multi-dimensional identity authentication data document fingerprint based on the optimized feature set to generate the biometric database.

[0009] In an alternative embodiment, the block operation on the fingerprint document based on the Rabin-Karp algorithm to obtain fingerprint features specifically comprises: finding specific features in the fingerprint document through sliding window and hash calculation; identifying the distribution position of the specific features in the fingerprint document data stream based on a predefined authentication mode in the biometric data; determining the distribution position and the predefined authentication mode as part of the document fingerprint to obtain the fingerprint features.

[0010] In an alternative embodiment, the identity authentication of the terminal device further comprises: recording an authentication log of each identity authentication, the authentication log including authentication time and used fingerprint features to facilitate auditing and tracking of the authentication process.

[0011] In an alternative embodiment, if the identity authentication is passed, a dynamic access policy is started based on the trust level, specifically comprising: if only certificate authentication is passed, granting minimum permissions, the minimum permissions including basic data collection permissions; if both certificate authentication and biometric authentication are passed, granting high-level operation permissions.

[0012] In an alternative embodiment, if the evaluation result is high risk, prompting the user to perform secondary biometric authentication, otherwise only granting the minimum permissions.

[0013] In an alternative embodiment, during the secondary biometric authentication, if continuous fingerprint verification failures or abnormal user behavior are detected, the session is immediately terminated and the terminal is isolated to prevent lateral penetration.

[0014] In an optional implementation, if the identity authentication is passed, a dynamic access strategy is started based on the trust level, and specifically further comprising: obtaining an access operation instruction; detecting the access operation instruction based on the RAdAC model; if a non-compliant protocol call or an abnormal instruction sending is detected, triggering the strategy engine to dynamically upgrade the multi-factor authentication or limit the operation permission to the minimum permission.

[0015] In an optional implementation, if the identity authentication is passed, a dynamic access strategy is started based on the trust level, and specifically further comprising: utilizing the attribute collector of the PIP to monitor the running state of the relay protection device in real time, and combining the micro-isolation algorithm to implement control over the power service data stream, so that even if the network boundary is broken, the attacker cannot penetrate horizontally based on the WAPI encrypted link; analyzing the historical access log and security events through the audit module to continuously optimize the risk assessment model, so as to adapt to the complex scenarios of heterogeneous device access and edge node management in the smart grid.

[0016] In an optional implementation, the identity authentication process and the dynamic access process are monitored in real time, and the risk assessment is continuously performed to obtain a risk assessment result, and specifically comprising: obtaining behavior pattern data of the terminal device, the behavior pattern data including operation logs and network traffic data; comparing the behavior pattern data with a preset normal mode to perform risk assessment and obtain the risk assessment result.

[0017] In an optional implementation, the behavior pattern data of the terminal device is obtained, and specifically comprising: generating authentication data based on the WAPI three-way peer-to-peer identification architecture, the authentication data including X.509 certificate two-way authentication logs, key negotiation records, and control plane signaling data between APs and ACs; combining a lightweight log collector set by the substation edge node to process heterogeneous security events of the WAPI identification server and the AC controller in real time; transmitting the authentication data and the heterogeneous security events to a SIEM analysis engine through a distributed message queue to build a full-flow monitoring network covering the wireless access layer and the core service layer; obtaining the behavior pattern data based on the full-flow monitoring network.

[0018] In an optional implementation, the WAPI power communication security access method based on zero trust further comprises: adopting an improved time window sliding algorithm to baseline model historical certificate issuance records to obtain a baseline modeling model; detecting device certificates based on the baseline modeling model; if an abnormal mode is detected in the device certificates within a preset time, combining a threat intelligence library to perform multi-dimensional correlation analysis on the abnormal mode to obtain an analysis result; and pushing the analysis result to an operation and maintenance alarm center.

[0019] The application further provides a zero-trust-based WAPI power communication security access system, comprising: a terminal device provided with a terminal mainboard and a WAPI security chip, wherein the WAPI security chip is integrated with an identity recognition module, and the identity recognition module is connected with the terminal mainboard through a special interface; an authentication server, which is in communication connection with the WAPI security chip and the identity recognition module respectively, and performs identity authentication on the terminal device, wherein the identity authentication comprises certificate authentication and biometric authentication; a data processing device, which is in communication connection with the authentication server, and when the identity authentication is passed, starts a dynamic access strategy for the network based on a trust level, and monitors the identity authentication process and the dynamic access process in real time, continuously performs risk assessment, and obtains a risk assessment result, and grants a dynamic access permission or directly terminates the access of the terminal device based on the assessment result.

[0020] The application further provides a storage medium storing a computer program, wherein the computer program is executed by a processor to implement the zero-trust-based WAPI power communication security access method.

[0021] The application has the beneficial effects that: the application can improve the reliability and business continuity of the system, and effectively prevent unauthorized access and potential network attacks by performing dynamic fingerprint authentication and dynamically granting access permissions while ensuring security and performing fine-grained access control on resources. BRIEF DESCRIPTION OF DRAWINGS

[0022] Figure 1 A flowchart of the zero-trust-based WAPI power communication security access method provided by an embodiment of the application is shown in the figure.

[0023] Figure 2 An architecture diagram of the zero-trust-based WAPI power communication security access system provided by another embodiment of the application is shown in the figure. DETAILED DESCRIPTION

[0024] The application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0025] As shown in the figure, according to the embodiment of the application, on the one hand, a zero-trust-based WAPI power communication security access method is provided, comprising the following steps: Figure 1

[0026] Step S101: performing identity authentication on the terminal device, wherein the identity authentication comprises certificate authentication and biometric authentication, and the biometric authentication comprises fingerprint authentication;

[0027] Step S103: if the identity authentication is passed, starting a dynamic access strategy for the network based on a trust level;

[0028] ​Step S105: Real-time monitoring of the identity authentication process and the dynamic access process, continuous risk assessment, and risk assessment results are obtained.

[0029] Step S107: Granting dynamic access rights or directly terminating access based on the assessment results.

[0030] In this embodiment, the terminal device needs to pass the certificate authentication when attempting to connect to the power communication network. During certificate authentication, the terminal device submits a digital certificate to the authentication server, which verifies the validity, integrity, and authenticity of the certificate. Based on the certificate authentication, biometric authentication, including fingerprint authentication, is further introduced to enhance the security of identity verification. This requires the user to provide biometric data, and the system verifies the user's identity by comparing it with the stored biometric template.

[0031] Once the identity authentication is passed, the dynamic access strategy will be started based on the trust level of the user or device, which can be based on various factors such as authentication methods, historical behavior, device security status, etc. Dynamic access strategy refers to dynamically adjusting access rights during the access process based on the operation behavior of the access process. The system monitors the identity authentication process in real time, including the details of certificate verification and biometric matching, and also monitors the dynamic access behavior of the user or device after obtaining access rights, such as the resources accessed, the frequency and mode of operation, etc. Based on the monitoring data, the system continuously conducts risk assessment to analyze whether there are abnormal behaviors or potential security threats. If the risk assessment result shows that the behavior of the user or device is in line with expectations and there is no security threat, the system will grant or maintain dynamic access rights as needed. If the risk assessment result shows that there are abnormal behaviors or potential security threats, the access rights will be directly terminated to prevent possible security incidents.

[0032] Through the above method steps, the power communication system can ensure security while achieving fine-grained access control to resources, thereby improving the reliability and business continuity of the system, and compared with the static access rights and single authentication in the prior art, it can effectively prevent unauthorized access and potential network attacks.

[0033] Further, in step S101, identity authentication is performed on the terminal device, which includes biometric authentication, specifically including the following steps:

[0034] Step S1011: Construct a biometric database, which includes a fingerprint template.

[0035] Step S1013: Acquire a fingerprint image.

[0036] Step S1015: Generate a fingerprint feature code to be verified based on the fingerprint image;

[0037] Step S1017: generating an identity authentication data document fingerprint based on the fingerprint feature code;

[0038] Step S1019: calculating the similarity based on the identity authentication data document fingerprint and the fingerprint template.

[0039] Step S1020: if the similarity exceeds a preset threshold, determining that the identity authentication is passed.

[0040] When a terminal device, such as a station (STA) device, needs to access a network, using the WAPI security protocol combined with fingerprint verification can improve the security of network access.

[0041] The terminal device sends an access request to an access point (AP) to indicate that it hopes to connect to the network. After the AP receives the access request, the authentication server first completes the regular WAPI certificate verification, and then requires the terminal device to perform fingerprint verification according to the security policy. The fingerprint collection module on the terminal device is started, prompting the operator to place the finger on the fingerprint collection module, and the fingerprint collection module acquires a clear fingerprint image. The collected fingerprint image is preprocessed, and the same algorithm process as when the database is built is used to extract fingerprint features such as endpoints, bifurcation points, and ridge directions from the preprocessed image. The extracted fingerprint features are converted into a fingerprint feature code to be verified. The fingerprint feature code contains multi-dimensional information of the fingerprint, and based on the fingerprint feature code, an identity authentication data document fingerprint can be generated for matching with the fingerprint template in the database. Among them, the similarity threshold value can be set according to the security requirements and application scenarios. The setting of the threshold value needs to balance the security and user experience, and avoid excessive false rejection and false recognition. By comparing the received fingerprint feature code with the template stored in the database, the similarity of the two is calculated, and when the similarity exceeds the preset threshold, it is determined that the verification is passed.

[0042] Further, the zero-trust-based WAPI power communication security access method further comprises: periodically updating the biometric database, including deleting expired fingerprint records and adding new authorized information.

[0043] In this embodiment, according to the security requirements and business processes, the review period of the biometric database is set, such as every 90 days. In each review period, the system automatically checks the fingerprint records in the database and identifies the expired or no longer valid records. The expired fingerprint records are securely deleted from the database to prevent misuse of old data and ensure that the deletion process does not affect the integrity and security of the database. Detailed information of the record deletion operation, including deletion time, number of deleted records, etc., can be used for subsequent security audit and compliance check. Register biometric information such as fingerprint for new users or devices. At the same time, detailed logs of each authentication are also recorded, including authentication time, fingerprint features used, etc., to facilitate subsequent audit and tracking.

[0044] Through the above steps, the zero-trust-based WAPI power communication security access method can ensure the continuous updating and maintenance of the biometric database, thereby improving the accuracy and security of identity authentication. At the same time, regularly updating the biometric database helps to adapt to the changing security requirements and business environment, ensuring the long-term stable operation of the system.

[0045] In this way, on the basis of maintaining the original security features of WAPI, dynamic identity verification based on biometrics is added, realizing more fine-grained access control.

[0046] Specifically, based on step S1011, a biometric database is constructed, specifically including the following steps:

[0047] Step S10111: Collecting a set of fingerprint minutiae and performing gray value binary conversion to obtain conversion data;

[0048] Step S10113: Using a line tracking algorithm to exclude false feature points from the conversion data to obtain accurate feature data;

[0049] Step S10115: Based on the accurate feature data, the coordinates, direction angles and topological structures of the fingerprint endpoints and bifurcation points are extracted to obtain a fingerprint document;

[0050] Step S10117: Based on the Rabin-Karp algorithm, the fingerprint document is divided into blocks to obtain fingerprint features;

[0051] Step S10119: Based on the Winnow algorithm, the fingerprint features are adjusted in weight and screened to obtain a feature optimization set;

[0052] Step S10120: Based on the feature optimization set, the MD5 algorithm is used to obtain multi-dimensional identity authentication data document fingerprints to generate a biometric database.

[0053] In this embodiment, the acquired fingerprint image is converted to grayscale, transforming the color image into a grayscale image. Binarization is then performed, converting the grayscale image into a black and white image to highlight the fingerprint's detailed features. The converted binarized image is stored as the basis for subsequent processing. During ridge tracing, false feature points caused by image noise or other reasons are identified and eliminated.

[0054] The Rabin-Karp algorithm is used to segment identity authentication data documents. Simultaneously, the Winnow algorithm is introduced to adjust and filter the weights of the extracted features. Feature weights are updated based on existing identity authentication data. In the context of identity authentication, the weights of features related to legitimate identity authentication are increased, while the weights of features related to illegitimate or irrelevant features are decreased. After processing by the Winnow algorithm, an optimized feature set is obtained, where features with higher weights better represent the core features of the identity authentication data document. These features can be further integrated into the document fingerprint. Finally, by combining the MD5 algorithm to provide a unique overall identifier for the document, a multi-dimensional identity authentication data document fingerprint is formed. The identity authentication data document fingerprint includes the overall hash value of the document, the location and content of key features, and the relative importance of these features, thus providing a comprehensive and discriminative feature representation for identity authentication.

[0055] Further, step S10117 involves segmenting the fingerprint document into blocks based on the Rabin-Karp algorithm to obtain fingerprint features, specifically including the following steps:

[0056] Step S101171: Find specific features in the fingerprint document by using a sliding window and hash calculation.

[0057] Step S101173: Identify the distribution location of specific features in the fingerprint document data stream using a predefined authentication pattern in the biometric data.

[0058] Step S101175: Determine the distribution location and predefined authentication mode as part of the document fingerprint to obtain fingerprint features.

[0059] This approach efficiently finds specific patterns or features in documents by using sliding windows and hash calculations. It predefines key authentication information patterns in biometric data, quickly identifies their distribution location in the data stream, and incorporates this location information, along with the pattern itself, as part of the document fingerprint. This scheme maintains core feature recognition capabilities even with local feature distortions, enhancing the robustness of identity authentication.

[0060] Furthermore, the authentication of terminal devices also includes recording an authentication log for each authentication, which includes the authentication time and the fingerprint features used, in order to facilitate auditing and tracking of the authentication process.

[0061] At the start of each authentication process, a new authentication log entry is initialized, recording the precise start and end times of the authentication, including the date and timestamp. It also records the specific fingerprint features used during authentication, such as the hash value or feature identifier of the fingerprint code. The entry records whether the authentication was successful and the reason for success or failure. If authentication involves personnel, it records their user ID or other identifying information. It records device information attempting to access the network, such as device type, device ID, and MAC address. It records network information the device attempted to access, such as the access point ID and network name. It records the IP address and geographical location information of the device during the access attempt, which is helpful for tracking and auditing. The authentication logs are periodically audited to check for abnormal authentication behavior or security incidents.

[0062] By meticulously logging every authentication transaction, network security can be improved, compliance requirements met, and rapid response and handling enabled in the event of a security incident. Authentication logs provide valuable information for auditing and tracing, helping organizations understand the full picture of a security incident and take appropriate security measures.

[0063] Furthermore, based on step S103: if authentication is successful, a dynamic access policy is initiated for the network based on the trust level, specifically including the following steps:

[0064] Step S1031: If only certificate authentication is passed, grant the minimum permissions, which include basic data collection permissions;

[0065] Step S1033: If both certificate authentication and biometric authentication are passed, then grant higher-level operation privileges.

[0066] For devices that are only certified by certificates, determine the minimum level of permissions that can be granted based on the assessment results to ensure that basic business functions can be performed while limiting potential security risks. Grant basic data collection permissions, allowing devices or users to access and collect necessary data, but restrict access to sensitive data and critical operations.

[0067] Monitor the behavior of devices or users granted the least privileges in real time to ensure that their operations comply with the expected security policies.

[0068] If a terminal device passes both certificate authentication and biometric authentication, it is granted higher-level operating privileges, allowing the device or user to access more parts of the network and perform more sensitive operations.

[0069] This strategy helps prevent unauthorized access and potential security threats, improving overall network security.

[0070] Furthermore, if the assessment result is high-risk, the user will be prompted to perform secondary biometric authentication; otherwise, only the minimum permissions will be granted.

[0071] If abnormal operations are detected, such as in power communication systems where a terminal device attempts to access an unauthorized network or makes frequent login attempts within the same timeframe, the user will be required to re-verify their fingerprint to ensure operational security. If the risk score exceeds a preset threshold, the assessment result is considered high-risk. Examples include the terminal's first access to an unauthorized network or geographically unfamiliar area, or the detection of unusual traffic spikes, abnormal access from specific IP addresses or ports, etc. In such cases, a secondary authentication prompt is sent to the user, requiring additional biometric authentication. The interaction is via a pop-up window asking the user whether they agree to secondary authentication. If the user agrees, the fingerprint recognition secondary authentication process begins; if the user disagrees, the system grants the device only the minimum permissions to reduce potential risks. If secondary authentication is successful, the user's risk score is updated, and access permissions are adjusted accordingly. If secondary authentication fails or the user fails the risk assessment, the system grants the user only the minimum permissions and prohibits the issuance of control commands. Secondary biometric authentication, as a strong identity verification method, effectively prevents unauthorized access and protects network security.

[0072] Furthermore, during the secondary biometric authentication process, if fingerprint verification fails repeatedly or abnormal user behavior is detected, the session is immediately terminated and the terminal is isolated to prevent lateral movement.

[0073] A counter can be set to record the number of consecutive fingerprint verification failures. A threshold can be set according to the security policy, such as three consecutive failed fingerprint verifications. A baseline of normal user behavior can be established, including operating habits and access patterns. User behavior is monitored in real time and compared to this baseline. If a user's behavior significantly deviates from the baseline, the system identifies it as abnormal behavior. This prevents lateral movement and effectively prevents the spread of security threats.

[0074] To achieve fine-grained, dynamic, and policy-based access control, the Risk-Adaptive Dynamic Access Control (RAdAC) model can be used to enhance the security of power distribution IoT systems. Its core lies in the deep integration of the zero-trust principle with a risk-adaptive mechanism, constructing a dynamic protection system capable of addressing complex security threats. The RAdAC model, through its fine-grained access control mechanism, enables system administrators to precisely control user access permissions to various resources, achieving refined management from subjects and objects to specific access behaviors, effectively reducing the attack surface and lowering the risk of malicious attacks. Simultaneously, the dynamic access control feature allows the system to adjust permission policies instantly based on real-time risk assessment results. When abnormal login behavior or changes in device security status are detected, multi-factor authentication or access restrictions are automatically triggered, ensuring that security measures always evolve in sync with the current threat landscape.

[0075] In the dynamic authorization process of the ZT-RAdAC model, the core access control mechanism revolves around the refined collaboration of key components such as PEP, PDP, PAP, and PIP. When an access subject initiates a request, the PEP, as the policy enforcement point, first receives and forwards the access request to the policy decision point PDP, triggering the initialization phase of the authorization process. The PDP then retrieves relevant policy rules from the policy management point PAP, and simultaneously coordinates the collection of environmental attributes required for policy evaluation through the context processor CH. During this process, the policy information point PIP plays a crucial role. It extracts pre-stored attribute values ​​from the attribute library AT, dynamically calls the attribute collector AR to acquire missing context data in real time, such as device status and environmental variables, and captures attribute changes through a continuous monitoring mechanism to support dynamic decision-making.

[0076] Furthermore, based on step S103, if authentication is successful, a dynamic access policy is initiated for the network based on the trust level, specifically including the following steps:

[0077] Step S1035: Obtain access operation instructions.

[0078] Step S1037: Detect access operation commands based on the RAdAC model.

[0079] Step S1039: If a non-compliant protocol call or abnormal instruction is detected, the policy engine is triggered to dynamically upgrade multi-factor authentication or restrict operation permissions to the minimum level.

[0080] Monitor and capture all access operation commands sent by users or devices, including file access requests, database queries, system configuration changes, etc. Use the RAdAC model to assess the risk of these commands, checking their compliance with security policies and requirements to ensure they do not violate any security rules or laws. Use machine learning algorithms or rule engines to detect abnormal patterns in the commands to identify potential malicious operations or attacks. Based on the RAdAC model's detection results, assess the security risk level of the commands. If non-compliant protocol calls or abnormal command sending are detected, trigger the policy engine to take appropriate security measures, including dynamically upgrading multi-factor authentication or restricting operation permissions to the minimum required level.

[0081] In power communication scenarios, the application of zero-trust fine-grained access control technology can be achieved through the deep integration of the RAdAC model and the WAPI security mechanism. Specifically, based on WAPI certificate two-way authentication, the dynamic risk adaptive mechanism of the RAdAC model is introduced. When a terminal device authenticated via WAPI accesses the SCADA system, the RAdAC risk adaptive engine continuously analyzes the timing characteristics of its operation commands, device health status, and communication traffic anomalies. If non-compliant protocol calls or abnormal command sending are detected, even if WAPI authentication has been passed, the system will still trigger the policy engine to dynamically upgrade multi-factor authentication or restrict its operation permissions to the minimum necessary scope.

[0082] Furthermore, based on step S103, if authentication is successful, a dynamic access policy is initiated for the network based on the trust level, specifically including the following steps:

[0083] Step S1032: Use the PIP attribute collector to monitor the operation status of the relay protection device in real time, and combine it with the micro-segmentation algorithm to control the power business data flow, so that even if the network boundary is breached, attackers cannot penetrate laterally based on the WAPI encrypted link.

[0084] Step S1034: Analyze historical access logs and security events through the audit module to continuously optimize the risk assessment model so as to adapt to the complex scenarios of heterogeneous device access and edge node management in the smart grid.

[0085] Through the above steps, the security system can ultimately evolve from passive defense to proactive prediction, taking into account both the high reliability and business continuity requirements of the power system.

[0086] Furthermore, based on step S105: real-time monitoring of the identity authentication process and dynamic access process, continuous risk assessment is conducted to obtain risk assessment results, specifically including the following steps:

[0087] Step S1051: Obtain the behavior pattern data of the terminal device, which includes operation logs and network traffic data;

[0088] Step S1053: Compare the behavioral pattern data with the preset normal pattern to conduct a risk assessment and obtain the risk assessment result.

[0089] In this embodiment, during real-time monitoring of the identity authentication process and dynamic access, the device's operation logs and network traffic data are collected in real time. The operation logs include operation time, frequency, accessed resources, etc., and are compared with preset normal behavior patterns. Based on the above method, the device's behavioral characteristics are continuously monitored. If abnormal operations are detected, such as in a power communication system, if the terminal device attempts to access an unauthorized network or frequently attempts to log in within the same time period, a risk assessment will be performed, requiring the user to re-verify their fingerprint to ensure the security of the operation.

[0090] Network traffic data reflects the communication status of terminal devices on the network, including information such as packet size, transmission frequency, destination IP address, and protocol type used. Analyzing network traffic data allows for the timely detection of abnormal network communication behavior.

[0091] Based on step S1051, the behavior pattern data of the terminal device is obtained, specifically including the following steps:

[0092] Step S10511: Generate authentication data based on the WAPI ternary peer authentication architecture. The authentication data includes X.509 certificate two-way authentication logs, key negotiation records, and control plane signaling data between AP / AC.

[0093] Step S10513: Combine the lightweight log collector set up at the substation edge node to process heterogeneous security events of WAPI authentication server and AC controller in real time in a standardized manner.

[0094] Step S10515: Transmit authentication data and heterogeneous security events to the SIEM analysis engine through a distributed message queue to build a full traffic monitoring network covering the wireless access layer and the core service layer.

[0095] Step S10517: Obtain behavioral pattern data based on the full traffic monitoring network.

[0096] By employing data analysis algorithms and machine learning models, the behavioral characteristics of terminal devices in different network scenarios can be extracted and modeled. These behavioral characteristics encompass multiple dimensions, including access frequency, session duration, data transmission volume, resource usage, and communication patterns. Comprehensive analysis of these behavioral characteristics allows for the accurate identification of normal and abnormal behavior patterns of terminal devices. For example, if a terminal device frequently attempts key negotiation and authentication within a short period, and each authentication uses a different IP address, this may be an abnormal behavior, suggesting that the terminal device may have been subjected to malicious attacks or unauthorized use. Continuous monitoring and analysis of these behavioral pattern data allows for the timely detection of potential security threats, enabling proactive preventative measures and effectively ensuring the security of terminal devices and the stable operation of the network.

[0097] By deploying a custom-developed lightweight log collector on the substation edge computing node, the modular design of the lightweight log collector enables standardized processing and initial filtering of security events generated by critical devices such as WAPI authentication servers and AC controllers. Distributed message queues transmit heterogeneous logs to the SIEM analysis engine in real time, ensuring the timeliness and reliability of handling massive amounts of security events. Simultaneously, fine-grained network telemetry data provides data support for the accurate execution of zero-trust policies. When the system detects suspicious behavior such as frequent certificate changes by terminals or abnormal broadcasts by APs, the SIEM risk correlation analysis module, based on predefined threat models and machine learning algorithms, immediately triggers the zero-trust policy engine to dynamically adjust the terminal's access permissions and, through standardized API linkage with the AC controller, forcibly shut down high-risk sessions. The entire process can be completed in milliseconds, significantly reducing threat dwell time.

[0098] Furthermore, the zero-trust-based WAPI power communication secure access method also includes the following steps:

[0099] Step S102: Use an improved time window sliding algorithm to perform baseline modeling on historical certificate issuance records to obtain a baseline modeling model;

[0100] Step S104: Detect the device certificate based on the baseline modeling model;

[0101] Step S106: If an abnormal pattern is detected in the device certificate within a preset time, a multi-dimensional correlation analysis of the abnormal pattern is performed in conjunction with the threat intelligence database to obtain the analysis results.

[0102] Step S108: Push the analysis results to the operation and maintenance alarm center.

[0103] In this embodiment, an improved time window sliding algorithm is used to perform baseline modeling on historical certificate issuance records, targeting the low-frequency, slow penetration characteristics unique to APT attacks. This algorithm can adaptively adjust the detection window size, effectively balancing the trade-off between detection sensitivity and false alarm rate. When an abnormal pattern is detected, such as a terminal certificate being repeatedly verified by multiple access points (APs) within a short period of time, multi-dimensional correlation analysis is performed in conjunction with the threat intelligence database to automatically increase the threat score of the security event and push it to the operation and maintenance alarm center. The entire system ultimately achieves a closed-loop security system, providing reliable technical support for the power Internet of Things (IoT) to cope with new network threats.

[0104] On the other hand, in conjunction with Figure 2, this invention also proposes a zero-trust-based WAPI power communication secure access system, comprising: a terminal device equipped with a terminal motherboard and a WAPI security chip, the WAPI security chip integrating an identity recognition module, the identity recognition module being connected to the terminal motherboard via a dedicated interface; an authentication server, communicatively connected to the WAPI security chip and the identity recognition module respectively, for authenticating the terminal device, the identity authentication including certificate authentication and biometric authentication; and a data processing device, communicatively connected to the authentication server, which, upon successful identity authentication, initiates a dynamic access policy for the network based on the trust level, and monitors the identity authentication process and the dynamic access process in real time, continuously performs risk assessment, obtains risk assessment results, and grants dynamic access permissions or directly terminates the terminal device's access based on the assessment results.

[0105] By using SIEM for real-time monitoring, building a fine-grained access control system for applications, and employing fingerprint biometric authentication, a zero-trust-based WAPI power communication secure access design is achieved. The overall architecture is as follows: Figure 2 As shown.

[0106] The identity verification module includes a fingerprint sensor. When a dedicated mobile device, such as an industrial tablet PC, connects to a wireless network, a zero-trust secure access mechanism is immediately activated. First, a standard WAPI certificate two-way authentication process is completed. Then, the system immediately requires biometric verification via the fingerprint sensor integrated into the terminal. The fingerprint image is captured in real time, binarized, and features are extracted to generate a signature code, which is then transmitted to the authentication server in encrypted form. The authentication server verifies the validity of the device certificate and compares this signature code with authorized templates in the fingerprint database. Only when both the certificate and fingerprint similarity meet the requirements is the user's identity confirmed as legitimate.

[0107] After successful authentication, the system does not grant static permissions; instead, the RAdAC dynamic access control model takes over. The policy decision point collects multi-dimensional contextual information from the policy information point in real time, including user identity and role, historical operation records, the current operating status of the target relay protection device, access time, terminal geographical location, terminal's own security status, and the specific operation type of the current request. If the assessment indicates a low-risk scenario, the necessary modification permissions are granted. However, if the system detects an anomaly, even if WAPI authentication has been successful, the system will still trigger the policy engine to dynamically upgrade multi-factor authentication or restrict operational permissions to the minimum necessary scope.

[0108] Throughout the session, SIEM real-time monitoring technology plays a continuous protective role. Lightweight log collectors deployed at the substation edge continuously gather authentication logs, policy decision logs, terminal operation commands, and network traffic data. For example, if the system detects a terminal frequently sending non-compliant protocol commands or an abnormal sequence of operation commands, it immediately identifies this high-risk behavior and triggers a standardized interface to link the zero-trust policy engine and controller. The policy engine dynamically adjusts permissions or terminates the current session accordingly, while the controller forcibly takes the high-risk terminal offline and isolates it from the network. The entire process is completed in milliseconds, effectively preventing potential malicious operations or attack spread. The audit module synchronously records all events throughout the process, providing data support for subsequent source tracing and model optimization, ultimately forming a closed-loop security protection system covering identity authentication, dynamic authorization, real-time monitoring, and response.

[0109] This invention, by constructing a "continuous verification, dynamic authorization" security mechanism and designing fine-grained access control policies tailored to the characteristics of power services, achieves a shift from network perimeter protection to service-inherent security, effectively enhancing the ability of power communication networks to resist advanced persistent threats. This invention covers key aspects such as terminal identity authentication, service traffic monitoring, and dynamic risk assessment, providing an innovative solution for the secure operation of WAPI access technology in power communication networks under new power system environments, and has significant value in ensuring the reliable operation of the power grid.

[0110] On the other hand, the present invention also proposes a computer storage medium storing a computer program, which, when executed by a processor, implements any one of the following: a zero-trust-based WAPI power communication secure access method.

[0111] Computer storage media may be simply referred to as storage media. Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other storage media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Dual Data SDRAM (DDRSDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), Rambus Direct RAM (RDRAM), Direct Memory Bus Dynamic RAM (DRDRAM), and Memory Bus Dynamic RAM (RDRAM). The various embodiments described in this specification are presented in a progressive manner, and similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, for embodiments of apparatus, devices, and non-volatile computer storage media, since they are substantially similar to the method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments.

[0112] The above embodiments are merely illustrative examples and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention.

Claims

1. A zero-trust-based WAPI power communication secure access method, characterized in that, include: The terminal device is authenticated, and the authentication includes certificate authentication and biometric authentication, the biometric authentication including fingerprint authentication. If the identity authentication is successful, a dynamic access policy is initiated for the network based on the trust level; Real-time monitoring of the identity authentication process and dynamic access process, continuous risk assessment, and obtaining risk assessment results; Based on the evaluation results, dynamic access permissions may be granted or access may be terminated directly.

2. The zero-trust-based WAPI power communication secure access method according to claim 1, characterized in that, The terminal device is authenticated, including biometric authentication, specifically including: Construct a biometric database, which includes fingerprint templates; Obtain fingerprint image; Generate a fingerprint feature code to be verified based on the fingerprint image; Generate an identity authentication data document fingerprint based on the fingerprint feature code; Calculate the similarity between the identity authentication data document fingerprint and the fingerprint template; If the similarity exceeds a preset threshold, the identity authentication is deemed successful.

3. The zero-trust-based WAPI power communication secure access method according to claim 2, characterized in that, Building a biometric database also includes: regularly updating the biometric database, including deleting expired fingerprint records and adding new authorization information.

4. The zero-trust-based WAPI power communication secure access method according to claim 2, comprising constructing a biometric database, specifically including: Collect a set of fingerprint minutiae and perform grayscale binary conversion to obtain the converted data; The ridge tracing algorithm is used to eliminate false feature points in the transformed data to obtain accurate feature data; Based on the precise feature data, the coordinates, orientation angles, and topological structure of the fingerprint endpoints and bifurcation points are extracted to obtain the fingerprint document; The fingerprint document is segmented into blocks based on the Rabin-Karp algorithm to obtain fingerprint features; The fingerprint features are weighted and filtered based on the Winnow algorithm to obtain an optimized feature set. Based on the aforementioned feature optimization set, the MD5 algorithm is used to obtain multi-dimensional identity authentication data document fingerprints, thereby generating the biometric database.

5. The zero-trust-based WAPI power communication secure access method according to claim 4, characterized in that, The fingerprint document is segmented into blocks based on the Rabin-Karp algorithm to obtain fingerprint features, specifically including: Using sliding windows and hash calculations to find specific features in fingerprint documents; Based on predefined authentication patterns in biometric data, the distribution location of the specific features in the fingerprint document data stream is identified; The distribution location and the predefined authentication pattern are determined as part of the document fingerprint to obtain the fingerprint feature.

6. The zero-trust-based WAPI power communication secure access method according to claim 1, characterized in that, Authentication of terminal devices also includes recording an authentication log for each authentication, the authentication log including the authentication time and the fingerprint features used, so as to facilitate auditing and tracking of the authentication process.

7. The zero-trust-based WAPI power communication secure access method according to claim 1, characterized in that, If the identity authentication is successful, a dynamic access policy is initiated for the network based on the trust level, specifically including: if only certificate authentication is successful, the minimum permissions are granted, which include basic data collection permissions; If both certificate authentication and biometric authentication are successful, higher-level operation privileges will be granted.

8. The zero-trust-based WAPI power communication secure access method according to claim 7, characterized in that, If the assessment result is high risk, the user will be prompted to perform secondary biometric authentication; otherwise, only the minimum permissions will be granted.

9. The zero-trust-based WAPI power communication secure access method according to claim 8, characterized in that, During the secondary biometric authentication process, if fingerprint verification fails repeatedly or user behavior is detected as abnormal, the session is immediately terminated and the terminal is isolated to prevent lateral movement.

10. The zero-trust-based WAPI power communication secure access method according to claim 7, characterized in that, If the identity authentication is successful, a dynamic access policy is initiated for the network based on the trust level, which specifically includes: Obtain access operation instructions; The access operation command is detected based on the RAdAC model; If a non-compliant protocol call or abnormal instruction is detected, the policy engine is triggered to dynamically upgrade multi-factor authentication or restrict operation permissions to the minimum required level.

11. The zero-trust-based WAPI power communication secure access method according to claim 7, characterized in that, If the identity authentication is successful, a dynamic access policy is initiated for the network based on the trust level, which specifically includes: The PIP attribute collector is used to monitor the operation status of the relay protection device in real time, and the micro-segmentation algorithm is combined to control the power business data flow, so that even if the network boundary is breached, attackers cannot penetrate laterally based on the WAPI encrypted link. By analyzing historical access logs and security events through the audit module, the risk assessment model is continuously optimized to adapt to the complex scenarios of heterogeneous device access and edge node management in smart grids.

12. The zero-trust-based WAPI power communication secure access method according to any one of claims 1 to 11, characterized in that, Real-time monitoring of the identity authentication process and dynamic access process, continuous risk assessment, and obtaining risk assessment results, specifically including: Acquire behavioral pattern data of the terminal device, the behavioral pattern data including operation logs and network traffic data; The behavioral pattern data is compared with a preset normal pattern to perform a risk assessment, and the risk assessment result is obtained.

13. The zero-trust-based WAPI power communication secure access method according to claim 12, characterized in that, Obtaining the behavior pattern data of the terminal device specifically includes: Authentication data is generated based on the WAPI ternary peer-to-peer authentication architecture. The authentication data includes X.509 certificate two-way authentication logs, key negotiation records, and control plane signaling data between AP / AC. Combined with a lightweight log collector set up at the substation edge node, heterogeneous security events from WAPI authentication server and AC controller are processed in real time in a standardized manner. The authentication data and heterogeneous security events are transmitted to the SIEM analysis engine through a distributed message queue, thereby building a full traffic monitoring network covering the wireless access layer and the core service layer. Behavioral pattern data is obtained based on the full traffic monitoring network.

14. The zero-trust-based WAPI power communication secure access method according to any one of claims 1 to 11, characterized in that, Also includes: An improved time window sliding algorithm is used to perform baseline modeling on historical certificate issuance records, resulting in a baseline modeling model. The device certificate is detected based on the baseline modeling model. If an abnormal pattern is detected in the device certificate within a preset time, a multi-dimensional correlation analysis of the abnormal pattern is performed in conjunction with the threat intelligence database to obtain the analysis results. The analysis results are then pushed to the operation and maintenance alarm center.

15. A zero-trust-based WAPI power communication secure access system, characterized in that, include: The terminal device includes a terminal motherboard and a WAPI security chip. The WAPI security chip integrates an identity recognition module, which is connected to the terminal motherboard via a dedicated interface. An authentication server is communicatively connected to the WAPI security chip and the identity recognition module, respectively, to perform identity authentication on the terminal device, the identity authentication including certificate authentication and biometric authentication; The data processing device communicates with the authentication server and, upon successful identity authentication, initiates a dynamic access policy for the network based on the trust level. It also monitors the identity authentication process and the dynamic access process in real time, continuously performs risk assessments, and obtains risk assessment results. Based on the evaluation results, dynamic access permissions may be granted or the terminal device's access may be terminated directly.

16. A storage medium, characterized in that, The device contains a computer program that, when executed by a processor, implements the zero-trust-based WAPI power communication secure access method as described in any one of claims 1 to 14.

Citation Information

Cited By

  • Intelligent unmanned equipment-oriented instruction security reinforcement system and verification method

    CN122160201A