A substation automation device trusted hardware device and trusted control method

CN115270098BActive Publication Date: 2026-08-18NARI NANJING CONTROL SYSTEM CO LTD +4
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210342362.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-02
Publication Date
2026-08-18
Estimated Expiration
2042-04-02

AI Technical Summary

Technical Problem

[0003]现有的变电站自动化系统主要采用数据网络分区、纵横向隔离等被动的边界安全防御方式,通过部署电力专用隔离装置、防火墙及入侵检测设备等实现对病毒及木马等攻击行为的识别与阻断,现有传统“封堵查杀”式的边界安全防护手段,已难以防范变电站自动化系统面临的旁路攻击、木马与病毒植入、软硬件漏洞等新的趋于复杂化、隐蔽化的安全风险,亟需提升变电站自动化设备自身的内生安全能力

Benefits of technology

[0040]本发明提出的变电站自动化装置可信硬件装置及可信控制过程,针对变电站自动化装置多核多板卡的架构特点,通过变电站自动化装置多核多板卡异构的可信硬件装置及装置可信控制过程,实现了变电站自动化装置的自身安全免疫的硬件基础,能够实现变电站自动化装置及板卡的可信身份硬件标识,提升变电站自动化装置具备内生安全的主动免疫能力,对提升变电站自动化装置安全防御能力有着积极的意义,支撑电网安全稳定运行。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115270098B_ABST
    Figure CN115270098B_ABST
Patent Text Reader

Abstract

The application discloses a substation automation device trusted hardware architecture and a trusted control method, and the trusted hardware architecture comprises a master control board, a power supply board, a plurality of service boards, a power supply bus, an inter-board communication bus and a trusted security control bus; the master control board and each service board are respectively provided with a trusted security control circuit; the trusted security control circuits of the master control board and each service board respectively correspond to a trusted computing chip and a trusted identity chip; the master control board comprises a processor, the trusted security control circuit in the master control board controls the power supply on-off of other circuits, the processor interacts with the trusted identity chips of other boards through the trusted security control bus to perform identity authentication on the corresponding boards, and then controls the power supply board to provide working power supply to the service boards that pass the identity authentication; the service boards that complete power-on obtain corresponding trusted service programs from the master control board and load and run the programs. The application can realize the hardware trusted identity authentication of the multiple boards in the substation automation device, and improve the active immunity ability of the in-born security of the substation automation device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of power system automation control and network communication technology, specifically to a trusted hardware device and trusted control method for substation automation equipment. Background Technology

[0002] The power system is a large-scale system involving grid dispatch automation, substation automation, relay protection, and distribution network automation. It is a key infrastructure vital to the national economy and people's livelihood; an attack on it would cause enormous losses and social impact. Current attack patterns against power systems are becoming increasingly sophisticated, with more covert attack methods, a highly diffused attack range, and a wide range of attack techniques. Attacks often employ bypassing existing secondary boundary security defenses to carry out attacks on the power grid. Substations are critical nodes in the power grid, responsible for switching between different voltage levels. Their safe and stable operation is of paramount importance to the overall security and stability of the power grid. Substation automation systems are the foundation for power grid measurement and control, providing comprehensive automation for the automatic monitoring, measurement, control, and communication with dispatching of primary and secondary equipment. During maintenance, operation, and expansion, an attack on any device in the substation automation system could lead to a catastrophic accident in the power grid. Therefore, substation automation systems must be safe, stable, and reliable.

[0003] Existing substation automation systems mainly adopt passive boundary security defense methods such as data network partitioning and vertical and horizontal isolation. By deploying power-specific isolation devices, firewalls, and intrusion detection equipment, they can identify and block attacks such as viruses and Trojans. However, the existing traditional "blocking and killing" boundary security protection methods are no longer sufficient to prevent new, increasingly complex and covert security risks faced by substation automation systems, such as side-channel attacks, Trojan and virus implantation, and software and hardware vulnerabilities. There is an urgent need to improve the inherent security capabilities of substation automation equipment itself.

[0004] Glossary

[0005] TPCM (Trusted Platform Control Module) is a core hardware module integrated into a trusted platform to establish and safeguard the source of trust. It employs encryption algorithms and proactive measurement to ensure that the startup code is trustworthy when read by the platform controller, and then builds a trust chain to guarantee the trustworthiness of each level. Summary of the Invention

[0006] The purpose of this invention is to provide a trusted hardware device and trusted control method for substation automation equipment, enabling trusted hardware identity authentication for multiple boards within the substation automation equipment and enhancing the proactive immunity capability of the substation automation equipment's inherent security. The technical solution adopted by this invention is as follows.

[0007] On one hand, the present invention provides a trusted hardware device for substation automation, including a main control board, a power supply board, multiple service boards, as well as a power bus, an inter-board communication bus, and a trusted security control bus; the main control board and each service board are also provided with trusted security control circuits; the main control board and each service board transmit service data through the inter-board communication bus.

[0008] The main control board includes a processor, and the trusted security control circuit in the main control board includes a trusted computing chip. The trusted security control circuit of each service board includes a trusted identity chip.

[0009] In each service board, the trusted security control circuit is powered by the trusted security control bus, while other circuits are powered by the power board through the power bus.

[0010] In the main control board, the trusted security control circuit controls the power supply of other circuits. The processor interacts with the trusted identity chip of other boards through the trusted security control bus to obtain identity authentication data to authenticate the corresponding boards. Based on the identity authentication result, it sends a power control signal to the power board. The power board is configured to respond to the received power control signal and provide working power to other circuits in the service boards that have passed identity authentication, except for the trusted security control circuit.

[0011] Once powered on, the service board retrieves the corresponding trusted service program from the main control board and loads and runs it.

[0012] Optionally, each board is installed in its corresponding backplane slot. Each board has an internal bus, and the internal bus of each board is connected to the power bus, the inter-board communication bus and the trusted security control bus through the backplane slot interface.

[0013] The ports in the backplane card slot interface used to connect the trusted security control circuit of the service board to the trusted security control bus include the in-place status detection port.

[0014] The main control board can determine the presence status of each service board by detecting the signal at the presence status detection port, and then authenticate the presence of each service board. There are several ways to implement presence status detection, such as: having the service board provide a high or low level to the corresponding signal line in the slot, with the main control board detecting this level; or measuring the voltage of the slot board's detection circuit online (the voltage generated varies depending on the resistance value of the detection resistor connected to each slot); or actively emitting a specific signal after the board is inserted.

[0015] Optionally, the trusted security control circuit of the main control board is powered by the trusted security control bus, while other circuits are powered by the power supply board. The trusted security control bus is powered on when the substation automation device is powered on.

[0016] Alternatively, all circuits on the main control board can be powered by the power supply board, and the trusted security control circuit and trusted security control bus of the main control board can be powered on along with the substation automation device. This allows the trusted security control circuit of the main control board to start operating immediately after the device is powered on, and the trusted security control circuits of the service boards can also start operating.

[0017] Optionally, in the trusted security control circuit of the main control board, the trusted computing chip is configured as follows:

[0018] During power-on operation, a trust measurement is performed on the boot program of the main control board processor. If the trust measurement passes, the other circuits of the main control board are powered on.

[0019] After the processor is powered on, the trusted computing chip performs trust measurements on the driver program, trusted control program, main control board application program and application program in the processor. If any measurement fails, the device fails to start, stops running and outputs an alarm; otherwise, the device continues to run.

[0020] Optionally, the process of the power-on service board obtaining the corresponding trusted service program from the main control board and loading and running it involves the main control board's processor sending the measured service board application to the corresponding service board that has passed identity authentication via a trusted security control bus.

[0021] Optionally, the trusted computing chip on the main control board is a TPCM chip, and the trusted identity chip on other boards is a TPCM chip or an encryption chip; the trusted identity chip pre-stores the encryption authentication certificate of the host board, and the corresponding key is pre-stored in the main control board processor;

[0022] The service board processor interacts with the trusted identity chips of other boards through a trusted security control bus to obtain identity authentication data for authenticating the corresponding boards, including:

[0023] Obtain the encrypted authentication certificate pre-stored in the trusted identity chip of the board;

[0024] The pre-stored key is used to decrypt and authenticate the obtained encrypted certificate. If the decryption is successful and the authentication is passed, the authentication of the corresponding board is successful.

[0025] Optionally, the power supply board includes a power control unit. After the main control board authenticates any service board, it sends a control command to the power supply board to control the power supply of the corresponding service board. In response to receiving the control command, the power supply board controls the power to be transmitted to the corresponding service board through the power bus via the power control unit.

[0026] If any service board fails authentication, the device will fail to start, stop operation, and output an alarm.

[0027] Optionally, the power supply board may also include a trusted identity chip, which communicates with the processor of the main control board via a trusted security control bus.

[0028] The processor of the main control board is also configured to: after power-on, obtain the encrypted authentication certificate pre-stored in the trusted identity chip on the power board for decryption and authentication; if the authentication is successful, perform identity authentication on each service board; otherwise, the device fails to start.

[0029] Optionally, the service board also includes a processor, and the trusted security control circuit of the service board also includes a trusted computing chip, which is used to perform a security measurement on the boot program of the service board processor, and after the measurement is passed, to control other circuits of the service board to be connected to the power bus and powered on.

[0030] After the processor of the service board is powered on, it runs the boot program that has passed the measurement and requests the corresponding service program that has passed the measurement from the processor of the main control board through the secure and trusted control bus, and then loads and runs the service program.

[0031] Secondly, this invention provides a trusted control method for a trusted hardware device of a substation automation system, executed by a main control board, the method comprising:

[0032] When the device is powered on, the trusted computing chip of the main control board powers on and runs, performing a trusted measurement on the boot program of the main control board processor. If the trusted measurement passes, it controls the other circuits in the main control board, including the processor, to be powered on.

[0033] After the processor is powered on, the trusted computing chip performs a trust measurement on the driver program, trusted control program, main control board business application and business board application in the processor. If any measurement fails, the device fails to start, stops running and outputs an alarm; otherwise, the device continues to run.

[0034] After the main control board processor program completes the measurement, the main control board processor obtains the identity authentication information of each service board through the trusted security control bus to perform identity authentication. For any service board, if the identity authentication is successful, the main control board processor sends a power control signal to the power board, so that the power board responds to the power control signal and provides working power to the other circuits in the corresponding service board that has passed identity authentication, except for the trusted security control circuit.

[0035] The processor of the main control board sends the measured business board application to the corresponding business board that has passed identity authentication through the trusted security control bus, so that the business board can load the corresponding business program and run it.

[0036] After all business board programs are loaded and running, the device is fully started. During normal operation, business data generated by the boards can be exchanged through the inter-board secure communication bus.

[0037] Optionally, the power supply board includes a trusted identity chip, which communicates with the processor of the main control board via a trusted security control bus.

[0038] The method also includes: after the main control board processor program completes the measurement, before authenticating the identity of the service board, it obtains the encrypted authentication certificate pre-stored in the trusted identity chip on the power board for decryption and authentication. If the authentication is successful, it continues to authenticate the identity of each service board; otherwise, the device fails to start.

[0039] Beneficial effects

[0040] The trusted hardware device and trusted control process proposed in this invention for substation automation devices, taking into account the multi-core and multi-board architecture of substation automation devices, realizes the hardware foundation for the self-security immunity of substation automation devices through the heterogeneous trusted hardware device and trusted control process of multi-core and multi-board devices. It can realize the trusted identity hardware identification of substation automation devices and boards, enhance the intrinsic security proactive immunity capability of substation automation devices, and has positive significance for improving the security defense capability of substation automation devices, supporting the safe and stable operation of the power grid. Attached Figure Description

[0041] Figure 1 The diagram shown is an embodiment of the trusted hardware device of the substation automation device of the present invention.

[0042] Figure 2 The diagram shown is a flowchart of an embodiment of the trusted control method of the trusted hardware device for substation automation according to the present invention. Detailed Implementation

[0043] The following description, in conjunction with the accompanying drawings and specific embodiments, provides further details.

[0044] This embodiment introduces a trusted hardware device for substation automation, including a main control board, a power supply board, multiple service boards, a power bus, an inter-board communication bus, and a trusted security control bus; the main control board and each service board are also equipped with trusted security control circuits; the main control board and each service board transmit service data through the inter-board communication bus.

[0045] The main control board includes a processor, and the trusted security control circuit in the main control board includes a trusted computing chip. The trusted security control circuit of each service board includes a trusted identity chip.

[0046] In each service board, the trusted security control circuit is powered by the trusted security control bus, while other circuits are powered by the power board through the power bus.

[0047] In the main control board, the trusted security control circuit controls the power supply of other circuits. The processor interacts with the trusted identity chip of other boards through the trusted security control bus to obtain identity authentication data to authenticate the corresponding boards. Based on the identity authentication result, it sends a power control signal to the power board. The power board is configured to respond to the received power control signal and provide working power to other circuits in the service boards that have passed identity authentication, except for the trusted security control circuit.

[0048] Once powered on, the service board retrieves the corresponding trusted service program from the main control board and loads and runs it.

[0049] refer to Figure 1 As shown, in the trusted hardware architecture of the substation automation device in this embodiment, the service boards include process layer interface boards, input acquisition boards, AC conversion boards, relay output boards, DC sampling boards, serial communication boards, inter-board communication backplanes, and other functional boards. This embodiment achieves the overall trusted hardware architecture of the device by setting trusted security control circuits in the main control board, power supply board, and each service board. Specifically, trusted computing chips are set on the main control board and service boards with processors, and trusted identity chips are set on each service board and power supply board. The trusted computing chip can be a TPCM chip, and the trusted identity chips on other boards can be either TPCM chips or encryption chips. To achieve identity authentication, the trusted identity chip pre-stores the encrypted authentication certificate of the current board, and the main control board processor pre-stores the corresponding key.

[0050] In this embodiment, each board is installed in its corresponding backplane slot. Each board has an intraboard bus. After the hardware architecture is improved, the intraboard bus of each board is connected to the power bus, inter-board communication bus and trusted security control bus through the backplane slot interface. The ports in the backplane slot interface used to connect the trusted security control circuit of the service board to the trusted security control bus include the in-position status detection port.

[0051] The main control board can determine the presence status of each service board by detecting the signal at the presence status detection port, and then authenticate the presence of each service board. There are several ways to implement presence status detection, such as: having the service board provide a high or low level to the corresponding signal line in the slot, with the main control board detecting this level; or measuring the voltage of the slot board's detection circuit online (the voltage generated varies depending on the resistance value of the detection resistor connected to each slot); or actively emitting a specific signal after the board is inserted.

[0052] In this embodiment, the trusted security control bus powers on along with the substation automation device, enabling the device to perform security and trust measurements and board authentication immediately upon power-up. The trusted security control circuit of the main control board can be powered by the trusted security control bus, while other circuits can be powered by the power supply board. Alternatively, all circuits on the main control board can be powered by the power supply board by default, but the connection between the processor and other circuits on the main control board and the power bus needs to be controlled by the trusted security control circuit, thus facilitating powering on the processor only after security measurements are performed. This ensures that the trusted security control circuit of the main control board can start operating immediately upon device power-up, and the trusted security control circuits of the service boards can also start operating.

[0053] refer to Figure 2 As shown, the working process of the trusted hardware architecture of the substation automation device in this embodiment involves the following contents.

[0054] After the device is powered on, the main control board is powered on, but only the trusted security control circuit is powered on by default; other circuits, such as the processor, are not powered on. At this time, the trusted computing chip in the trusted security control circuit of the main control board performs a trust measurement on the processor's boot program. If the trust measurement passes, it controls the other circuits in the main control board, including the processor, to be powered on.

[0055] After the main control board processor is powered on, the trusted computing chip performs trust measurements on the driver program, trusted control program, main control board business application and business board application in the processor. If any measurement fails, the device fails to start, stops running and outputs an alarm; otherwise, the device continues to run.

[0056] After all the trust metrics of the main control board processor program pass, the main control board obtains the encrypted authentication certificate pre-stored in the trusted identity chip on the power board through the trusted security control bus for decryption and authentication. If the authentication is successful, the identity authentication of each service board will continue to be performed in sequence according to the card slot position; otherwise, the device will fail to start.

[0057] The authentication process for the business board includes: obtaining the encrypted authentication certificate pre-stored in the trusted identity chip of the board; decrypting the obtained encrypted authentication certificate and verifying the identity using the pre-stored key; if the decryption is successful and the identity verification is passed, the authentication of the corresponding board is successful.

[0058] The power supply board includes a power control unit. After the main control board successfully authenticates any service board, it sends a control command to the power supply board to power on the corresponding service board. Upon receiving the control command, the power supply board controls the power supply to be transmitted to the corresponding service board via the power bus through the power control unit. If any service board fails authentication, the device fails to start, the main control board stops the device and outputs an alarm.

[0059] After the service board completes identity authentication and power-on, it obtains the corresponding trusted service program with passed metrics from the main control board through the trusted security control bus and loads and runs it.

[0060] For service boards with their own processors, the trusted security control circuit of the service board also includes a trusted computing chip. This trusted computing chip performs a security measurement on the boot program of the service board's processor, and after the measurement is passed, controls the other circuits of the service board to connect to the power bus and be powered on. After the service board's processor is powered on, it runs the measured boot program and requests the corresponding measured service program from the main control board's processor through the trusted security control bus, then loads and runs the service program. If the service board has a service relationship with other service boards that requires data interaction, the service board's processor needs to authenticate with the service boards with which it has a service relationship after powering on. The specific process is the same as the authentication principle of the main control board for service boards.

[0061] After the service board is running normally, the interaction and communication between different services are carried out through the inter-board secure communication bus on the backplane. The encryption of the communication link is achieved by the hardware communication chip after the main control board and the service board have negotiated the security.

[0062] As can be seen from the above embodiments, the present invention realizes the hardware foundation for the self-security immunity of substation automation devices, enables trusted identity hardware identification of substation automation devices and boards, and enhances the intrinsic security proactive immunity capability of substation automation devices.

[0063] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.

Claims

1. A trusted hardware device for substation automation, comprising a main control board, a power supply board, and multiple service boards, characterized in that, It also includes a power bus, an inter-board communication bus, and a trusted security control bus; The main control board and each business board are also equipped with a trusted security control circuit; The main control board and each service board transmit service data through an inter-board communication bus. The main control board includes a processor, and the trusted security control circuit in the main control board includes a trusted computing chip. The trusted security control circuit of each service board includes a trusted identity chip. In each service board, the trusted security control circuit is powered by the trusted security control bus, while other circuits are powered by the power board through the power bus. In the main control board, the trusted security control circuit controls the power supply of other circuits. The processor interacts with the trusted identity chip of other boards through the trusted security control bus to obtain identity authentication data to authenticate the corresponding boards. Based on the identity authentication result, it sends a power control signal to the power board. The power board is configured to respond to the received power control signal and provide working power to other circuits in the service boards that have passed identity authentication, except for the trusted security control circuit. Once powered on, the service board retrieves the corresponding trusted service program from the main control board and loads and runs it. The power supply board also includes a trusted identity chip, which communicates with the processor of the main control board via a trusted security control bus. The processor of the main control board is also configured to: after power-on, obtain the encrypted authentication certificate pre-stored in the trusted identity chip on the power board for decryption and authentication; if the authentication is successful, perform identity authentication on each service board; otherwise, the device fails to start. The service board also includes a processor, and the trusted security control circuit of the service board also includes a trusted computing chip. The trusted computing chip is used to perform a security measurement on the boot program of the service board processor, and after the measurement is passed, to control the other circuits of the service board to be connected to the power bus and powered on. After the processor of the service board is powered on, it runs the boot program that has passed the measurement and requests the corresponding service program that has passed the measurement from the processor of the main control board through the secure and trusted control bus, and then loads and runs the service program.

2. The trusted hardware device for substation automation according to claim 1, characterized in that, Each board is installed in its corresponding backplane slot. Each board has an internal bus, and the internal bus of each board is connected to the power bus, the inter-board communication bus and the trusted security control bus through the backplane slot interface. The ports in the backplane card slot interface used to connect the trusted security control circuit of the service board to the trusted security control bus include the in-place status detection port.

3. The trusted hardware device for substation automation according to claim 1, characterized in that, The trusted security control circuit of the main control board is powered by the trusted security control bus, while other circuits are powered by the power supply board. The trusted security control bus is powered on when the substation automation device is powered on. Alternatively, all circuits on the main control board are powered by the power supply board, and the trusted security control circuit and trusted security control bus of the main control board are powered on along with the substation automation equipment.

4. The trusted hardware device for substation automation according to claim 1, characterized in that, In the trusted security control circuit of the main control board, the trusted computing chip is configured as follows: During power-on operation, a trust measurement is performed on the boot program of the main control board processor. If the trust measurement passes, the other circuits of the main control board are powered on. After the processor is powered on, the trusted computing chip performs trust measurements on the driver program, trusted control program, main control board application program and application program in the processor. If any measurement fails, the device fails to start, stops running and outputs an alarm; otherwise, the device continues to run.

5. The trusted hardware device for substation automation according to claim 4, characterized in that, The process of the power-on completed service board obtaining the corresponding trusted service program from the main control board and loading and running it is as follows: the processor of the main control board sends the measured service board application to the corresponding service board that has passed identity authentication through the trusted security control bus.

6. The trusted hardware device for substation automation according to claim 1, characterized in that, The trusted computing chip on the main control board uses a TPCM chip, while the trusted identity chips on other boards use either TPCM chips or encryption chips. The trusted identity chip pre-stores the encryption authentication certificate of the host board, and the corresponding key is pre-stored in the main control board processor. The service board processor interacts with the trusted identity chips of other boards through a trusted security control bus to obtain identity authentication data for authenticating the corresponding boards, including: Obtain the encrypted authentication certificate pre-stored in the trusted identity chip of the board; The pre-stored key is used to decrypt and authenticate the obtained encrypted certificate. If the decryption is successful and the authentication is passed, the authentication of the corresponding board is successful.

7. The trusted hardware device for substation automation according to claim 1, characterized in that, The power board includes a power control unit. After the main control board authenticates any service board, it sends a control command to the power board to control the power supply of the corresponding service board. In response to receiving the control command, the power board controls the power supply to be transmitted to the corresponding service board through the power bus via the power control unit. If any service board fails authentication, the device will fail to start, stop operation, and output an alarm.

8. A trusted control method based on the trusted hardware device of the substation automation device according to any one of claims 1-7, executed by a main control board, characterized in that the method... include: When the device is powered on, the trusted computing chip of the main control board powers on and runs, performing a trusted measurement on the boot program of the main control board processor. If the trusted measurement passes, it controls the other circuits in the main control board, including the processor, to be powered on. After the processor is powered on, the trusted computing chip performs a trust measurement on the driver program, trusted control program, main control board business application and business board application in the processor. If any measurement fails, the device fails to start, stops running and outputs an alarm; otherwise, the device continues to run. After the main control board processor program completes the measurement, the main control board processor obtains the identity authentication information of each service board through the trusted security control bus to perform identity authentication. For any service board, if the identity authentication is successful, the main control board processor sends a power control signal to the power board, so that the power board responds to the power control signal and provides working power to the other circuits in the corresponding service board that has passed identity authentication, except for the trusted security control circuit. The processor of the main control board sends the measured business board application to the corresponding business board that has passed identity authentication through the trusted security control bus, so that the business board can load the corresponding business program and run it.

Citation Information

Patent Citations

  • Credible starting method suitable for service board in VPX device

    CN105930732A

  • Computer motherboard and computer

    CN207051905U