Analysis and processing method of two-protection contradiction of relay protection device based on FMVEA analysis method
The game theory model established by using FMVEA analysis and swarm intelligence algorithm resolves the conflict between functional safety and information security in relay protection devices, optimizes the safety protection scheme, and improves the safety and stability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HARBIN INST OF TECH
- Filing Date
- 2022-11-22
- Publication Date
- 2026-05-08
AI Technical Summary
The lack of effective methods in the existing technology to analyze and address the contradiction between functional safety and information security in relay protection devices may lead to the introduction of new vulnerabilities when deploying unilateral security measures, affecting the stability and security of the system.
A game model of functional safety and information security of relay protection devices is established by adopting the FMVEA analysis method, combined with expert scoring and swarm intelligence algorithm. The contradiction types between safety measures are described by the five-tuple, and the optimal safety protection scheme is obtained by using swarm intelligence algorithm.
It has achieved the analysis and handling of the contradiction between functional safety and information security measures of relay protection devices, screened out the safety protection scheme without contradiction, improved the safety protection capability of the device, and avoided new vulnerabilities caused by unilateral safety measures.
Smart Images

Figure CN115859586B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of functional safety and information security integration, specifically involving a method for analyzing and handling the contradiction between functional safety and information security in relay protection devices based on FMVEA analysis. Background Technology
[0002] As a crucial component of the power system, relay protection devices play a vital role in ensuring the stable operation of the power system. However, with the gradual development of power systems towards intelligence, the information security threats they face are becoming increasingly serious. Many malicious attackers attempt to control or disrupt the operation of the power system by attacking relay protection devices. Relay protection security measures include functional safety measures and information security measures. Functional safety measures ensure the normal and reliable operation of relay protection devices, minimizing the risk of malfunctions or failures to operate due to device inherent limitations. Information security measures reduce the probability of successful intrusion by attackers and prevent attackers or unauthorized personnel from obtaining core system data, thereby reducing the probability of malicious tampering. When functional safety and information security measures are deployed simultaneously in a single device, they can both promote each other and present contradictions. However, current research on functional safety and information security often focuses on one aspect, lacking a method suitable for analyzing and handling the contradictions between the two. Therefore, it is necessary to propose a method for analyzing and handling the contradictions between functional safety and information security in relay protection devices.
[0003] Unilateral information security measures may introduce new functional safety vulnerabilities into the entire system. Furthermore, unilateral functional safety measures may introduce new information security vulnerabilities, and in some cases, even if the information security capabilities of relay protection devices are improved, it may still contradict their functional safety requirements. This demonstrates a contradiction between functional safety and information security measures. However, currently, there are few methods to analyze and resolve this contradiction. Summary of the Invention
[0004] In view of the contradiction between functional safety and information security in relay protection devices, there are currently few methods to analyze and handle the contradiction between the two safety systems. This invention provides a method for analyzing and handling the contradiction between functional safety and information security in relay protection devices based on FMVEA analysis.
[0005] The objective of this invention is achieved through the following technical solution:
[0006] Step 1: Select functional safety measures and information security measures, and evaluate the attributes of the two types of security measures by using expert scoring.
[0007] Step 2: Using the quintuple form, define and describe the types of contradictions between the two security measures;
[0008] Step 3: Use FMVEA analysis to identify the contradictions between the two selected safety measures;
[0009] Step 4: Establish a game model of functional safety measures and information security measures for relay protection devices, and use swarm intelligence algorithms to find the optimal safety protection scheme.
[0010] Compared with the prior art, the present invention has the following advantages:
[0011] This invention analyzes the conflict between functional safety measures and information security measures in relay protection devices, establishes a game model of the conflict between these two measures, and solves the model. Compared to traditional methods that only deploy functional safety measures or only deploy information security measures, which have significant limitations, this method can analyze and handle the conflict between functional safety measures and information security measures in relay protection devices, screen security protection schemes, obtain conflict-free security protection schemes, and improve the security protection capability of relay protection devices. Attached Figure Description
[0012] Figure 1 This is an overall flowchart of the method for analyzing and handling the contradiction between two safety features in a relay protection device based on the FMVEA analysis method of the present invention;
[0013] Figure 2 This is an example of the analysis and handling of the two safety contradictions in the relay protection device of the present invention;
[0014] Figure 3 This is a flowchart illustrating the specific process of the present invention: a method for analyzing and handling the contradictions between two safety features in a relay protection device based on the FMVEA analysis method. Detailed Implementation
[0015] The technical solution of the present invention will be further described below with reference to the accompanying drawings, but it is not limited thereto. Any modifications or equivalent substitutions to the technical solution of the present invention that do not depart from the spirit and scope of the technical solution of the present invention should be covered within the protection scope of the present invention. Specific Implementation Method 1
[0017] This invention provides a method for analyzing and handling the contradiction between two safety features in relay protection devices based on FMVEA analysis, such as... Figure 1 As shown, the method includes the following steps:
[0018] Step 1: Select functional safety measures and information security measures, and evaluate the attributes of the two types of security measures by using expert scoring.
[0019] Step 2: Using the quintuple form, define and describe the types of contradictions between the two security measures;
[0020] Step 3: Use FMVEA analysis to identify the contradictions between the two selected safety measures;
[0021] Step 4: Establish a game model of functional safety measures and information security measures for relay protection devices, and use swarm intelligence algorithms to find the optimal safety protection scheme.
[0022] like Figure 3 As shown, the specific implementation steps are as follows:
[0023] Step S1: Select functional safety measures for the relay protection device according to the international standard IEC 61508;
[0024] Step S2: Select information security measures for the relay protection device according to the international standard IEC 62443;
[0025] Step S3: Using expert scoring, evaluate the security protection capabilities, risk reduction capabilities, consumption of device computing resources, impact on communication real-time performance, and memory usage attributes of functional safety measures and information security measures. The maximum score for each indicator is 5 points, and the minimum score is 0 points. The scores for each indicator are integers, where each score represents the degree of a certain security measure corresponding to the indicator. The higher the score, the more obvious the security measure is considered to have this attribute, and the lower the score, the less obvious the security measure is considered to have this attribute. The expert scoring rules are designed according to conventional experience in this field.
[0026] Step S4: Based on the expert scoring sheet for safety measures, to visualize the types of contradictions, the safety measures are expressed as a quintuple, with the formula:
[0027] Measure=(Object,Sort,Aim,Capacity,Influence)
[0028] In the formula: Object refers to the assets to be protected by functional safety measures and information security measures, including important equipment and / or communication information. Important equipment includes one or more combinations of sampling units, storage units, data processing units, and execution units. Important communication information includes one or two combinations of commands and messages. Sort refers to the type of security measure, i.e., whether the security measure protects from a functional safety perspective or an information security perspective. Aim refers to the protection objective that the security measure aims to achieve for the equipment or communication information. For example, for storage units, the objective is to prevent data tampering in memory; for important communication information such as control commands, the objective is to prevent data from being eavesdropped on, tampered with, or leaked. Capacity represents the protective capability of the security measure. This part comprehensively considers the protective capability of the security measure and its ability to reduce device risk. Influence refers to the impact on the system after taking security measures. This part comprehensively considers the impact of security measures on the real-time performance of device communication, the consumption of device computing resources, and the amount of memory occupied.
[0029] Step S5: Classify the contradictions between functional safety measures and information security measures into repetitive contradictions and conflicting contradictions;
[0030] Step S6: Combining Failure Mode and Effects Analysis (FMVEA) methods, select the type of conflict to be analyzed. If you choose to analyze a repetitive conflict between two safety measures, proceed to step S7; if you choose to analyze a conflicting conflict between two safety measures, proceed to step S10.
[0031] Step S7: Analyze the repetitive contradictions between the two security measures, select the security measure to be analyzed. If functional security measures are selected, proceed to step S8; if information security measures are selected, proceed to step S9.
[0032] Step S8: Using the FMVEA analysis method, traverse the selected functional safety measures to determine the impact of the functional safety measures, potential causes, vulnerabilities and threat factors, and estimate the frequency or probability of failure modes and threat modes occurring within a predetermined time.
[0033] Step S9: Using the FMVEA analysis method, traverse the selected information security measures to determine the impact of the information security measures, potential causes, vulnerabilities and threat factors, and estimate the frequency or probability of failure modes and threat modes occurring within a predetermined time.
[0034] Step S10: Analyze the conflict between the two safety measures. Based on the device resources consumed by the safety measures and the safety protection capabilities achieved, analyze the conflict between the various safety measures using the FMVEA analysis method. The strength of the conflict is relative to the device's own conditions. The more abundant the device's own resources, the less obvious the conflict.
[0035] Step S11: Establish a static game model of functional safety measures and information security measures of relay protection device to describe the process of functional safety measures and information security measures competing for device computing resources;
[0036] Step S12: With the goal of maximizing the respective benefit functions of functional safety measures and information security measures, and with resource allocation as a constraint, use swarm intelligence algorithms to find the optimal security protection scheme.
[0037] Step S13: Perform one iteration on the functional safety measures and information security measures population based on the swarm intelligence algorithm, and select the optimal individual;
[0038] Step S14: Calculate the fitness of the optimal individual for both safety measures, proceed to the second iteration, compare the fitness calculated in the second iteration with that calculated in the previous iteration, and select the optimal safety protection scheme.
[0039] Step S15: Determine whether the maximum number of iterations has been reached. If yes, output the optimal security protection scheme; otherwise, proceed to step S13.
[0040] Example 1:
[0041] For ease of understanding, Figure 2 An example of the method for analyzing and handling the contradiction between two safety features in the relay protection device of the present invention is given.
[0042] like Figure 3 As shown, the specific implementation steps of the method for analyzing and handling the contradiction between two safety features in the relay protection device in this embodiment are as follows:
[0043] Step S1: Select functional safety measures for relay protection devices according to the international standard IEC 61508.
[0044] In this embodiment, the selected functional safety measures include: (1) In order to reduce the possibility of malicious tampering by attackers with important data stored in the device, such as setting values and keys, verification codes such as CRC check codes and Hamming codes are added when storing data; (2) In order to ensure the security of program storage and that the program can run in a stable memory environment, the stack is monitored in real time, and the stack memory usage rate is statistically analyzed in real time to prevent stack overflow events; (3) The program in the device is generally stored in EPROM or FLASH program storage space. In order to prevent attackers and low-privilege personnel from obtaining important data therein, access control is set, such as locking the memory to read-only mode. Once the lock is unlocked, the program will be locked out of the memory. In addition, the data in memory can be deleted immediately. In addition, identity authentication measures can be set up, and different permissions can be assigned to operators in the form of account and password. (4) Sometimes the device will work in an abnormal state. In order to record the changes of relevant electrical quantities before and after the fault, and to provide data support for subsequent analysis of the cause of the fault, the fault recording function safety measure is set up. (5) The line operation status will change with the load. At this time, there will be normal switching operations. The device needs to record this information and upload the data regularly. Therefore, the log recording and uploading function safety measure is set up. (6) In order to ensure that the execution unit receives the command correctly, the additional verification code measure is set up, and the contact signal is fed back to the data processing unit to form a confirmation closed loop.
[0045] Step S2: Select information security measures for relay protection devices in accordance with the international standard IEC 62443.
[0046] In this embodiment, the selected information security measures include: (1) using encryption measures to prevent the theft of key information in the relay protection device. The encryption measures mainly adopt encryption based on the AES algorithm and encryption based on the ECC algorithm; (2) using key-related hash operation message authentication code (HMAC) to verify data integrity and authenticate identity, and to authenticate the visitor to prevent receiving data from illegal nodes; (3) considering the possibility of hash collision, using digital signature to authenticate the received data; (4) considering the length of data exchanged between devices, when the length of the transmitted data exceeds the upper limit of the single transmission length of the communication protocol, the measure of adding a communication sequence number is adopted to split the data and transmit it one by one; (5) adding a communication timestamp to prevent replay attacks; (6) adopting intrusion detection measures to prevent malicious attacks.
[0047] Step S3: Using expert scoring, evaluate the security protection capabilities, risk reduction capabilities, consumption of device computing resources, impact on communication real-time performance, and memory usage attributes of functional safety measures and information security measures. The higher the score, the more obvious the security measure's attribute is considered, and the lower the score, the less obvious the security measure's attribute is considered.
[0048] In this embodiment, the expert evaluation results of functional safety measures are shown in Table 1, and the expert evaluation results of information security measures are shown in Table 2.
[0049] Table 1 Expert Evaluation Results of Functional Safety Measures
[0050]
[0051] Table 2 Expert Evaluation Results of Information Security Measures
[0052]
[0053]
[0054] Step S4: Combining the expert scoring sheets for the two safety measures, to visualize the types of contradictory items, the safety measures are expressed as a quintuple, with the formula:
[0055] Measure=(Object,Sort,Aim,Capacity,Influence).
[0056] Step S5: Classify the contradictions between functional safety measures and information security measures into repetitive contradictions and conflicting contradictions.
[0057] In this embodiment, a repetitive contradiction refers to a situation where the security measures in the system protect the same assets and achieve the same security objectives, which can be represented by a quintuple:
[0058] (Measure1·Object=Measure2·Object,Measure1·Aim=Measure2·Aim)
[0059] In this embodiment, conflict-type contradictions are further divided into conflicts of the same type of security measures and conflicts of different types of security measures. Conflicts of the same type of security measures refer to situations where the types of security measures are consistent, but the desired effects they achieve conflict. This can be represented by a quintuple:
[0060] (Measure1·Sort=Measure2·Sort, Measure1·Aim≠Measure2·Aim)
[0061] In this embodiment, conflict between different types of security measures refers to situations where security measures of different types affect each other during their execution, which can be represented by a quintuple:
[0062] (Measure1·Sort≠Measure2·Sort, Measure1·Aim≠Measure2·A im).
[0063] Step S6: Combining Failure Mode and Effects Analysis (FMVEA) methods, select the type of conflict to be analyzed. If you choose to analyze a repetitive conflict between two safety measures, proceed to step S7; if you choose to analyze a conflicting conflict between two safety measures, proceed to step S10.
[0064] Step S7: Analyze the repetitive contradictions between the two security measures, select the security measure to be analyzed. If functional security measures are selected, proceed to step S8; if information security measures are selected, proceed to step S9.
[0065] Step S8: Using the FMVEA analysis method, traverse the selected functional safety measures to determine the impact of the functional safety measures, potential causes, vulnerabilities and threat factors, and estimate the frequency or probability of failure modes and threat modes occurring within a predetermined time.
[0066] In this embodiment, the two additional checksum security measures have different targets: one applies to data storage and the other to data transmission. Therefore, there is no overlap or contradiction between them. There is some functional overlap between memory protection and data storage additional checksum measures. If memory protection is selected, the probability of an attacker successfully tampering with the data is low, so there is no need to select the data storage additional checksum measure, which can save the device's computing resources. However, considering that the device's setting value will change with the line's operating status, this means that memory protection is not always enabled, and attackers still have a chance to successfully tamper with the data inside the device. Therefore, this contradiction is not addressed, and both security measures are retained. There is no overlap or contradiction among the remaining functional security measures.
[0067] Step S9: Using the FMVEA analysis method, traverse the selected information security measures to determine the impact of the information security measures, potential causes, vulnerabilities and threat factors, and estimate the frequency or probability of failure modes and threat modes occurring within a predetermined time.
[0068] In this embodiment, there are overlapping contradictions between AES and ECC encryption measures; overlapping contradictions between communication data integrity verification and HMAC data integrity verification; and partial overlapping contradictions between digital signature and HMAC data integrity verification. Typically, devices use only one encryption algorithm. AES encryption offers both security and real-time performance compared to ECC encryption, while ECC encryption improves security compared to AES encryption. ECC is suitable for applications with lower real-time requirements but higher security requirements. For relay protection devices, ECC encryption can be used to encrypt and store the device's settings. Both communication data integrity verification and HMAC data integrity verification aim to ensure the integrity of communication messages. However, HMAC data integrity verification has an additional function: the generation of the HMAC authentication code is related to the input key, thus it serves both as a data integrity verification function and a simple authentication function. Furthermore, most communication protocols include data integrity verification, so a separate setting is unnecessary. An ideal hash function is collision-free, but this is difficult to achieve in actual algorithm design. Considering this characteristic, digital signature algorithms improve the reliability of authentication based on hash functions.
[0069] Step S10: Analyze the conflict-type contradictions between safety measures. Based on the device resources consumed by the safety measures and the safety protection capabilities achieved, analyze the conflict-type contradictions between the various safety measures using the FMVEA analysis method.
[0070] In this embodiment, the functional safety measures are independent of each other and do not interfere with each other. However, among the information security measures, encryption and HMAC data integrity verification are contradictory. Encryption measures reduce communication real-time performance to improve security, while HMAC data integrity verification is designed to improve communication real-time performance; therefore, there is a certain conflict between the two. Information security measures consume significant device computing resources during execution. For example, the ECC encryption algorithm involves complex mathematical calculations, requiring considerable computing resources, which can affect the normal execution of functional safety measures. Figure 2 The diagram illustrates the conflict between the aforementioned functional safety measures and information security measures.
[0071] Step S11: Establish a static game model of functional safety measures and information security measures of relay protection device to describe the process of functional safety measures and information security measures competing for device computing resources.
[0072] In this embodiment, the game model between functional safety measures and information security measures can be represented as a triple, with the formula:
[0073] GM = (RO, CO, PR)
[0074] Among them: (1)RO=(RO A ,RO E ) represents the objects participating in the game process, where: RO A For functional safety measures, RO E Information security measures;
[0075] (2) CO = (COA, COE) represents the specific security protection measures of each of the two participating players, where: COA = {COA1, COA2, ..., COA} j} represents the optional functional safety protection measures combination for relay protection devices, where COE = {COE1, COE2, ..., COE} l} represents a combination of optional information security protection measures for relay protection devices;
[0076] (3) PR = (PR A ,PR E Let PR be the payoff function for each of the two players in the game. A For the benefit function of deploying functional safety measures, PR E This refers to the payoff function for deploying information security measures. In the game model between functional safety measures and information security measures, the value of the payoff function represents the magnitude by which various security measures improve the relative safety protection capability of the relay protection device.
[0077] Step S12: With the goal of maximizing the respective benefit functions of functional safety measures and information security measures, and with resource allocation as a constraint, use swarm intelligence algorithms to find the optimal security protection scheme.
[0078] In this embodiment, the profit function is:
[0079]
[0080] In the formula: This represents the sum of the ability to improve the safety protection capability and reduce the risk of relay protection devices after deploying functional safety measures. This represents the sum of the computational resources consumed by the relay protection device and the impact on the real-time performance of communication when deploying functional safety measures. This represents the sum of the ability to improve the security protection capabilities and reduce the risks of relay protection devices after deploying information security measures. This represents the sum of the computational resources consumed by relay protection devices and the impact on the real-time performance of communications when deploying information security measures.
[0081] In this embodiment, the optimal resource allocation strategy and Must meet:
[0082]
[0083] In the formula: This represents the sum of the ability to improve the safety protection capability and reduce the risk of relay protection devices under the optimal allocation strategy. This represents the sum of the computational resources consumed by the relay protection device and the impact on communication real-time performance under the optimal allocation strategy. This represents the sum of the ability to improve the safety protection capability and reduce the risk of relay protection devices under the optimal allocation strategy. This represents the sum of the computational resources consumed by the relay protection device and the impact on communication real-time performance under the optimal allocation strategy.
[0084] Step S13: Based on the swarm intelligence algorithm, perform an iteration on the functional safety measures and information security measures population, and select the optimal individual.
[0085] Step S14: Calculate the fitness of the optimal individual for both safety measures, and proceed to the second iteration. Compare the fitness calculated in the second iteration with that calculated in the previous iteration to select the optimal safety protection scheme.
[0086] Step S15: Determine whether the maximum number of iterations has been reached. If so, output the optimal security protection scheme; otherwise, proceed to step S13.
[0087] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
Claims
1. A method for analyzing and handling the contradiction between two safety features in relay protection devices based on FMVEA analysis, characterized in that, The method includes the following steps: Step 1: Select functional safety measures and information security measures, and evaluate the attributes of the two types of security measures by using expert scoring. Step 2: Using the quintuple form, define and describe the types of contradictions between two security measures; the formula for calculating a security measure as a quintuple is: ; In the formula, The assets that functional safety measures and information security measures are intended to protect; This refers to the type of security measure, specifically whether the security measure provides protection from the perspective of functional safety or information security. This refers to the protection objectives that security measures are intended to achieve for assets; Indicates the protective capability of safety measures; This indicates the impact of the security measures on the system after they were implemented. Step 3: Use FMVEA analysis to find the contradiction between the two selected security measures; combine Failure Mode Vulnerability and FMVEA impact analysis to select the type of contradiction to be analyzed. (1) If you choose to analyze the repetitive contradiction between the two security measures, first select the security measures to be analyzed. If you choose functional safety measures, combine FMVEA analysis to traverse the selected functional safety measures, determine the degree of impact, potential causes, vulnerabilities and threat factors of the functional safety measures, and estimate the frequency or probability of failure modes and threat modes within a predetermined time. If you choose information security measures, combine FMVEA analysis to traverse the selected information security measures, determine the degree of impact, potential causes, vulnerabilities and threat factors of the information security measures, and estimate the frequency or probability of failure modes and threat modes within a predetermined time. (2) If you choose to analyze the conflict between the two security measures, combine FMVEA analysis to analyze the conflict between the security measures based on the device resources consumed by the security measures and the security protection capabilities achieved. Step 4: Establish a game model of functional safety measures and information security measures for relay protection devices, and use swarm intelligence algorithms to find the optimal safety protection scheme.
2. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 1, characterized in that: In step one, functional safety measures are selected for the relay protection device according to the international standard IEC 61508; and information security measures are selected for the relay protection device according to the international standard IEC 62443.
3. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 1, characterized in that: In step one, the attributes of functional safety measures and information security measures include security protection capabilities and the ability to reduce device risks, consumption of device computing resources, impact on communication real-time performance, and memory usage. Among each attribute, the higher the score, the more obvious the attribute of the safety measure is considered, and the lower the score, the less obvious the attribute of the safety measure is considered.
4. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 1, characterized in that: In step two, the contradictions between functional safety measures and information security measures are classified and handled into repetitive contradictions and conflicting contradictions.
5. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 1, characterized in that: In step four, with the goal of maximizing the respective benefit functions of functional safety measures and information security measures, and with resource allocation as a constraint, the optimal security protection scheme is obtained using a swarm intelligence algorithm.
6. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 5, characterized in that: The specific steps for finding the optimal security protection scheme using swarm intelligence algorithms are as follows: The population of functional safety measures and information security measures is iterated once using the swarm intelligence algorithm, and the optimal individual is selected. The fitness of the optimal individual of the two safety measures is calculated comprehensively, and the second iteration is performed. The fitness calculated in the second iteration is compared with that of the previous iteration to select the optimal security protection scheme. It is then determined whether the maximum number of iterations has been reached. If so, the optimal security protection scheme is output; otherwise, the process is repeated.
7. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 1, characterized in that: The game theory model is used to describe the process by which functional safety measures and information security measures compete for device computing resources.
8. The method for analyzing and handling the contradiction between two safety features in a relay protection device based on FMVEA analysis as described in claim 1, characterized in that: After security measures are implemented, their impact on the system includes the impact on the real-time performance of device communication, the consumption of device computing resources, and the amount of memory occupied.
Citation Information
Patent Citations
Markov signal game-based moving target defense strategy selection method and equipment
CN110460572A
Optical measurement equipment space target measurement site selection system and method based on optimal observation energy efficiency
CN115270643A