Data Communication System for Distribution Network Protection Based on SM1 National Cryptography Algorithm

Through identity authentication and key authentication of identity library switches, confidential machines and encryption switches based on SM1 national secret algorithm, the problem of limited manufacturer selection and equipment selection is solved, and the data communication security and installation and maintenance convenience of the distribution network protection system are improved.

CN115865329BActive Publication Date: 2025-07-25GUANGDONG POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211479148.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-23
Publication Date
2025-07-25
Estimated Expiration
2042-11-23

AI Technical Summary

Technical Problem

In the existing distribution network protection system, manufacturer selection and equipment selection are limited, which increases the difficulty of deployment, installation and maintenance, and reduces the security of data communication transmission.

Method used

The identity library switch based on the SM1 national secret algorithm, the confidentiality machine and the encryption switch are used to verify the identity authentication protocol request and reply protocol, and the communication blocking state is de-alived, and the identity key authentication is carried out through the SM1 national secret algorithm to ensure the security of service data transmission.

Benefits of technology

It improves the identity authentication security performance of the communication system, reduces the difficulty of deployment, installation and maintenance, enhances the security of data communication transmission, and avoids the adaptation of protection devices and terminals and secondary development work.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865329B_ABST
    Figure CN115865329B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of power data protection, and discloses a data communication system for distribution network protection based on the SM1 national cryptographic algorithm. An identity authentication protocol request is sent to a security machine through an identity library switch, and a reply protocol for responding to the identity authentication protocol request from the security machine is received. It is verified whether the reply protocol is correct. If the verification of the reply protocol is correct, the communication blocking states between the external distribution network protection device and the encryption switch are respectively released, so as to obtain the service data in the external distribution network protection device. An identity key authentication is also performed with the encryption switch through the SM1 national cryptographic algorithm. If the authentication is successful, the service data is forwarded to the encryption switch, and the MAC of the protection terminal is bound through the encryption switch, excluding the possibility of illegal devices accessing the authenticated encryption switch, thereby improving the identity authentication security performance of the communication system, reducing the difficulty of deployment, installation and maintenance, and at the same time, improving the security of data communication transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power data protection, and in particular to a data communication system for distribution network protection based on the SM1 national secret algorithm. Background Art

[0002] At present, due to the large number of cascade switches in the distribution network, the traditional overcurrent, distance and other protection methods are adopted, and the protection setting coordination is very difficult, the protection action selectivity is poor, and the action time is long. The existing distribution network protection system uses Ethernet transmission for data transmission, and the control cannot be faster and more accurate. The distribution network site-based fast protection system is a distribution network protection system created to solve the above problems.

[0003] The existing method is to couple identity authentication with protection services, and the communication system only serves as a channel for data transmission. Since identity authentication is too closely bound to the services, different manufacturers, different devices of the same manufacturer, and different software versions of the same device cannot complete identity authentication normally, and secondary development work with the confidentiality machine is required before they can be used. This leads to certain restrictions on the choice of manufacturers and equipment, increases the difficulty of deployment, installation and maintenance, and at the same time, reduces the security of data communication transmission. Summary of the invention

[0004] The present invention provides a data communication system for distribution network protection based on the SM1 national secret algorithm, which solves the technical problem that the selection of manufacturers and equipment is subject to certain restrictions, the difficulty of deployment, installation and maintenance is increased, and at the same time, the security of data communication transmission is reduced.

[0005] In view of this, the first aspect of the present invention provides a data communication system for distribution network protection based on the SM1 national encryption algorithm, comprising: an identity library switch, a confidentiality machine and a plurality of encryption switches;

[0006] The identity database switch is respectively connected to the security machine, the encryption switch and an external power distribution network protection device for communication;

[0007] The identity database switch is used to initiate an identity authentication protocol request to the security machine, receive a reply protocol from the security machine in response to the identity authentication protocol request, and verify whether the reply protocol is correct. If the reply protocol is verified to be correct, the communication blocking state between it and the external distribution network protection device and the encryption switch is released, and the service data in the external distribution network protection device is obtained. It is also used to perform identity key authentication with the encryption switch through the SM1 national secret algorithm. If the authentication is successful, the service data is forwarded to the encryption switch;

[0008] The security machine is used to send a reply protocol in response to the identity authentication protocol request to the identity database switch;

[0009] The encryption switch is used to forward the service data to the protection terminal with a locked MAC address after receiving the service data forwarded by the identity database switch.

[0010] Optionally, the identity database switch includes a first network side interface, a first service interface, a confidentiality machine interface, a confidentiality protocol component, and a first data blocking / forwarding component;

[0011] The first network side interface is communicatively connected with other switches;

[0012] The first service interface is communicatively connected with an external protection device and other Ethernet devices;

[0013] The security machine interface is in communication connection with the security machine;

[0014] The confidentiality protocol component is used to initiate an identity authentication protocol request to the confidentiality machine, receive a reply protocol from the confidentiality machine in response to the identity authentication protocol request, and match the reply protocol in a preset confidentiality machine authentication protocol library. If the match is successful, the reply protocol is determined to be correct, and an instruction to release the communication blocking state is sent to the first data blocking / forwarding component; it is also used to obtain the identity library information sent by the confidentiality machine, and is also used to receive the identity key encrypted by the SM1 national secret algorithm sent by the encryption switch, match the identity key with the identity library information, and if the match is successful, send an identity authentication confirmation code to the corresponding encryption switch;

[0015] The first data blocking / forwarding component is used to control the communication status of the first service interface and the first network side interface to switch to a communication blocking state or release the communication blocking state.

[0016] Optionally, the confidentiality protocol component is used to obtain the source switch ID of the encryption switch, and is also used to send a preset switch ID table and the source switch ID to the first data blocking / forwarding component, wherein the preset switch ID table includes the switch ID that has been authenticated;

[0017] The first data blocking / forwarding component is used to receive the preset switch ID table and the source switch ID sent by the confidentiality protocol component, and is also used to match the source switch ID in the preset switch ID table. If the match is successful, the business data is forwarded to the encryption switch corresponding to the source switch ID. It is also used to encapsulate the source switch ID and the destination switch ID into the forwarded business data. If the match is unsuccessful, the business data is not forwarded to the encryption switch corresponding to the source switch ID, and the business data is discarded.

[0018] Optionally, the non-disclosure protocol component is used to detect the communication state of the interface of the security machine. If the communication state of the interface of the security machine is disconnected, the stored identity database information is cleared and a new identity authentication protocol request is sent to the security machine.

[0019] Optionally, the encryption switch includes a second network side interface, a second service interface, an identity authentication chip, a second data blocking / forwarding component and a MAC locking component;

[0020] The second network side interface is communicatively connected with other switches;

[0021] The second service interface is communicatively connected with the protection terminal and other Ethernet devices;

[0022] The identity authentication chip is used to encrypt the identity information based on the SM1 national secret algorithm to form an identity key, and send the identity key to the identity library switch, and is also used to receive the identity authentication confirmation code sent by the identity library switch, and is also used to send an instruction to release the communication blocking state to the second data blocking / forwarding component after obtaining the identity authentication confirmation code;

[0023] The second data blocking / forwarding component is used to release the communication blocking state of the second service interface of the second network side interface according to the instruction for releasing the communication blocking state sent by the identity authentication chip, and is also used to generate a source switch ID according to the locked MAC address, and send the source switch ID to the identity library switch, and is also used to receive the preset switch ID table sent by the confidentiality protocol component and the service data forwarded by other switches and the corresponding source switch ID and destination switch ID, and is also used to match the source switch ID in the preset switch ID table, and if the match is unsuccessful, the corresponding service data is discarded, and is also used to match the destination switch ID in the preset switch ID table, and if the match is successful, the service data is sent to the MAC locking component, and if the match is unsuccessful, the service data is forwarded to other encryption switches;

[0024] The MAC locking component is used to obtain the communication data packets of the second service interface, identify the MAC address of the protected terminal in the communication data packets, and when the MAC record is in the open state, record the MAC address of the protected terminal in the MAC address table. It is also used to lock the MAC address table when the MAC record is in the locked state. After obtaining the communication data packets of the second service interface, it identifies the source MAC of the communication data packets, matches the source MAC in the locked MAC address table. If the match fails, it discards the corresponding communication data packets. If the match is successful, it forwards the service data to the data blocking / forwarding component. It is also used to send the service data sent by the data blocking / forwarding component to the protected terminal with the MAC address locked.

[0025] As can be seen from the above technical solutions, the present invention has the following advantages:

[0026] The present invention initiates an identity authentication protocol request to the security machine through the identity library switch, receives the reply protocol of the security machine in response to the identity authentication protocol request, and verifies whether the reply protocol is correct. If the verification of the reply protocol is correct, it releases the communication blocking states between the external distribution network protection device and the encryption switch respectively, so as to obtain the service data in the external distribution network protection device. It also performs identity key authentication with the encryption switch through the SM1 national encryption algorithm. If the authentication is successful, it forwards the service data to the encryption switch, binds the MAC of the protected terminal through the encryption switch, eliminates the possibility of illegal devices accessing the authenticated encryption switch, thereby improving the identity authentication security performance of the communication system, and is independent of the service system, avoiding the adaptation and secondary development work of the protection device and the protected terminal for identity authentication, reducing the difficulty of deployment, installation and maintenance. At the same time, it improves the security of data communication transmission. Description of the Drawings

[0027] Figure 1 It is a schematic structural diagram of a data communication system for distribution network protection based on the SM1 national encryption algorithm provided by an embodiment of the present invention;

[0028] Figure 2 It is a schematic structural diagram of the identity library switch provided by an embodiment of the present invention;

[0029] Figure 3 It is a schematic structural diagram of the encryption switch provided by an embodiment of the present invention. Detailed Embodiments

[0030] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0031] For ease of understanding, please refer to Figure 1 , a data communication system for distribution network protection based on the SM1 national cryptography algorithm provided by the present invention includes: an identity library switch 10, a security machine 20, and multiple encryption switches 30;

[0032] The identity library switch 10 is respectively communicatively connected to the security machine 20, the encryption switch 30, and an external distribution network protection device 40;

[0033] Among them, the switches are connected by optical fibers.

[0034] The identity library switch 10 is used to initiate an identity authentication protocol request to the security machine 20, receive the reply protocol of the security machine 20 in response to the identity authentication protocol request, and is also used to verify whether the reply protocol is correct. If the reply protocol is verified to be correct, the communication blocking states between it and the external distribution network protection device 40 and the encryption switch 30 are released respectively. It is also used to obtain the service data in the external distribution network protection device 40, and is also used to perform identity key authentication with the encryption switch 30 through the SM1 national cryptography algorithm. If the authentication is successful, the service data is forwarded to the encryption switch 30;

[0035] The security machine 20 is used to send a reply protocol in response to the identity authentication protocol request to the identity library switch 10;

[0036] It should be noted that in the initial state, except for the interface of the security machine 20, other access ports of the identity library switch 10 are blocked, and the access ports of the encryption switch 30 are blocked. At this time, only the information in the identity authentication process can be transmitted between the identity library switch 10 and the encryption switch 30, and the service data is not transmitted.

[0037] The identity library switch 10 communicates with the security machine 20. The identity authentication switch integrates the authentication protocol of the security machine 20. The security machine 20 sends a reply protocol in response to the identity authentication protocol request to the identity library switch 10. After the protocol is verified correctly, the identity library switch 10 removes the blocking function of the interface with the protection device and normalizes data reception and transmission. Without the protocol verification of the security machine 20, the interface between the identity library switch 10 and the protection device remains blocked.

[0038] After the encrypted switch 30 accesses the network, it transmits the identity secret key to the identity database switch 10 through the built-in SM1 national cryptography algorithm, and finally obtains the identity secret key authentication. If the authentication is successful, the service data is forwarded to the encrypted switch 30.

[0039] The encrypted switch 30 is used to forward the service data to the protected terminal 50 with the MAC address locked after receiving the service data forwarded by the identity database switch 10.

[0040] Among them, the protected terminal can be a distribution network battle area type protection terminal.

[0041] Among them, the encrypted switch 30 only forwards service data to the protected terminal with the MAC address locked, and does not forward service data to the protected terminal with the unlocked MAC address.

[0042] It should be noted that a data communication system for distribution network protection based on the SM1 national cryptography algorithm provided by the present invention initiates an identity authentication protocol request to the security machine through the identity database switch, receives the reply protocol of the security machine in response to the identity authentication protocol request, verifies whether the reply protocol is correct. If the reply protocol is verified to be correct, the communication blocking states between it and the external distribution network protection device and the encrypted switch are released respectively, so as to obtain the service data in the external distribution network protection device. It also performs identity secret key authentication with the encrypted switch through the SM1 national cryptography algorithm. If the authentication is successful, the service data is forwarded to the encrypted switch. By binding the MAC of the protected terminal through the encrypted switch, the possibility of illegal devices accessing the authenticated encrypted switch is excluded, thereby improving the identity authentication security performance of the communication system, and it is independent of the service system, avoiding the adaptation and secondary development work of the protection device and the protected terminal for identity authentication, reducing the difficulty of deployment, installation and maintenance. At the same time, the security of data communication transmission is improved.

[0043] In a specific embodiment, as Figure 2 shown, the identity database switch includes a first network side interface 101, a first service interface 102, a security machine interface 103, a security protocol component 104 and a first data blocking / forwarding component 105;

[0044] The first network side interface 101 is communicatively connected to other switches;

[0045] The first service interface 102 is communicatively connected to the external protection device and other Ethernet devices;

[0046] The security machine interface 103 is communicatively connected to the security machine;

[0047] The confidentiality protocol component 104 is used to initiate an identity authentication protocol request to the confidentiality machine, receive a reply protocol from the confidentiality machine in response to the identity authentication protocol request, and match the reply protocol in a preset confidentiality machine authentication protocol library. If the match is successful, the reply protocol is determined to be correct, and an instruction to release the communication blocking state is sent to the first data blocking / forwarding component; it is also used to obtain the identity library information sent by the confidentiality machine, and is also used to receive the identity key encrypted by the SM1 national secret algorithm sent by the encryption switch, match the identity key with the identity library information, and if the match is successful, send an identity authentication confirmation code to the corresponding encryption switch;

[0048] It should be noted that if the security machine does not reply or the reply protocol is incorrect, the confidentiality protocol component 104 will not perform subsequent work.

[0049] When the confidentiality protocol component 104 obtains the correct protocol response from the confidentiality machine, it also obtains the identity library information preset by the confidentiality machine and stores it.

[0050] Among them, the confidentiality agreement component 104 obtains the identity key encrypted by the SM1 national secret algorithm from the data blocking / forwarding component (entering the network interface), and then calculates and matches it with the stored identity database information. If the match is correct, the identity authentication confirmation code is sent to the corresponding encryption switch. If it does not match, the identity authentication confirmation code is not replied.

[0051] The first data blocking / forwarding component 105 is used to control the communication state of the first service interface 102 and the first network side interface 101 to switch to a communication blocking state or release the communication blocking state.

[0052] The confidentiality protocol component 104 is used to detect the communication state of the secure machine interface 103. If the communication state of the secure machine interface 103 is disconnected, the stored identity database information is cleared and a new identity authentication protocol request is sent to the secure machine.

[0053] In a specific embodiment, the confidentiality protocol component 104 is used to obtain the source switch ID of the encryption switch, and is also used to send a preset switch ID table and a source switch ID to the first data blocking / forwarding component 105, wherein the preset switch ID table includes the switch ID that has been authenticated;

[0054] Among them, when information is transmitted, the data blocking / forwarding component of the encryption switch will add its own encryption switch ID (ID is automatically generated by the switch according to its own MAC address, the switch MAC is unique, and the ID is unique), that is, the source switch ID, and the destination switch ID of the data. When the confidentiality protocol component 104 receives the identity key sent by the encryption switch, it records the source ID information it carries. For the ID with matching identity information, the confidentiality protocol component 104 broadcasts the preset switch ID table to its own data blocking / forwarding component and the data blocking / forwarding components of all encryption switches, and informs the data blocking / forwarding components of all switches of the switch ID that has completed the authentication correctly, and sends it once after completing an authentication process.

[0055] The preset switch ID table includes the IDs of switches that have passed authentication.

[0056] The first data blocking / forwarding component 105 is used to receive the preset switch ID table and the source switch ID sent by the confidentiality protocol component 104, and is also used to match the source switch ID in the preset switch ID table. If the match is successful, the business data is forwarded to the encryption switch corresponding to the source switch ID. It is also used to encapsulate the source switch ID and the destination switch ID into the forwarded business data. If the match is unsuccessful, the business data is not forwarded to the encryption switch corresponding to the source switch ID, and the business data is discarded.

[0057] In a specific embodiment, Figure 3 As shown, the encryption switch includes a second network side interface 301, a second service interface 302, an identity authentication chip 303, a second data blocking / forwarding component 304 and a MAC locking component 305;

[0058] The second network side interface 301 is connected to other switches for communication;

[0059] The second service interface 302 is connected to the protection terminal and other Ethernet devices for communication;

[0060] The identity authentication chip 303 is used to encrypt the identity information based on the SM1 national secret algorithm to form an identity key, send the identity key to the identity database switch, and receive the identity authentication confirmation code sent by the identity database switch. After obtaining the identity authentication confirmation code, it is also used to send an instruction to the second data blocking / forwarding component to release the communication blocking state;

[0061] Among them, the identity authentication chip 303 adopts the model SC1041 chip (National Cryptography Administration Certificate No.: GM001119920201567).

[0062] The second data blocking / forwarding component 304 is used to release the communication blocking state of the second service interface 302 of the second network side interface 301 according to the instruction of releasing the communication blocking state sent by the identity authentication chip 303, and is also used to generate a source switch ID according to the locked MAC address, and send the source switch ID to the identity library switch, and is also used to receive the preset switch ID table sent by the confidentiality protocol component and the service data forwarded by other switches and the corresponding source switch ID and destination switch ID, and is also used to match the source switch ID in the preset switch ID table, if the match is unsuccessful, the corresponding service data is discarded, and is also used to match the destination switch ID in the preset switch ID table, if the match is successful, the service data is sent to the MAC locking component, and if the match is unsuccessful, the service data is forwarded to other encryption switches;

[0063] The MAC locking component 305 is used to obtain the communication data message of the second service interface 302, identify the MAC address of the protection terminal in the communication data message, and when the MAC record is in an open state, record the MAC address of the protection terminal in the MAC address table. It is also used to lock the MAC address table when the MAC record is in a locked state, and then obtain the communication data message of the second service interface 302, identify the message source MAC in the communication data message, and match the message source MAC in the locked MAC address table. If the match fails, the corresponding communication data message is discarded. If the match is successful, the service data is forwarded to the data blocking / forwarding component. It is also used to send the service data sent by the data blocking / forwarding component to the protection terminal with a locked MAC address.

[0064] Among them, when the MAC locking component 305 receives the communication data message of the service interface, it automatically learns the source MAC address of the communication data message (the MAC of the protection terminal), records it in the MAC address table, and adds it after learning the new MAC. The MAC locking component 305 is initially in an open state, does not process the data, and forwards it normally. After the MAC locking component 305 is modified to the locked state, the MAC address table stops learning new MACs, and the MAC address table is fixed to the table items before being unlocked. After the MAC locking component 305 is modified to the locked state, after receiving data from the service interface, it first compares the source MAC of the message with the locked MAC table. If the source MAC of the message is not in the locked MAC table, it is considered to be illegal access device data, and the message is discarded and not forwarded to the data blocking / forwarding component. If the source MAC of the message is in the locked MAC table, it is considered to be correct device data and forwarded to the data blocking / forwarding component for subsequent processes.

[0065] At the same time, the message transmitted from the data blocking / forwarding component to the MAC locking component 305 is not compared with the MAC table and is forwarded downward normally.

[0066] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.

[0067] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0068] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0069] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.

Claims

1. A data communication system for distribution network protection based on the SM1 national cryptographic algorithm, characterized in that, include: Identity vault switches, privacy machines and multiple encryption switches; The identity database switch is respectively connected to the security machine, the encryption switch and an external power distribution network protection device for communication; The identity database switch is used to initiate an identity authentication protocol request to the security machine, receive a reply protocol from the security machine in response to the identity authentication protocol request, and verify whether the reply protocol is correct. If the reply protocol is verified to be correct, the communication blocking state between it and the external distribution network protection device and the encryption switch is released, and the service data in the external distribution network protection device is obtained. It is also used to perform identity key authentication with the encryption switch through the SM1 national secret algorithm. If the authentication is successful, the service data is forwarded to the encryption switch; The security machine is used to send a reply protocol in response to the identity authentication protocol request to the identity database switch; The encryption switch is used to forward the service data to the protection terminal with a locked MAC address after receiving the service data forwarded by the identity database switch.

2. The data communication system for distribution network protection based on the SM1 national cryptographic algorithm according to claim 1, wherein The identity database switch includes a first network side interface, a first service interface, a confidentiality machine interface, a confidentiality protocol component, and a first data blocking / forwarding component; The first network side interface is communicatively connected with other switches; The first service interface is communicatively connected with an external protection device and other Ethernet devices; The security machine interface is in communication connection with the security machine; The confidentiality protocol component is used to initiate an identity authentication protocol request to the confidentiality machine, receive a reply protocol from the confidentiality machine in response to the identity authentication protocol request, and match the reply protocol in a preset confidentiality machine authentication protocol library. If the match is successful, the reply protocol is determined to be correct, and an instruction to release the communication blocking state is sent to the first data blocking / forwarding component; it is also used to obtain the identity library information sent by the confidentiality machine, and is also used to receive the identity key encrypted by the SM1 national secret algorithm sent by the encryption switch, match the identity key with the identity library information, and if the match is successful, send an identity authentication confirmation code to the corresponding encryption switch; The first data blocking / forwarding component is used to control the communication status of the first service interface and the first network side interface to switch to a communication blocking state or release the communication blocking state.

3. The data communication system for distribution network protection based on the SM1 national cryptographic algorithm according to claim 2, wherein The confidentiality agreement component is used to obtain the source switch ID of the encryption switch, and is also used to send a preset switch ID table and the source switch ID to the first data blocking / forwarding component, wherein the preset switch ID table includes the switch ID that has been authenticated; The first data blocking / forwarding component is used to receive the preset switch ID table and the source switch ID sent by the confidentiality protocol component, and is also used to match the source switch ID in the preset switch ID table. If the match is successful, the business data is forwarded to the encryption switch corresponding to the source switch ID. It is also used to encapsulate the source switch ID and the destination switch ID into the forwarded business data. If the match is unsuccessful, the business data is not forwarded to the encryption switch corresponding to the source switch ID, and the business data is discarded.

4. The data communication system for distribution network protection based on the SM1 national cryptographic algorithm according to claim 2, wherein The non-disclosure protocol component is used to detect the communication state of the interface of the security machine. If the communication state of the interface of the security machine is disconnected, the stored identity database information is cleared and a new identity authentication protocol request is sent to the security machine.

5. The data communication system for distribution network protection based on the SM1 national cryptographic algorithm according to claim 3, wherein The encryption switch includes a second network side interface, a second service interface, an identity authentication chip, a second data blocking / forwarding component and a MAC locking component; The second network side interface is communicatively connected with other switches; The second service interface is communicatively connected with the protection terminal and other Ethernet devices; The identity authentication chip is used to encrypt the identity information based on the SM1 national secret algorithm to form an identity key, and send the identity key to the identity library switch, and is also used to receive the identity authentication confirmation code sent by the identity library switch, and is also used to send an instruction to release the communication blocking state to the second data blocking / forwarding component after obtaining the identity authentication confirmation code; The second data blocking / forwarding component is used to release the communication blocking state of the second service interface of the second network side interface according to the instruction for releasing the communication blocking state sent by the identity authentication chip, and is also used to generate a source switch ID according to the locked MAC address, and send the source switch ID to the identity library switch, and is also used to receive the preset switch ID table sent by the confidentiality protocol component and the service data forwarded by other switches and the corresponding source switch ID and destination switch ID, and is also used to match the source switch ID in the preset switch ID table, and if the match is unsuccessful, the corresponding service data is discarded, and is also used to match the destination switch ID in the preset switch ID table, and if the match is successful, the service data is sent to the MAC locking component, and if the match is unsuccessful, the service data is forwarded to other encryption switches; The MAC locking component is used to obtain the communication data packets of the second service interface, identify the MAC address of the protected terminal in the communication data packets, and record the MAC address of the protected terminal in the MAC address table when the MAC record is in the open state. It is also used to lock the MAC address table when the MAC record is in the locked state, then obtain the communication data packets of the second service interface, identify the source MAC of the communication data packets, match the source MAC in the locked MAC address table. If the match fails, the corresponding communication data packets are discarded. If the match is successful, the service data is forwarded to the data blocking / forwarding component. It is also used to send the service data sent by the data blocking / forwarding component to the protected terminal with the MAC address locked.

Citation Information

Patent Citations

  • Power distribution terminal security access platform and implementation method thereof

    CN107018134A

  • Security protection performance evaluation method applicable to power wireless private network terminal

    CN107124715A