Network Security Early Warning and Protection System and Method Based on Electric Power Information Mimicry Technology

By establishing an intranet simulation system and a virtual database in the power information system, and using the appearance virtual information packet and the intranet one-way private key for encrypted communication, the problem of security protection in the existing technology cannot be carried out in the case of unknown access objects, and efficient confidentiality and leakage prevention of power information are achieved.

CN115883122BActive Publication Date: 2025-06-20STATE GRID LIAONING ELECTRIC POWER CO LTD +4
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210705523.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-21
Publication Date
2025-06-20
Estimated Expiration
2042-06-21

AI Technical Summary

Technical Problem

The prior art is difficult to protect security when the system does not know whether the access object is an attack object, resulting in the information data in the power information system being easily leaked.

Method used

The network security early warning and protection system based on power information mimicry technology is adopted. By establishing an intranet simulation system and an intranet virtual database in the power information intranet system, the appearance virtual information packet is used to simulate false encrypted power information data packets, and encrypted communication is carried out through the intranet unidirectional private key and one-way encryption channel to prevent the data in the power information database from being directly acquired.

Benefits of technology

It effectively increases the confidentiality mechanism of power information, improves the effect of power information to prevent leakage, and promptly intercept potential attacks through the intranet early warning system to ensure the security of the power information system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883122B_ABST
    Figure CN115883122B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security early warning and protection system and method based on power information mimicry technology. The system includes an access entrance end, an external power information network system, and an internal power information network system. The internal power information network system includes an internal network simulation system. There is an internal network channel permission between the external power information network system and the internal network simulation system. By establishing an internal network simulation system and an internal network virtual database in the internal power information network system, false encrypted power information data packets are simulated using appearance virtual information packets to prevent the direct acquisition of power information data in the power information database. The design of the internal network one-way encryption channel module can further protect the confidentiality of the power information database when the appearance virtual information packets are obtained without encryption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power grid information communication security, and particularly relates to a network security early warning and protection system and method based on power information mimicry technology. Background Art

[0002] Power information involves various information secrets. It is necessary to carry out network security protection on power information to avoid malicious attacks and leakage of power information, so as to ensure the network security of power information. The power information management system includes an external network and an internal network of power information, and network security protection systems are provided in both the external network and the internal network of power information.

[0003] Although the protection function of the existing network security protection system is very high, when the network security protection system is breached, the information data inside the power information system will be directly exposed. At this time, the confidentiality mechanism of power information is in the weakest state, and there is a high risk of power information leakage. The power information database in the power information system lacks an information confidentiality mechanism, which is likely to cause power information leakage and there is a risk of network security.

[0004] Prior Art 1 (CN112398876A) "A Network Security Early Warning System Based on Adaptive Mimicry Technology" includes: a simulation proxy host, a real host, a main server, a simulation server, and a traffic monitoring unit. A number of real hosts are connected to the main server to form an internal network. The simulation proxy host is used to simulate the operation of the real host. The simulation server is used to simulate the operation of the main server. The traffic monitoring unit and a number of the simulation proxy hosts are respectively connected to the simulation server to form an external network that simulates the operation of the internal network. The external network is connected to the Internet, and encrypted communication can be carried out between the main server and the simulation server. The traffic monitoring unit and a number of the simulation proxy hosts are respectively connected to the simulation server to form an external network that simulates the operation of the internal network. The external network is connected to the Internet, and attack behaviors are filtered through the external network, which can greatly improve the security of the internal network and prevent the internal network from being attacked. The deficiency of Prior Art Document 1 is that the simulation internal network and external network established in Prior Art Document 1 protect the system on the premise of knowing the attack object, and it is impossible to achieve security protection of the system when the system does not know whether the access object is an attack object; when the system is in a normal state, the internal network simulation system operates normally, and both normal access customers and access customers with attack purposes need to access through the internal network simulation system. At this time, the apparent virtual information packet is the real data packet that needs to be decrypted for normal access customers, and for access customers with attack purposes, the apparent virtual information packet is a false empty data packet. Summary of the Invention

[0005] To address the deficiencies in the existing technologies, the objective of the present invention is to provide a network security early warning and protection system and method based on power information mimicry technology, which can provide security protection for the system when the system does not know whether the access object is an attack object, and solve the problem of leakage of power information in the power information system database.

[0006] The present invention adopts the following technical solutions.

[0007] On the one hand, the present invention proposes a network security early warning and protection system based on power information mimicry technology, including: an access entrance end, a power information external network system, a power information internal network system. The access entrance end is connected to the power information external network system, and the power external network system is connected to the power information internal network system; among them, the power information internal network system includes an internal network simulation system; a power information database, a representation virtual information packet, an internal network bidirectional encryption channel module, a unidirectional encryption channel module, and an internal network early warning system; among them, the power information database is connected to the representation virtual information packet through the internal network bidirectional encryption channel module and the unidirectional encryption channel module;

[0008] The internal network simulation system is provided with an internal network virtual database, and the internal network virtual database stores the representation virtual information packet.

[0009] An internal network channel permission module and a unidirectional access random channel module are provided between the power information external network system and the internal network simulation system. After the access client is permitted by the internal network channel permission module, it enters the internal network simulation system through the unidirectional access random channel module; when the access client selects an access request target in the internal network simulation system, the internal network virtual database provides the representation virtual information packet, and the representation virtual information packet is an encrypted empty information packet;

[0010] When the access client cannot obtain the representation virtual information packet without the key, the unidirectional encryption channel module is opened between the representation virtual information packet and the power information database, and at the same time, the internal network early warning system is triggered. The internal network early warning system issues an interception instruction to the internal network channel permission module, and the internal network bidirectional encryption channel module between the representation virtual information packet and the power information database is closed;

[0011] When the access client obtains the bidirectional matching key and the internal network unidirectional private key, and at the same time opens the internal network bidirectional encryption channel module and the unidirectional encryption channel module, the access client obtains the power information data in the power information database through the unidirectional access random channel module.

[0012] The power information external network system includes: an access record module, an application access module, an application data information packet, an application data file, and an external network bidirectional encryption channel module;

[0013] The external network bidirectional encryption channel module needs to be opened with a bidirectional matching key.

[0014] The application access module is connected to the application data file through the external network two-way encryption channel module;

[0015] The application data information packet is connected to the application data file through the external network two-way encryption channel module;

[0016] The access record module includes an access record data analysis module, and the access record data analysis module is used to analyze whether the identity information of the accessing customer is abnormal;

[0017] The application access module internally has an application data information packet. The application data information packet is a virtual information packet that simulates the application data file, and the application data information packet is an encrypted information packet;

[0018] When the analysis result of the access record data analysis module is non-abnormal, the accessing customer obtains the application data file through the external network two-way encryption channel module between the application access module and the application data file;

[0019] When the analysis result of the access record data analysis module is abnormal, the accessing customer obtains the application data file through the external network two-way encryption channel module between the application data information packet and the application data file.

[0020] The internal network two-way encryption channel module needs to be opened with a two-way matching key. The two-way matching key is an asymmetric key mastered by the accessing customer and the power information internal network system.

[0021] The one-way encryption channel module needs to be opened with an internal network one-way private key. The internal network one-way private key is a private key unidirectionally mastered by the power internal network system.

[0022] Preferably, an external network firewall is set up between the access entrance end and the power information external network system for network security protection of the power information external network system;

[0023] An internal network firewall is set up between the power system external network system and the power information internal network system for network security protection of the power information internal network system.

[0024] Preferably, an identity information identification and filtering module is set up between the power information external network system and the external network firewall for identifying and filtering the identity information of the accessing customer.

[0025] The access record module is used to record the identity information and access information of the accessing customer.

[0026] The power information external network system further includes an external network early warning system. When the application data information packet is obtained without encryption, the external network early warning system is triggered, and the external network early warning system will send an access shutdown instruction to the access entrance end.

[0027] On the other hand, the present invention provides a network security early warning and protection method based on power information mimic technology.

[0028] When an access customer enters the power information external network system through the access entrance,

[0029] Step 1.1, the external network firewall performs a network security scan on the access customer;

[0030] Step 1.2, the identity information recognition and filtering module recognizes and filters the information of the access customer, and records the identity information into the access record system. The access customer enters the power information external network system;

[0031] Step 1.3, the access record data analysis module in the access record system analyzes whether the identity information of the access customer is abnormal. When the analysis result of the access record data analysis module is non-abnormal, the access customer obtains the application data file through the external network two-way encryption channel module between the application access and the application data file, and opens the external network two-way encryption channel by using the two-way matching key. The access customer obtains the application data file.

[0032] When the analysis result of the access record data analysis module is abnormal, the access customer obtains the application data file through the external network two-way encryption channel module between the application data information packet and the application data file, and opens the external network two-way encryption channel by using the two-way matching key. The application data file will be directly transmitted into the application data information packet. The access customer directly obtains the unencrypted application data information packet. At the same time, it will trigger the external network warning system in the power information external network system. The external network warning system sends an access shutdown instruction to the access entrance, and the access entrance is closed.

[0033] When an access customer enters the power information internal network system through the power information external network system,

[0034] Step 2.1, the internal network firewall performs an information security scan on the access customer. After being permitted by the access internal network channel permission module, the access customer enters the internal network simulation system through the one-way access random channel module;

[0035] Step 2.2, the access customer enters the internal network simulation system and selects the required access request target. The corresponding apparent virtual information packet will be displayed inside the internal network virtual database. At this time, the apparent virtual information packet is an encrypted empty information packet;

[0036] Step 2.3: The accessing customer opens the intranet two-way encryption channel module between the apparent virtual information packet and the power information database using the two-way matching key. The data information in the power information database will be automatically transmitted to the apparent virtual information packet. When the accessing customer does not have the key to obtain the apparent virtual information packet, the apparent virtual information packet is an empty information packet at this time, and the intranet warning system will be triggered. The intranet warning system sends an interception instruction to the intranet channel module to obtain the access target request information of the accessing customer. At the same time, the intranet two-way encryption channel module that requires two-way key matching between the apparent virtual information packet and the power information database is closed;

[0037] Step 2.4: When the accessing customer obtains the power information database through two-way key matching and simultaneously obtains the intranet one-way private key provided by the power information intranet system, the accessing customer obtains the power information data in the power information database through the one-way access random channel.

[0038] The beneficial effects of the present invention are as follows. Compared with the prior art,

[0039] 1. By establishing an intranet simulation system and an intranet virtual database in the power information intranet system, the present invention can use the apparent virtual information packet to simulate a false encrypted power information data packet, thereby preventing the direct acquisition of the power information data in the power information database, increasing the confidentiality mechanism of the power information, improving the effect of preventing power information leakage. At the same time, the design of the intranet one-way private key and its one-way encryption channel can close the intranet two-way encryption channel of the power information database when the apparent virtual information packet is obtained without a password, further protecting the confidentiality of the power information database.

[0040] 2. By using the access record system and the access record data analysis module in cooperation, the present invention can analyze the identity information of the accessing customer and select different channels for obtaining the application data file according to the identity information of the accessing customer. The design of the application data information packet can simulate a false application data information packet, thereby preventing the direct acquisition of the application data information by the accessing customer with a suspicious identity, which is beneficial to encrypt and protect the application data information in the power information extranet system. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 is the flowchart of the power information internal and external network system of the present invention;

[0042] Figure 2 is the flowchart of the security warning protection method for the power information extranet system of the present invention;

[0043] Figure 3 is the flowchart of the security warning protection method for the power information intranet system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0044] The present application will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and cannot be used to limit the protection scope of the present application.

[0045] Embodiment 1.

[0046] A network security early warning and protection system based on power information mimicry technology.

[0047] Please refer to Figures 1 - 3 , a network security early warning and protection system based on power information mimicry technology, including: an access entrance end, a power information external network system, a power information internal network system, the access entrance end is connected to the power information external network system, and the power external network system is connected to the power information internal network system;

[0048] Among them, the power information internal network system includes an internal network simulation system, a power information database, a representation virtual information packet, an internal network two-way encryption channel module, a one-way encryption channel module, and an internal network early warning system; among them, the power information database and the representation virtual information packet are connected through the internal network two-way encryption channel module and the one-way encryption channel module;

[0049] The internal network simulation system is provided with an internal network virtual database, and the internal network virtual database stores the representation virtual information packet.

[0050] An internal network channel permission module and a one-way access random channel module are provided between the power information external network system and the internal network simulation system. After the access customer is permitted by the internal network channel permission module, it enters the internal network simulation system through the one-way access random channel module; when the access customer selects an access request target in the internal network simulation system, the internal network virtual database provides the representation virtual information packet, and the representation virtual information packet is an encrypted empty information packet;

[0051] When the access customer cannot obtain the representation virtual information packet without the key, the one-way encryption channel module is opened between the representation virtual information packet and the power information database, and at the same time, the internal network early warning system is triggered. The internal network early warning system issues an interception instruction to the internal network channel permission module, and the internal network two-way encryption channel module between the representation virtual information packet and the power information database is closed;

[0052] When the access customer obtains the two-way matching key and the internal network one-way private key, and at the same time opens the internal network two-way encryption channel module and the one-way encryption channel module, the access customer obtains the power information data in the power information database through the one-way access random channel module.

[0053] The power information external network system includes: an access record module, an application access module, an application data information packet, an application data file, and an external network two-way encryption channel module;

[0054] The external network two-way encryption channel module needs to be opened with a two-way matching key;

[0055] The application access module is connected to the application data file through the external network two-way encryption channel module;

[0056] The application data information packet is connected to the application data file through the external network two-way encryption channel module;

[0057] The access record module includes an access record data analysis module, which is used to analyze whether the identity information of the accessing customer is abnormal;

[0058] The application access module internally has an application data information packet, which is a virtual information packet simulating the application data file and is an encrypted information packet;

[0059] When the analysis result of the access record data analysis module is normal, the accessing customer obtains the application data file through the external network two-way encryption channel module between the application access module and the application data file;

[0060] When the analysis result of the access record data analysis module is abnormal, the accessing customer obtains the application data file through the external network two-way encryption channel module between the application data information packet and the application data file.

[0061] The internal network two-way encryption channel module needs to be opened with a two-way matching key, and the two-way matching key is an asymmetric key mastered by the accessing customer and the power information internal network system.

[0062] The one-way encryption channel module needs to be opened with an internal network one-way private key, and the internal network one-way private key is a private key unidirectionally mastered by the power internal network system.

[0063] Preferably in this embodiment, an external network firewall is established between the access entrance end and the power information external network system for network security protection of the power information external network system;

[0064] An internal network firewall is provided between the power system external network system and the power information internal network system for network security protection of the power information internal network system.

[0065] Preferably in this embodiment, an identity information identification and filtering module is provided between the power information external network system and the external network firewall for identifying and filtering the identity information of the accessing customer.

[0066] The access record module is used to record the identity information and access information of the accessing customer.

[0067] The power information external network system further includes an external network warning system. When the application data information packet is obtained without encryption, the external network warning system is triggered, and the external network warning system will send an access shutdown instruction to the access entrance end.

[0068] There is an intranet channel permission and a one-way access random channel between the power information external network system and the intranet simulation system. After being permitted by the intranet channel permission, one can enter the intranet simulation system through the one-way access random channel. The one-way access random channel is a one-way random channel that can only be entered or exited, which can reduce the risk scope of network security. At the same time, it is beneficial to prevent the leakage of power information data. The channel of the one-way access random channel leading to the power information external network system is provided with an intranet one-way private key.

[0069] Embodiment 2.

[0070] A network security early warning and protection method based on power information mimicry technology includes the following steps:

[0071] When an access customer enters the power information external network system through the access entrance end,

[0072] When an access customer enters the power information external network system through the access entrance end,

[0073] Step 1.1, the external network firewall performs network security scanning on the access customer;

[0074] Step 1.2, the identity information identification and filtering module identifies and filters the information of the access customer, and records the identity information into the access record system. The access customer enters the power information external network system;

[0075] Step 1.3, the access record data analysis module in the access record system analyzes whether the identity information of the access customer is abnormal. When the analysis result of the access record data analysis module is non-abnormal, the access customer obtains the application data file through the external network two-way encryption channel module between the application access and the application data file, and opens the external network two-way encryption channel by using the two-way matching key. The access customer obtains the application data file.

[0076] When the analysis result of the access record data analysis module is abnormal, the access customer obtains the application data file through the external network two-way encryption channel module between the application data information packet and the application data file, and opens the external network two-way encryption channel by using the two-way matching key. The application data file will be directly transmitted into the application data information packet. The access customer directly obtains the un-decrypted application data information packet, and at the same time, it will trigger the external network early warning system in the power information external network system. The external network early warning system sends an access closing instruction to the access entrance end, and the access entrance end is closed.

[0077] When an access customer enters the power information internal network system through the power information external network system,

[0078] Step 2.1, the internal network firewall performs information security scanning on the access customer, and after being permitted by the access to the internal network channel permission module, the access customer enters the internal network simulation system through the one-way access random channel module;

[0079] Step 2.2, the accessing customer enters the intranet simulation system, selects the target access request needed, and the corresponding apparent virtual information packet will be displayed inside the intranet virtual database. At this time, the apparent virtual information packet is an encrypted empty information packet.

[0080] Step 2.3, the accessing customer opens the intranet two-way encryption channel module between the apparent virtual information packet and the power information database by using the two-way matching key. The data information in the power information database will be automatically transmitted into the apparent virtual information packet. When the accessing customer cannot obtain the apparent virtual information packet without the key, at this time, the apparent virtual information packet is an empty information packet, and at the same time, the intranet warning system will be triggered. The intranet warning system sends an interception instruction to the intranet channel module to obtain the access target request information of the accessing customer. At the same time, the intranet two-way encryption channel module that requires two-way key matching between the apparent virtual information packet and the power information database is closed.

[0081] Step 2.4, when the accessing customer obtains the power information database through two-way key matching and at the same time obtains the intranet one-way private key provided by the power information intranet system, the accessing customer obtains the power information data in the power information database through the one-way access random channel.

[0082] The beneficial effects of the present invention are as follows. Compared with the prior art,

[0083] 1. By establishing an intranet simulation system and an intranet virtual database in the power information intranet system, the present invention can use the apparent virtual information packet to simulate a fake encrypted power information data packet, thereby preventing the direct acquisition of the power information data in the power information database, increasing the confidentiality mechanism of the power information, improving the effect of preventing power information leakage. At the same time, the design of the intranet one-way private key and its one-way encryption channel can close the intranet two-way encryption channel of the power information database when the apparent virtual information packet is obtained without a password, further protecting the confidentiality of the power information database.

[0084] 2. By the combined use of the access record system and the access record data analysis module, the present invention can analyze the identity information of the accessing customer, and according to the identity information of the accessing customer, select different channels for obtaining the application data file. The design of the application data information packet can simulate a fake application data information packet, thereby preventing the application data information packet from being directly obtained by the accessing customer with a suspicious identity, which is beneficial to encrypt and protect the application data information packet in the power information extranet system.

[0085] The applicant of the present invention has made a detailed description and illustration of the embodiments of the present invention in conjunction with the accompanying drawings. However, those skilled in the art should understand that the above embodiments are only the preferred implementation schemes of the present invention, and the detailed description is only to help readers better understand the spirit of the present invention, rather than a limitation on the protection scope of the present invention. On the contrary, any improvement or modification made based on the spirit of the present invention should fall within the protection scope of the present invention.

Claims

1. A network security early warning and protection system based on power information mimicry technology, comprising: Access entrance terminal, external power information network system, internal power information network system. The access entrance terminal is connected to the external power information network system, and the external power network system is connected to the internal power information network system; The internal power information network system includes an internal network simulation system. It is characterized in that The internal power information network system further includes: a power information database, a representation virtual information packet, an internal network bidirectional encryption channel module, a unidirectional encryption channel module, and an internal network warning system. Among them, the power information database is connected to the representation virtual information packet through the internal network bidirectional encryption channel module and the unidirectional encryption channel module; The internal network simulation system is provided with an internal network virtual database, and the internal network virtual database stores the representation virtual information packet. An internal network channel permission module and a unidirectional access random channel module are provided between the external power information network system and the internal network simulation system. After being permitted by the internal network channel permission module, the access client enters the internal network simulation system through the unidirectional access random channel module. When the access client selects an access request target in the internal network simulation system, the internal network virtual database provides the representation virtual information packet, and the representation virtual information packet is an encrypted empty information packet; When the access client fails to obtain the representation virtual information packet without the secret key, the unidirectional encryption channel module is opened between the representation virtual information packet and the power information database, and at the same time, the internal network warning system is triggered. The internal network warning system issues an interception instruction to the internal network channel permission module, and the internal network bidirectional encryption channel module between the representation virtual information packet and the power information database is closed; When the access client obtains the bidirectional matching secret key and the internal network unidirectional private key, and at the same time opens the internal network bidirectional encryption channel module and the unidirectional encryption channel module, the access client obtains the power information data in the power information database through the unidirectional access random channel module.

2. The network security early warning and protection system based on power information mimicry technology according to claim 1, characterized in that: The external power information network system includes: an access record module, an application access module, an application data information packet, an application data file, and an external network bidirectional encryption channel module; The external network bidirectional encryption channel module needs to be opened with a bidirectional matching secret key; The application access module is connected to the application data file through the external network bidirectional encryption channel module; The application data information packet is connected to the application data file through the external network bidirectional encryption channel module; The access record module includes an access record data analysis module, and the access record data analysis module is used to analyze whether the identity information of the access client is abnormal; The application access module internally has an application data information packet. The application data information packet is a virtual information packet simulating the application data file, and the application data information packet is an encrypted information packet; When the analysis result of the access record data analysis module is normal, the access client obtains the application data file through the external network bidirectional encryption channel module between the application access module and the application data file; When the analysis result of the access record data analysis module is abnormal, the access client obtains the application data file through the external network bidirectional encryption channel module between the application data information packet and the application data file.

3. The network security early warning and protection system based on power information mimicry technology according to claim 1, characterized in that: The internal network bidirectional encryption channel module needs to be opened with a bidirectional matching secret key, and the bidirectional matching secret key is an asymmetric secret key mastered by the access client and the internal power information network system.

4. The network security early warning and protection system based on power information mimicry technology according to claim 1, characterized in that: The unidirectional encryption channel module needs to be opened with an internal network unidirectional private key, and the internal network unidirectional private key is a private key unidirectionally mastered by the internal power network system.

5. The network security early warning and protection system based on power information mimicry technology according to claim 4, characterized in that An external network firewall is established between the access entrance end and the power information external network system to provide network security protection for the power information external network system; An internal network firewall is provided between the power system external network system and the power information internal network system to provide network security protection for the power information internal network system.

6. The network security early warning and protection system based on power information mimicry technology according to claim 5, characterized in that: An identity information recognition and filtering module is provided between the power information external network system and the external network firewall to identify and filter the identity information of access customers.

7. The network security early warning and protection system based on power information mimicry technology according to claim 2, characterized in that: The access record module is used to record the identity information and access information of access customers.

8. The network security early warning and protection system based on power information mimicry technology according to claim 2, characterized in that: The power information external network system further includes an external network warning system. When the application data information packet is obtained without encryption, the external network warning system is triggered, and the external network warning system will send an access closing instruction to the access entrance end.

9. The network security early warning and protection method based on the power information mimicry technology is realized by using the network security early warning and protection system based on the power information mimicry technology according to any one of claims 1 to 8, and is characterized in that, It includes the following steps: When an access customer enters the power information external network system through the access entrance end, Step 1.1, the external network firewall performs a network security scan on the access customer; Step 1.2, the identity information recognition and filtering module identifies and filters the information of the access customer, and records the identity information into the access record system. The access customer enters the power information external network system; Step 1.3, the access record data analysis module in the access record system analyzes whether the identity information of the access customer is abnormal. When the analysis result of the access record data analysis module is normal, the access customer obtains the application data file through the external network two-way encryption channel module between the application access and the application data file, and opens the external network two-way encryption channel by using the two-way matching key. The access customer obtains the application data file; When the analysis result of the access record data analysis module is abnormal, the access customer obtains the application data file through the external network two-way encryption channel module between the application data information packet and the application data file, and opens the external network two-way encryption channel by using the two-way matching key. The application data file will be directly transmitted into the application data information packet. The access customer directly obtains the unencrypted application data information packet, and at the same time, the external network warning system in the power information external network system will be triggered. The external network warning system sends an access closing instruction to the access entrance end, and the access entrance end is closed.

10. The network security early warning and protection method based on the power information mimicry technology according to claim 9 is characterized in that, The method further includes the following steps: When an access customer enters the power information internal network system through the power information external network system, Step 2.1, the internal network firewall performs an information security scan on the access customer. After being permitted by the access internal network channel permission module, the access customer enters the internal network simulation system through the one-way access random channel module; Step 2.2, the access customer enters the internal network simulation system and selects the required access request target. The corresponding virtual information packet on the surface will be displayed inside the internal network virtual database. At this time, the virtual information packet on the surface is an encrypted empty information packet; Step 2.3, the accessing customer opens the intranet two-way encryption channel module between the virtual appearance information packet and the power information database using the two-way matching key. The data information in the power information database will be automatically transmitted to the virtual appearance information packet. When the accessing customer has no key to obtain the virtual appearance information packet, at this time, the virtual appearance information packet is an empty information packet, and at the same time, the intranet warning system will be triggered. The intranet warning system sends an interception instruction to the intranet channel module to obtain the access target request information of the accessing customer. At the same time, the intranet two-way encryption channel module that requires two-way key matching between the virtual appearance information packet and the power information database is closed; Step 2.4, when the accessing customer obtains the power information database through two-way key matching and at the same time obtains the intranet one-way private key provided by the power information intranet system, the accessing customer obtains the power information data in the power information database through the one-way access random channel.

Citation Information

Patent Citations

  • Network security early warning system based on self-adaptive mimicry technology

    CN112398876A

  • IPSec VPN system based on many-core processor and encryption and decryption processing method

    CN106341404A

  • Network security protection practical training system for electric power monitoring system

    CN209607185U