Security protection system and method for intelligent power distribution terminal
By combining blockchain technology with domestically developed cryptographic algorithms, the system achieves identity authentication and message encryption/decryption for intelligent power distribution terminals, solving the problem of insufficient security protection for intelligent power distribution terminals in network cloud deployment and improving system security and operation and maintenance efficiency.
Patent Information
- Application Number
- CN202310306547.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-27
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2043-03-27
AI Technical Summary
The existing power distribution automation system has an imperfect security protection system during the deployment of intelligent and cloud-based networks, making it difficult to cope with complex penetration network intrusions. In particular, with the development of smart IoT terminal hardware platformization and software APPization, there are problems of complex system vulnerabilities and reduced attack difficulty.
A lightweight identity authentication method based on blockchain technology is adopted, combined with domestic high-strength cryptographic algorithms for terminal identity management and message encryption/decryption, to establish a local operation and maintenance strategy for intelligent power distribution terminals, and to achieve isolation and protection of container resources through kernel-level access control and system call restrictions.
It enables efficient identity authentication and rapid encryption/decryption of intelligent power distribution terminals, improves the security protection capabilities of terminals, reduces the construction and maintenance costs of trust infrastructure, and enhances the ability to resist complex network attacks.
Smart Images

Figure CN116366326B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of power Internet of Things security protection technology, and relates to security protection systems and methods for intelligent power distribution terminals. Background Technology
[0002] With the construction and development of the power Internet of Things (IoT), distribution master stations, distribution terminals, and operation and maintenance technologies will all evolve towards intelligence and interconnectivity. Compared to the traditional "master station-communication network-terminal" architecture of distribution monitoring systems, the business models, functional positioning, and working methods of each link will become more flexible, open, and efficient. For example, distribution terminals will be upgraded with edge computing capabilities, low-voltage equipment will be widely connected, edge-to-edge devices will communicate and interact, and master station systems will be deployed in the cloud. Currently, the security protection system of distribution automation systems is based on the principles of "security zoning, dedicated networks, horizontal isolation, and vertical authentication," forming a defense-in-depth system that spans the production control area and the management information area, covering master stations, communication, terminals, and boundary layers. However, the focus of network security defense is mainly on boundary protection, and the security protection system for cloud-based deployment of distribution business and intelligent terminals is still imperfect, making it difficult to effectively cope with various increasingly complex and intelligent penetrating network intrusions.
[0003] With the development of smart IoT terminals towards "hardware platformization and software app-based architecture," the large-scale application of container technology, which serves as the carrier for application software, has introduced new security risks. On the one hand, the "hardware platformization and software app-based architecture" often utilizes the Linux operating system, leading to rapid software iteration, increased system complexity and vulnerabilities, enhanced openness, and reduced attack difficulty. On the other hand, various professional sectors have customized and developed multiple app applications to support the development of energy interconnection services, often employing containerized deployment methods. While containerized deployment of terminal apps improves the perception level and user responsiveness of the energy internet, it also brings new risks and challenges to the cybersecurity of smart IoT terminals. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this application provides a security protection system and method for intelligent power distribution terminals. It conducts research on security protection technologies for intelligent power distribution terminals, designs an identity authentication method for intelligent power distribution terminals based on blockchain technology, proposes a fast encryption and decryption method for intelligent power distribution terminal messages that meets the requirements of rapid horizontal information interaction, and conducts local operation and maintenance security protection design for intelligent power distribution terminals to improve the efficiency of terminal debugging, inspection, and maintenance.
[0005] To achieve the above objectives, the present invention adopts the following technical solution:
[0006] A security protection system for intelligent power distribution terminals includes a terminal identity authentication module, a message fast encryption / decryption module, an intelligent terminal local operation and maintenance module, and a terminal container security module;
[0007] The terminal identity authentication module is used for lightweight identity management and authentication of the power distribution secondary system based on a lightweight blockchain distributed terminal identity management mechanism using national cryptographic algorithms.
[0008] The message fast encryption / decryption module is used to perform intelligent power distribution terminal message encryption / decryption based on an automatically adapted message encryption / decryption mechanism, combined with elliptic curve operations and bilinear pairing operations.
[0009] The intelligent terminal local operation and maintenance module is used to establish a near-field security operation and maintenance strategy for intelligent power distribution terminals based on the near-field operation and maintenance needs and security risk control elements of power distribution terminals, and to perform secure local operation and maintenance of intelligent power distribution terminals based on security hardening and data encryption algorithms and security operation and maintenance traffic auditing algorithms.
[0010] The terminal container security module is used to establish policies for file access control within containers, resource isolation between containers, and resource call restriction between containers and the kernel, based on the kernel-level access control and system call restriction mechanism of the power distribution terminal. This enables comprehensive isolation of container resources from multiple perspectives on the terminal, ensuring the security protection of the intelligent power distribution terminal.
[0011] The present invention further includes the following preferred embodiments:
[0012] Preferably, in the terminal identity authentication module, a consortium blockchain is built with the cloud master station as the management node and the intelligent terminal as the accounting and endorsement node. The lightweight RAFT consensus algorithm and lightweight cryptographic algorithm are used to realize the fast processing of transactions, forming a terminal self-organizing authentication network, and terminal identity management and authentication are performed based on the terminal self-organizing authentication network.
[0013] Preferably, the terminal identity authentication module includes an identity management unit and an identity authentication unit;
[0014] The identity management unit adopts Diffie-Hellman key exchange and SM2 key exchange protocols to establish a one-to-one identity authentication protocol between power distribution terminals, thereby realizing secure communication in the existing terminal network structure.
[0015] A group key negotiation protocol based on elliptic curves and bilinear pairing cryptographic primitives is established to create a one-to-many authentication protocol between power distribution terminals, enabling secure offline interaction between power distribution terminals in the system.
[0016] Based on the SM9 national cryptographic algorithm, a lightweight authentication protocol is established under an identity-based cryptographic system. A certificate-free trust system is constructed that naturally binds the identity information of terminal devices with public keys. Blockchain technology, zero-knowledge proofs, and commitment protocol cryptographic tools are used to conduct distributed certificate issuance and management based on the system's identity management needs.
[0017] Preferably, the identity authentication unit employs terminal device fingerprint extraction technology to store terminal device fingerprint information, access control information, and electrical topology diagram on the blockchain, thereby achieving efficient and rapid intelligent terminal access and real-time network behavior authentication.
[0018] Preferably, in the message fast encryption and decryption module, for the message protocol characteristics, transmission mode, and real-time requirements of the intelligent distribution terminal in the distributed feeder automation no-return mode and the differential protection constant-interaction mode, an intelligent distribution terminal message encryption and decryption strategy for short message and segmented long message types is established, and business keys are securely stored and key indexed according to the vertical and horizontal business characteristics.
[0019] By analyzing message protocol identifiers, field identifiers, and algorithm identifiers, the system automatically adapts message encryption and decryption strategies to encrypt and decrypt different business messages.
[0020] Preferably, the intelligent power distribution terminal message encryption and decryption strategy, for short messages, logically integrates key expansion round operations and block encryption round operations through mathematical theoretical derivation and code logic analysis, and coordinates the operation of round key expansion and round operation fusion;
[0021] For long messages, considering the frequency of single key usage and ciphertext correlation, a context structure suitable for continuous encryption and decryption of long messages is established. The extended key, initialization vector, and authentication variables are dynamically stored, and a three-stage message encryption and decryption process of key initialization + loop encryption and decryption + data authentication is performed.
[0022] Preferably, in the message fast encryption / decryption module, a resource-sharing symmetric algorithm is used to establish an intelligent power distribution terminal message encryption / decryption strategy for short messages and segmented long messages. Furthermore, based on vertical and horizontal business characteristics, secure storage and key indexing of business keys are performed. Specifically:
[0023] First, establish a key-level protection system for intelligent power distribution terminals, classify key types for equipment, applications, and personnel, clarify the responsibilities and scope of use of each key, and realize encrypted key storage within the terminal;
[0024] Secondly, based on the operational logic of symmetric cryptography algorithms, a lookup table is constructed by integrating nonlinear and linear transformations. According to the characteristics of the hardware platform and the parallelism of the encryption and decryption working modes, fine-grained and coarse-grained parallel control are achieved by using in-round pipeline and block parallel optimization techniques respectively.
[0025] Finally, a key protection system and indexing mechanism are constructed within the security chip, employing white-box and side-channel attack resistance technologies to ensure the security of business key generation, storage, and use.
[0026] Preferably, the message fast encryption / decryption module employs an asymmetric cryptographic algorithm to embed intelligent power distribution terminal message encryption / decryption strategies for short messages and segmented long messages, and performs secure storage and key indexing of business keys based on vertical and horizontal business characteristics. Specifically:
[0027] Based on the domestic SM2 and SM9 asymmetric cryptographic algorithms and considering the resource size of the intelligent power distribution terminal hardware platform, an asymmetric cryptographic algorithm module that conforms to the authentication protocol of the intelligent power distribution terminal is designed and implemented to perform signature authentication and public key encryption.
[0028] The asymmetric cryptography module includes the SM2 elliptic curve cryptosystem and the SM9 bilinear pairing cryptosystem;
[0029] For the SM2 elliptic curve cryptosystem, a hybrid operation mechanism of affine coordinates and Jacobian coordinates is used to accelerate point group operations, and sliding window and Montgomery ladder constant time implementation techniques are used to optimize point multiplication operations and resist side-channel attacks by power analysis and time analysis.
[0030] For the SM9 bilinear pairing cryptosystem, the Karatsuba algorithm and cyclic subgroup features are used to construct a finite extended field underlying operation module. Furthermore, the computational overhead of bilinear pairing is reduced through batch modular inversion and multilinear pairing concurrency techniques, thereby realizing identity authentication and data encryption based on the identity cryptosystem.
[0031] Preferably, in the intelligent terminal local operation and maintenance module, wireless communication and data encryption are implemented based on security hardening and data encryption algorithms, specifically:
[0032] First, analyze the security of the SPP protocol and add an encryption process to the application layer;
[0033] Secondly, to address the security issues of the Bluetooth SPP protocol, a key sequence is generated based on the national cryptographic algorithm to encrypt the application layer, decoupling the underlying protocol and enabling the application layer to encrypt and decrypt data.
[0034] Finally, in conjunction with existing wireless communication protocols, a dynamic key sequence is used to encrypt the SPP protocol application layer data.
[0035] Preferably, in the intelligent terminal local operation and maintenance module, traffic auditing is performed based on a security operation and maintenance traffic auditing algorithm, specifically:
[0036] First, the data packets and protocols are analyzed to extract communication information, and in conjunction with the protocol specifications, the instruction execution, data parsing, and channel coding of the master and slave devices are obtained.
[0037] Secondly, the information content is identified by combining the duration of communication and using the location of the management frame data packets.
[0038] Finally, through feature engineering, traffic analysis, and machine learning, the target identity, operation commands, malicious behavior, and illegal connections are identified and audited.
[0039] Preferably, in the terminal container security module, the kernel-level access control and system call restriction mechanisms include SELinux, AppArmor, and Seccomp.
[0040] Preferably, in the terminal container security module, the file access control policy inside the container is specifically as follows:
[0041] First, each file in the container's file system is marked. Then, the access status of each file in the container's file system is observed through simulation. This allows us to determine the files that the container application needs to access during the initialization and stable operation phases, thereby generating a detailed file access authorization policy. Finally, this policy is combined with manual judgment to determine and eliminate necessary data file access restrictions.
[0042] Preferably, the inter-container resource isolation strategy is as follows:
[0043] By analyzing file access authorization policies and the shared file system mount point mapping of containers, the minimum intersection of files between containers is analyzed, thereby deriving resource isolation strategies between containers to eliminate unnecessary shared file access permissions.
[0044] Preferably, the resource access restriction strategy between the container and the kernel is as follows:
[0045] By placing hooks in kernel mode, the system calls used by container applications during runtime, excluding normal file system access, are monitored. This includes the use of sockets, hardware interfaces, shared memory, etc., thereby obtaining the system permissions that container applications need to obtain during normal operation, and ultimately obtaining kernel resource usage restriction policies.
[0046] A security protection method for intelligent power distribution terminals, the method comprising:
[0047] A lightweight blockchain-based distributed terminal identity management mechanism based on national cryptographic algorithms is used for lightweight identity management and authentication in power distribution secondary systems.
[0048] Based on an automatically adaptable message encryption and decryption mechanism, combined with elliptic curve operations and bilinear pairing operations, intelligent power distribution terminal message encryption and decryption is performed.
[0049] To address the near-field operation and maintenance needs of power distribution terminals and the elements of security risk management, a near-field security operation and maintenance strategy for intelligent power distribution terminals is established. Based on security hardening and data encryption algorithms as well as security operation and maintenance traffic auditing algorithms, a secure local operation and maintenance strategy for intelligent power distribution terminals is implemented.
[0050] Based on the kernel-level access control and system call restriction mechanism of the power distribution terminal, we establish policies for file access control within containers, resource isolation between containers, and resource call restriction between containers and the kernel. This enables comprehensive isolation of container resources from multiple perspectives on the terminal, ensuring the security protection of intelligent power distribution terminals.
[0051] The beneficial effects achieved by this application are:
[0052] This invention enables intelligent power distribution terminal identity authentication based on blockchain technology, achieves rapid encryption and decryption of intelligent power distribution terminal messages based on domestically developed high-strength commercial cryptographic algorithms, realizes local operation and maintenance security protection for intelligent power distribution terminals supporting short-range communication methods such as RFID and Bluetooth, and achieves kernel-level container resource isolation protection for power distribution terminals. Attached Figure Description
[0053] Figure 1 This is a system structure diagram of the present invention;
[0054] Figure 2 This is a schematic diagram illustrating the principle of terminal identity management and authentication based on a terminal self-organizing authentication network in this invention.
[0055] Figure 3 This invention relates to the intelligent power distribution terminal message encryption and decryption strategy;
[0056] Figure 4 This is a schematic diagram illustrating the construction principle of the intelligent power distribution terminal message encryption and decryption strategy based on symmetric algorithms of this invention.
[0057] Figure 5 This is a schematic diagram illustrating the construction principle of the intelligent power distribution terminal message encryption and decryption strategy based on an embedded asymmetric cryptographic algorithm, as described in this invention.
[0058] Figure 6 This is a flowchart of the security operation and maintenance process of this invention;
[0059] Figure 7 This is a schematic diagram illustrating the wireless communication and data encryption principles of this invention;
[0060] Figure 8 This is a schematic diagram illustrating the principle of secure operation and maintenance traffic auditing in this invention.
[0061] Figure 9 This is a diagram of the overall architecture of the security chip in a specific implementation of the present invention;
[0062] Figure 10 This is the embedded safety module in the power distribution terminal during a specific implementation of the present invention;
[0063] Figure 11 This is a Bluetooth-based operation and maintenance security module in the specific implementation of this invention;
[0064] Figure 12This is a localized operation and maintenance tool based on a mobile terminal in the specific implementation of this invention;
[0065] Figure 13 This is a diagram of the dual-kernel shared memory system architecture in a specific implementation of the present invention;
[0066] Figure 14 This is a diagram of the dual-kernel shared memory software structure in a specific implementation of the present invention. Detailed Implementation
[0067] The present application will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention, and should not be construed as limiting the scope of protection of the present application.
[0068] like Figure 1 As shown, the security protection system for intelligent power distribution terminals of the present invention includes a terminal identity authentication module, a message fast encryption and decryption module, an intelligent terminal local operation and maintenance module, and a terminal container security module.
[0069] In practical implementation, considering the security protection needs brought about by the massive access and interconnection of intelligent power distribution terminals, we will analyze the security risks faced by business information interaction such as distributed feeder automation and differential protection, and carry out research on technologies related to terminal identity authentication, rapid message encryption and decryption, intelligent terminal local operation and maintenance, and terminal container security.
[0070] The terminal identity authentication module is used for a lightweight blockchain distributed terminal identity management mechanism based on national cryptographic algorithms to achieve "decentralization" of terminal identity authentication and perform lightweight identity management and authentication in the power distribution secondary system.
[0071] Based on the current network architecture, business model, and trust system of the power distribution secondary system, this paper analyzes the security risks faced by horizontal interconnection and interaction, and studies the security protection requirements of new services such as distributed feeder automation and differential protection. Based on the consortium blockchain architecture and the horizontal networking mode of terminals, a lightweight blockchain distributed identity management method is designed. From the perspectives of identity trust and data confidentiality, an authentication key exchange protocol and a group key negotiation protocol based on domestic cryptographic algorithms are studied to achieve lightweight and fast "end-to-end" authentication.
[0072] Furthermore, in specific implementation, we first analyze the structural characteristics of the trust system in the current power distribution secondary system, construct a distributed terminal identity management mechanism based on lightweight blockchain to achieve "decentralization" of terminal identity authentication, and further integrate domestic cryptographic algorithms and other cryptographic technologies to achieve lightweight and fast horizontal identity authentication in the power distribution secondary system, providing technical support for the security protection technology system of intelligent power distribution terminals.
[0073] The terminal identity authentication module establishes a consortium blockchain with the cloud master station as the management node and intelligent terminals as the ledger and endorsement nodes. It employs a lightweight RAFT consensus algorithm and lightweight cryptographic algorithms to achieve rapid transaction processing, forming a self-organizing terminal authentication network. Terminal identity management and authentication are then performed based on this self-organizing authentication network. Figure 2 As shown.
[0074] In practice, the terminal identity authentication module includes an identity management unit and an identity authentication unit;
[0075] In the identity management unit, cryptographic protocols such as Diffie-Hellman key exchange and SM2 key exchange are used to establish a one-to-one identity authentication protocol between power distribution terminals, thereby realizing secure communication in the existing terminal network structure.
[0076] A group key negotiation protocol based on elliptic curves and bilinear pairwise cryptographic primitives is established to create a one-to-many authentication protocol between power distribution terminals, enabling offline secure interaction between power distribution terminals in the system and providing security support for the implementation and expansion of functions such as distributed feeder automation and differential protection.
[0077] Based on the SM9 national cryptographic algorithm, a lightweight authentication protocol is established under an identity-based cryptographic system. This constructs a certificate-free trust system where terminal device identity information and public keys are naturally bound. Utilizing blockchain technology and cryptographic tools such as zero-knowledge proofs and commitment protocols, distributed certificate issuance and management are implemented based on the system's identity management needs. This effectively solves the certificate distribution and management problems in traditional public-key cryptography, providing a new direction for the development of security protection technology for power distribution secondary systems.
[0078] The identity authentication unit employs terminal device fingerprint extraction technology to store terminal device fingerprints and other identity information, access control information, and electrical topology diagrams on the blockchain. This enables efficient and rapid intelligent terminal access and real-time network behavior authentication, thereby decentralizing the identity authentication system of the power distribution secondary system, reducing the construction and maintenance costs of trust infrastructure, and providing theoretical basis and technical support for system security authentication and information interaction.
[0079] The message fast encryption / decryption module is used to perform efficient and adaptable intelligent power distribution terminal message fast encryption / decryption based on an automatically adaptable message encryption / decryption mechanism, combined with computationally intensive elliptic curve operations and bilinear pairing operations.
[0080] Intelligent power distribution terminal message fast encryption and decryption technology based on domestically developed high-strength commercial cryptographic algorithms
[0081] Based on the application requirements for rapid information exchange between intelligent power distribution terminals, this paper analyzes the characteristics of intelligent power distribution terminal messages and studies efficient and adaptable rapid encryption and decryption technologies for intelligent power distribution terminal messages. According to the characteristics of power distribution terminal hardware platform resources, combined with the algorithm complexity, key length and working mode of domestic high-strength commercial cryptographic algorithms, this paper studies the embedded rapid implementation technology of cryptographic algorithms.
[0082] Furthermore, in specific implementation, firstly, based on the message characteristics of intelligent power distribution terminals, an automatically adaptable message encryption and decryption mechanism is designed. Secondly, according to the security protocol and algorithm usage mode, various cryptographic engineering optimization techniques are adopted to accelerate the running efficiency of domestic block cipher algorithms. Finally, the hardware platform of intelligent power distribution terminals is adapted, and high-computational-load elliptic curve operations and bilinear pairing operations are studied and implemented to provide service support for the security protection technology system of intelligent power distribution terminals.
[0083] In the aforementioned message fast encryption and decryption module, for the message protocol characteristics, transmission mode, and real-time requirements of intelligent distribution terminal in distributed feeder automation no-return mode and differential protection constant-return mode, intelligent distribution terminal message encryption and decryption strategies of short message, segmented long message, etc. are established, and business keys are securely stored and key indexed according to vertical and horizontal business characteristics.
[0084] By analyzing message protocol identifiers, field identifiers, algorithm identifiers, etc., the system automatically adapts message encryption and decryption strategies to meet the fast encryption and decryption needs of different business messages such as business interactions, remote commands, and firmware upgrades.
[0085] like Figure 3 As shown, the intelligent power distribution terminal message encryption and decryption strategy, for short messages, through mathematical theoretical derivation and code logic analysis, logically integrates key expansion round operation and block encryption round operation, and coordinates the operation of round key expansion and round operation fusion to reduce the proportion of key expansion operation overhead, so as to solve the problem of low encryption and decryption efficiency of short messages caused by frequent key changes;
[0086] For long messages, considering the frequency of single key usage and ciphertext correlation, a context structure suitable for continuous encryption and decryption of long messages is established. Data such as extended keys, initialization vectors, and authentication variables are dynamically stored. Three-stage message encryption and decryption is performed, consisting of key initialization, loop encryption and decryption, and data authentication, to reduce the computational overhead of key expansion, key indexing, and data concatenation.
[0087] like Figure 4 As shown, the message fast encryption / decryption module can employ a resource-sharing, domestically developed high-strength symmetric algorithm to establish intelligent power distribution terminal message encryption / decryption strategies for short messages, segmented long messages, and other types of messages. Furthermore, based on vertical and horizontal business characteristics, it performs secure storage and key indexing of business keys. Specifically:
[0088] Furthermore, for the security protocol design and message encapsulation format of intelligent power distribution terminals, the domestic SM4 / SM7 cryptographic algorithms are selected. Combined with the working mode characteristics of block ciphers such as ECB and CBC, the rapid implementation technology of domestic high-strength symmetric algorithms with resource sharing is studied.
[0089] First, establish a key-level protection system for intelligent power distribution terminals, classify key types for equipment, applications, and personnel, clarify the responsibilities and scope of use of each key, and realize encrypted key storage within the terminal to reduce the security risks caused by uncontrolled terminal keys;
[0090] Secondly, based on the operational logic of the domestic symmetric cryptography algorithm, a lookup table is constructed by integrating nonlinear and linear transformations. According to the characteristics of the hardware platform and the parallelism of the encryption and decryption working mode, optimization techniques such as in-round pipeline and block parallelism are used to realize fine-grained and coarse-grained parallel control respectively.
[0091] Finally, a key protection system and indexing mechanism are constructed within the security chip, employing white-boxing and side-channel attack resistance technologies to ensure the security of business key generation, storage, and usage.
[0092] like Figure 5 As shown, the message fast encryption / decryption module can employ domestically developed asymmetric cryptographic algorithms to embed intelligent power distribution terminal message encryption / decryption strategies for short messages, segmented long messages, and other types of messages. Furthermore, based on vertical and horizontal business characteristics, it performs secure storage and key indexing of business keys. Specifically:
[0093] Based on the domestic SM2 and SM9 asymmetric cryptographic algorithms and considering the resource size of the intelligent power distribution terminal hardware platform, an asymmetric cryptographic algorithm module that conforms to the authentication protocol of the intelligent power distribution terminal is designed and implemented to perform signature authentication and public key encryption.
[0094] For the SM2 elliptic curve cryptosystem, a hybrid operation mechanism of affine coordinates and Jacobian coordinates is used to accelerate point group operations, and constant-time implementation techniques such as sliding window and Montgomery ladder are used to optimize point multiplication operations, and to resist side-channel attacks such as power consumption analysis and time analysis.
[0095] For the SM9 bilinear pairing cryptosystem, the Karatsuba algorithm and cyclic subgroup features are used to construct a finite extended field underlying operation module. Furthermore, the computational overhead of bilinear pairing is reduced through techniques such as batch modular inversion and multilinear pairing concurrency, enabling protocol applications such as identity authentication and data encryption based on the identity cryptosystem.
[0096] The intelligent terminal local operation and maintenance module is used to establish a near-field security operation and maintenance strategy for intelligent power distribution terminals based on the near-field operation and maintenance needs and security risk control elements of power distribution terminals, and to perform secure local operation and maintenance of intelligent power distribution terminals based on security hardening and data encryption algorithms and security operation and maintenance traffic auditing algorithms.
[0097] This research aims to address the near-field operation and maintenance needs of intelligent power distribution terminal APP upgrades, configuration changes, and switch operations. It also studies near-field security operation and maintenance solutions for intelligent power distribution terminals, analyzes the security risks of near-field operation and maintenance technologies such as RFID and Bluetooth, and researches Bluetooth and RFID security hardening and data encryption technologies based on national cryptographic algorithms. Furthermore, it investigates secure operation and maintenance traffic auditing technologies to address security issues such as illegal operations, data leaks, malicious attacks, and APP vulnerabilities.
[0098] Furthermore, in specific implementation, firstly, based on the near-field operation and maintenance needs of power distribution terminals and the elements of security risk control, a near-field security operation and maintenance strategy for intelligent power distribution terminals is established; then, the security risks of near-field operation and maintenance technologies such as RFID and Bluetooth are analyzed, and Bluetooth and RFID security hardening and data encryption algorithms based on national cryptographic algorithms are studied; finally, in response to issues such as data leakage, tampering, loss, interception, malicious attacks, and APP vulnerabilities, a security operation and maintenance traffic auditing algorithm is studied.
[0099] Furthermore, in specific implementation, the intelligent terminal local operation and maintenance module, based on technologies such as dynamic permission authentication, access control, protocol auditing, and port isolation, achieves security protection for applications, interfaces, configuration switches, system files, and interactive data. It establishes a near-field security operation and maintenance strategy for the intelligent power distribution terminal. Combining operation and maintenance scenario requirements and control elements, the strategy's entities mainly consist of a security center, operation and maintenance terminal, intelligent power distribution terminal, UKey, RFID, etc., and it has both online and offline security operation and maintenance modes. The security operation and maintenance process is as follows: Figure 6 As shown.
[0100] First, the operations and maintenance personnel submit an operations and maintenance application to the security center;
[0101] Secondly, after the application is approved, if the power distribution terminal is online, the policy information will be directly sent to the power distribution terminal; if the power distribution terminal is offline, the policy information will be imported into the ukey and sent to the operation and maintenance personnel.
[0102] Then, when performing near-field maintenance, the maintenance personnel complete multi-factor authentication on the maintenance terminal side, scan the RFID tag, initiate Bluetooth communication with the power distribution terminal, perform authorized maintenance operations, and audit and record the maintenance operations in real time.
[0103] Finally, the power distribution terminal records and asynchronously reports the logs.
[0104] Furthermore, this study analyzes the authentication methods, protocol specifications, and encryption mechanisms of wireless communications such as RFID and Bluetooth. It also enhances Bluetooth authentication, authorization, confidentiality, and message integrity by combining the SM2 algorithm, and researches wireless communication and data encryption technologies based on Chinese cryptographic algorithms.
[0105] In the intelligent terminal local operation and maintenance module, wireless communication and data encryption are implemented based on security hardening and data encryption algorithms, specifically:
[0106] First, analyze the security of the SPP protocol and add an encryption process to the application layer;
[0107] Secondly, to address the security issues of the Bluetooth SPP protocol, a key sequence is generated based on the national cryptographic algorithm to encrypt the application layer, decoupling the underlying protocol and enabling the application layer to encrypt / decrypt data.
[0108] Finally, combining existing wireless communication protocols, a dynamic key sequence is used to encrypt the SPP protocol application layer data, such as... Figure 7 As shown.
[0109] In the intelligent terminal local operation and maintenance module, traffic auditing is performed based on a security operation and maintenance traffic auditing algorithm, specifically:
[0110] First, the data packets and protocols are analyzed to extract communication information, and in conjunction with the protocol specifications, the instruction execution, data parsing, and channel coding of the master and slave devices are obtained.
[0111] Secondly, the information content is identified by combining the duration of communication and using the location of the management frame data packets.
[0112] Finally, through feature engineering, traffic analysis, and machine learning, the target identity, operation commands, malicious behavior, and illegal connections are identified and audited.
[0113] The principle diagram of security operation and maintenance traffic audit is as follows: Figure 8 As shown.
[0114] The terminal container security module is used to establish policies for file access control within containers, resource isolation between containers, and resource call restriction between containers and the kernel, based on the kernel-level access control and system call restriction mechanism of the power distribution terminal. This enables comprehensive isolation of container resources from multiple perspectives, effectively ensuring the security protection of intelligent power distribution terminals.
[0115] To address security risks such as container escape, denial of service, and vulnerability of image files, this study investigates technologies such as mandatory access control and system call restrictions in the operating system kernel. It aims to achieve container resource isolation and protection at the kernel level, including within containers, between containers, and between containers and the kernel, and to develop a kernel-level container resource isolation and protection module for an intelligent power distribution terminal container security enhancement suite.
[0116] In its specific implementation, this invention conducts a comprehensive examination of the mandatory access control technology provided by the Linux kernel.
[0117] The kernel-level access control and system call restriction mechanisms include SELinux, AppArmor, and Seccomp.
[0118] 1) SELinux:
[0119] SELinux is a mandatory access control mechanism in the Linux kernel that restricts programs from accessing files and network resources. It is based on the Linux security module.
[0120] On the host machine, SELinux's permission mechanism can be used to minimize the access permissions of main programs, thereby reducing or completely eliminating the risk of harm to the system caused by program and daemon failures or errors (such as buffer overflows or misconfigurations). However, SELinux does not support container namespaces. Therefore, in container scenarios, restrictions on shared file access between containers are mainly implemented through the design of SELinux security labels on the file system.
[0121] 2) AppArmor:
[0122] AppArmor is also based on Linux security modules and is an application-by-application access control mechanism provided by the Linux kernel. It can restrict application access to the file system, network resources, and Linux capabilities.
[0123] AppArmor can work within a namespace-mapped userspace file system, thus providing good support for containers. In container scenarios, this invention primarily uses AppArmor's per-application configuration files to achieve resource isolation within containers and restrictions on container usage of kernel resources.
[0124] 3) Seccomp:
[0125] Seccomp is a technique for fine-grained access control of application system calls.
[0126] Throughout the application's lifecycle, the system call permissions required in the initialization and working states differ. Typically, the former requires more permissions, while the latter requires fewer. Attacks often occur in the working state rather than the initialization state; therefore, it is necessary to dynamically adjust the application's system call permissions to reduce the number of interfaces exposed by the kernel to user-space processes, thereby reducing the kernel attack surface. Seccomp uses EBPF technology to efficiently filter system call numbers and specific parameters, such as socket port numbers. In container scenarios, this invention utilizes Seccomp technology to restrict the system call permissions of container applications.
[0127] This invention establishes a multi-faceted container resource comprehensive isolation and protection technology based on the kernel-level access control and system call restriction mechanism of the power distribution terminal, and establishes policies for internal file access control, resource isolation between containers, and resource call restriction between containers and the kernel.
[0128] The process is divided into three stages:
[0129] First, the container application is analyzed inside the container to extract file access information, and corresponding authorization policies are generated based on the principle of minimizing access sets.
[0130] Secondly, based on the principle of minimizing resource sharing between containers, corresponding authorization policies are generated for the mounted folders shared between containers;
[0131] Finally, the kernel system calls of each container application are monitored in real time to generate an authorization policy for container access to the kernel.
[0132] 1) Container internal file access control policy:
[0133] First, each file in the container's file system is marked. Then, the access status of each file in the container's file system is observed through simulation. This allows us to determine the files that the container application needs to access during the initialization and stable operation phases, thereby generating a detailed file access authorization policy. Finally, this policy is combined with manual judgment to determine and eliminate necessary data file access restrictions.
[0134] 2) Inter-container resource isolation strategy:
[0135] By analyzing file access authorization policies and the shared file system mount point mapping of containers, the minimum intersection of files between containers is analyzed, thereby deriving resource isolation strategies between containers to eliminate unnecessary shared file access permissions.
[0136] 3) Resource access restriction strategy between container and kernel:
[0137] By placing hooks in kernel mode, the system calls used by container applications during runtime, excluding normal file system access, are monitored. This includes the use of sockets, hardware interfaces, shared memory, etc., thereby obtaining the system permissions that container applications need to obtain during normal operation, and ultimately obtaining kernel resource usage restriction policies.
[0138] Furthermore, based on the system call logs from kernel-mode hooks and manual analysis, the difference between the container's initialization state and its working state can be determined, thereby specifying fine-grained isolation strategies for accessing system-level resources through system calls.
[0139] Furthermore, the present invention is implemented as follows based on the above:
[0140] I. Development of a security chip supporting fast data read and encryption / decryption for intelligent power distribution terminals:
[0141] Combining high performance and low power consumption requirements, we analyzed existing chip architectures and designed a SoC architecture that meets the fast encryption and decryption needs of distributed power distribution terminals and differential protection. We analyzed the implementation requirements of cryptographic algorithms and the characteristics of hardware platforms, developed dedicated hardware units for cryptographic implementation, and provided an independently controllable extended instruction set for cryptographic operations. Combining the fast encryption and decryption technology of power distribution terminal messages, we developed an embedded cryptographic operation library that supports the domestic cryptographic algorithm system. We developed a dedicated security chip for distributed terminals in the power distribution network, completed the relevant performance requirements, and after obtaining the State Cryptography Administration's model certificate and internal functional performance testing, we promoted it in conjunction with the "State Grid Chip" program and applied it in the field of localized protection and control of the power distribution network within the company.
[0142] (1) Design a SoC architecture that meets the fast encryption and decryption requirements of distributed power distribution terminals and differential protection.
[0143] First, we analyze the chip architecture of mainstream security chips, study the requirements for high-performance and low-power chip architectures, and investigate the design characteristics of CPU cores based on the ARM architecture. Combining the completely open-source nature of the RISC-V architecture, we design a RISC-V architecture CPU core that can replace the ARM architecture, achieving complete independent control of the CPU core. Based on this, we further integrate national cryptographic algorithm modules, system bus modules, RAM, FLASH, peripheral interface modules, etc., and finally design a dedicated security chip SoC architecture that meets the fast encryption and decryption requirements of distributed power distribution terminals and differential protection.
[0144] (2) Establish a dedicated hardware unit for cryptographic implementation and provide an independently controllable extended instruction set for cryptographic operations.
[0145] This paper analyzes the implementation requirements of the national cryptographic algorithm, extracts high-frequency instruction segments from the algorithm program, and designs an independently controllable extended instruction set for cryptographic operations to reduce the number of instructions required by the cryptographic algorithm. Considering the characteristics of frequently used permutation instructions (substitution and shift instructions) with varying bit widths in the cryptographic algorithm, a dedicated hardware unit for combining permutation cryptographic instructions based on the Butterfly and iButterfly network structures is designed. This unit unifies permutation and shift operations within a single hardware module, enabling it to perform 64-bit, 128-bit, and larger bit-width permutation operations within a few instruction cycles. It also enables various types of short-word shifts and large-bit-width shift operations, improving the processing performance of symmetric encryption algorithms.
[0146] (3) Establish an embedded cryptographic operation library that supports domestic cryptographic algorithm systems.
[0147] Targeting the implementation methods of the national cryptographic algorithms SM1, SM2, SM3, SM4, SM7, and SM9, and combining the fast encryption and decryption technology for power distribution terminal messages, which uses a "round key expansion + round operation" operation mode for short messages and a three-stage message encryption and decryption mechanism of "key initialization + loop encryption and decryption + data authentication" for long messages, we developed an embedded cryptographic operation library that supports the domestic cryptographic algorithm system. We also developed cryptographic modules for the SM1, SM2, SM3, SM4, SM7, and SM9 algorithms in the security chip, which are connected to the CPU core through a high-speed system bus to meet the chip's performance requirements for fast encryption and decryption.
[0148] (4) Establish a dedicated security chip for distributed terminals in the power distribution network.
[0149] Based on the above research plan, a 32-bit CPU core for a security chip based on the RISC-V architecture was developed. The CPU core employs the RISC-V instruction set and dedicated fast encryption / decryption extension instructions, integrates a national cryptographic algorithm module, and integrates a memory protection unit (MPU) to protect sensitive data. Based on the CPU core, a security chip SOC platform was built, and a dedicated security chip for distributed distribution network terminals was developed. This chip features environmental monitoring capabilities, resistance to SPA / DPA / EMA / DEMA attacks, and rich peripheral interfaces. After obtaining the national cryptographic bureau's model certificate and undergoing internal functional performance testing, it will be promoted and applied in the field of localized protection and control of distribution networks within the company, in conjunction with the company's "National Grid Chip" plan.
[0150] Security chip performance parameter targets:
[0151] 1. Encryption and decryption time not exceeding 2ms (data size not exceeding 200 bytes)
[0152] 2. SM1 algorithm encryption / decryption speed: 80Mbps@80MHz
[0153] 3. SM2 algorithm signature speed: 200 signatures / second @ 80MHz
[0154] 4. SM2 algorithm encryption speed: 100 times / second @ 80MHz
[0155] 5. SM2 algorithm decryption speed: 150 times / second @ 80MHz
[0156] 6. SM3 algorithm encryption / decryption speed: 100Mbps@80MHz
[0157] 7. SM4 algorithm encryption / decryption speed: 90Mbps@80MHz
[0158] The overall architecture of the security chip is as follows Figure 9 As shown.
[0159] II. Development of security modules and dedicated local maintenance tools for intelligent operation and maintenance of power distribution terminals
[0160] First, we designed the overall system architecture, functional framework, and deployment scheme for intelligent operation and maintenance of power distribution terminals. We expanded the secure access proxy function of existing terminals, developed an embedded security module for power distribution terminals, and implemented remote operation and maintenance authorization with the cloud master station's security center, secure access authentication and communication with operation and maintenance terminals, and fine-grained access control. We developed localized operation and maintenance tools based on mobile terminals to achieve secure access, operation authorization, and log auditing with power distribution terminals, meeting the on-site operation and maintenance needs for localized switch operations, configuration changes, and system upgrades. We developed a Bluetooth security module to support secure access and secure data transmission for existing operation and maintenance tools. We conducted joint debugging and testing of the on-site operation and maintenance system for power distribution terminals, and invited the State Grid Security Red Team to conduct penetration testing verification.
[0161] (1) Establish as follows Figure 10 The power distribution terminal embedded safety module shown
[0162] Based on the near-field operation and maintenance scenario of power distribution terminals, this study investigates technologies such as authentication and authorization, secure access, behavior auditing, and fine-grained access control for power distribution terminals, and develops an embedded security module for power distribution terminals; an identity authentication module based on cryptography, certificates, and biometric token technologies; a behavior authorization module based on dynamic authentication and trust assessment technologies; a behavior auditing module based on instruction analysis and anomaly detection technologies; a policy routing module based on micro-segmentation and network awareness technologies; and an access control module based on constraint differentiation technologies.
[0163] (2) Establish such Figure 11 The operation and maintenance security module shown is based on Bluetooth communication.
[0164] To meet the near-field wireless communication needs of power distribution terminal operation and maintenance, this study investigates technologies such as secure access, access control, behavior analysis, and data leakage prevention for power distribution terminals. Specifically, it develops an operation and maintenance security module based on Bluetooth communication; a secure access module based on digital certificates and multi-factor authentication; a wireless access control module based on Bluetooth protocol and micro-segmentation technology; a behavior analysis module based on feature matching, machine learning, and self-supervised learning; and a data leakage prevention module based on national cryptographic algorithms and application layer protocol enhancement technologies.
[0165] (3) Establish such Figure 12 The illustrated localized operation and maintenance tool based on mobile terminals
[0166] To meet the needs of near-field operation and maintenance, a localized operation and maintenance tool based on Bluetooth communication technology was developed. In conjunction with the application functions of the power distribution terminal, configuration management functions for manipulating configuration files were developed; switch operation functions for setting switch attributes were developed; APP management functions for updating applications were developed; container management functions for operating containers were developed; power distribution terminal system management functions were developed; and functions for information data exchange and collection were developed. Simultaneously, for secure access, secure access functions based on identity authentication, encryption authentication, and wireless communication technologies were developed.
[0167] III. Development of intelligent power distribution terminals with embedded fast encryption / decryption security chips
[0168] First, we investigated and analyzed existing terminal hardware electrical components, and proposed domestic alternatives for components that are not domestically controlled. From the perspective of business requirements, we proposed a dual-core shared memory system architecture. Then, to address the security issue of Docker containers' inability to effectively isolate pseudo-file systems, we implemented Docker container isolation and protection technology. Finally, to meet the high reliability and low latency requirements brought about by the terminal running multiple services, we proposed a multi-channel information interaction scheme for security chips to meet the real-time and security requirements of terminal services.
[0169] (1) Dual-kernel shared memory system scheme
[0170] This study investigates data synchronization between real-time and non-real-time kernels. Communication between different kernels can be achieved using storage peripherals or shared memory. Data synchronization via storage peripherals is implemented through a mutual exclusion mechanism; communication via shared memory is achieved through a data preparation-interrupt triggering method. This approach results in fast synchronization speed and high efficiency, improving the real-time performance, reliability, and efficiency of data synchronization, thus meeting the overall system requirements. The hardware structure is as follows: Figure 13 .
[0171] (2) Intelligent power distribution terminal software structure design
[0172] Based on the design principles of "layered design, high cohesion, low coupling, and platformization," the software design of an intelligent power distribution terminal is carried out. The requirements of real-time and non-real-time business scenarios are analyzed. Based on a non-real-time kernel, Docker containers run on the operating system to realize non-real-time blockchain, IoT, and other business application functions. Logical isolation is adopted between different containers within the system. Analysis is conducted from the perspectives of file access control within containers, resource isolation between containers, and resource call restrictions between containers and the kernel, implementing multi-angle comprehensive container resource isolation and protection technology. The need for shared data among multiple services is analyzed, and the mechanism for inter-container communication is studied. An encrypted proxy runs on the host to realize secure vertical communication interaction in the cloud. Based on the non-real-time kernel, access to a dedicated encryption chip enables real-time multi-channel secure business interaction between terminals. Multi-terminal synchronization control technology based on second pulses meets the high synchronization requirements of measurement and control protection. Combined with 5G technology, applications in multiple scenarios such as power distribution automation and differential protection are realized, achieving rapid fault isolation. The software structure design is as follows: Figure 14 As shown.
[0173] In summary, compared with the prior art, the present invention has the following beneficial effects:
[0174] 1: A Blockchain-Based Intelligent Power Distribution Terminal Identity Authentication Method
[0175] Currently, power distribution secondary systems operate on the principles of "security zoning, dedicated networks, horizontal isolation, and vertical authentication," forming a centralized trust system and a "cloud master station-terminal" identity authentication mechanism. However, as master stations gradually evolve towards cloud deployment and terminals become increasingly intelligent, the centralized trust system presents challenges such as authentication node failures and excessively high trust costs, necessitating decentralized, lightweight, and rapid trust management and identity authentication. The key challenge of this project lies in how to deploy a lightweight blockchain system on resource-constrained terminal node networks, improve the security protection system for "end-to-end" interconnection, and design a matching decentralized, lightweight identity authentication protocol to achieve trustworthy entities and legitimate identities.
[0176] Solution of this invention:
[0177] (1) Analyze the security risks faced by the horizontal interconnection and interaction of the secondary power distribution system, and combine the characteristics of core blockchain technologies such as the lightweight RAFT consensus algorithm to build a large-scale consortium chain, form a terminal self-organizing authentication network, and construct a distributed terminal identity management system.
[0178] (2) Research the security protection requirements of new services such as distributed feeder automation and differential protection, design a distributed certificate issuance and management mechanism and an identity authentication protocol based on SM2 / SM9 national cryptographic algorithms to achieve efficient horizontal identity authentication between ends.
[0179] 2: Intelligent power distribution terminal message fast encryption and decryption technology
[0180] With the widespread application of rapid protection technologies such as intelligent distributed feeder automation and differential protection in power distribution secondary systems, existing horizontal encryption technologies cannot meet the requirements for rapid information encryption and decryption. The network risks arising from plaintext transmission between intelligent terminals pose high security and timeliness requirements for horizontal services. The key and challenging aspects of this project are how to construct automatically adaptable message encryption and decryption logic and design an intelligent power distribution terminal message adaptive fast encryption and decryption mechanism to achieve parallel control of fine and coarse granularities, accelerate the efficiency of cryptographic algorithms, and effectively ensure the security of communication data.
[0181] Solution of this invention:
[0182] (1) Analyze the message characteristics of intelligent distribution terminals in the distributed feeder automation no-return mode and the differential protection constant-return mode, and design an automatically adaptable message encryption and decryption logic to achieve efficient and adaptable fast encryption and decryption of terminal messages.
[0183] (2) Analyze the security protocol design and message encapsulation format of intelligent power distribution terminal, design the key level protection system of intelligent power distribution terminal, and study the rapid implementation technology of domestic SM4 / SM7 high-strength symmetric algorithm with resource sharing and the embedded rapid implementation technology of domestic SM2 / SM9 asymmetric cryptographic algorithm.
[0184] 3: Develop a dedicated security chip for domestically developed and controllable national cryptographic algorithms.
[0185] Currently, the CPU cores in domestic security encryption chips generally use the ARM instruction set. However, since the ARM instruction set is a closed-source instruction set, it faces intellectual property barriers and potential unknown backdoor vulnerabilities. Furthermore, the core technology may be subject to supply disruptions. Therefore, adopting an independently controllable RISC-V instruction set architecture is essential. However, the RISC-V ecosystem is currently immature, and there are no precedents for its implementation in the field of power-specific security chips. Overcoming the immaturity of the RISC-V architecture and developing a dedicated security chip for power distribution terminals that meets the requirements for fast message encryption and decryption is the key and challenging aspect of this project.
[0186] Solution of this invention:
[0187] (1) The project team has successfully developed a general-purpose 32-bit single-core high-performance processor for embedded systems based on the RISC-V architecture, as well as a supporting embedded operating system and software toolchain. Based on the existing work of the project team, a secure encryption chip CPU core based on the RISC-V architecture was designed.
[0188] (2) Combining the characteristics of domestic commercial cryptographic algorithms with terminal message fast encryption and decryption technology, we developed a dedicated hardware unit for cryptographic implementation, a cryptographic operation extended instruction set and an embedded cryptographic operation library, and constructed a dedicated national cryptographic algorithm cryptographic module.
[0189] (3) Based on the RISC-V architecture CPU core and dedicated national cryptographic algorithm cryptographic module, develop an embedded, independent, controllable, high-performance, low-power security chip that can replace the ARM architecture.
[0190] 4: Safety protection technology to meet the requirements of short-range communication of power distribution terminals
[0191] As business operations expand, terminal inspection, maintenance, and debugging require the introduction of near-field wireless communication (NFC) to complete the maintenance work. However, NFC technology is susceptible to security vulnerabilities such as identity spoofing, eavesdropping attacks, and replay attacks that tamper with information. Existing NFC protection measures are insufficient to meet security requirements, necessitating enhancements to NFC authentication methods, protocol specifications, and encryption techniques. Furthermore, internationally recognized cryptographic algorithms have been repeatedly reported to have been cracked, exploited, and attacked, posing significant security risks. There are currently no readily available solutions for applying Chinese national cryptographic algorithms to NFC. Therefore, how to utilize Chinese national cryptographic algorithms for security hardening and data encryption in NFC has become one of the key challenges and difficulties of this project.
[0192] Solution of this invention:
[0193] (1) Establish an encryption authentication scheme based on the national cryptographic algorithm, and use the SM2 algorithm to enhance Bluetooth authentication, authorization, confidentiality and message integrity, so as to realize the secure protection of encrypted data transmission and authentication authorization.
[0194] (2) Establish an application layer data processing flow based on a security protocol. By adding an encryption process at the application layer, the security performance of the wireless communication protocol can be improved, breaking through existing bottlenecks and realizing the enhancement and hardening of the security protocol.
[0195] (3) Establish a secure link protection based on radio frequency fingerprinting, and use frequency jump transient characteristics for device identification to deal with the detection and protection of threat attacks, thereby enhancing the communication security of the link layer.
[0196] A security protection method for intelligent power distribution terminals, the method comprising:
[0197] A lightweight blockchain-based distributed terminal identity management mechanism based on national cryptographic algorithms is used for lightweight identity management and authentication in power distribution secondary systems.
[0198] Based on an automatically adaptable message encryption and decryption mechanism, combined with elliptic curve operations and bilinear pairing operations, intelligent power distribution terminal message encryption and decryption is performed.
[0199] To address the near-field operation and maintenance needs of power distribution terminals and the elements of security risk management, a near-field security operation and maintenance strategy for intelligent power distribution terminals is established. Based on security hardening and data encryption algorithms as well as security operation and maintenance traffic auditing algorithms, a secure local operation and maintenance strategy for intelligent power distribution terminals is implemented.
[0200] Based on the kernel-level access control and system call restriction mechanism of the power distribution terminal, we establish policies for file access control within containers, resource isolation between containers, and resource call restriction between containers and the kernel. This enables comprehensive isolation of container resources from multiple perspectives on the terminal, ensuring the security protection of intelligent power distribution terminals.
[0201] This disclosure can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of this disclosure.
[0202] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0203] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0204] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.
[0205] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. A security protection system for intelligent power distribution terminals, comprising a terminal identity authentication module, a message fast encryption / decryption module, an intelligent terminal local operation and maintenance module, and a terminal container security module, characterized in that: The terminal identity authentication module is used for lightweight blockchain distributed terminal identity management mechanism based on national cryptographic algorithms to perform lightweight identity management and authentication of the power distribution secondary system. In the terminal identity authentication module, a consortium blockchain is built with the cloud master station as the management node and the intelligent terminal as the accounting and endorsement node. The lightweight RAFT consensus algorithm and lightweight cryptographic algorithm are used to realize the fast processing of transactions, forming a terminal self-organizing authentication network, and terminal identity management and authentication are performed based on the terminal self-organizing authentication network. The fast message encryption / decryption module is used to perform intelligent power distribution terminal message encryption / decryption based on an automatically adaptable message encryption / decryption mechanism, combined with elliptic curve operations and bilinear pairing operations. Within this module, for the intelligent power distribution terminal message protocol characteristics, transmission modes, and real-time requirements in distributed feeder automation no-return-talk mode and differential protection constant-talk mode, a smart power distribution terminal message encryption / decryption strategy for short message and segmented long message types is established. Furthermore, based on vertical and horizontal business characteristics, secure storage of business keys and key indexing are performed. The intelligent terminal local operation and maintenance module is used to establish a near-field security operation and maintenance strategy for intelligent power distribution terminals based on the near-field operation and maintenance needs and security risk control elements of power distribution terminals, and to perform secure local operation and maintenance of intelligent power distribution terminals based on security hardening and data encryption algorithms and security operation and maintenance traffic auditing algorithms. The terminal container security module is used to establish policies for file access control within containers, resource isolation between containers, and resource call restriction between containers and the kernel, based on the kernel-level access control and system call restriction mechanism of the power distribution terminal. This enables comprehensive isolation of container resources from multiple perspectives, ensuring the security of the intelligent power distribution terminal. Specifically, the file access control policy within the container is as follows: First, each file in the container's file system is marked. Then, the access status of each file in the container's file system is observed through simulated operation. This determines the files that the container application needs to access during initialization and stable operation, generating a detailed file access authorization policy. Finally, this policy is combined with manual judgment to eliminate unnecessary data file access restrictions. The inter-container resource isolation strategy is as follows: by analyzing the minimum intersection of files between containers through file access authorization policies and the shared file system mount point mapping of containers, the inter-container resource isolation strategy is derived to eliminate unnecessary shared file access permissions. The specific strategy for restricting resource calls between the container and the kernel is as follows: by placing hooks in the kernel mode, the system calls used by the container application during runtime, excluding normal file system access, are monitored, including the use of sockets, hardware interfaces, and shared memory. This allows the container application to obtain the system permissions it needs to run normally, and ultimately to obtain a kernel resource usage restriction strategy.
2. The security protection system for intelligent power distribution terminals according to claim 1, characterized in that: The terminal identity authentication module includes an identity management unit and an identity authentication unit; The identity management unit adopts Diffie-Hellman key exchange and SM2 key exchange protocols to establish a one-to-one identity authentication protocol between power distribution terminals, thereby realizing secure communication in the existing terminal network structure. A group key negotiation protocol based on elliptic curves and bilinear pairing cryptographic primitives is established to create a one-to-many authentication protocol between power distribution terminals, enabling secure offline interaction between power distribution terminals in the system. Based on the SM9 national cryptographic algorithm, a lightweight authentication protocol is established under an identity-based cryptographic system. A certificate-free trust system is constructed that naturally binds the identity information of terminal devices with public keys. Blockchain technology, zero-knowledge proofs, and commitment protocol cryptographic tools are used to conduct distributed certificate issuance and management based on the system's identity management needs.
3. The security protection system for intelligent power distribution terminals according to claim 2, characterized in that: The identity authentication unit employs terminal device fingerprint extraction technology to store terminal device fingerprint information, access control information, and electrical topology diagrams on the blockchain, enabling efficient and rapid intelligent terminal access and real-time network behavior authentication.
4. The security protection system for intelligent power distribution terminals according to claim 1, characterized in that: The fast message encryption / decryption module analyzes message protocol identifiers, field identifiers, and algorithm identifiers to automatically adapt message encryption / decryption strategies and perform encryption / decryption on different business messages.
5. The security protection system for intelligent power distribution terminals according to claim 4, characterized in that: The intelligent power distribution terminal message encryption and decryption strategy, for short messages, logically integrates key expansion round operations and block encryption round operations through mathematical theoretical derivation and code logic analysis, and coordinates the operation of round key expansion and round operation fusion. For long messages, considering the frequency of single key usage and ciphertext correlation, a context structure suitable for continuous encryption and decryption of long messages is established. The extended key, initialization vector, and authentication variables are dynamically stored, and a three-stage message encryption and decryption process of key initialization + loop encryption and decryption + data authentication is performed.
6. The security protection system for intelligent power distribution terminals according to claim 4, characterized in that: The fast message encryption / decryption module employs a resource-sharing symmetric algorithm to establish intelligent power distribution terminal message encryption / decryption strategies for short messages and segmented long messages. It also performs secure storage and key indexing of business keys based on vertical and horizontal business characteristics. Specifically: First, establish a key-level protection system for intelligent power distribution terminals, classify key types for equipment, applications, and personnel, clarify the responsibilities and scope of use of each key, and realize encrypted key storage within the terminal; Secondly, based on the operational logic of symmetric cryptography algorithms, a lookup table is constructed by integrating nonlinear and linear transformations. According to the characteristics of the hardware platform and the parallelism of the encryption and decryption working modes, fine-grained and coarse-grained parallel control are achieved by using in-round pipeline and block parallel optimization techniques respectively. Finally, a key protection system and indexing mechanism are constructed within the security chip, employing white-box and side-channel attack resistance technologies to ensure the security of business key generation, storage, and use.
7. The security protection system for intelligent power distribution terminals according to claim 4, characterized in that: The fast message encryption / decryption module employs an embedded asymmetric cryptographic algorithm to establish intelligent power distribution terminal message encryption / decryption strategies for short messages and segmented long messages. It also performs secure storage and key indexing of business keys based on vertical and horizontal business characteristics. Specifically: Based on the domestic SM2 and SM9 asymmetric cryptographic algorithms and considering the resource size of the intelligent power distribution terminal hardware platform, an asymmetric cryptographic algorithm module that conforms to the authentication protocol of the intelligent power distribution terminal is designed and implemented to perform signature authentication and public key encryption. The asymmetric cryptography module includes the SM2 elliptic curve cryptosystem and the SM9 bilinear pairing cryptosystem; For the SM2 elliptic curve cryptosystem, a hybrid operation mechanism of affine coordinates and Jacobian coordinates is used to accelerate point group operations, and sliding window and Montgomery ladder constant time implementation techniques are used to optimize point multiplication operations and resist side-channel attacks by power analysis and time analysis. For the SM9 bilinear pairing cryptosystem, the Karatsuba algorithm and cyclic subgroup features are used to construct a finite extended field underlying operation module. Furthermore, the computational overhead of bilinear pairing is reduced through batch modular inversion and multilinear pairing concurrency techniques, thereby realizing identity authentication and data encryption based on the identity cryptosystem.
8. The security protection system for intelligent power distribution terminals according to claim 1, characterized in that: In the intelligent terminal local operation and maintenance module, wireless communication and data encryption are implemented based on security hardening and data encryption algorithms, specifically: First, analyze the security of the SPP protocol and add an encryption process to the application layer; Secondly, to address the security issues of the Bluetooth SPP protocol, a key sequence is generated based on the national cryptographic algorithm to encrypt the application layer, decoupling the underlying protocol and enabling the application layer to encrypt and decrypt data. Finally, in conjunction with existing wireless communication protocols, a dynamic key sequence is used to encrypt the SPP protocol application layer data.
9. The security protection system for intelligent power distribution terminals according to claim 1, characterized in that: In the intelligent terminal local operation and maintenance module, traffic auditing is performed based on a security operation and maintenance traffic auditing algorithm, specifically: First, the data packets and protocols are analyzed to extract communication information, and in conjunction with the protocol specifications, the instruction execution, data parsing, and channel coding of the master and slave devices are obtained. Secondly, the information content is identified by combining the duration of communication and using the location of the management frame data packets. Finally, through feature engineering, traffic analysis, and machine learning, the target identity, operation commands, malicious behavior, and illegal connections are identified and audited.
10. The security protection system for intelligent power distribution terminals according to claim 1, characterized in that: In the terminal container security module, the kernel-level access control and system call restriction mechanisms include SELinux, AppArmor, and Seccomp.
11. A security protection method for intelligent power distribution terminals, the method being implemented based on the system described in any one of claims 1-10, characterized in that: The method includes: A lightweight blockchain-based distributed terminal identity management mechanism based on national cryptographic algorithms is used for lightweight identity management and authentication in power distribution secondary systems. Based on an automatically adaptable message encryption and decryption mechanism, combined with elliptic curve operations and bilinear pairing operations, intelligent power distribution terminal message encryption and decryption is performed. To address the near-field operation and maintenance needs of power distribution terminals and the elements of security risk management, a near-field security operation and maintenance strategy for intelligent power distribution terminals is established. Based on security hardening and data encryption algorithms as well as security operation and maintenance traffic auditing algorithms, a secure local operation and maintenance strategy for intelligent power distribution terminals is implemented. Based on the kernel-level access control and system call restriction mechanism of the power distribution terminal, we establish policies for file access control within containers, resource isolation between containers, and resource call restriction between containers and the kernel. This enables comprehensive isolation of container resources from multiple perspectives on the terminal, ensuring the security protection of intelligent power distribution terminals.
Citation Information
Patent Citations
Dual-system realization system and method for mobile terminal based on Docker containers
CN108446159A
Communication message security interaction method and device of distribution automation system
CN109257327A
Power tower monitoring data encryption method and device based on alliance block chain and Beidou
CN112069520A