Security management method and system, Ukey and nonvolatile storage medium

By binding the Ukey to the management server and transmitting authorized encrypted files, combined with the authentication of the KVM gateway device, the problem of lack of control over the host information security of the substation system is solved. Centralized management of the Ukey and monitoring of abnormal operations are realized, improving the security and traceability of the system.

CN117201166BActive Publication Date: 2026-02-10STATE GRID BEIJING ELECTRIC POWER CO +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311281007.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-28
Publication Date
2026-02-10
Estimated Expiration
2043-09-28

AI Technical Summary

Technical Problem

The information security and operational security of the substation power monitoring system host lack effective control measures, especially the account password authentication method, which has security vulnerabilities, is easy to attack and difficult to manage.

Method used

By binding a Ukey to a management server, the management server transmits an authorized encrypted file to remove the masking software's obfuscation of the system host. Combined with a KVM gateway device for authentication and operation control, centralized management and authorization of the Ukey are achieved.

Benefits of technology

This improved the information security management level of the substation system host, standardized the use and operation of Ukey, realized centralized management of Ukey and real-time monitoring of abnormal operations, and ensured the security and traceability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117201166B_ABST
    Figure CN117201166B_ABST
Patent Text Reader

Abstract

The application discloses a kind of safe management and control method, system, Ukey and nonvolatile storage medium.Therein, the method includes: in the case where connection is established with management server, the personal information and work information of target personnel are transmitted to management server, wherein the management server is used to manage the Ukey of transformer substation, the Ukey is bound with target personnel, and the Ukey is used to remove the shielding of shielding software in the system host of transformer substation system from the system host;Receive the authorized encrypted file fed back by the management server, wherein the authorized encrypted file corresponds to the target host in the system host;Disconnect the connection with the management server, and establish the connection with the target host;The authorized encrypted file is transmitted to the target host, and the target host removes the shielding of shielding software from the target host after verifying the legality of the authorized encrypted file.The application solves the technical problem that the information security and use security of the system host of transformer substation lack effective control means.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of substation information security, in particular to a security management method and system, a Ukey and a nonvolatile storage medium. BACKGROUND

[0002] The host of a substation power monitoring system is mostly authenticated by an account password, which has serious security problems and is the most vulnerable target for attackers. Since it is a single-factor authentication, the security only depends on the password, and once the password is leaked, the user can be impersonated. More seriously, the user often chooses a simple and easy-to-guess password, which poses a serious security risk to the system.

[0003] At present, there is no effective solution to the above problems. SUMMARY

[0004] The embodiments of the present application provide a security management method and system, a Ukey and a nonvolatile storage medium to at least solve the technical problem of lack of effective management means for the information security and use security of the system host of a substation.

[0005] According to one aspect of the embodiments of the present application, a security management method is provided, comprising: transmitting personal information and work information of a target person to a management server in a case of establishing a connection with the management server, wherein the management server is used to manage a Ukey of a substation, the Ukey is bound to the target person, and the Ukey is used to remove the shielding of a shielding software in a target host of the substation system host; receiving an authorized encrypted file fed back by the management server, wherein the authorized encrypted file corresponds to the target host; disconnecting the connection with the management server and establishing a connection with the target host; and transmitting the authorized encrypted file to the target host, wherein the target host removes the shielding of the shielding software after verifying that the authorized encrypted file is legal.

[0006] Optionally, the management server pre-records a device number of the Ukey and an authorized user of the Ukey, and the management server verifies the Ukey according to the device number and determines whether the personal information of the target person matches the authorized user in a case of establishing a connection with the Ukey; and in a case that the Ukey passes the verification and the target person matches the authorized user, the management server transmits the authorized encrypted file to the Ukey, wherein the authorized encrypted file includes a unique host identifier of the target host, and the authorized encrypted file is used to remove the shielding of the shielding software in the target host.

[0007] Optionally, the authorized encrypted file may further include at least one of the following: the name of the management department corresponding to the target personnel, the name of the target personnel, the device number of the Ukey, the unique serial number of the masking software, and the release time limit; wherein, the unique serial number of the masking software is generated based on the unique host identifier of the target host, and the release time limit is the time interval for releasing the masking software from masking the target host.

[0008] Optionally, the release time limit is determined by the management server based on the work information and written into the authorized encryption file, and the time unit of the release time limit includes at least one of the following: day, hour, minute.

[0009] Optionally, transmitting the authorized encrypted file to the target host includes: inserting the UKey into the KVM gateway device corresponding to the target host; transmitting the authorized encrypted file to the KVM device via the UKey, wherein the KVM gateway device is used to transmit the authorized encrypted file to the target host, and upon receiving the identity recognition information returned by the masking software after verifying the authorized encrypted file, to remove the screen masking of the target host and release the keyboard and mouse mapping of the target host.

[0010] Optionally, the above method further includes: the KVM gateway device monitoring the insertion status of the UKey, and disconnecting the operation command to the target host and re-masking the target host after the UKey is removed.

[0011] According to another aspect of the present invention, a Ukey is also provided, the Ukey including a stored program, wherein the program controls the Ukey to execute any of the security management methods described above when it is running.

[0012] According to another aspect of the present invention, a security management system is also provided, including: a management server, a target host, and the aforementioned UKey, wherein the target host is one of the substation system hosts.

[0013] Optionally, the security management system further includes a KVM gateway device, wherein the KVM gateway device corresponds to the target device and is used to control the screen display and keyboard and mouse mapping of the target host.

[0014] According to another aspect of the present invention, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored program, wherein, when the program is executed, the device where the non-volatile storage medium is located is controlled to perform any of the above-described security management methods.

[0015] According to another aspect of the present invention, a computer device is also provided, the computer device including a memory and a processor, the memory being used to store a program, and the processor being used to run the program stored in the memory, wherein the program executes any of the security control methods described above when it is run.

[0016] In this embodiment of the invention, a complete UKey-related management scheme is adopted. The personal and work information of the target personnel is transmitted to a management server. The management server manages the UKeys of the substation, and each UKey is bound to a target personnel. The UKey is used to remove the masking software from the substation system host. The system host receives an authorized encrypted file from the management server, which corresponds to the target host in the system host. The connection with the management server is disconnected, and a connection with the target host is established. The authorized encrypted file is transmitted to the target host, which, after verifying the validity of the authorized encrypted file, removes the masking software from the target host. This achieves the goal of securely and compliantly removing the masking from the substation system host, thereby improving the technical effect of information security management of the substation system host and solving the technical problem of lacking effective control measures for the information security and operational security of the substation system host. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0018] Figure 1 This is a flowchart illustrating the security control method provided according to an embodiment of the present invention;

[0019] Figure 2 This is a schematic diagram of the connection relationship of a KVM gateway device according to an optional embodiment of the present invention;

[0020] Figure 3 This is a schematic diagram of the architecture of the UKey security management method provided by an optional embodiment of the present invention;

[0021] Figure 4 This is a structural block diagram of a safety control device provided according to an embodiment of the present invention. Detailed Implementation

[0022] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0024] To facilitate the identification of operators of substation system mainframes and ensure the reliability and accountability of subsequent operations, this invention provides an embodiment that uses a hardware U-key to control user access, such as for remote authorization and identity verification. Currently, in most cases, the U-key is assigned to users with appropriate permissions. When used, the U-key is inserted into the host computer's USB port, and after verifying identity, the user can operate the mainframe for business operations. After use, the operator keeps the U-key or returns it to the relevant department for safekeeping.

[0025] The above process may have the following defects and deficiencies: 1. Chaotic account management. The account system is poorly managed, with shared accounts, weak password accounts, zombie accounts, and temporary accounts scattered everywhere, making unified management impossible. 2. Improper UKey storage. A large number of UKeys are stored separately by multiple employees, and the storage process is poorly supervised, resulting in UKeys being placed haphazardly and stored in disarray. 3. Non-standard UKey usage. For example, operators use UKeys to access the system host outside of working hours or by unauthorized personnel. Or, after completing business operations, operators fail to sign out promptly as required, and the signed-out items are not stored properly. 4. Incomplete UKey control mechanism. The traditional model relies on human supervision and simple ledgers to record UKey storage and usage, but the process of personnel storage and UKey usage cannot be effectively controlled. 5. Delayed identification of abnormal risks. Due to the lack of effective real-time control measures, abnormal UKey usage is not detected in a timely manner, and the cause is difficult to determine due to the lack of relevant records.

[0026] To address the aforementioned problems, this invention proposes a Ukey security management method and system for the main unit of a substation power monitoring system. The equipment in the substation includes transformers, circuit breakers, disconnect switches, grounding switches, capacitors, reactors, surge arresters, current transformers, voltage transformers, etc. The main unit is a host device capable of connecting to a display screen, and may include a monitoring system host, a protection device host, an automation control host, etc. These host devices are typically equipped with displays for showing and monitoring the substation's operating status, power parameters, alarm information, etc.

[0027] Figure 1 This is a flowchart illustrating the security control method provided according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:

[0028] Step S102: With a connection established with the management server, the personal and work information of the target personnel is transmitted to the management server. The management server is used to manage the Ukey of the substation. The Ukey is bound to the target personnel and is used to remove the masking software in the substation system host from the system host.

[0029] It's important to note that a Ukey is a hardware device, short for USB Key (Universal Serial BusKey), also known as a USB encryption lock or USB security lock. It's a portable storage device used to store and protect sensitive data. Ukeys are typically provided with a USB interface and can be plugged into computers, laptops, or other USB-enabled devices. Internally, it integrates encryption and storage chips for encrypting, storing, and protecting data. Its main functions include: 1. Data Storage: Ukeys can be used as portable storage devices where users can store files, documents, photos, and other data. 2. Data Encryption: The built-in encryption chip in the Ukey encrypts and protects the data stored within, ensuring confidentiality and security. 3. Authentication and Authorization: Ukeys can be used for identity authentication and authorized access; users need to insert the correct Ukey to access protected resources or systems. 4. Application Expansion: Ukeys can also be integrated with various applications, such as digital signatures, encryption / decryption tools, VPN clients, etc., providing more functions and services.

[0030] Ukey is widely used in the field of information security, especially in scenarios requiring high security and data protection, such as finance, e-commerce, and government agencies. It can effectively protect the confidentiality of user data, provide secure authentication and access control, and prevent data leaks and unauthorized access.

[0031] Step S104: Receive the authorization encryption file fed back by the management server, wherein the authorization encryption file corresponds to the target host in the system host.

[0032] Step S106: Disconnect from the management server and establish a connection with the target host.

[0033] Step S108: The authorized encrypted file is transmitted to the target host, wherein the target host removes the masking software from the target host after verifying the legality of the authorized encrypted file.

[0034] Through the above steps, a complete UKey-related management scheme is adopted. This involves transmitting the target personnel's personal and work information to a management server. The management server manages the substation's UKeys, which are bound to the target personnel. The UKeys are used to remove the masking software from the substation's system host. The system host receives an authorized encrypted file from the management server, which corresponds to the target host within the system host. The connection with the management server is then disconnected, and a connection with the target host is established. The authorized encrypted file is transmitted to the target host, which, after verifying the file's validity, removes the masking software. This achieves the goal of securely and compliantly removing the masking from the substation's system host, thereby improving the technical level of information security management for the substation's system host. Ultimately, this solves the technical problem of lacking effective control measures for the information security and operational security of the substation's system host.

[0035] In the above embodiments, the safety management system can deploy screen masking software on the operating system of various versions of the substation system host. The masking software is deployed according to the relevant version of the operating system after manual confirmation. After installation, the full-screen display priority of the masking software is at the top of all programs, and it captures the keyboard and mouse focus into the input box. The masking software works in conjunction with a UKey; inserting the UKey automatically removes the masking and releases the keyboard and mouse focus. Removing (unplugging) the UKey automatically masks the screen and captures the keyboard and mouse focus.

[0036] Each host is equipped with a screen masking software, which has a unique serial number across the entire network. The serial number is composed of 11 independent numbers and characters. The masking software has a built-in super user and password. The user and password fields on the login window of the masking software are not displayed and are entered silently. The super user and password are authorized using a UKey. The independent UKey has a time-limited authorization. The timer starts when the UKey is inserted. After the time limit expires, the screen masking function will be activated regardless of whether the UKey is inserted.

[0037] The management server records the device number and authorized user for each UKey. UKeys are bound to authorized users. Authorization hosts and time limits for UKeys are restricted based on work content, with time limits specified in dates, hours, and minutes. The management server configures a ledger of all monitoring host screen-masking software within the substation and configures a maintenance interface based on the substation directory tree. The management server has flexible authorization capabilities for UKeys. UKeys can be authorized to unmask monitoring hosts in different locations. The serial numbers of the screen-masking software within the substation match the serial numbers recorded on the management server. Different screen-masking software within the same substation can be authorized separately as needed. The management server is configured with a USB concentrator for centralized management of UKey devices. The management server automatically recognizes the inserted UKey device number and associates it with the screen-masking software serial number on the authorization server to complete the authorization.

[0038] A software asset register is a tool or document used to record and manage all software assets within an organization. It's a centralized database or document storing software asset information, used to track and monitor software resources used within the organization. A software register typically includes the following information: 1. Software Name and Version: Records basic information such as the name, version number, and publisher of each software. 2. License Information: Records the license type, number of licenses, and expiration date for each software to ensure compliance and legality. 3. Installation Location: Records the installation location of each software within the organization, including servers, workstations, or other devices. 4. User Information: Records the users of each software for licensing and license allocation. 5. Purchase Information: Records the purchase date, supplier, and purchase price of the software for financial management and budget planning. 6. Update and Maintenance Information: Records the software's update and maintenance status, including update dates and version updates, to ensure the software is kept up-to-date.

[0039] As an optional embodiment, the management server pre-records the device number of the Ukey and the authorized user corresponding to the Ukey. When the management server establishes a connection with the Ukey, it verifies the Ukey based on the device number and determines whether the personal information of the target user matches the authorized user. If the Ukey is verified and the target user matches the authorized user, the management server receives the authorization encrypted file transmitted to the Ukey. The authorization encrypted file includes the unique identifier of the target host and is used to remove the masking software from the target host.

[0040] Compared with the prior art, the present invention has the following technical effects:

[0041] 1. The system enables better centralized management, application authorization, and operation monitoring of UKeys, standardizing UKey device management and operator information verification. Administrators can comprehensively review UKey usage, host operation records, and abnormal operations in real time, making the usage of the entire substation power monitoring system's host traceable, thus ensuring greater security and standardization.

[0042] 2. The system boasts high installation reliability, does not affect the operation of existing power business systems, and does not alter the wiring of existing business systems. In the event of a KVM gateway failure, the masking software can operate independently. The KVM gateway only audits video signal recordings and does not perform any control functions.

[0043] As an optional embodiment, the authorized encryption file may also include at least one of the following: the name of the management department corresponding to the target personnel, the name of the target personnel, the device number of the Ukey, the unique serial number of the masking software, and the release time limit; wherein, the unique serial number of the masking software is generated based on the unique host identifier of the target host, and the release time limit is the time interval for releasing the masking software from masking the target host.

[0044] As an optional embodiment, the release time limit is determined by the management server based on the work information and written into the authorized encryption file. The time unit for the release time limit includes at least one of the following: day, hour, minute.

[0045] As an optional embodiment, transmitting the authorized encrypted file to the target host includes: inserting a UKey into the KVM gateway device corresponding to the target host; transmitting the authorized encrypted file to the KVM device via the UKey, wherein the KVM gateway device is used to transmit the authorized encrypted file to the target host, and upon receiving the identity recognition information returned after the masking software verifies the authorized encrypted file, to remove the screen masking of the target host and release the keyboard and mouse mapping of the target host.

[0046] A KVM gateway is a device used to manage and control remote servers. It can connect to multiple servers over a network and allow users to access and manage these servers through a unified interface.

[0047] KVM is an abbreviation for Keyboard, Video, and Mouse. A KVM gateway typically has multiple KVM ports, which can connect to the keyboard, monitor, and mouse interfaces of multiple servers. Through a KVM gateway, users can remotely access and control these servers over the network, just as if they were directly connected to them.

[0048] KVM gateways typically offer additional features such as remote power management, virtual media support (allowing for remote loading and installation of operating systems), remote console recording and playback, etc. They can simplify server management, improve the efficiency of remote maintenance, and reduce the need for physical access to servers.

[0049] In summary, a KVM gateway is a device for remotely accessing and controlling servers. It provides keyboard, video, and mouse interfaces, as well as other features, enabling users to remotely manage multiple servers.

[0050] As an optional implementation, the KVM gateway device monitors the insertion status of the UKey, and disconnects the operation command to the target host and re-masks the target host after the UKey is removed.

[0051] According to an embodiment of the present invention, a Ukey is also provided. The Ukey includes a stored program, wherein the program controls the Ukey to execute any of the above-described security management methods during runtime.

[0052] According to an embodiment of the present invention, a security management system is also provided, including: a management server, a target host, and the aforementioned UKey, wherein the target host is one of the substation system hosts.

[0053] Optionally, the security management system also includes a KVM gateway device, which corresponds to the target device and is used to control the screen display and keyboard and mouse mapping of the target host.

[0054] Figure 2 This is a schematic diagram of the connection relationship of a KVM gateway device according to an optional embodiment of the present invention. Figure 3 This is a schematic diagram of the architecture of a UKey security management method provided according to an optional embodiment of the present invention. Based on Figure 2 and Figure 3 The present invention provides the following optional implementation methods, as shown in the optional embodiments:

[0055] 1. Substation main unit security authorization software:

[0056] The authorization software is installed on the management server, recording the device number and authorized user of each UKey. The UKey is then bound to the authorized user. The authorized host and authorization period are restricted based on the job content, with the authorization period specified in dates, hours, and minutes.

[0057] The authorized software contains a complete list of monitoring host masking software within the substation, and configures the maintenance interface based on the substation's directory tree.

[0058] The authorization software allows for flexible authorization to the UKey. The UKey can be authorized to disable the screen-masking function of monitoring hosts at different locations. The serial number of the screen-masking software within the substation matches the serial number recorded on the management server. Furthermore, different screen-masking software within the same substation can be authorized separately as needed. The UKey can simultaneously authorize multiple stations and different hosts (one-to-many).

[0059] The licensed software must be able to set management department information (the name of the management department that generates the license file).

[0060] After the software is authorized, an encrypted authorization file is generated (the content must include: the name of the management department, the name of the user, the UKey device number, the unique number of the masking software, and the time limit). The file can be generated directly on the local machine or copied to the corresponding UKey; or it can be transmitted to the authorized user through the internal secure network, and the user can then copy the encrypted authorization file to the corresponding UKey.

[0061] The authorized software has the function of generating a superuser password for a specified masking software. The password must include the authorization period. The software also records the users of the superuser account.

[0062] 2. Substation internal host shielding software:

[0063] The shielding software is installed on the host computer inside the substation. Each host computer is equipped with one set of shielding software. Based on the host computer's unique hardware device number, a unique serial number for the shielding software is generated. The serial number is composed of 11 independent numbers and characters.

[0064] The screen masking software is deployed according to the specific operating system version after manual verification. Once installed, the software must be displayed full-screen on top of all programs and capture keyboard and mouse focus within the login box. The software works in conjunction with a UKey; inserting the UKey automatically removes the mask and releases keyboard and mouse focus. Removing (unplugging) the UKey, or if the UKey becomes invalid (exceeding the set time limit), automatically masks the screen and captures keyboard and mouse focus.

[0065] The time limit reference time is the time of the computer host with the masking software installed.

[0066] In case of UKey failure or other emergencies, the super authorization mode can be used in an emergency. The authorized administrator uses the authorization software to generate a super user password and informs the authorized user of the super account password by phone.

[0067] The masking software has a built-in superuser password decryption algorithm that can decrypt the superuser password generated by the authorized software, obtain the authorization time limit, and match it with the masking software. The password field in the masking software does not display characters, allowing for silent input. In superuser mode, if there is no keyboard or mouse operation for 10 minutes (configurable), the screen will be automatically masked until the next superuser password is entered or a UKey is inserted.

[0068] After each use, the computer's USB port must be closed. When you unplug the UKey, a large message (red text on a yellow background, bold, 36-point font) will appear on the screen blocking software indicating that the USB port is closed. The message will disappear after 10 seconds. When you plug the UKey back in, the message will disappear immediately.

[0069] The network security monitoring device whitelists UKey insertion behavior and does not trigger alarms.

[0070] The masking software needs to record UKey usage logs, including the name of the authorized management department, the name of the user, the insertion time, and the removal time. It should also record the superuser's usage time.

[0071] The screen-masking software has the function of detecting USB flash drive insertion and preventing it from running automatically. When a non-UKey flash drive is inserted, if it has been authorized, the screen will be automatically masked again (to prevent the user from operating the flash drive) and a prompt will appear indicating that the flash drive will be formatted (it can identify non-local authorized UKeys and prompt accordingly). When the user confirms the formatting of the flash drive or the user removes the flash drive, the screen masking will automatically exit if it has been authorized.

[0072] 3. UKey:

[0073] UKey does not have wireless communication capabilities. It can only transfer data via a USB port. To save costs and reduce software complexity, UKey uses a common USB flash drive. The flash drive needs a unique hardware device number for binding with authorized users and generating encrypted authorization files.

[0074] 4. KVM Gateway

[0075] Add a KVM gateway for each host in the station. Connect the keyboard, mouse and monitor of the backend host to the KVM gateway first, and then map them to the backend host. At the same time, connect the KVM gateway as a station control device to the station control layer network.

[0076] The system assigns a unique identification code to both the KVM gateway and the masking software on the backend host. The KVM gateway and the masking software communicate via the station control network to achieve one-way authentication of the backend host. It controls the keyboard and mouse by detecting whether a Ukey is inserted and extracting the maintenance information from it, and audits the monitor video and keyboard input information in real time. The masking software manages screen masking by recognizing the keyboard and mouse information on the backend host. The KVM gateway is the main entity managing the physical signals of the video signal, keyboard, and mouse. Its primary functions include authenticating the masking software and Ukey, maintaining and auditing the video signal, controlling and auditing keyboard and mouse signals based on the maintenance information in the Ukey, and providing time synchronization functionality.

[0077] The KVM gateway monitors the identity information of the masking software in real time and performs one-way authentication. After successful authentication, it begins real-time detection of the UKey. If the masking software's identity signal is lost, it is considered an authentication failure, and the task will automatically end when there are maintenance tasks.

[0078] After the KVM gateway detects the UKey insertion, it performs an integrity check on the XML file within it. If the check passes, it extracts the operation and maintenance management information and performs a preliminary verification based on the identity recognition information to determine if the operation and maintenance objects in the file include the current backend host. Upon successful verification, it controls keyboard and mouse mapping based on the work ticket time range and performs auditing.

[0079] The KVM gateway synchronizes time through the station control layer network and the station's internal synchronous clock to verify the validity of the start and end times of maintenance in the XML file.

[0080] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0081] Through the above description of the embodiments, those skilled in the art can clearly understand that the security control method according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0082] According to embodiments of the present invention, a security control device for implementing the above-described security control method is also provided. Figure 4 This is a structural block diagram of a safety control device provided according to an embodiment of the present invention, such as... Figure 4 As shown, the security control device includes: a first transmission module 42, a receiving module 44, a connection establishment module 46, and a second transmission module 48. The security control device will be described below.

[0083] The first transmission module 42 is used to transmit the personal and work information of the target personnel to the management server when a connection is established with the management server. The management server is used to manage the Ukey of the substation. The Ukey is bound to the target personnel and is used to remove the masking software in the substation system host from the system host.

[0084] The receiving module 44 is connected to the first transmission module 42 and is used to receive the authorized encrypted file fed back by the management server, wherein the authorized encrypted file corresponds to the target host in the system host;

[0085] Establish connection module 46, connected to receiving module 44, is used to disconnect from the management server and establish a connection with the target host;

[0086] The second transmission module 48, connected to the connection establishment module 46, is used to transmit the authorized encrypted file to the target host. The target host removes the masking software from the target host after verifying the legality of the authorized encrypted file.

[0087] It should be noted that the first transmission module 42, the receiving module 44, the connection establishment module 46, and the second transmission module 48 mentioned above correspond to steps S102 to S108 in the embodiments. The four modules and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments.

[0088] Embodiments of the present invention may provide a computer device. Optionally, in this embodiment, the computer device may be located in at least one of a plurality of network devices in a computer network. The computer device includes a memory and a processor.

[0089] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the security control method and device in this embodiment of the invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned security control method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0090] The processor can access information and applications stored in memory via a transmission device to perform the following steps: When a connection is established with the management server, the personal and work information of the target personnel is transmitted to the management server, whereby the management server manages the substation's Ukey, which is bound to the target personnel and used to remove the masking software from the substation's system host; the processor receives an authorized encrypted file from the management server, whereby the authorized encrypted file corresponds to the target host in the system host; the processor disconnects from the management server and establishes a connection with the target host; the processor transmits the authorized encrypted file to the target host, whereby the target host removes the masking software from the target host after verifying the validity of the authorized encrypted file.

[0091] Optionally, the processor may also execute program code for the following steps: the management server pre-records the device number of the Ukey and the authorized user corresponding to the Ukey; when the management server establishes a connection with the Ukey, it verifies the Ukey based on the device number and determines whether the personal information of the target user matches the authorized user; when the Ukey is verified and the target user matches the authorized user, the management server receives the encrypted authorization file transmitted to the Ukey, wherein the encrypted authorization file includes the unique identifier of the target host and is used to remove the masking software from the target host.

[0092] Optionally, the processor may also execute program code that includes the following steps: the authorized encrypted file may also include at least one of the following: the name of the management department corresponding to the target personnel, the name of the target personnel, the device number of the Ukey, the unique serial number of the masking software, and the release time limit; wherein, the unique serial number of the masking software is generated based on the unique host identifier of the target host, and the release time limit is the time interval for releasing the masking software from masking the target host.

[0093] Optionally, the processor may also execute program code that performs the following steps: the time limit is determined by the management server based on the work information and written into the authorization encryption file, and the time unit for the time limit removal includes at least one of the following: day, hour, minute.

[0094] Optionally, the processor may also execute program code for the following steps: transmitting the authorized encrypted file to the target host, including: inserting the UKey into the KVM gateway device corresponding to the target host; transmitting the authorized encrypted file to the KVM device via the UKey, wherein the KVM gateway device is used to transmit the authorized encrypted file to the target host, and upon receiving the identity recognition information returned after the masking software verifies the authorized encrypted file, removes the screen masking of the target host and releases the keyboard and mouse mapping of the target host.

[0095] Optionally, the processor may also execute program code that performs the following steps: the KVM gateway device monitors the insertion status of the UKey, disconnects the operation command to the target host after the UKey is removed, and re-masks the target host.

[0096] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a non-volatile storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0097] Embodiments of the present invention also provide a non-volatile storage medium. Optionally, in this embodiment, the non-volatile storage medium can be used to store the program code executed by the security control method provided in the above embodiments.

[0098] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.

[0099] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: Upon establishing a connection with the management server, transmitting the target personnel's personal and work information to the management server, wherein the management server manages the substation's Ukey, the Ukey is bound to the target personnel, and the Ukey is used to remove the masking software from the substation system host; receiving an authorized encrypted file from the management server, wherein the authorized encrypted file corresponds to the target host in the system host; disconnecting from the management server and establishing a connection with the target host; transmitting the authorized encrypted file to the target host, wherein the target host removes the masking software from the target host after verifying the validity of the authorized encrypted file.

[0100] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: the management server pre-records the device number of the Ukey and the authorized user corresponding to the Ukey; when the management server establishes a connection with the Ukey, it verifies the Ukey based on the device number and determines whether the personal information of the target user matches the authorized user; when the Ukey is verified and the target user matches the authorized user, the management server receives an authorized encrypted file transmitted to the Ukey, wherein the authorized encrypted file includes the host unique identifier of the target host and is used to remove the masking software from the target host.

[0101] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: the authorized encryption file further includes at least one of the following: the name of the management department corresponding to the target personnel, the name of the target personnel, the device number of the Ukey, the unique serial number of the masking software, and the release time limit; wherein, the unique serial number of the masking software is generated based on the unique identifier of the target host, and the release time limit is the time interval for releasing the masking software from masking the target host.

[0102] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: the release time limit is determined by the management server based on the work information and written into the authorized encryption file, and the time unit of the release time limit includes at least one of the following: day, hour, minute.

[0103] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: transmitting the authorized encrypted file to the target host, including: inserting the UKey into the KVM gateway device corresponding to the target host; transmitting the authorized encrypted file to the KVM device by the UKey, wherein the KVM gateway device is used to transmit the authorized encrypted file to the target host, and upon receiving the identity recognition information returned after the masking software verifies the authorized encrypted file, to remove the screen masking of the target host and release the keyboard and mouse mapping of the target host.

[0104] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: the KVM gateway device monitors the insertion status of the UKey, and disconnects the operation command to the target host and re-masks the target host after the UKey is removed.

[0105] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0106] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0107] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0108] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0109] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0110] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0111] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A safety management and control method, characterized in that, include: Once a connection is established with the management server, the personal and work information of the target personnel is transmitted to the management server. The management server is used to manage the Ukey of the substation, the Ukey is bound to the target personnel, and the Ukey is used to remove the masking software in the substation system host from the system host. The system receives an authorized encrypted file from the management server, wherein the authorized encrypted file corresponds to the target host in the system host. Disconnect from the management server and establish a connection with the target host; The authorized encrypted file is transmitted to the target host, wherein the target host removes the masking software from the target host after verifying the legitimacy of the authorized encrypted file; The step of transmitting the authorized encrypted file to the target host includes: inserting the Ukey into the KVM gateway device corresponding to the target host; transmitting the authorized encrypted file to the KVM gateway device using the Ukey, wherein the KVM gateway device is used to transmit the authorized encrypted file to the target host, and upon receiving the identity recognition information returned after the masking software verifies the authorized encrypted file, to remove the screen masking of the target host and release the keyboard and mouse mapping of the target host; The method further includes: the KVM gateway device monitoring the insertion status of the Ukey, and disconnecting the operation command to the target host and re-masking the target host after the Ukey is removed.

2. The method according to claim 1, characterized in that, The management server pre-records the device number of the Ukey and the authorized user corresponding to the Ukey. When the management server establishes a connection with the Ukey, it verifies the Ukey based on the device number and determines whether the personal information of the target user matches the authorized user. If the Ukey is verified and the target user matches the authorized user, the management server receives the authorization encrypted file transmitted to the Ukey. The authorization encrypted file includes the unique host identifier of the target host and is used to remove the masking software from the target host.

3. The method according to claim 2, characterized in that, The authorized encrypted file also includes at least one of the following: the name of the management department corresponding to the target personnel, the name of the target personnel, the device number of the Ukey, the unique serial number of the masking software, and the release time limit; wherein, the unique serial number of the masking software is generated based on the unique host identifier of the target host, and the release time limit is the time interval for releasing the masking software from masking the target host.

4. The method according to claim 3, characterized in that, The expiration time limit is determined by the management server based on the work information and written into the authorized encryption file. The time unit of the expiration time limit includes at least one of the following: day, hour, minute.

5. A computer device, the computer device comprising a memory and a processor, the memory for storing a program, and the processor for running the program stored in the memory, wherein, When the program runs, it executes the security control method described in any one of claims 1-4.

6. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, wherein, when the program is executed, it controls the device containing the non-volatile storage medium to perform the security management method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Safety authentication method applied to multi-unit server management

    CN103067176A

  • Server management method and device, electronic equipment and readable storage medium

    CN113765712A

  • Identity authentication method and device, computer readable storage medium and computer equipment

    CN116662957A