A redundant safety isolation and protection system

By building a redundant safety isolation protection system and using multiple safety isolation devices to standby each other, the communication instability caused by failures during power station data integration is solved, and the stability and availability of data aggregation is improved without adding devices.

CN117319013BActive Publication Date: 2025-07-29POWERCHINA HUADONG ENG CORP LTD +1

Patent Information

Application Number
CN202311213175.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-19
Publication Date
2025-07-29
Estimated Expiration
2043-09-19

AI Technical Summary

Technical Problem

In the process of power station data integration, the communication cannot be stable when the safety isolation device fails, and the backup communication link increases construction costs and does not fully utilize the existing interfaces, resulting in unstable data integration.

Method used

Without adding a secure isolation device, a redundant secure isolation protection system is built, and multiple secure isolation devices are used to be backups for each other, forming a main and backup communication link, and realizing the stability of data transmission through TCP direct connection and file forwarding.

Benefits of technology

When partial interfaces or single unit of the safety isolation device fail, ensure the stable data interaction between each safety partition, improve the stability and availability of power station data aggregation, and meet the safety protection regulations of the power monitoring system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117319013B_ABST
    Figure CN117319013B_ABST
Patent Text Reader

Abstract

The present invention provides a redundant security isolation and protection system, which includes a first acquisition server, an industrial firewall, a first forward security isolation device or a first reverse security isolation device located in the production control area, a second acquisition server, a second forward security isolation device or a second reverse security isolation device located in the non-production control area, and a third acquisition server located in the management information area. Without adding or changing the common triangular topology structure of the power station, the present invention fully exploits the capabilities of existing security isolation devices. On the basis of meeting the safety protection regulations of the national power monitoring system, a redundant security isolation and protection system is constructed based on the common triangular topology structure. By using multiple security isolation devices as backups for each other, it can achieve stable data interaction in each security zone in the case of partial interface failures of the security isolation devices or failures of a single security isolation device, and can effectively improve the stability of data aggregation and the availability of data in the power station.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a redundant security isolation and protection system. Background Art

[0002] The construction of a new power system with wind power and photovoltaic power as the main body has become the development goal of China's power industry. However, with the large-scale and intermittent access of wind power and photovoltaic power sources to the power grid, the safe and stable operation of the power grid has been greatly impacted. How to ensure the safe and stable operation of the power grid has become a new challenge faced by China's power industry. As a new form of energy covering all links of the source, grid, load, and storage, the intelligent energy system and integrated energy service regulate the flow of various energy categories in each link of the energy system through digital means, and it is an effective security guarantee technology in the process of building a new power system. In this process, each energy power station needs to carry out operation optimization management work based on data-driven, so there is a need for massive data aggregation and mining in the power station, which is also the only way to realize the data value of the power station. The above-mentioned data aggregation and mining work is generally carried out in the management information sub-region.

[0003] At present, after long-term development in the industry, various types of energy plants have formed numerous automated and informatized business systems. According to the "Regulations on the Security Protection of Power Monitoring Systems" and the "Guidelines for the Network Security Protection of Power Monitoring Systems (GB / T 36572-2018)", the power station network is divided into a production control area and a management information area. Among them, the production control area is further divided into a production control zone and a production non-control zone. A firewall is deployed between the production control zone and the production non-control zone to achieve logical isolation, and a one-way (forward and reverse) security isolation device is deployed between the production control area and the management information area to achieve or approach physical isolation. The topological structures of the connections of the power monitoring system security zones include chain, triangle, and star structures. The above-mentioned business systems are scattered in each security zone of the power station, and data needs to be integrated across security zones to the management information area through security devices. Among them, the forward security isolation device supports two data sending methods: TCP direct connection and file forwarding, and the reverse security isolation device only supports one data sending method: file forwarding. The TCP direct connection transmission method completes direct communication between the internal and external networks through a virtual IP, and the isolation device returns the success or failure result of the TCP communication in the form of a single bit. In the file forwarding transmission method, the forward security isolation device forwards the text files in the specified folder on the internal network server to the specified folder on the external network server. If the forwarding is successful, the file on the internal network server is deleted; if it fails, the file is not deleted. Therefore, it can be judged whether the forwarding is successful based on whether the file is deleted, and the reverse security isolation device is vice versa. Currently, power stations generally integrate the data of control systems such as the computer monitoring system in the production control area and monitoring systems such as the unit status monitoring system in the production non-control area in the management information area. Therefore, the triangle topology structure is generally adopted to achieve data integration from the production control area to the management information area and from the production non-control area to the management information area. In this process, security devices, especially security isolation devices, have become a bottleneck affecting the data integration of many business systems. Although security isolation devices all provide multiple internal network interfaces and external network interfaces as backup interfaces, it is still inevitable that all interfaces cannot communicate in the case of equipment failures, and manual on-site switching is required when some interfaces fail. How to ensure the stability of data integration has become a major problem.

[0004] Chinese Patent CN111724276A discloses a power plant data transmission method and system integrating self-diagnosis and channel optimization, which provides an additional set of forward and reverse security isolation devices as a backup communication link for data integration from the production control area to the management information area. Its disadvantages are that a backup communication link is constructed by increasing the construction cost, the data cross-region transmission requirements of various monitoring systems in the production non-control area are not considered, and the interfaces of the already configured security isolation devices are not fully utilized. Summary of the Invention

[0005] In view of the deficiencies in the existing technology, combined with the characteristics of the commonly used triangular topology structure in power stations and the multiple available interface structures on the safety isolation device, the present invention provides a redundant safety isolation and protection system to exploit the capabilities of existing devices without adding safety isolation devices and achieve stable integration of data in each safety zone of the power station.

[0006] To achieve the above object, the present invention adopts the following technical solutions:

[0007] A redundant safety isolation and protection system, comprising:

[0008] - A first acquisition server, an industrial firewall, and a first forward safety isolation device located in the production control area;

[0009] - A second acquisition server and a second forward safety isolation device located in the non-production control area;

[0010] - A third acquisition server located in the management information area;

[0011] The first acquisition server, the industrial firewall, and the second acquisition server are connected in sequence to form a communication link between the production control area and the non-production control area;

[0012] The first acquisition server, the first forward safety isolation device, and the third acquisition server are connected in sequence to form a primary communication link from the production control area to the management information area;

[0013] The second acquisition server, the second forward safety isolation device, and the third acquisition server are connected in sequence to form a primary communication link from the non-production control area to the management information area;

[0014] The first acquisition server, the industrial firewall, the second forward safety isolation device, and the third acquisition server are connected in sequence to form a standby communication link from the production control area to the management information area.

[0015] While adopting the above technical solutions, the present invention can also adopt or combine the following technical solutions:

[0016] As a preferred technical solution of the present invention: The second acquisition server, the industrial firewall, the first forward safety isolation device, and the third acquisition server are connected in sequence to form a standby communication link from the non-production control area to the management information area.

[0017] As a preferred technical solution of the present invention: The first acquisition server constructs a primary communication channel from the first type of business system in the production control area to the third type of business system in the management information area via the first forward safety isolation device and the third acquisition server in a TCP direct connection manner;

[0018] The first acquisition server constructs a standby communication channel from the first type of business system in the production control area to the third type of business system in the management information area through the TCP direct connection method via the industrial firewall, the second forward security isolation device, and the third acquisition server;

[0019] The first acquisition server monitors the communication status of the primary communication channel. If it is found that normal communication cannot be established, the first acquisition server switches to using the standby communication channel for communication;

[0020] If the first acquisition server finds that the primary communication channel resumes normalcy, the first acquisition server resumes using the primary communication channel for communication.

[0021] As a preferred technical solution of the present invention: The second acquisition server constructs the primary communication channel from the second type of business system in the non-production control area to the third type of business system in the management information area through the TCP direct connection method via the second forward security isolation device and the third acquisition server;

[0022] The second acquisition server constructs a standby communication channel from the second type of business system in the non-production control area to the third type of business system in the management information area through the TCP direct connection method via the industrial firewall, the first forward security isolation device, and the third acquisition server;

[0023] The second acquisition server monitors the communication status of the primary communication channel. If it is found that normal communication cannot be established, the second acquisition server switches to using the standby communication channel for communication;

[0024] If the second acquisition server finds that the primary communication channel resumes normalcy, the second acquisition server resumes using the primary communication channel for communication.

[0025] As a preferred technical solution of the present invention: The first acquisition server includes a primary forwarding folder and a standby forwarding folder. Files in the primary forwarding folder are forwarded to the third acquisition server via the first forward security isolation device through the file forwarding method. After successful forwarding, the files in the primary forwarding folder are deleted, serving as the primary communication channel from the first type of business system in the production control area to the third type of business system in the management information area;

[0026] The first acquisition server forwards the files in the standby forwarding folder to the third acquisition server via the industrial firewall and the second forward security isolation device through the file forwarding method. After successful forwarding, the files in the standby forwarding folder are deleted, serving as the standby communication channel from the first type of business system in the production control area to the third type of business system in the management information area;

[0027] The first collection server monitors the file status in the primary forwarding folder. If it is found that a file is not forwarded normally, the first collection server stores the file in the backup forwarding folder instead and uses the backup communication channel for communication.

[0028] If the first collection server finds that the file in the primary forwarding folder resumes normal forwarding, the first collection server stores the file in the primary forwarding folder again and resumes using the primary communication channel for communication.

[0029] As a preferred technical solution of the present invention: The second collection server includes a primary forwarding folder and a backup forwarding folder. The files in the primary forwarding folder are forwarded to the third collection server via the second forward security isolation device by means of file forwarding. After successful forwarding, the files in the primary forwarding folder are deleted, serving as the primary communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area.

[0030] The second collection server forwards the files in the backup forwarding folder to the third collection server via the industrial firewall and the first forward security isolation device by means of file forwarding. After successful forwarding, the files in the backup forwarding folder are deleted, serving as the backup communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area.

[0031] The second collection server monitors the file status in the primary forwarding folder. If it is found that a file is not forwarded normally, the second collection server stores the file in the backup forwarding folder instead and uses the backup communication channel for communication.

[0032] If the second collection server finds that the file in the primary forwarding folder resumes normal forwarding, the second collection server stores the file in the primary forwarding folder again and resumes using the primary communication channel for communication.

[0033] The present invention also provides another redundant security isolation and protection system.

[0034] To this end, the above object of the present invention is achieved by the following technical solutions:

[0035] A redundant security isolation and protection system, comprising:

[0036] - The first collection server, industrial firewall, and first reverse security isolation device located in the production control area;

[0037] - The second collection server and second reverse security isolation device located in the production non-control area;

[0038] - The third collection server located in the management information area;

[0039] The third acquisition server, the first reverse security isolation device, and the first acquisition server are connected in sequence to form a primary communication link from the management information zone to the production control zone;

[0040] The third acquisition server, the second reverse security isolation device, and the second acquisition server are connected in sequence to form a primary communication link from the management information zone to the production non-control zone;

[0041] The third acquisition server, the second reverse security isolation device, the industrial firewall, and the first acquisition server are connected in sequence to form a standby communication link from the management information zone to the production control zone.

[0042] As a preferred technical solution of the present invention: The third acquisition server, the first reverse security isolation device, the industrial firewall, and the second acquisition server are connected in sequence to form a standby communication link from the management information zone to the production non-control zone.

[0043] As a preferred technical solution of the present invention: The third acquisition server includes a first primary forwarding folder and a first standby forwarding folder. The files in the first primary forwarding folder are forwarded to the first acquisition server via the first reverse security isolation device by means of file forwarding. After successful forwarding, the files in the first primary forwarding folder are deleted, serving as the primary communication channel from the third type of business system in the management information zone to the first type of business system in the production control zone;

[0044] The third acquisition server forwards the files in the first standby forwarding folder to the first acquisition server via the second reverse security isolation device and the industrial firewall by means of file forwarding. After successful forwarding, the files in the first standby forwarding folder are deleted, serving as the standby communication channel from the third type of business system in the management information zone to the first type of business system in the production control zone;

[0045] The third acquisition server monitors the status of the files in the first primary forwarding folder. If it is found that the files are not forwarded normally, the third acquisition server stores the files in the first standby forwarding folder instead and uses the standby communication channel for communication;

[0046] If the third acquisition server finds that the files in the first primary forwarding folder resume normal forwarding, the third acquisition server stores the files in the first primary forwarding folder instead and resumes using the primary communication channel for communication.

[0047] As a preferred technical solution of the present invention: the third collection server includes a second primary forwarding folder and a second backup forwarding folder. Files in the second primary forwarding folder are forwarded to the second collection server via the second reverse security isolation device by means of file forwarding. After successful forwarding, the files in the second primary forwarding folder are deleted, serving as the primary communication channel from the third type of business system in the management information zone to the second type of business system in the production non-control zone.

[0048] The third collection server forwards the files in the second backup forwarding folder to the second collection server via the first reverse security isolation device and the industrial firewall by means of file forwarding. After successful forwarding, the files in the second backup forwarding folder are deleted, serving as the backup communication channel from the third type of business system in the management information zone to the second type of business system in the production non-control zone.

[0049] The third collection server monitors the status of the files in the second primary forwarding folder. If it is found that the files are not forwarded normally, the third collection server stores the files in the second backup forwarding folder instead and uses the backup communication channel for communication.

[0050] If the third collection server finds that the files in the second primary forwarding folder resume normal forwarding, the third collection server stores the files in the second primary forwarding folder instead and resumes using the primary communication channel for communication.

[0051] The present invention provides a redundant security isolation and protection system. Compared with the prior art, it has the following advantages and beneficial effects:

[0052] On the basis of not adding or changing the common triangular topology structure of the power station, fully exploiting the capabilities of existing security isolation device equipment, and on the basis of meeting the safety protection regulations of the national power monitoring system, a redundant security isolation and protection system is constructed based on the common triangular topology structure. By using multiple security isolation devices as backups for each other, it can achieve stable data interaction in each security zone in the case of partial interface failures of the security isolation devices or failures of a single security isolation device, effectively improving the stability of power station data aggregation and the availability of data, and serving the construction of smart power stations and new power systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a schematic diagram of the structure of a redundant security isolation and protection system provided by the present invention.

[0054] Figure 2 It is a schematic diagram of the structure of another redundant security isolation and protection system provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The following further describes the present invention with reference to the drawings and embodiments, but it is not intended to limit the present invention.

[0056] As Figure 1 shown, a redundant security isolation and protection system includes: a first acquisition server, an industrial firewall, and a first forward security isolation device located in the production control area; a second acquisition server and a second forward security isolation device located in the non-production control area; and a third acquisition server located in the management information area. Both forward isolation devices are SysKeeper-2000 100M forward isolators, each having a total of 4 internal network ports from the first internal network port to the fourth internal network port and a total of 4 external network ports from the first external network port to the fourth external network port. The internal network ports and the external network ports correspond one by one to form communication channels, and there is logical isolation between the internal network ports, between the external network ports, and between internal and external network ports with different serial numbers. The first acquisition server, the industrial firewall, and the second acquisition server are connected in sequence to form a communication link between the production control area and the non-production control area. The first acquisition server is connected to the first internal network port of the first forward security isolation device, and the first external network port of the first forward security isolation device is connected to the third acquisition server to form a primary communication link from the production control area to the management information area, such as Figure 1 the link formed by the thin solid line shown in Figure 1 ; the second acquisition server is connected to the first internal network port of the second forward security isolation device, and the first external network port of the second forward security isolation device is connected to the third acquisition server to form a primary communication link from the non-production control area to the management information area, such as Figure 1 the link formed by the thick solid line shown in

[0057] ; the first acquisition server is connected to the second internal network port of the second forward security isolation device via the industrial firewall, and the second external network port of the second forward security isolation device is connected to the third acquisition server to form a backup communication link from the production control area to the management information area, such as Figure 1 the link formed by the thin dashed line shown in

[0058] The first collection server constructs the primary communication channel from the first type of business system in the production control area to the third type of business system in the management information area via the first positive security isolation device and the third collection server in a TCP direct connection manner; the first collection server constructs the backup communication channel from the first type of business system in the production control area to the third type of business system in the management information area via the industrial firewall, the second positive security isolation device, and the third collection server in a TCP direct connection manner; the first collection server monitors the communication status of the primary communication channel. If it is found that normal communication cannot be established, the first collection server switches to using the backup communication channel for communication; if the first collection server finds that the primary communication channel resumes normal operation, the first collection server resumes using the primary communication channel for communication.

[0059] The second collection server constructs the primary communication channel from the second type of business system in the non-production control area to the third type of business system in the management information area via the second positive security isolation device and the third collection server in a TCP direct connection manner; the second collection server constructs the backup communication channel from the second type of business system in the non-production control area to the third type of business system in the management information area via the industrial firewall, the first positive security isolation device, and the third collection server in a TCP direct connection manner; the second collection server monitors the communication status of the primary communication channel. If it is found that normal communication cannot be established, the second collection server switches to using the backup communication channel for communication; if the second collection server finds that the primary communication channel resumes normal operation, the second collection server resumes using the primary communication channel for communication.

[0060] The first collection server includes a primary forwarding folder and a backup forwarding folder. It forwards the files in the primary forwarding folder to the third collection server via the first positive security isolation device in a file forwarding manner. After successful forwarding, the files in the primary forwarding folder are deleted, serving as the primary communication channel from the first type of business system in the production control area to the third type of business system in the management information area; the first collection server forwards the files in the backup forwarding folder to the third collection server via the industrial firewall and the second positive security isolation device in a file forwarding manner. After successful forwarding, the files in the backup forwarding folder are deleted, serving as the backup communication channel from the first type of business system in the production control area to the third type of business system in the management information area; the first collection server monitors the status of the files in the primary forwarding folder. If it is found that the files are not forwarded normally, the first collection server stores the files in the backup forwarding folder instead and switches to using the backup communication channel for communication; if the first collection server finds that the files in the primary forwarding folder resume normal forwarding, the first collection server stores the files in the primary forwarding folder instead and resumes using the primary communication channel for communication.

[0061] The second collection server includes a primary forwarding folder and a backup forwarding folder. Through the file forwarding method, the files in the primary forwarding folder are forwarded to the third collection server via the second forward security isolation device. After successful forwarding, the files in the primary forwarding folder are deleted, serving as the primary communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area. The second collection server forwards the files in the backup forwarding folder to the third collection server via the industrial firewall and the first forward security isolation device through the file forwarding method. After successful forwarding, the files in the backup forwarding folder are deleted, serving as the backup communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area. The second collection server monitors the status of the files in the primary forwarding folder. If it is found that the files are not forwarded normally, the second collection server will store the files in the backup forwarding folder instead and use the backup communication channel for communication. If the second collection server finds that the files in the primary forwarding folder resume normal forwarding, the second collection server will store the files in the primary forwarding folder instead and resume using the primary communication channel for communication.

[0062] As Figure 2 shown, another redundant security isolation and protection system may include: a first reverse security isolation device and a second reverse security isolation device. Both reverse isolation devices are SysKeeper-2000 100M reverse isolations, each having a total of 4 internal network ports from the first internal network port to the fourth internal network port and a total of 4 external network ports from the first external network port to the fourth external network port. The internal network ports and the external network ports are in one-to-one correspondence to form communication channels, and there is logical isolation between the internal network ports, between the external network ports, and between the internal and external network ports with different serial numbers. The third collection server is connected to the first external network port of the first reverse security isolation device, and the first internal network port of the first reverse security isolation device is connected to the first collection server, forming the primary communication link from the management information area to the production control area, as Figure 2 shown by the link formed by the thin solid line in the figure; the third collection server is connected to the first external network port of the second reverse security isolation device, and the first internal network port of the second reverse security isolation device is connected to the second collection server, forming the primary communication link from the management information area to the production non-control area, as Figure 2 shown by the link formed by the thick solid line in the figure; the third collection server is connected to the second external network port of the second reverse security isolation device, and the second external network port of the second reverse security isolation device is connected to the first collection server via the industrial firewall, forming the backup communication link from the management information area to the production control area, as Figure 2 shown by the link formed by the thin dashed line in the figure.

[0063] The third collection server is connected to the second external network port of the first reverse security isolation device, and the second internal network port of the first reverse security isolation device is connected to the second collection server via the industrial firewall, forming the backup communication link from the management information area to the production non-control area, as Figure 2The link formed by the thick dashed line shown in the figure.

[0064] The third acquisition server includes a first primary forwarding folder and a first backup forwarding folder. Files in the first primary forwarding folder are forwarded to the first acquisition server via the first reverse security isolation device by means of file forwarding. After successful forwarding, the files in the first primary forwarding folder are deleted, serving as the primary communication channel from the third-class business system in the management information zone to the first-class business system in the production control zone; the third acquisition server forwards the files in the first backup forwarding folder to the first acquisition server via the second reverse security isolation device and the industrial firewall by means of file forwarding. After successful forwarding, the files in the first backup forwarding folder are deleted, serving as the backup communication channel from the third-class business system in the management information zone to the first-class business system in the production control zone; the third acquisition server monitors the status of the files in the first primary forwarding folder. If it is found that the files are not forwarded normally, the third acquisition server changes to store the files in the first backup forwarding folder and uses the backup communication channel for communication; if the third acquisition server finds that the files in the first primary forwarding folder are restored to normal forwarding, the third acquisition server changes to store the files in the first primary forwarding folder and resumes using the primary communication channel for communication.

[0065] The third acquisition server includes a second primary forwarding folder and a second backup forwarding folder. Files in the second primary forwarding folder are forwarded to the second acquisition server via the second reverse security isolation device by means of file forwarding. After successful forwarding, the files in the second primary forwarding folder are deleted, serving as the primary communication channel from the third-class business system in the management information zone to the second-class business system in the non-production control zone; the third acquisition server forwards the files in the second backup forwarding folder to the second acquisition server via the first reverse security isolation device and the industrial firewall by means of file forwarding. After successful forwarding, the files in the second backup forwarding folder are deleted, serving as the backup communication channel from the third-class business system in the management information zone to the second-class business system in the non-production control zone; the third acquisition server monitors the status of the files in the second primary forwarding folder. If it is found that the files are not forwarded normally, the third acquisition server changes to store the files in the second backup forwarding folder and uses the backup communication channel for communication; if the third acquisition server finds that the files in the second primary forwarding folder are restored to normal forwarding, the third acquisition server changes to store the files in the second primary forwarding folder and resumes using the primary communication channel for communication.

[0066] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Any simple modification or equivalent change made to the above embodiments based on the technical essence of the present invention falls within the protection scope of the present invention.

Claims

1. A redundant safety isolation and protection system, characterized in that: The redundant security isolation and protection system includes: - A first collection server, an industrial firewall, and a first forward security isolation device located in the production control area; - A second collection server and a second forward security isolation device located in the non-production control area; - A third collection server located in the management information area; The first collection server, the industrial firewall, and the second collection server are connected in sequence to form a communication link between the production control area and the non-production control area; The first collection server, the first forward security isolation device, and the third collection server are connected in sequence to form the primary communication link from the production control area to the management information area; The second collection server, the second forward security isolation device, and the third collection server are connected in sequence to form the primary communication link from the non-production control area to the management information area; The first collection server, the industrial firewall, the second forward security isolation device, and the third collection server are connected in sequence to form a backup communication link from the production control area to the management information area; The second collection server, the industrial firewall, the first forward security isolation device, and the third collection server are connected in sequence to form a backup communication link from the non-production control area to the management information area; The first collection server includes a primary forwarding folder and a backup forwarding folder. Files in the primary forwarding folder are forwarded to the third collection server via the first forward security isolation device by file forwarding. After successful forwarding, the files in the primary forwarding folder are deleted, serving as the primary communication channel from the first type of business system in the production control area to the third type of business system in the management information area; The first collection server forwards files in the backup forwarding folder to the third collection server via the industrial firewall and the second forward security isolation device by file forwarding. After successful forwarding, the files in the backup forwarding folder are deleted, serving as the backup communication channel from the first type of business system in the production control area to the third type of business system in the management information area; The first collection server monitors the status of files in the primary forwarding folder. If it is found that the files are not forwarded normally, the first collection server stores the files in the backup forwarding folder instead and uses the backup communication channel for communication; If the first collection server finds that the files in the primary forwarding folder resume normal forwarding, the first collection server stores the files in the primary forwarding folder instead and resumes using the primary communication channel for communication.

2. The redundant security isolation and protection system according to claim 1, wherein: The first collection server constructs the primary communication channel from the first type of business system in the production control area to the third type of business system in the management information area via the first forward security isolation device and the third collection server in a TCP direct connection manner; The first collection server constructs the backup communication channel from the first type of business system in the production control area to the third type of business system in the management information area via the industrial firewall, the second forward security isolation device, and the third collection server in a TCP direct connection manner; The first collection server monitors the communication status of the primary communication channel. If it is found that normal communication cannot be established, the first collection server uses the backup communication channel for communication; If the first acquisition server detects that the primary communication channel has returned to normal, the first acquisition server resumes communicating using the primary communication channel.

3. The redundant security isolation and protection system according to claim 1, characterized in that: The second acquisition server constructs a primary communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area through the second positive security isolation device and the third acquisition server in a TCP direct connection manner; The second acquisition server constructs a backup communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area through the industrial firewall, the first positive security isolation device, and the third acquisition server in a TCP direct connection manner; The second acquisition server monitors the communication status of the primary communication channel. If it detects that normal communication is not possible, the second acquisition server switches to using the backup communication channel for communication; If the second acquisition server detects that the primary communication channel has returned to normal, the second acquisition server resumes communicating using the primary communication channel.

4. The redundant security isolation and protection system according to claim 1, characterized in that: The second acquisition server includes a primary forwarding folder and a backup forwarding folder. Through the file forwarding method, the files in the primary forwarding folder are forwarded to the third acquisition server via the second positive security isolation device. After successful forwarding, the files in the primary forwarding folder are deleted, serving as the primary communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area; The second acquisition server forwards the files in the backup forwarding folder to the third acquisition server via the industrial firewall and the first positive security isolation device through the file forwarding method. After successful forwarding, the files in the backup forwarding folder are deleted, serving as the backup communication channel from the second type of business system in the production non-control area to the third type of business system in the management information area; The second acquisition server monitors the status of the files in the primary forwarding folder. If it detects that the files have not been forwarded normally, the second acquisition server changes to store the files in the backup forwarding folder and switches to using the backup communication channel for communication; If the second acquisition server detects that the files in the primary forwarding folder have resumed normal forwarding, the second acquisition server changes to store the files in the primary forwarding folder and resumes communicating using the primary communication channel.

5. A redundant safety isolation and protection system, characterized in that: The redundant security isolation and protection system includes: - The first acquisition server, industrial firewall, and first reverse security isolation device located in the production control area; - The second acquisition server and second reverse security isolation device located in the production non-control area; - The third acquisition server located in the management information area; The third acquisition server, the first reverse security isolation device, and the first acquisition server are connected in sequence to form a primary communication link from the management information area to the production control area; The third acquisition server, the second reverse security isolation device, and the second acquisition server are connected in sequence to form a primary communication link from the management information area to the production non-control area; The third acquisition server, the second reverse security isolation device, the industrial firewall, and the first acquisition server are connected in sequence to form a backup communication link from the management information area to the production control area; The third acquisition server, the first reverse security isolation device, the industrial firewall, and the second acquisition server are connected in sequence to form a standby communication link from the management information area to the production non-control area; The third acquisition server includes a first primary forwarding folder and a first standby forwarding folder. Files in the first primary forwarding folder are forwarded to the first acquisition server via the first reverse security isolation device by means of file forwarding. After successful forwarding, the files in the first primary forwarding folder are deleted, serving as the primary communication channel from the third-class business system in the management information area to the first-class business system in the production control area; The third acquisition server forwards the files in the first standby forwarding folder to the first acquisition server via the second reverse security isolation device and the industrial firewall by means of file forwarding. After successful forwarding, the files in the first standby forwarding folder are deleted, serving as the standby communication channel from the third-class business system in the management information area to the first-class business system in the production control area; The third acquisition server monitors the status of the files in the first primary forwarding folder. If it is found that the files are not forwarded normally, the third acquisition server changes to store the files in the first standby forwarding folder and uses the standby communication channel for communication; If the third acquisition server finds that the files in the first primary forwarding folder resume normal forwarding, the third acquisition server changes to store the files in the first primary forwarding folder and resumes using the primary communication channel for communication.

6. The redundant security isolation and protection system according to claim 5, wherein: The third acquisition server includes a second primary forwarding folder and a second standby forwarding folder. Files in the second primary forwarding folder are forwarded to the second acquisition server via the second reverse security isolation device by means of file forwarding. After successful forwarding, the files in the second primary forwarding folder are deleted, serving as the primary communication channel from the third-class business system in the management information area to the second-class business system in the production non-control area; The third acquisition server forwards the files in the second standby forwarding folder to the second acquisition server via the first reverse security isolation device and the industrial firewall by means of file forwarding. After successful forwarding, the files in the second standby forwarding folder are deleted, serving as the standby communication channel from the third-class business system in the management information area to the second-class business system in the production non-control area; The third acquisition server monitors the status of the files in the second primary forwarding folder. If it is found that the files are not forwarded normally, the third acquisition server changes to store the files in the second standby forwarding folder and uses the standby communication channel for communication; If the third acquisition server finds that the files in the second primary forwarding folder resume normal forwarding, the third acquisition server changes to store the files in the second primary forwarding folder and resumes using the primary communication channel for communication.

Citation Information

Patent Citations

  • Power plant data transmission method and system integrating self-diagnosis and channel optimization

    CN111724276A

  • Cross-security partition data access transmission system

    CN114363096A

  • Dual-homing protection system, dual-homing protection method and related equipment

    CN115942157A

  • Transformer substation secondary security system

    CN212572614U

  • Redundant forward safety isolation protection structure

    CN221768051U

Cited By

  • A power plant data full lifecycle governance system

    CN122413255A

  • A power station data full life cycle management system

    CN122413255B