A network security system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture
By dividing the network into regions and deploying security isolation devices and management platforms in the cloud-edge collaborative 1+6+N smart thermal power plant architecture, the problem of insufficient network security in smart thermal power plants has been solved, achieving comprehensive security and stable operation, and improving the system's protection level and data security.
Patent Information
- Application Number
- CN202410872633.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-01
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-07-01
AI Technical Summary
Existing network security technologies cannot effectively protect the network of cloud-edge collaborative 1+6+N smart thermal power plants from cyberattacks, resulting in insufficient system security and failing to meet the informatization, digitalization, and intelligentization needs of smart thermal power plants.
A network security system adopts a cloud-edge collaborative 1+6+N smart thermal power plant architecture, including a physical security layer, a network security layer, an application security layer, and a data security layer. By rationally dividing network areas, deploying security isolation devices and a security management platform, network isolation and partitioning are achieved, and comprehensive security is provided in combination with network security protection strategies.
It has improved the protection level of network security architecture, enhanced the system's resistance to attacks, reduced project construction costs, ensured the stable operation of the network and the confidentiality and integrity of data, and promoted the development of smart thermal power plants towards intelligence and efficiency.
Smart Images

Figure CN118555129B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of cybersecurity technology for thermal power units, specifically relating to a cybersecurity system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture. Background Technology
[0002] A smart thermal power plant is a form of realization based on the concept of "intelligent power generation." It takes a new generation of integrated intelligent control system as its core, utilizes a big data cloud platform for operational data storage, and is supported by a unified integrated control platform. It comprehensively expands and integrates real-time data processing, subsystem operation assessment and control, and plant-level and regional management decision-making, achieving informatization, automation, and intelligence in the operation, maintenance, and management of the power plant, and realizing comprehensive personnel and equipment safety control.
[0003] Currently, smart thermal power plants have become a new trend in power plant development. In order to achieve the goals of energy conservation, consumption reduction, and emission reduction, a new power generation concept and model of cloud-edge collaborative 1+6+N smart thermal power plants has been launched. Based on a hyper-converged integrated edge cloud platform, it covers six major application scenarios including power plant infrastructure, safety, operation, maintenance, fuel, and management. Through the construction of smart thermal power plants, the core competitiveness of power plants can be effectively enhanced, and the sustainable development of power plants can be promoted.
[0004] The construction of a smart thermal power plant is based on industrial internet technology, building a three-dimensional intelligent technology architecture of "cloud-edge collaboration." A lightweight enterprise edge cloud is constructed at the power plant, interconnected with the group's cloud platform. On this architecture, a hyper-converged integrated smart platform (1+6+N model) is built, consisting of six major application systems (smart infrastructure, smart security, smart operation, smart maintenance, smart management, and smart fuel) and N smart functional modules. As a critical infrastructure, the smart thermal power plant faces risks from cyberattacks and security threats. Cybersecurity technology is crucial in the smart thermal power plant architecture, including data encryption, access control, identity authentication, and intrusion detection, to ensure the secure and stable operation of the system.
[0005] Ensuring the normal operation of the cloud-edge collaborative 1+6+N smart thermal power plant network, free from attacks by various network hackers, has become an urgent and unavoidable issue for business systems. The foundation for achieving informatization, digitalization, intelligence, security, and smart technology urgently requires a network security system based on the cloud-edge collaborative 1+6+N smart thermal power plant architecture. Summary of the Invention
[0006] The purpose of this invention is to overcome the problem that existing network security technologies cannot meet the security requirements of cloud-edge collaborative 1+6+N smart thermal power plant networks, and to propose a network security system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture.
[0007] To achieve the above objectives, the present invention adopts the following technical solution:
[0008] A network security system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture includes a physical security layer, which comprises a production control zone, an information management zone, and a two-network convergence boundary zone. The production control zone is the first zone of the power plant, the information management zone is the third zone of the power plant, and the two-network convergence boundary zone is set between the first and third zones of the power plant.
[0009] A physical security layer for the convergence of the two power grids is set up in the boundary area. This physical security layer is used for forward isolation between Power Plant Zone 1 and Power Plant Zone 3. A physical security layer for Power Plant Zone 1 is set up. This physical security layer is used for functional isolation zoning and protection infrastructure of Power Plant Zone 1. A physical security layer for Power Plant Zone 3 is set up. This physical security layer is used for functional isolation zoning and protection infrastructure of Power Plant Zone 3.
[0010] The physical safety layer of Zone 3 of the power plant is connected to the physical safety layer of Zone 1 of the power plant through the physical safety layer of the two-network convergence boundary.
[0011] Furthermore, the physical security layer at the boundary of the two-network convergence includes a one-way isolation gateway, which is used for one-way data transfer from power plant zone 1 to power plant zone 3. The one-way isolation gateway adopts one-way non-feedback transmission.
[0012] The one-way data transfer is as follows: Zone 3 of the power plant cannot actively transmit data to Zone 1 of the power plant. Data from Zone 1 of the power plant is transmitted to Zone 3 of the power plant through a one-way isolation gate. The data from Zone 1 of the power plant includes data on the analysis of production status and data on guiding the business of each zone of Zone 3 of the power plant.
[0013] Furthermore, the physical security layer of Zone 1 of the power plant includes the core area of Zone 1, the safety management area of Zone 1, and other functional areas of Zone 1. The core area of Zone 1 is equipped with a core switch, and switches are also installed in the safety management area and other functional areas of Zone 1. The core switch of Zone 1 connects to the DCS, the physical security layer of the two-network convergence boundary, and other switches. Firewalls are installed between the core switch of Zone 1 and the DCS, the physical security layer of the two-network convergence boundary, and other switches. Both the core switch and other switches in Zone 1 adopt a dual-machine backup mechanism. The safety management area of Zone 1 is equipped with a security module for Zone 1.
[0014] Furthermore, the physical safety layer of the power plant's third zone includes the core area of the power plant's third zone, the safety management area of the power plant's third zone, the exit area, the 1+6+N plant-side edge cloud smart business area, and other functional areas of the power plant's third zone;
[0015] The core area of Zone 3 of the power plant is equipped with a core switch. This core switch connects to the security management area, the 1+6+N plant-side edge cloud intelligent business area, and other functional areas of Zone 3. The core switch also connects to the firewall of Zone 3. Furthermore, the core switch connects to the egress area, which in turn connects to the firewall and intrusion prevention system of Zone 3. The egress area connects to the external network.
[0016] The power plant's third zone safety management area is equipped with a third zone safety module.
[0017] Furthermore, both the production control area and the information management area are equipped with host servers. The host servers deploy host security management systems and install security software, including antivirus software and identity authentication access control systems. The host security management system is connected to the security modules of power plant zone 1 and power plant zone 3 respectively. The host security management system adopts a single host offline operation security management system.
[0018] Furthermore, both the safety module in Zone 1 and the safety module in Zone 3 of the power plant are equipped with a safety management platform. The safety management platform is equipped with safety applications, including database auditing applications, log auditing applications, data backup applications, and safety operation and maintenance applications.
[0019] Furthermore, the firewall in Zone 3 of the power plant adopts HA deployment. The firewall between the core switch of Zone 3 and the security management area, the 1+6+N plant-side edge cloud intelligent business area and other functional areas of Zone 3 of the power plant adopts serial HA deployment. The firewall and intrusion prevention system between the core switch of Zone 3 and the egress area adopt gateway HA deployment.
[0020] Furthermore, the core switch in Zone 3 of the power plant adopts a dual-redundant switch, which uses VRRP technology. Specifically, it uses static routing, VRRP, and firewall HA hot standby technology to implement a dual-link redundancy backup mechanism through the IP address range allocated by the smart thermal power plant.
[0021] Furthermore, the dual-link redundancy backup mechanism is as follows: when the link and equipment are working normally, the bidirectional interconnection of the network platform of the 1+6+N plant-side edge cloud smart business area in the third power plant uses a 10 Gigabit link; when the primary equipment fails, the communication is forwarded by migrating the equipment through the VRRP virtual gateway.
[0022] Furthermore, it includes a network security layer, an application security layer, and a data security layer. The application security layer is deployed on the security management platform of the physical security layer and is used for intrusion prevention, security management of power plant zone 1, security management of power plant zone 3, and host security management.
[0023] The application security layer is deployed on the security management platform of the application security layer for antivirus, access control and authentication, auditing and security operation and maintenance management; the application security layer deploys the security monitoring system;
[0024] The data security layer is deployed on top of the network security layer and the application security layer, and is used for data lifecycle security, data access security, and critical data protection.
[0025] Compared with the prior art, the present invention has the following beneficial technical effects:
[0026] This invention proposes a cloud-edge collaborative 1+6+N smart power plant network security system. It integrates the smart power plant network with the power plant information management regional network into a unified, holistic network, forming a unified network security framework. Combined with network security protection strategies, this comprehensively enhances the protection level of the network security architecture, providing comprehensive security assurance for smart power plants. This invention not only provides a comprehensive and efficient solution in the field of network security for smart power plants but also offers reliable protection for the digital transformation of smart power plants, promoting their advancement towards intelligence and efficiency.
[0027] Furthermore, the physical security layer of the two-network convergence network security framework achieves network isolation through network area division and the deployment of security isolation devices; the network security layer maintains the security of the entire network and its data exchange; the application security layer ensures the security of internal application layers; and the data security layer ensures the integrity, confidentiality, and availability of data. Through the convergence of the two networks, information security construction and operation and management platform construction can be highly reused, which can greatly reduce the cost of project construction.
[0028] Furthermore, the two-network convergence network security framework organically integrates the office network of the power plant's three-zone information management network with the smart power plant network. Its advantages are: clear network structure, high redundancy and scalability, low operation and maintenance complexity, low economic investment, and clear division of responsibilities.
[0029] Furthermore, the network security system's protection strategies span multiple security levels and are applied to various system modules, comprehensively improving the protection level of the network security architecture and enhancing the system's resistance to attacks. By integrating the smart thermal power plant network with the power plant information management regional network into a single network, the construction of the operation and management platform and security platform can be carried out in a unified manner, reducing the complexity of network operation and maintenance.
[0030] Furthermore, by rationally dividing network areas and deploying security isolation devices, this invention achieves isolation between networks of different security levels, effectively preventing the spread of network attacks and improving the overall security of the system.
[0031] Furthermore, by deploying an intelligent security monitoring system at the application security layer, this invention can promptly detect anomalies and take corresponding countermeasures, ensuring the stable operation of the system. The data security layer employs various data security measures, including data lifecycle security, data access security, and critical data protection, ensuring the confidentiality and integrity of important data. Attached Figure Description
[0032] The accompanying drawings are provided to further understand the invention and constitute a part of this invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.
[0033] Figure 1 This is a schematic diagram illustrating the integration of the power plant's three-zone information management network with the smart power plant network.
[0034] Figure 2 This is a schematic diagram of the 1+6+N smart thermal power plant network security architecture integrating two networks according to the present invention. Detailed Implementation
[0035] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0036] Example 1
[0037] See Figure 1 and Figure 2 A network security system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture includes a physical security layer, which comprises a production control zone, an information management zone, and a two-network convergence boundary zone. The production control zone is the first power plant zone, the information management zone is the third power plant zone, and the two-network convergence boundary zone is set between the first and third power plant zones.
[0038] A physical security layer for the convergence of the two power grids is set up in the boundary area. This physical security layer is used for forward isolation between Power Plant Zone 1 and Power Plant Zone 3. A physical security layer for Power Plant Zone 1 is set up. This physical security layer is used for functional isolation zoning and protection infrastructure of Power Plant Zone 1. A physical security layer for Power Plant Zone 3 is set up. This physical security layer is used for functional isolation zoning and protection infrastructure of Power Plant Zone 3.
[0039] The physical safety layer of Zone 3 of the power plant is connected to the physical safety layer of Zone 1 of the power plant through the physical safety layer of the two-network convergence boundary.
[0040] Preferably, the physical security layer of the two-network integration boundary includes a one-way isolation gate for one-way data transfer from power plant zone 1 to power plant zone 3. The one-way isolation gate adopts one-way non-feedback transmission.
[0041] The one-way data transfer is as follows: Zone 3 of the power plant cannot actively transmit data to Zone 1 of the power plant. Data from Zone 1 of the power plant is transmitted to Zone 3 of the power plant through a one-way isolation gate. The data from Zone 1 of the power plant includes data on the analysis of production status and data on guiding the business of each zone of Zone 3 of the power plant.
[0042] Preferably, the physical security layer of Zone 1 of the power plant includes the core area of Zone 1, the safety management area of Zone 1, and other functional areas of Zone 1. The core area of Zone 1 is equipped with a core switch, and the safety management area and other functional areas of Zone 1 are also equipped with switches. The core switch of Zone 1 is connected to the DCS, the physical security layer of the two-network convergence boundary, and other switches. Firewalls are installed between the core switch of Zone 1 and the DCS, the physical security layer of the two-network convergence boundary, and other switches. The core switch and other switches of Zone 1 adopt a dual-machine backup mechanism. The safety management area of Zone 1 is equipped with a security module for Zone 1.
[0043] Preferably, the physical security layer of the three zones of the power plant includes the core zone of the three zones, the safety management zone of the three zones, the exit zone, the 1+6+N plant-side edge cloud smart business zone, and other functional zones of the three zones of the power plant.
[0044] The core area of Zone 3 of the power plant is equipped with a core switch. This core switch connects to the security management area, the 1+6+N plant-side edge cloud intelligent business area, and other functional areas of Zone 3. The core switch also connects to the firewall of Zone 3. Furthermore, the core switch connects to the egress area, which in turn connects to the firewall and intrusion prevention system of Zone 3. The egress area connects to the external network.
[0045] The power plant's third zone safety management area is equipped with a third zone safety module.
[0046] Preferably, both the production control area and the information management area are equipped with host servers. The host servers deploy a host security management system and install security software, including antivirus software and an identity authentication access control system. The host security management system is connected to the security modules of power plant zone 1 and power plant zone 3 respectively. The host security management system adopts a single host offline operation security management system.
[0047] Preferably, both the safety module in Zone 1 and the safety module in Zone 3 of the power plant are equipped with a safety management platform. The safety management platform is equipped with safety applications, including database auditing applications, log auditing applications, data backup applications, and safety operation and maintenance applications.
[0048] Preferably, the firewall in Zone 3 of the power plant is deployed using HA (High Availability). The firewall between the core switch of Zone 3 and the security management zone, the 1+6+N plant-side edge cloud intelligent business zone, and other functional zones of Zone 3 is deployed in a serial HA configuration. The firewall and intrusion prevention system connecting the core switch of Zone 3 and the egress zone are deployed in a gateway HA configuration.
[0049] Preferably, the core switch of the power plant's three zones adopts a dual-redundant switch, which uses VRRP technology. Specifically, it uses static routing, VRRP, and firewall HA hot standby technology to implement a dual-link redundancy backup mechanism through the IP address range allocated by the smart thermal power plant.
[0050] Preferably, the dual-link redundancy backup mechanism is as follows: when the link and equipment are working normally, the bidirectional interconnection of the network platform of the 1+6+N plant-side edge cloud smart business area in the third power plant uses a 10 Gigabit link; when the primary equipment fails, the communication is forwarded by migrating the equipment through the VRRP virtual gateway.
[0051] Preferably, it includes a network security layer, an application security layer, and a data security layer. The application security layer is deployed on the security management platform of the physical security layer and is used for intrusion prevention, security management of power plant zone 1, security management of power plant zone 3, and host security management.
[0052] The application security layer is deployed on the security management platform of the application security layer for antivirus, access control and authentication, auditing and security operation and maintenance management; the application security layer deploys the security monitoring system;
[0053] The data security layer is deployed on top of the network security layer and the application security layer, and is used for data lifecycle security, data access security, and critical data protection.
[0054] Example 2
[0055] This embodiment provides a network security system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture. The following describes the network security system in detail by specifying the necessary functional components, the network security architecture of the two networks convergence, and the network security protection strategy.
[0056] The essential functional components include the following seven points: network isolation and partitioning, identity authentication and access control, boundary security protection, intelligent security monitoring and response, data security and encryption, security auditing and compliance, and security training and awareness enhancement.
[0057] Network isolation and partitioning is the first line of defense for network security in a 1+6+N smart power plant architecture. Network isolation and partitioning are used to divide the network environment of a smart power plant into different areas and ensure isolation between them, thereby reducing the risk of lateral movement attacks and data breaches.
[0058] Identity authentication and access control are effective means of ensuring that only authorized users can access the network resources of a thermal power plant. Through strict identity authentication and meticulous access control, the system can effectively differentiate the permissions of different users, prevent unauthorized users from entering the system through network vulnerabilities, and thus ensure system security.
[0059] Perimeter security is a crucial element in preventing external cyberattacks. This process involves monitoring and filtering network data flows using tools such as firewalls and intrusion detection and prevention systems to identify and interrupt malicious attacks in real time. To ensure manageable perimeter security, technical means must be employed to implement physical or logical isolation between vertical and horizontal zones; simultaneously, only verified and compliant business protocols should be allowed to transmit at the boundary, prohibiting the flow of any unauthorized data. In the 1+6+N cloud-edge collaborative smart thermal power plant, particular emphasis is placed on the network security boundary of the smart operation center, boundary security in the convergence of the two networks, and the perimeter security protection strategy for the smart thermal power plant.
[0060] The intelligent security monitoring and response function aims to achieve real-time monitoring and rapid response to cybersecurity threats, thereby effectively reducing potential losses from security risks. This function relies on the comprehensive application of intrusion prevention and malware protection technologies. Specific implementation methods include integrating antivirus software, deploying intrusion detection systems, monitoring and auditing systems, log auditing systems, and security operation and maintenance management systems to ensure comprehensive identification and rapid handling of potential threats. In terms of cybersecurity protection strategies, a proactive defense approach is adopted, enabling asset mapping, vulnerability awareness, and operational management, thereby strengthening real-time monitoring and timely response capabilities against cyber threats.
[0061] Data security and encryption are crucial for smart thermal power plants, ensuring the integrity, confidentiality, and availability of critical information assets to prevent unauthorized access or tampering. By embedding a data security layer within a cybersecurity framework, employing digital certificates to verify the integrity of transmitted data, using encryption algorithms to protect data confidentiality, and implementing regular backup strategies to ensure data availability, smart thermal power plants can build an impenetrable data security defense.
[0062] Security auditing and retrospective analysis are crucial tools for assessing and improving the cybersecurity of thermal power plants. Auditing network activities allows for the timely detection of abnormal behavior; tracing the location of network incidents provides a basis for investigation and handling of security events. Furthermore, analyzing security audit data can identify weaknesses in the security system, providing a basis for adjusting security strategies.
[0063] Safety training and awareness enhancement are essential measures to ensure the cybersecurity of smart thermal power plants, playing a crucial role in personnel management. By establishing and improving safety management systems and clarifying employees' safety responsibilities and operating procedures, cybersecurity risks can be effectively mitigated. Regularly organized safety training and drills aim to improve employees' safety awareness and emergency response capabilities, ensuring they can take swift and effective action when facing potential threats. Especially in a converged network environment, this helps clarify the division of responsibilities, thereby ensuring the security and stability of the entire network environment.
[0064] The 1+6+N Smart Thermal Power Plant Two-Network Integration Network Security Architecture refers to the organic integration of the power plant's three-zone information management network (office network) with the smart power plant network. Its advantages are: clear network structure, high redundancy and scalability, low operation and maintenance complexity, low economic investment, and clear division of responsibilities.
[0065] The production control zone (Zone 1) mainly includes: the core zone, the security management zone, and other functional zones related to production control (hyperconverged intelligent architecture functional platform, OPC server zone, intelligent controller zone, and terminal access zone). The core zone deploys the power plant's Zone 1 core switch and firewall, which meet the dual-machine backup mechanism. The power plant's Zone 1 core switch is connected to the switches in each functional zone.
[0066] The one-way gateway is deployed using the HA mechanism.
[0067] The Information Management Zone (Zone 3) mainly comprises seven sub-zones: Core Zone, Egress Zone, Plant Edge Cloud Platform, and Security Management Zone (Access Zone, Video Surveillance Zone, 5G Access Zone). The Core Zone deploys two redundant core switches. The Egress Zone employs an HA (High Availability) mechanism to deploy intrusion prevention devices and firewalls, while other functional zones also utilize HA mechanisms to deploy firewalls connected to the core switches.
[0068] Total number of network security devices: 18 firewalls (6 in Power Plant Zone 1 and 12 in Power Plant Zone 3); 4 core switches (2 in Power Plant Zone 1 and 2 in Power Plant Zone 3); 2 one-way network gateways.
[0069] This embodiment presents a network security system for a cloud-edge collaborative 1+6+N smart thermal power plant architecture. It adopts a cloud-edge collaborative 1+6+N network security framework for the convergence of the two networks in a smart thermal power plant. This network security architecture is divided into four layers: a physical security layer, a network security layer, an application security layer, and a data security layer. The physical security layer focuses on the protection of infrastructure; the network security layer is responsible for maintaining the security of the entire network and its data exchange; the application security layer ensures the security of the application layer within the smart thermal power plant network; and the data security layer guarantees the integrity, confidentiality, and availability of data.
[0070] The physical security layer, which deploys the cybersecurity infrastructure of a smart thermal power plant, is fundamental to its cybersecurity. During the convergence of the two networks (production control and information management), the rational division of network areas and the deployment of security isolation devices (such as firewalls and gateways) achieve isolation between networks of different security levels, preventing the spread of network attacks. The physical security layer of the 1+6+N smart thermal power plant cybersecurity architecture includes the following devices: unidirectional gateways that achieve forward isolation between the production control area (Zone 1) and the information management area (Zone 3); core switches that achieve network isolation and partitioning for the converged two networks; and firewalls that ensure physical security at the boundary of the converged two networks. In addition to the deployment of cybersecurity infrastructure, the physical security layer also focuses on the security of the physical environment and the protection of the cybersecurity infrastructure.
[0071] The physical security layer needs to meet the following security requirements: network isolation and partitioning in the convergence of the two networks: network isolation is divided into network isolation between Zone 1 and Zone 3 of the power plant, and isolation between various functional zones in Zone 3 of the power plant. To achieve network isolation and partitioning functions in the convergence of the two networks, switches with dual-machine backup mechanisms are deployed in the core and various functional zones of Zone 1 of the smart thermal power plant, and switches with dual-machine backup mechanisms are deployed in the core and various functional areas of Zone 3 of the power plant.
[0072] Physical security of the two-network convergence boundary area: The boundary of the smart thermal power plant area is divided into three interconnection boundaries, subsystem access boundaries, plant-side edge cloud boundaries, and one-zone interconnection boundaries. At the one-zone interconnection boundary, a one-way isolation gateway is used to achieve secure and controllable one-way data transfer from zone one to the smart thermal power plant platform. High-performance firewalls are deployed at the three interconnection boundaries, plant-side edge cloud boundaries, and subsystem access boundaries.
[0073] The 1+6+N Smart Thermal Power Plant Production Control Zone (Zone 1) is the most crucial part of the power plant's information system, housing dispatch automation systems, substation automation systems, relay protection systems, and automatic safety control systems. No data is permitted to enter Zone 1 to avoid affecting its normal production operations or exposing its equipment to network intrusion threats.
[0074] To ensure network security in Power Plant Zone 1, at the physical security level, a one-way network gateway is deployed in series with two machines between the production control zone and the information management zone. This enables one-way data transfer between the Power Plant Zone 1 OPC server and the information management zone (Zone 3). Power Plant Zone 3 is prohibited from actively transmitting data to Power Plant Zone 1 in any way. Furthermore, data from Power Plant Zone 1 is transmitted to Power Plant Zone 3 via the one-way network gateway for analyzing production conditions and guiding business operations in various sections of Power Plant Zone 3. The one-way network gateway employs "one-way, feedback-free transmission" technology, guaranteeing absolutely one-way data flow at the physical link layer and transport layer.
[0075] Dual-redundant switches are crucial for ensuring stable network communication at the physical security layer. The basic switch deployment for the physical security layer includes: deploying switches with dual-machine backup mechanisms in the core and various functional zones of Zone 1 of the smart power plant; and deploying switches with dual-machine backup mechanisms in all functional areas of Zone 3 of the power plant. To meet the needs of network convergence, integrating the Zone 3 power plant network with the smart power plant, dual-redundant core switches with VRRP technology are deployed in the core area of Zone 3 to connect the various functional areas of Zone 3 after network convergence, such as the access area, egress area, 1+6+N plant-side edge cloud smart service area, and security management area.
[0076] To avoid disruptions to business system communication or even system / platform paralysis due to single device failures or physical link interruptions, the core switches in the three zones of the integrated smart thermal power plant employ VRRP technology for dual-machine redundancy during network design. Using the IP address range allocated by the power plant, static routing + VRRP, and firewall HA hot standby technology, a dual-link redundancy backup mechanism is implemented. Under normal link and equipment operation, bidirectional communication between the three zones of the smart thermal power plant network platform uses 10 Gigabit links. In the event of a primary device failure, a VRRP virtual gateway migrates the backup device for communication forwarding, ensuring normal communication between the three zones and the smart thermal power plant network platform.
[0077] To meet the security requirements of each functional zone in Zone III of the power plant after the integration of the power plant's main network and the smart power plant's network, each functional zone in Zone III is connected to the core switch of Zone III via a firewall deployed with High Availability (HA). To meet the boundary security requirements of the network integration, high-performance next-generation firewalls are deployed at the interconnection boundaries of Zone III, the plant-side edge cloud boundary, and the subsystem access boundary. The firewalls in each functional zone of the smart power plant's Zone III are deployed in a serial HA configuration to ensure smooth data communication and effectively enhance network reliability.
[0078] To meet the security requirements of the power plant's Zone III exit boundary, a firewall and intrusion prevention system are implemented at the Zone III exit area. To meet the physical security requirements of the Zone III exit area after the integration of the two networks, a firewall is deployed at the exit area of the smart thermal power plant, using a gateway configuration for high availability (HA) to ensure smooth data communication and effectively enhance network reliability. The functions of the high-performance next-generation firewall include: filtering various data entering and leaving the network; managing and analyzing the behavior of incoming and outgoing traffic; blocking specific prohibited services or traffic; recording information and activities passing through the firewall; and detecting and warning of various attack machines originating from the network.
[0079] The physical security layer focuses on the protection of infrastructure, including data center security, equipment security, and communication line security. It should ensure the physical environment of the data center is secure, such as fireproofing, waterproofing, and lightning protection; equipment security requires that the equipment itself have the ability to resist vandalism and theft; and secure communication requires preventing lines from being illegally cut or eavesdropped on.
[0080] Regarding physical environment security, a dedicated department or personnel should be designated to be responsible for computer room security, managing access to the computer room, and regularly maintaining and managing facilities such as power supply and distribution, air conditioning, temperature and humidity control, and fire protection. A computer room security management system should be established, stipulating regulations for physical access, the bringing in and out of items, and environmental security. Visitors should not be received in important areas, and paper documents and removable media containing sensitive information should not be placed there indiscriminately. Regarding the maintenance of security equipment, a dedicated department or personnel should be designated to regularly maintain various equipment (including backup and redundant equipment) and lines. A comprehensive facility and hardware / software maintenance management system should be established, clearly defining the responsibilities of maintenance personnel and repair procedures to ensure the standardization and effectiveness of maintenance work. Furthermore, information processing equipment should undergo strict approval before being removed from the computer room or office location. Important data on equipment containing storage media should be encrypted when taken out of the work environment. Before being scrapped or reused, equipment containing storage media should be completely erased or securely overwritten to ensure that sensitive data and authorized software on the equipment cannot be recovered and reused.
[0081] The network security layer is the second layer in the 1+6+N smart power plant network security architecture, built upon the network security facilities of the physical security layer. This layer is responsible for maintaining the security of the entire network and its data exchange, focusing primarily on two core aspects: external communication security and internal security management.
[0082] External Communication Security: The network security layer views the smart power plant network as a whole, focusing on protecting the security of communications between the power plant's internal network and the outside world. Internal Security Management: Security management platforms are deployed within the functional zones of the security management areas in Power Plant Zone 1 and Power Plant Zone 3. These two platforms serve as security modules for Power Plant Zone 1 and Power Plant Zone 3 respectively, ensuring the security of other functional zones within Power Plant Zone 1 and Power Plant Zone 3.
[0083] The network security layer is a key component of the smart thermal power plant network security framework, encompassing three parts: the intrusion prevention system for the converged network boundary area, the security management platform, and host security.
[0084] In the network security architecture of a smart thermal power plant, the Zone 1 network, serving as a dedicated network for the plant's internal production area, is not directly connected to the external network. It communicates with the controlled network in Zone 3 through a forward isolation device. Due to this isolation, Zone 1 does not require an intrusion prevention system. Network communication security between the power plant and the outside world is concentrated in the exit zone of Zone 3, the only module in the network security framework directly connected to the external network. Here, a highly available intrusion prevention system is deployed, installed in series behind the firewall in the exit zone. The intrusion prevention system is responsible for real-time monitoring and filtering of all data packets entering and leaving the power plant, effectively monitoring and defending against various malicious attacks and network threats. 1. The system integrates deep content inspection, advanced security protection, and application identification and management technologies, working in conjunction with a finely tuned intrusion attack signature database. It can identify and block various mainstream network attack types in real time, including malicious scanning, buffer overflows, denial-of-service attacks, SQL injection, suspicious code execution, worms, Trojans, and spyware. 2. The intrusion prevention system (IPS) seamlessly integrates with the threat intelligence cloud platform, utilizing real-time threat intelligence to monitor suspicious sessions and file transfers within the internal network. It also categorizes and prioritizes internal threats, enabling administrators to take swift action based on the specific situation. 3. Through close collaboration with firewall products, the IPS enhances the power plant's defense capabilities, particularly in attack identification and interception. When an attack is detected, the IPS uses its advanced detection technology to identify it and swiftly blocks the attack through automated measures such as blacklisting and session restrictions, ensuring optimal network security for the smart thermal power plant.
[0085] In the smart thermal power plant network architecture, the security management platform is deployed in the security management areas of Power Plant Zone 1 and Power Plant Zone 3, respectively, serving as the core security module protecting the 1+6+N smart thermal power plant network and its various functional zones. The security management platform of Power Plant Zone 1 is connected to the security management area through a secure access switch, while the security management platform of Power Plant Zone 3 is connected through a set of highly available secure access switches and firewalls. These devices are aggregated via dual gigabit links and then connected to the core switch, ensuring high reliability and security of the network connection.
[0086] The security management platform integrates various security applications such as database auditing, log system auditing, backup system auditing, operations and maintenance auditing, and privileged account management. It supports a wide range of security needs and handles tasks ranging from basic data protection to complex behavioral analysis. The platform provides comprehensive security auditing and monitoring capabilities, enabling real-time monitoring and analysis of network activity, effectively identifying and rapidly responding to abnormal behavior. Furthermore, the platform is responsible for extracting and analyzing firewall information and monitoring the status and activity of devices at all levels throughout the plant to ensure a rapid response capability to potential threats.
[0087] The host security management system provides host security solutions for servers and terminal computers in smart thermal power plants. It consists of terminal security software and a host security management platform located within a security management area. A host security management client is deployed on each server and connected to the host security management platform in the security management area, forming a unified security protection for all terminals within the power plant. Furthermore, the host security management system also supports offline operation of individual hosts, providing protection for isolated network devices.
[0088] The system supports unified terminal asset management, terminal security check, and terminal compliance check. It also supports one-click isolation and handling of security incidents, full-network threat positioning of hot events, source tracing and analysis of historical behavior data, and remote assistance in evidence collection and investigation analysis, effectively improving the security defense capabilities of hosts.
[0089] The application security layer is the third layer in the smart thermal power plant's network security architecture, focusing on application-level security within the networks of Zone 1 and Zone 3 of the power plant. This layer integrates network security applications widely deployed in each functional area of Zone 1 and Zone 3, ensuring comprehensive protection for applications within the power plant network. The application security layer includes not only basic security software installed on various host servers, such as antivirus software and identity authentication access control systems, but also various security applications in the security management platforms of Zone 1 and Zone 3, such as database auditing, log auditing, data backup, and security operations and maintenance. The application security layer is a key component of the smart thermal power plant's network security architecture, encompassing antivirus, access control, and various auditing and operations and maintenance applications. It enables intelligent security monitoring and response, security auditing and backtracking functions, and identity authentication and access control functions.
[0090] Antivirus software is deployed on all terminal hosts and servers, forming the core application of the host security management system. The antivirus software enhances the antivirus capabilities of terminal hosts within the power plant's Zone 1 and Zone 3 networks, ensuring that malware versions and malicious code libraries are kept up-to-date, thereby effectively defending against virus threats. Specific virus protection measures include: regularly updating operating system patches and upgrading antivirus software, with scheduled forced updates configured on the server; real-time monitoring of network data to block documents and programs from unknown sources; ensuring that antivirus software automatically starts every time a computer boots up; regularly performing antivirus scans; hardware isolation when internal computers malfunction, and performing antivirus treatment and system reinstallation on affected computers; and monitoring virus threat events to provide necessary information for the overall network's virus protection management.
[0091] In the 1+6+N network security architecture of a smart thermal power plant, the application security layer undertakes the key functions of identity authentication and access control. This layer ensures that access to all system software in Zone 1 and Zone 3 of the power plant, as well as the use of various platforms and data, undergoes strict identity verification and access control.
[0092] The identity authentication function emphasizes strict monitoring and management of user login behavior. It should employ a combination of two or more authentication technologies, such as passwords, PINs, and biometrics, to verify user identity. Authentication information should have complexity requirements and be changed regularly. System settings include login failure handling functions that can automatically terminate sessions, limit the number of unauthorized login attempts, and automatically log out upon connection timeout. During remote management, all sensitive information, such as passwords, is encrypted during network transmission to prevent identity theft. The system backend also allows administrators to configure login timeouts and the number of unauthorized login attempts, further enhancing security. Access control ensures that legitimate users can access appropriate resources while preventing unauthorized access. Access control is based on the precise allocation of user accounts and permissions. Each user account has clearly defined permission settings to match user work needs. Default accounts are not set, and expired accounts are promptly deleted or disabled. Account sharing is strictly prohibited to maintain clear and secure account management. Permission settings follow the principle of least privilege, granting users only the permissions necessary to complete their tasks. Refine the granularity of access control, with the subject being the user level or process level, and the object being the file or database table level.
[0093] The application security layer includes a database auditing system, a log auditing system, an operations and maintenance auditing system, and a backup system. These systems are all deployed on the security management platform of the network security layer, providing comprehensive security auditing and data protection.
[0094] The database auditing system monitors database activity in real time, performing fine-grained operational audits and compliance management. It identifies risky behaviors and issues alerts, while simultaneously blocking potential attacks. The system also records and analyzes user access, assisting in generating compliance reports and incident tracking. Configuration and log collection are performed through device management interfaces, enhancing database security. The log auditing system standardizes logs from network devices, security devices, and application systems, conducting in-depth security analysis through a correlation analysis engine to reconstruct the true situation behind events and support incident accountability. The system also centrally manages all log information, monitors asset operating status, and helps administrators comprehensively audit the security status of information systems. The operations and maintenance auditing system supports real-time monitoring and historical queries for multiple protocols, achieving unified account management and single sign-on, and possessing comprehensive operations and maintenance risk control functions. The system manages third-party operations and maintenance activities, providing unified management of accounts and resources, comprehensively recording operations and maintenance activities, promptly tracking erroneous operations, enhancing access control, and preventing unauthorized operations. The backup system provides unattended, real-time centralized backup protection. In the event of data loss due to physical or logical failures, rapid recovery is achieved through a backup appliance. Deploying a backup system in an off-site data center supports disaster recovery and ensures data integrity and continuous system operation.
[0095] In building a cybersecurity framework for smart thermal power plants, the data security layer is a crucial link in protecting the plant's critical data assets from unauthorized acquisition or tampering, thereby ensuring the smooth implementation of data security and encryption functions. The core of data security lies in the rational use of data, mitigating data security risks, and maximizing the value of data assets. The data security layer includes data lifecycle security, data access security, and critical data protection.
[0096] In the data security layer of a smart thermal power plant, comprehensive security measures are designed to protect data at every stage of its lifecycle, including data creation, storage, transmission, and deletion.
[0097] Data Creation Security: The data creation phase involves ensuring the integrity and security of data from the source. Strict data input control and verification mechanisms are employed to prevent the generation of erroneous data and unauthorized access to sensitive data. Data Storage Security: Data storage utilizes a data lake architecture, supporting the secure storage of both structured and unstructured data. All stored data is protected with high-strength encryption technology. Furthermore, a database auditing system continuously monitors the data storage environment, auditing all database activities to ensure the security of the storage process and alerting to any abnormal behavior. Data Transmission Security: Data is transmitted using encryption protocols such as SSL / TLS to protect data transmission over the network, preventing interception or tampering during transit. Encrypted transmission ensures the confidentiality and integrity of data transmission, preventing data leakage. Data Deletion Security: When data is no longer needed, secure data deletion strategies are employed to handle expired or useless data, including the complete erasure of data records from storage media. Standardized data destruction procedures are used to ensure data is unrecoverable, preventing potential security risks associated with discarded data. Data Access Security: Ensures the security and compliance of data during access. All stored data is encrypted using high-strength encryption technology, ensuring that even if unauthorized access is received, the content cannot be deciphered. Fine-grained access control policies guarantee that only strictly authenticated and authorized users can access specific data. Role-based access control allows for precise definition of which users or user groups have permission to access specific data resources, effectively managing and restricting access to sensitive data. Data security auditing tracks and records all data access activities, including user identity, access time, access type, and accessed data content. This helps monitor and review all data access behavior to ensure compliance and provides necessary information and evidence for responding to potential data breaches.
[0098] Regarding the protection of critical data, a key focus should be on data integrity, confidentiality, and availability. This can be achieved through the following measures: Integrity Guarantee: To ensure the integrity of data transmission, digital signature security measures are employed. Each data packet is signed with a private key before transmission. The private key is stored on a secure client device, such as a USB key, to ensure its security and immutability. Upon receiving a data packet, the signature is verified using the corresponding public key. This verification step is crucial to ensuring that data has not been tampered with during transmission, as any unauthorized modification of the data content will result in signature verification failure. Confidentiality Guarantee: All sensitive information is stored in encrypted form, using advanced encryption algorithms to ensure data security during storage and transmission. Especially in the face of high-privilege database account leaks or hacker database breaches, encryption measures effectively prevent data content from being deciphered even if unauthorized access is made. Furthermore, strict access control and authentication mechanisms, such as multi-factor authentication, are implemented to ensure that only authorized personnel can access critical data. Availability Guarantee: Critical data is regularly backed up, and a data-level disaster recovery strategy is implemented to ensure continuous data availability. All critical data undergoes a full backup at least once daily. All backup data is not only stored locally, but also uses off-site backup media storage to prevent simultaneous data loss due to local disasters. A data backup and recovery system is established to quickly restore data in the event of accidental loss.
[0099] The cybersecurity architecture of smart thermal power plants has comprehensively considered all aspects from the physical security layer to the data security layer, constructing a comprehensive security system. However, with technological advancements and the continuous evolution of security threats, there is a possibility for further improvement and enhancement of the cybersecurity architecture. To supplement and strengthen the converged cybersecurity architecture, the following series of cybersecurity protection strategies are proposed. These strategies further emphasize functional enhancements based on the existing cybersecurity architecture, spanning multiple security levels and applying to various system modules. Each cybersecurity protection strategy, as a whole, can significantly optimize multiple layers within the cybersecurity architecture, comprehensively improving its protection level.
[0100] The 1+6+N smart thermal power plant network security protection strategy includes: proactive defense strategy, intelligent anomaly monitoring strategy, boundary security protection strategy, and redundancy backup strategy.
[0101] In the cybersecurity architecture of smart thermal power plants, proactive defense strategies play a crucial role, ensuring that the plant's network environment not only defends against known threats but also prevents unknown attacks and responds quickly to emerging security risks. This strategy permeates multiple layers of the entire cybersecurity architecture, excelling in identity authentication and access control, intelligent security monitoring and response, security auditing and backtracking, and security training and awareness enhancement. Proactive defense strategies are implemented through a privileged account management system. This system manages high-privilege accounts distributed across various assets such as hosts, network devices, and security devices. The privileged account management system strengthens account security through automated account detection and abnormal account analysis, achieving lifecycle management of accounts, from discovery, organization, analysis, maintenance to secure storage. Furthermore, the system supports password policy management, including automatic password changes, password verification, and historical password rollback, ensuring account security and compliance. Intelligent security monitoring and response: enhancing real-time monitoring and timely response capabilities against network threats. At the technical level, proactive defense strategies integrate cloud technology and local network resources, deploying advanced security monitoring systems such as a security brain and intelligent traffic analysis tools. These systems utilize threat intelligence and machine learning algorithms to monitor and analyze network traffic and user behavior in real time to identify potential security threats. When anomalies or potential attacks are detected, the systems can automatically trigger defensive measures, such as isolating attack behavior and automatically blocking attack paths, effectively reducing the impact on power plant operations. Security Audit and Retrospective Analysis: The proactive defense strategy achieves security audit and retrospective functions through advanced monitoring systems and security log management. Utilizing security big data technologies and intelligent analysis tools, such as security cloud brains and log correlation analysis systems, the strategy can record and analyze all network activity and transaction logs. These systems provide detailed context for each security incident, including the time, location, users involved, and their behaviors. Through this data, security teams can quickly trace the source and path of any security incident, effectively conduct incident analysis and retrospective analysis, and ensure that problems can be quickly located and resolved. At the management level, the proactive defense strategy includes security governance, risk assessment, and asset management, ensuring closed-loop management of network security. This management strategy makes network security not only limited to technical protection but also encompasses the entire organization's security culture and practices, thereby achieving visualization of security objectives, proactive defense, and automated operation. Security training and awareness enhancement functions are also implemented.
[0102] In the cybersecurity of smart thermal power plants, intelligent anomaly monitoring strategies enhance security effectiveness by integrating artificial intelligence (AI) and machine learning (MLR) technologies. These strategies conduct in-depth analysis of massive amounts of security data to effectively identify potential security threats and abnormal behaviors. AI and MLR technologies not only improve the accuracy of security incident detection but also reduce false alarms, effectively addressing emerging threats by automatically adjusting security measures. The application of this technology ensures the timeliness and adaptability of response measures, making security protection more intelligent and automated. Furthermore, intelligent anomaly monitoring strategies monitor network and system activity in real time through behavioral analysis and anomaly detection technologies. These strategies use AI algorithms to learn normal behavioral patterns and automatically detect abnormal behaviors that do not conform to these patterns. This approach significantly enhances the early detection capability of insider threats and advanced persistent threats, enabling early intervention and preventing potential security vulnerabilities from evolving into larger-scale security incidents.
[0103] In smart thermal power plants, the key to protecting boundary areas lies in deploying high-performance next-generation firewalls (NGFWs). These firewalls play a crucial role at the three-zone interconnection boundary, the plant-side edge-cloud boundary, and the subsystem access boundary. Offering granular access control down to the application level, these firewalls combine application identification and user identification technologies to provide integrated application control policies from L3 to L7. Their wizard-driven, visual policy management simplifies the deployment process, making security policy implementation more efficient and precise. Furthermore, NGFWs support enhanced protection and detection capabilities, ensuring meticulous monitoring and control of all inbound and outbound traffic, significantly improving data center security. High-performance next-generation firewalls can filter various data entering and leaving the network, manage and analyze the behavior of inbound and outbound traffic, prohibit specific prohibited services or traffic, record firewall information content and activities, and detect and warn against various attack machines originating from the network. They provide network security protection and audit control functions, while also possessing high throughput and low latency network characteristics, and offering load balancing and intelligent routing functions to ensure high-quality network services for customers. The Boundary Zone Intrusion Prevention System (IDS) provides critical security protection for smart power plants, focusing on monitoring and blocking potential malicious attacks and threats. This system leverages advanced threat intelligence and security capabilities in tandem, along with an integrated security strategy, to detect and respond in real time to various attacks, including buffer overflows, SQL injection, and malware proliferation. Coupled with a precise intrusion attack signature database, IDS ensures the continuous security of application systems and the integrity of the network boundary, thus providing a robust security defense for the entire power plant network. The forward isolation device in the boundary zone ensures secure data transmission between Zone 1 and the smart power plant platform. This device achieves one-way data communication between the two networks through non-network transmission methods, preventing any form of backward data flow and effectively blocking potential network attacks. The forward isolation device uses comprehensive filtering technologies, such as MAC, IP, PORT, and protocol filtering, to ensure that only rigorously verified data packets can pass through. Simultaneously, this device also possesses strong anti-attack capabilities and high availability technology, ensuring the safe and stable operation of the power system and meeting the critical requirements of business continuity.
[0104] Smart thermal power plants must employ redundancy design to achieve multi-machine, multi-line backup of critical equipment and lines, preventing disruptions to business system communication or even system / platform paralysis due to single equipment failures or physical link interruptions. Therefore, in network design, redundancy backup strategies utilize technologies such as VRRP, virtualization, and HA to achieve dual-machine or multi-machine redundancy for critical network equipment (such as core switches, aggregation switches, and perimeter firewalls). The network redundancy backup strategy of smart thermal power plants effectively enhances the system's fault tolerance capabilities through carefully designed multi-machine, multi-link configurations. Critical equipment such as core switches and firewalls adopt high availability (HA) configurations to achieve automatic switching in the event of equipment failure, ensuring the continuity of critical services. Link redundancy is achieved through link aggregation technology; when one link fails, the system automatically switches to a backup link, ensuring continuous data transmission and stable network operation. Furthermore, next-generation firewalls and aggregation switches in edge cloud environments also employ stacking and HA strategies to enhance the security and reliability of data processing and transmission. The backup system enables unattended, real-time centralized backup protection. In the event of data loss due to physical or logical failures, rapid recovery is achieved through the backup appliance. Deploying a backup system in a remote data center supports disaster recovery, ensuring data integrity and continuous system operation.
[0105] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit its scope of protection. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that after reading the present invention, they can still make various changes, modifications or equivalent substitutions to the specific implementation of the invention, but these changes, modifications or equivalent substitutions are all within the scope of protection of the pending claims of the invention.
Claims
1. A network security system of a cloud-edge collaboration 1+6+N intelligent thermal power plant architecture, characterized in that, The physical security layer comprises a production control area, an information management area and a two-network fusion boundary area; the production control area is a power plant area 1, the information management area is a power plant area 3, and the two-network fusion boundary area is arranged between the power plant area 1 and the power plant area 3; The two-network fusion boundary area is provided with a two-network fusion boundary physical security layer, which is used for forward isolation of the power plant area 1 and the power plant area 3; the power plant area 1 is provided with a power plant area 1 physical security layer, which is used for function isolation partition and protection of infrastructure of the power plant area 1; the power plant area 3 is provided with a power plant area 3 physical security layer, which is used for function isolation partition and protection of infrastructure of the power plant area 3; The power plant area 3 physical security layer and the power plant area 1 physical security layer are connected through the two-network fusion boundary physical security layer; The power plant area 1 physical security layer comprises a power plant area 1 core area, a power plant area 1 safety management area and a power plant area 1 other function area; the power plant area 1 core area is provided with a power plant area 1 core switch, the power plant area 1 safety management area and the power plant area 1 other function area are each provided with a switch, the power plant area 1 core switch is connected with a DCS, the two-network fusion boundary physical security layer and the switches, a firewall is arranged between the power plant area 1 core switch and the DCS, the two-network fusion boundary physical security layer and the switches, and the power plant area 1 core switch and the switches adopt a dual-machine backup mechanism; the power plant area 1 safety management area is provided with a power plant area 1 safety module; The power plant area 3 physical security layer comprises a power plant area 3 core area, a power plant area 3 safety management area, an export area, a 1+6+N plant side edge cloud wisdom business area and a power plant area 3 other function area; The power plant area 3 core area is provided with a power plant area 3 core switch, which is connected with the power plant area 3 safety management area, the 1+6+N plant side edge cloud wisdom business area and the power plant area 3 other function area; a power plant area 3 firewall is arranged between the power plant area 3 core switch and the power plant area 3 safety management area, the 1+6+N plant side edge cloud wisdom business area and the power plant area 3 other function area; the power plant area 3 core switch is connected with the export area, a power plant area 3 firewall and an intrusion prevention system are arranged between the power plant area 3 core switch and the export area, and the export area is connected with an external network; The power plant area 3 safety management area is provided with a power plant area 3 safety module; The production control area and the information management area are each provided with a host server, the host server is deployed with a host safety management system and installed with safety software, the safety software comprises antivirus software and an identity authentication access control system; the host safety management system is connected with the power plant area 1 power plant area 3 safety module and the power plant area 3 power plant area 3 safety module, and the host safety management system adopts a single host offline running safety management system; The power plant area 1 safety module and the power plant area 3 safety module are each provided with a safety management platform, the safety management platform is installed with safety applications, and the safety applications comprise a database audit application, a log audit application, a data backup application and a safety operation application; The firewall of the third area of the power plant adopts HA deployment, the firewall of the third area of the power plant between the core switch of the third area of the power plant and the safety management area, the 1+6+N factory side edge cloud wisdom business area and other functional areas of the third area of the power plant adopts HA deployment in series, and the firewall of the third area of the power plant connected between the core switch of the third area of the power plant and the export area and the intrusion prevention system adopt HA deployment in gateway form.
2. The network security system of a cloud-edge collaboration 1+6+N smart thermal power plant architecture according to claim 1, wherein, The physical security layer of the two-network fusion boundary includes a one-way isolation gateway, which is used for one-way data transfer between the first area of the power plant and the third area of the power plant, and the one-way isolation gateway adopts one-way non-feedback transmission; The one-way data transfer is as follows: the third area of the power plant cannot actively transmit data to the first area of the power plant, and the data of the first area of the power plant is transmitted to the third area of the power plant through the one-way isolation gateway, and the data of the first area of the power plant includes data of the first area of the power plant analyzing production and guiding the business of each sub-area of the third area of the power plant.
3. The network security system of a cloud-edge collaboration 1+6+N smart thermal power plant architecture according to claim 1, characterized in that, The core switch of the third area of the power plant adopts a dual-redundancy switch, which adopts VRRP technology, specifically through the IP address segment distributed by the wisdom power plant, uses static routing, VRRP and firewall HA hot standby technology to realize dual-link redundancy backup mechanism.
4. The network security system of a cloud-edge collaboration 1+6+N smart thermal power plant architecture according to claim 3, characterized in that, The dual-link redundancy backup mechanism is as follows: when the link and device are working normally, the dual-directional intercommunication of the network platform of the 1+6+N factory side edge cloud wisdom business area of the third area of the power plant uses gigabit link; when the main device fails, the VRRP virtual gateway migration device is used for forwarding communication.
5. The network security system of a cloud-edge collaboration 1+6+N smart thermal power plant architecture according to claim 4, characterized in that, The network security layer, the application security layer and the data security layer are included, the application security layer is deployed on the security management platform of the physical security layer, and is used for intrusion prevention, safety management of the first area of the power plant, safety management of the third area of the power plant and host safety management; The application security layer is deployed on the security management platform of the application security layer, and is used for antivirus, access control and identity authentication, audit and security operation and maintenance management; the application security layer deploys a security monitoring system; The data security layer is deployed on the network security layer and the application security layer, and is used for data life cycle security, data access security and key data protection.
Citation Information
Patent Citations
Private cloud platform architecture suitable for smart power plant
CN114760302A