A novel power distribution master station system information interaction security defense method, device and system

Through dynamic trust evaluation and real-time monitoring, the information interaction security problem of the distribution master station system is solved, and dynamic trust evaluation of the client and real-time response to abnormal behavior are achieved to ensure the safety of the power grid.

CN118869338BActive Publication Date: 2025-10-17NARI NANJING CONTROL SYSTEM CO LTD +4
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411163522.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-23
Publication Date
2025-10-17
Estimated Expiration
2044-08-23

AI Technical Summary

Technical Problem

The existing distribution master station system faces uncontrollable security risks and hidden and intelligent attacks. Traditional protection measures are ineffective. The high interactivity between users and the power grid leads to a lower attack threshold and insufficient information interaction security.

Method used

By calculating the user's initial trust evaluation value, setting access rights, establishing a temporary dedicated link, and monitoring client behavior in real time, dynamically updating the trust evaluation value, disconnecting abnormal links, and building a dynamic trust evaluation system.

Benefits of technology

It eliminates direct channels for malicious access and attacks, monitors abnormal behavior in real time, establishes an effective information interaction security defense system, and ensures the safe and stable operation of the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118869338B_ABST
    Figure CN118869338B_ABST
Patent Text Reader

Abstract

The application discloses a novel power distribution master station system information interaction security defense method, device and system. The method comprises the following steps: calculating an initial trust evaluation value according to user registration information and configuring an access strategy; calculating a current trust evaluation value of a user according to a user data access request, combining the access strategy to judge whether to agree to the user access request, if yes, issuing a notification to a security proxy gateway of the power distribution master station system, and establishing a temporary special link for the client to access data of the power distribution master station system by the security proxy gateway; acquiring client user behavior data monitored by the security gateway proxy in real time, dynamically evaluating the user, and controlling the shutdown of the temporary special link. The method realizes that there is no data access network link between the client and the power distribution master station system before the trust value of the user is dynamically evaluated, and fundamentally eliminates the way of directly maliciously accessing and attacking the power distribution master station system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, and in particular to a novel power distribution master station system information interaction security defense method, device and system. BACKGROUND

[0002] With a large number of Internet of Things devices and multi-investment subject assets accessing the power distribution master station system, uncontrollable security risks are brought to the boundary of the power distribution grid, and the high interactivity between users and the grid leads to the expansion of the attack surface of the power distribution grid; the high friendliness of the operation mode leads to the lowering of the attack threshold.

[0003] On the other hand, the international network security situation is becoming increasingly severe, and security threats are developing towards concealment, intelligence and hybridization, and there are numerous targeted attack methods for industrial Internet of Things systems, and static and patch-based protection techniques are gradually ineffective. SUMMARY

[0004] The present application is proposed to overcome the deficiencies of the prior art, and provides a novel power distribution master station system information interaction security defense method, device and system.

[0005] Technical solution: In a first aspect, a novel power distribution master station system information interaction security defense method is provided, which comprises the following steps:

[0006] According to the user registration information and the client information at the time of registration, the initial trust evaluation value of the registered user is calculated, and if the initial trust evaluation value is lower than the preset trust threshold, the registration is rejected; for the registered user, the access permission is set according to the user identity information;

[0007] According to the user data access request and the client information at the time of access, the current trust evaluation value of the user is calculated, and it is judged whether the current trust evaluation value and the access permission corresponding to the current user data access request meet the requirements, and if not, the access request is rejected; if it meets the requirements, a notification is sent to the security proxy gateway of the power distribution master station system, and the security proxy gateway establishes a temporary dedicated link for the client to access the data of the power distribution master station system;

[0008] The dedicated link information fed back by the security gateway proxy and the client user behavior data monitored by the security gateway proxy in real time are obtained, and the trust evaluation value of the user is updated, and when the user behavior data is abnormal or the updated trust evaluation value is lower than the specified threshold, the security proxy gateway is notified to disconnect the temporary dedicated link of the corresponding user.

[0009] Preferably, the user registration information includes user account, identity, department and post; the client information is the client itself related information received and collected by the security kit installed on the client, including one or more of system information, software information, hardware information, user information, network address and system log;

[0010] According to the user registration information and the client information at the time of registration, an initial trust evaluation value of the registered user is calculated, comprising:

[0011] According to the obtained client information, it is checked whether there is a security vulnerability, whether there is suspected malware, a current network risk, and whether there is an unsafe operation behavior through a system log, and an initial trust evaluation value of the current registered user is generated in combination with user identity and post information in the user registration information.

[0012] Preferably, it is judged whether the current trust evaluation value and the access permission corresponding to the current user data access request meet the requirements, comprising:

[0013] It is judged whether the current trust evaluation value is higher than a preset access trust threshold value, if not, the requirements are not met, and the current access request is rejected; if yes, the access permission of the current user is obtained according to the user identity information, and the obtained access permission is compared with the access permission corresponding to the data type of the power master station system data requested by the current data access request, if the former is higher than the latter, the current user access is agreed, otherwise the current access request is rejected.

[0014] Preferably, a notification is sent to the security proxy gateway of the power master station system, and the content of the notification includes one or more of the user's identity information, the trust evaluation value, the permission, the network address, the client hardware information, the requested data address and the port;

[0015] A special temporary data access link with the power master station system is established by the security proxy gateway according to the content of the notification, the special link established is bound with the client user identity, and special link information is fed back;

[0016] The special link information includes a newly established link network address, a port, a validity period, and a client user identity; the client performs data access through the link network address and the port within the validity period.

[0017] Preferably, according to the client user behavior data monitored by the security proxy gateway in real time, the trust evaluation value of the user is updated, when the user behavior data is abnormal or the updated trust evaluation value is lower than a specified threshold value, the security proxy gateway is notified to disconnect the temporary special link of the corresponding user, comprising:

[0018] The client user behavior data monitored in real time includes login information, operation information, network connection, data query request, data modification request; the trust evaluation value of the user is updated according to the user behavior data, if the updated trust evaluation value is lower than a specified threshold value, the security proxy gateway is notified to disconnect the temporary special link of the corresponding user;

[0019] Acquire real-time monitored client user behavior data, judge whether the client user behavior data is abnormal, if there is any one of illegal port, illegal process, illegal connection, network attack behavior, abnormal traffic, notify the security proxy gateway to disconnect the temporary dedicated link of the corresponding user.

[0020] In a second aspect, a novel power distribution master station system information interaction security defense device includes:

[0021] A registration management module is configured to calculate an initial trust evaluation value of a registered user according to user registration information and client information at the time of registration, and to reject the registration if the initial trust evaluation value is lower than a preset trust threshold; and to set access permissions according to user identity information for a user who has successfully registered.

[0022] An access management module is configured to calculate a current trust evaluation value of a user according to a user data access request and client information at the time of access, to judge whether the current trust evaluation value and access permissions corresponding to the current user data access request meet the requirements, to reject the access request if they do not meet the requirements, and to notify a security proxy gateway of a power distribution master station system if they meet the requirements, so that the security proxy gateway establishes a temporary dedicated link for the client to access data of the power distribution master station system.

[0023] A link management module is configured to acquire dedicated link information fed back by a security gateway proxy and client user behavior data monitored by the security gateway proxy in real time, to update a trust evaluation value of a user, and to notify the security proxy gateway to disconnect a temporary dedicated link of the corresponding user when the user behavior data is abnormal or the updated trust evaluation value is lower than a specified threshold.

[0024] In a third aspect, a computer device is provided, which includes one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the programs are implemented when executed by the processors to implement the steps of the novel power distribution master station system information interaction security defense method according to the first aspect.

[0025] In a fourth aspect, a computer storage medium is provided, which stores a computer program, and the computer program is implemented when executed by the processors to implement the steps of the novel power distribution master station system information interaction security defense method according to the first aspect.

[0026] In a fifth aspect, a novel power distribution master station system information interaction security defense system includes:

[0027] A client security suite is configured to collect client information, user registration information, and user data access requests, and send them to a dynamic trust evaluation component.

[0028] A dynamic trust evaluation component is used to calculate the initial trust evaluation value of the registered user based on the user registration information and the client information at the time of registration. If the initial trust evaluation value is lower than the preset trust threshold, the registration is rejected; for users who have successfully registered, access rights are set according to the user identity information; and the current trust evaluation value of the user is calculated based on the user data access request and the client information at the time of access, and it is determined whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements. If not, the access request is rejected; if it meets the requirements, a notification is sent to the security proxy gateway of the distribution master station system, and the security proxy gateway establishes a temporary dedicated link for the client to access the distribution master station system data; and the dedicated link information fed back by the security gateway agent and the client user behavior data monitored in real time by the security gateway agent are obtained, and the trust evaluation value of the user is updated. When the user behavior data is abnormal or the updated trust evaluation value is lower than the specified threshold, the security proxy gateway is notified to disconnect the temporary dedicated link of the corresponding user;

[0029] The security proxy gateway is used to establish a temporary dedicated link for the client to access the distribution master station system data based on the notification of the dynamic trust evaluation component, and feed back the link information and client user behavior data to the dynamic trust evaluation component.

[0030] Beneficial Effects: Compared with existing technologies, this invention offers the following advantages: Before a client's trust value is dynamically evaluated, no data access network link exists between the client and the distribution master station system, fundamentally eliminating direct malicious access and attacks against the distribution master station system. Client behavior is monitored in real time during data access, and any anomalies detected immediately close the data access link and update the trust evaluation value. Access policies are implemented to control client data access, establishing an effective information exchange security defense system and ensuring the safe and stable operation of the power grid. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a structural block diagram of the information interaction security defense system of the new power distribution master station system of the present invention.

[0032] Figure 2 This is a client registration flow chart of the present invention.

[0033] Figure 3 This is a client data access flow chart of the present invention. DETAILED DESCRIPTION

[0034] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings.

[0035] like Figure 1 As shown, the embodiment provides a new type of information interaction security defense system for power distribution master station system, including:

[0036] A client security suite running on the client device is used to collect client information, user registration information, user data access requests, and send them to the dynamic trust assessment component through the network;

[0037] The dynamic trust assessment component is deployed between the master station system cluster and the network exit, and can be deployed on a separate server or integrated with an existing server. It is used for dynamic trust assessment of the client and sends a notification to the proxy gateway when the relevant security control conditions are met.

[0038] The security proxy gateway is used to establish a temporary dedicated link for the client to access the data of the power distribution master station system according to the notification of the dynamic trust assessment component, and feedback the link information to the dynamic trust assessment component.

[0039] Based on the system, a new type of power distribution master station system information interaction security defense method is provided, which includes the following steps:

[0040] S1, client user registration, the power distribution master station system dynamic trust assessment component calculates the trust evaluation value of the newly registered user and generates an access strategy.

[0041] S2, the client user requests data access, and the dynamic trust assessment component judges whether to agree to the user request according to the trust evaluation value and the access strategy, and notifies the power distribution master station system security proxy gateway if it agrees.

[0042] S3, establish a dedicated data access link, the security proxy gateway establishes a temporary dedicated link for the client to access the data of the power distribution master station system, and the client user realizes data access by using the dedicated link.

[0043] S4, the security gateway proxy monitors the client user behavior in real time, closes the link immediately when an anomaly is found, and synchronizes the abnormal information to the dynamic trust assessment component in real time to realize a new round of dynamic assessment of the client user.

[0044] In specific implementation, in order to realize the dynamic trust assessment component to calculate the trust evaluation value of the newly registered user, as shown in Figure 2 The client user registration in S1 should include: user account, identity, department and post, and the type of power distribution master station system data required for access. The power distribution master station system deploys a dynamic trust assessment component, and the client user installs a special client security suite before registration. The client security suite is responsible for collecting client information, including: system information, software information, hardware information, user information, network address, system log, etc. During registration, the registration information is encrypted and submitted to the dynamic trust assessment component.

[0045] The trust evaluation value in S1 is generated according to the information submitted by the client security suite, checking whether the client system has security vulnerabilities, whether there is suspected malware, current network risks, and whether there are unsafe operation behaviors through system log checking, etc. The trust evaluation value of the current registered client user is generated, and if it is lower than the preset trust threshold, the registration is not allowed. The specific checking contents are as follows:

[0046] In terms of data security, it is checked whether the client encrypts data and whether security protection measures are taken to protect data security during data transmission.

[0047] In terms of network security, it is checked whether the client uses an effective firewall, whether an intrusion detection or active defense system is installed to protect the network from malicious attacks.

[0048] In terms of device security, it is checked whether the client device has remote locking, data erasing and other security policies to reduce the security risks caused by device loss or leakage.

[0049] In terms of application security, it is checked whether the client has installed application security audit, vulnerability scanning, program isolation and other measures to prevent security risks caused by applications.

[0050] In terms of system security, through system environment scanning, system log analysis and other means, it is checked whether the client system has important security patches, whether high-risk ports are closed, whether there are records of accessing insecure websites, etc. to prevent security risks caused by system health problems.

[0051] For the registered user, the access permission is determined according to the user identity information.

[0052] The access strategy in S1 is to automatically identify the legality of data access requests according to the data access permissions of the client user, and directly refuse illegal access. The dynamic trust evaluation component automatically generates the data access permissions of the user according to the registration information of the client user, according to the user identity, department post and the type of data to be accessed in the power distribution master station system. The data within the access permission range of the client is judged to be legal, and the data outside the access permission is judged to be illegal and refused to access. If the client user needs to access data outside the existing permissions, the client user needs to submit an application, and the power distribution master station system administrator agrees to give the corresponding permission and generate the corresponding access strategy.

[0053] To realize the security defense when the client user requests data access, such as Figure 3As shown, the client user in S2 requests data access, the dynamic trust evaluation component performs a new round of trust value evaluation on the current client user, and if the evaluation value exceeds the preset trust threshold, the dynamic trust evaluation component judges whether the user has data access permission according to the user identity information. If the access permission also meets the requirements, the dynamic trust evaluation component notifies the security proxy gateway to prepare a special data access link. Specifically, if the current trust evaluation value exceeds the preset trust threshold, it means that the current user is trustworthy, and the user identity information of the current access is obtained to obtain the access permission of the user. The access permission obtained is compared with the access permission corresponding to the power distribution master station system data type requested by the current data access request. If the former is higher than the latter, the current user is allowed to access. The former is higher than the latter means that the former permission is higher than or equal to the latter permission. For example, the user access permission is a system administrator, and the requested data type corresponds to ordinary access to certain data, which meets the requirements. If the requested data type corresponds to core business management data, it also meets the requirements because it is a system administrator. If the user access permission is a normal user and the requested data type corresponds to core business system management data, it does not meet the requirements. The correspondence between the access permission and the identity information can be mapped in advance.

[0054] The dynamic trust evaluation component in S2 notifies the security proxy gateway to prepare a special data access link. The notification content includes the user's identity information, trust evaluation value, permission, network address, client hardware information, requested data address and port, etc.

[0055] In S3, the special data access link is established, which means that after receiving the notification of the dynamic trust evaluation component to establish a special data access link, the security proxy gateway establishes a special temporary data access link with the power distribution master station system. The special link is bound to the client user identity, and the network address, port and validity period of the newly established link are fed back to the dynamic trust evaluation component together with the client user identity. The dynamic trust evaluation component feeds back to the client user, and the client performs data access through the link network address and port within the validity period.

[0056] The real-time monitoring of the client user behavior in S4 includes the login information, operation information, network connection, data query request, data modification request, illegal port, illegal process, illegal connection, network attack behavior, abnormal traffic, etc. The dynamic trust evaluation component dynamically updates the trust evaluation value according to the user behavior information. If the evaluation value is lower than the preset trust threshold, the security proxy gateway is notified to close the current link. If illegal ports, illegal processes, illegal connections, network attack behaviors, abnormal traffic, etc. occur, the security proxy gateway is immediately notified to close the current link.

[0057] According to the method, before the dynamic evaluation of the trust value of the client is completed, the client does not exist a data access network link with the power distribution master station system, so as to fundamentally eliminate the way of directly maliciously accessing and attacking the power distribution master station system. The behavior of the client is monitored in real time during the data access process, the data access link is closed immediately when an abnormality is found, and the trust evaluation value is updated. Through the access strategy, the data access of the client is controlled, an effective information interaction security defense system is established, and the safe and stable operation of the power grid is ensured.

[0058] The application further provides a novel power distribution master station system information interaction security defense device, which comprises:

[0059] A registration management module is configured to calculate an initial trust evaluation value of a registered user according to user registration information and client information at the time of registration, and to reject the registration if the initial trust evaluation value is lower than a preset trust threshold value; and to set an access permission according to user identity information for a user who has successfully registered.

[0060] An access management module is configured to calculate a current trust evaluation value of a user according to a user data access request and client information at the time of access, to determine whether the current trust evaluation value and an access permission corresponding to the current user data access request meet the requirements, to reject the access request if the requirements are not met, and to send a notification to a security proxy gateway of the power distribution master station system to establish a temporary special link for the client to access data of the power distribution master station system by the security proxy gateway if the requirements are met.

[0061] A link management module is configured to acquire special link information fed back by the security proxy gateway and user behavior data of the client monitored by the security proxy gateway in real time, to update the trust evaluation value of the user, and to notify the security proxy gateway to disconnect the temporary special link of the corresponding user when the user behavior data is abnormal or the updated trust evaluation value is lower than a specified threshold value.

[0062] The user registration information comprises a user account, identity, department and post, and the client information is related information of the client itself collected by a security kit installed on the client, and comprises one or more of system information, software information, hardware information, user information, a network address and system logs.

[0063] The registration management module calculates the initial trust evaluation value of the registered user according to the user registration information and the client information at the time of registration.

[0064] According to the acquired client information, whether there is a security vulnerability, whether there is suspected malicious software and a current network risk are checked, whether there is an unsafe operation behavior is checked through system logs, and the initial trust evaluation value of the current registered user is generated in combination with the user identity and post information in the user registration information.

[0065] Preferably, the access management module determines whether the current trust evaluation value and the access right corresponding to the current user data access request meet the requirements, including:

[0066] determining whether the current trust evaluation value is higher than a preset access trust threshold, if not, the requirements are not met, and the current access request is rejected; if yes, the access right of the current user is obtained according to the user identity information, and the obtained access right is compared with the access right corresponding to the power distribution master station system data type requested by the current data access request, if the former is higher than the latter, the current user access is agreed, otherwise the current access request is rejected.

[0067] Preferably, the access management module sends a notification to the power distribution master station system security agent gateway, and the notification content includes one or more of the user's identity information, trust evaluation value, right, network address, client hardware information, requested data address and port;

[0068] The security agent gateway establishes a special temporary data access link with the power distribution master station system according to the notification content, binds the established special link with the client user identity, and feeds back the special link information;

[0069] The special link information includes: the network address, port and validity period of the newly established link together with the client user identity; the client performs data access through the link network address and port within the validity period.

[0070] Preferably, the link management module updates the trust evaluation value of the user according to the real-time monitoring of the client user behavior data by the security agent gateway, and notifies the security agent gateway to disconnect the temporary special link of the corresponding user when the user behavior data is abnormal or the updated trust evaluation value is lower than a specified threshold, including:

[0071] The real-time monitoring of the client user behavior data includes: login information, operation information, network connection, data query request, data modification request; the trust evaluation value of the user is updated according to the user behavior data, and if the updated trust evaluation value is lower than a specified threshold, the security agent gateway is notified to disconnect the temporary special link of the corresponding user;

[0072] The real-time monitoring of the client user behavior data is obtained, and it is determined whether the client user behavior data is abnormal, if any one of the following is abnormal: illegal port, illegal process, illegal connection, network attack behavior, abnormal traffic, the security agent gateway is notified to disconnect the temporary special link of the corresponding user.

[0073] It should be understood that the novel power distribution master station system information interaction security defense device in the embodiments of the present application can realize all the technical solutions in the method embodiments described above, the functions of each functional module thereof can be realized according to the methods in the method embodiments described above, and the specific implementation process can be referred to the related description in the above embodiments, which will not be described here in detail.

[0074] The present application also provides a computer device, comprising one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the program is executed by the processor to realize the steps of the novel power distribution master station system information interaction security defense method as described above.

[0075] The present application also provides a computer storage medium having a computer program stored thereon, wherein the computer program is executed by the processor to realize the steps of the novel power distribution master station system information interaction security defense method as described above.

[0076] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, device (system), computer device or computer program product. Therefore, the present application can adopt a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0077] The present application is described with reference to flowcharts according to the method of the embodiments of the present application. It should be understood that each flow in the flowchart and the combination of the flows in the flowchart can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a means for implementing the functions specified in the flow Figure 1 The device specified in one flow or multiple flows.

[0078] These computer program instructions can also be stored in a computer readable memory capable of guiding the computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer readable memory produce a product including instruction means, which realizes the functions specified in the flow Figure 1 The device specified in one flow or multiple flows.

[0079] These computer program instructions can also be loaded into a computer or other programmable data processing devices, so that a series of operational steps are performed on the computer or other programmable devices to generate a computer-implemented process, so that the instructions executed by the computer or other programmable devices provide operational steps for implementing the functions specified in the flowchart block or multiple flowcharts. Figure 1 The flowchart blocks or multiple flowcharts in the flowchart blocks specify the functions of one or more steps.

Claims

1. A novel information interaction security defense method for a power distribution master station system, characterized in that: The method comprises the following steps: Calculate the initial trust evaluation value of the registered user based on the user registration information and the client information at the time of registration. If the initial trust evaluation value is lower than the preset trust threshold, the registration is rejected. For users who have successfully registered, set access rights based on the user identity information. The user registration information includes: user account, identity, department and position. The client information is client-side related information collected and received by the security suite installed on the client, including one or more of: system information, software information, hardware information, user information, network address, and system log. Calculate the initial trust evaluation value of the registered user based on the user registration information and the client information at the time of registration. The calculation includes: checking for security vulnerabilities, suspected malware, and current network risks based on the acquired client information, and checking for unsafe operations through system logs. Combined with the user identity and position information in the user registration information, generate the initial trust evaluation value of the current registered user. Based on the user data access request and the client information at the time of access, the user's current trust evaluation value is calculated, and it is judged whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements. If not, the access request is rejected; if it meets the requirements, a notification is sent to the distribution master station system security proxy gateway, and the security proxy gateway establishes a temporary dedicated link for the client to access the distribution master station system data; wherein, judging whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements includes: judging whether the current trust evaluation value is higher than a preset access trust threshold, if not, it does not meet the requirements and the current access request is rejected; if so, the access rights of the user currently accessing are obtained based on their identity information, and the obtained access rights are compared with the access rights corresponding to the type of distribution master station system data requested by the current data access request. If the former is higher than the latter, the current user access is granted, otherwise the current access request is rejected; Obtain temporary dedicated link information fed back by the security gateway agent and client user behavior data monitored in real time by the security proxy gateway, update the trust evaluation value for the user, and notify the security proxy gateway to disconnect the temporary dedicated link for the corresponding user when the user behavior data is abnormal or the updated trust evaluation value is lower than the specified threshold. Specifically, it includes: Obtain real-time monitored client user behavior data, update the user's trust evaluation value based on the user behavior data, and notify the security proxy gateway to disconnect the corresponding user's temporary dedicated link if the updated trust evaluation value is lower than the specified threshold; Obtain real-time monitored client user behavior data and determine whether there are any anomalies in the client user behavior data. If any of the following items are found: illegal ports, illegal processes, illegal connections, network attack behaviors, and abnormal traffic, the security proxy gateway will be notified to disconnect the temporary dedicated link for the corresponding user. The client user behavior data monitored in real time includes: client login information, operation information, network connection status, data query requests, and data modification requests.

2. The method according to claim 1, characterized in that Sending a notification to the security proxy gateway of the power distribution master station system, the content of the notification including: one or more of the user's identity information, trust evaluation value, authority, network address, client hardware information, requested data address and port; The security proxy gateway establishes a temporary dedicated link with the power distribution master station system based on the content of the notification, binds the established temporary dedicated link to the client user identity, and feeds back the temporary dedicated link information; The temporary dedicated link information includes: the newly established link network address, port, validity period and client user identity; the client accesses data within the validity period through the link network address and port.

3. A new type of information interaction security defense device for power distribution master station system, characterized in that: include: The registration management module is used to calculate the initial trust evaluation value of the registered user based on the user registration information and the client information at the time of registration. If the initial trust evaluation value is lower than the preset trust threshold, the registration is rejected; For successfully registered users, access rights are set based on the user's identity information; wherein the user registration information includes: user account, identity, department and position; the client information is client-related information collected and received by the security suite installed on the client, including: one or more of: system information, software information, hardware information, user information, network address, and system log; calculating the initial trust evaluation value of the registered user based on the user registration information and the client information at the time of registration includes: checking for security vulnerabilities, suspected malware, and current network risks based on the obtained client information, and checking for unsafe operations through system logs, and generating the initial trust evaluation value of the current registered user based on the user identity and position information in the user registration information; An access management module is used to calculate the user's current trust evaluation value based on the user data access request and the client information at the time of access, and to determine whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements. If not, the access request is rejected. If they meet the requirements, a notification is sent to the distribution master station system security proxy gateway, and the security proxy gateway establishes a temporary dedicated link for the client to access the distribution master station system data. The determination of whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements includes: determining whether the current trust evaluation value is higher than a preset access trust threshold. If not, it does not meet the requirements and the current access request is rejected. If so, the access rights of the user currently accessing are obtained based on their identity information, and the obtained access rights are compared with the access rights corresponding to the type of distribution master station system data requested by the current data access request. If the former is higher than the latter, the current user's access is granted, otherwise the current access request is rejected. The link management module is used to obtain the dedicated link information fed back by the security gateway agent and the client user behavior data monitored in real time by the security gateway agent, update the trust evaluation value for the user, and notify the security proxy gateway to disconnect the temporary dedicated link for the corresponding user when the user behavior data is abnormal or the updated trust evaluation value is lower than the specified threshold. Specifically, it includes: Obtain real-time monitored client user behavior data, update the user's trust evaluation value based on the user behavior data, and notify the security proxy gateway to disconnect the corresponding user's temporary dedicated link if the updated trust evaluation value is lower than the specified threshold; Obtain real-time monitored client user behavior data and determine whether there are any anomalies in the client user behavior data. If any of the following items are found: illegal ports, illegal processes, illegal connections, network attack behaviors, and abnormal traffic, the security proxy gateway will be notified to disconnect the temporary dedicated link for the corresponding user. The client user behavior data monitored in real time includes: client login information, operation information, network connection status, data query requests, and data modification requests.

4. A computer device, characterized in that: The device includes one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the new distribution master station system information interaction security defense method as described in any one of claims 1-2 are implemented.

5. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the new distribution master station system information interaction security defense method as described in any one of claims 1-2 are implemented.

6. A new type of information interaction security defense system for power distribution master station system, characterized by: include: A client security suite, configured to collect client information, user registration information, and user data access requests, and send the collected information to a dynamic trust assessment component; wherein the user registration information includes: user account, identity, department, and position; and the client information includes: one or more of: system information, software information, hardware information, user information, network address, and system logs; A dynamic trust evaluation component is used to calculate the initial trust evaluation value of the registered user based on the user registration information and the client information at the time of registration. If the initial trust evaluation value is lower than the preset trust threshold, the registration is rejected; for users who have successfully registered, access rights are set according to the user identity information; and the current trust evaluation value of the user is calculated based on the user data access request and the client information at the time of access, and it is determined whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements. If not, the access request is rejected; if it meets the requirements, a notification is sent to the security proxy gateway of the distribution master station system, and the security proxy gateway establishes a temporary dedicated link for the client to access the distribution master station system data; and the dedicated link information fed back by the security gateway agent and the client user behavior data monitored in real time by the security gateway agent are obtained, and the trust evaluation value of the user is updated. When the user behavior data is abnormal or the updated trust evaluation value is lower than the specified threshold, the security proxy gateway is notified to disconnect the temporary dedicated link of the corresponding user; Calculating the initial trust evaluation value of a registered user based on the user registration information and the client information at the time of registration includes: checking for security vulnerabilities, suspected malware, and current network risks based on the acquired client information, and checking for unsafe operations through system logs, and combining the user identity and position information in the user registration information to generate the initial trust evaluation value of the current registered user; Determining whether the current trust evaluation value and the access rights corresponding to the current user data access request meet the requirements, including: determining whether the current trust evaluation value is higher than a preset access trust threshold; if not, it does not meet the requirements and the current access request is rejected; if so, obtaining the access rights of the current accessing user based on their identity information, comparing the obtained access rights with the access rights corresponding to the type of distribution master station system data requested by the current data access request; if the former is higher than the latter, granting the current user access; otherwise, rejecting the current access request; Update the trust evaluation value for the user. When the user behavior data shows abnormalities or the updated trust evaluation value is lower than the specified threshold, notify the security proxy gateway to disconnect the temporary dedicated link for the corresponding user. Specifically, it includes: Obtain real-time monitored client user behavior data, update the user's trust evaluation value based on the user behavior data, and notify the security proxy gateway to disconnect the corresponding user's temporary dedicated link if the updated trust evaluation value is lower than the specified threshold; Obtain real-time monitored client user behavior data and determine whether there are any anomalies in the client user behavior data. If any of the following items are found: illegal ports, illegal processes, illegal connections, network attack behaviors, and abnormal traffic, the security proxy gateway will be notified to disconnect the temporary dedicated link for the corresponding user. The real-time monitored client user behavior data includes: client login information, operation information, network connection status, data query requests, and data modification requests; The security proxy gateway is used to establish a temporary dedicated link for the client to access the distribution master station system data based on the notification of the dynamic trust evaluation component, and feed back the temporary dedicated link information and client user behavior data to the dynamic trust evaluation component.

Citation Information

Patent Citations

  • Cross-domain zero-trust authentication system for electric power information communication system based on cloud side-end fusion

    CN115603987A

  • Zero-trust system access control method and device and zero-trust system

    CN116319024A