Method and apparatus for accessing tpcm device based on secure and trusted switch
By utilizing the TPCM device access method and apparatus of a secure and trusted switch, and employing trusted reports and signature verification of the SM9 functional module, the decentralized problem of device access authentication in industrial control systems is solved, thereby improving system security and management efficiency.
Patent Information
- Application Number
- CN202411229416.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-03
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-09-03
AI Technical Summary
Existing technologies have failed to effectively solve the problem of device access authentication in industrial control systems, especially in decentralized environments where there is a lack of advanced security strategies to deal with malicious code attacks, and traditional protection methods are inadequate.
By participating in TPCM device access through a secure and trusted switch, decentralized device access authentication is achieved. Trusted reports, identity authentication, and signature verification mechanisms are used in conjunction with the SM9 functional module for signature verification, an access control whitelist is established, and access frequency, communication relationship, and aging time policies are executed.
It enhances the security of industrial control systems, identifies abnormal attacks, reduces the resource consumption of the security management platform, and achieves ease of device access and cost-effectiveness.
Smart Images

Figure CN119094206B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure and trusted switch technology, and in particular to a method and apparatus for accessing TPCM devices based on a secure and trusted switch. Background Technology
[0002] Industrial control systems (ICS), as an important strategic resource, are used in more than 80% of critical infrastructure. They have capabilities such as controlling the switching of hydropower stations, detecting the status of power grids, or controlling the pressure of fuel and gas pipelines, playing an important role in the national infrastructure development.
[0003] Currently, the information security of industrial control systems (ICS) faces severe challenges. A 2018 white paper on industrial information security released by Kaspersky Lab profoundly revealed the grim security situation in the global industrial sector. According to the white paper, among its extensive survey of globally representative industrial enterprises and organizations, at least 30% of respondents confirmed they had experienced cyberattacks. Given that nearly 20% of respondents did not provide detailed statistics, this percentage is likely even more alarming. Of particular note is that malicious code has quietly become a major security threat to industrial control systems (ICS) and their monitoring and control terminals. The spread and destructive actions of this malicious code are extremely covert, capable of penetrating traditional security networks centered on physical isolation, rendering existing defenses inadequate and necessitating more advanced and comprehensive security strategies. Frequent security incidents highlight the urgency of strengthening protection. With the development of new technologies, traditional protection mechanisms are insufficient, requiring a shift towards proactive immune protection. Driven by both legal and technological advancements, building a proactive defense technology system for industrial control systems, particularly through key technologies such as trusted verification and demonstration applications in hot industries, has become crucial for enhancing the security protection capabilities of national production system infrastructure.
[0004] Regarding the current state of system network security implementation, the following patents have been researched:
[0005] In the patent with publication number "CN111083131A" and invention title "A method for lightweight identity authentication of sensing terminals for power Internet of Things", the method sends encrypted data and signature value to the edge Internet of Things agent through the Internet of Things terminal. After the edge agent decrypts and verifies the data, it feeds back the authentication status to the terminal based on the correctness of decryption and signature verification results.
[0006] In the patent with publication number "CN 107579819 B" and invention title "A Method and System for Generating SM9 Digital Signatures", the two parties involved in the digital signature process exchange a temporary public key and ciphertext to jointly generate and verify the digital signature, ensuring that the private key is secure and not leaked, and improving the fairness of the signing process between the two parties.
[0007] In the patent with publication number "CN 109951288 B" and invention title "A hierarchical signature method and system based on SM9 digital signature algorithm", a tree structure is constructed to manage the KGC and user terminals at each level, ensuring that the user's private key length is constant, the verification process is efficient, requiring only two bilinear pairing operations, and the scheme is secure under the standard model.
[0008] In the patent with publication number "CN107438005B" and invention title "SM9 Joint Digital Signature Method and Apparatus", the identifier private key generated by the key generation center is divided into two parts and stored separately on the signing client and the server. After both parties sign independently, the client synthesizes the complete signature. Even if the sub-key of either party is lost, it will not affect the overall security, thereby enhancing the security of digital signatures.
[0009] Some of the aforementioned patents are based on proxy-based identity authentication and are applied in the Internet of Things industry. They involve research on the modification of the SM9 algorithm and the improvement of digital signature security, but do not address related applications in industrial control systems, nor do they involve decentralized device access authentication methods for industrial control systems. Summary of the Invention
[0010] To address the problems existing in the prior art, this invention provides a method and apparatus for accessing TPCM devices based on a secure and trusted switch. By using a secure and trusted switch to access TPCM devices, the security of the industrial control system is improved. It eliminates the need for third-party involvement, achieves decentralization, simplifies management, facilitates implementation, and is economical and practical.
[0011] Firstly, this invention proposes a TPCM device access method based on a secure and trusted switch, applied to a secure and trusted switch used in an industrial control system. The industrial control system further includes a security management platform, a target TPCM device, and multiple other TPCM devices connected to the secure and trusted switch. The method includes:
[0012] In response to the access request information sent by the target TPCM device, a request to send trusted report information is sent to the target TPCM device;
[0013] In response to a trusted report sent by the target TPCM device, the trusted report is sent to the security management platform so that the security management platform can evaluate the trusted report;
[0014] In response to the assessment pass information sent by the security management platform, the first identity information of the target TPCM device is sent to the signature verification device; and the signature verification device is sent information to the target TPCM device to send the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device verifies the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device; wherein, the signature verification device is one of a plurality of other TPCM devices;
[0015] In response to the signature verification pass information sent by the signature verification device, the access control whitelist is updated according to the first identity information and the second identity information of the target TPCM device; the access control whitelist is stored in the secure and trusted switch;
[0016] In response to the trusted policy based on the target TPCM device sent by the security management platform, the trusted policy is executed; the trusted policy includes an access frequency policy, a communication relationship control policy, and an access control whitelist aging time policy.
[0017] In an optional embodiment, the method further includes:
[0018] In response to the signature verification failure information sent by the signature verification device, a first alarm message is sent to the target TPCM device, the first alarm message including access failure information.
[0019] In an optional embodiment, the access frequency strategy includes:
[0020] After the step of responding to the access request information sent by the target TPCM device, the following steps are performed:
[0021] Determine the number of times the target TPCM device will be accessed;
[0022] The access frequency of the target TPCM device is determined based on the number of accesses.
[0023] If the access frequency exceeds a preset access frequency threshold range, the connection between the target TPCM device and the secure and trusted switch is disconnected, a second alarm message is generated, and the second alarm message is sent to the security management platform; otherwise, the step of sending a request to the target TPCM device to send a trusted report message continues.
[0024] In an optional embodiment, the communication relationship control strategy includes:
[0025] Acquire communication data of the target TPCM device, and determine a first communication relationship of the target TPCM device based on the communication data; the first communication relationship is the communication relationship between the target TPCM device and other devices connected to the secure and trusted switch, the other devices including multiple other TPCM devices;
[0026] Determine whether the first communication relationship satisfies the pre-stored preset communication relationship. If not, prevent the target TPCM device from communicating with other devices, generate a third alarm message, and send the third alarm message to the security management platform.
[0027] In an optional embodiment, the first identity information of the target TPCM device includes the factory serial number and / or chip serial number of the target TPCM device; the second identity information of the target TPCM device includes the MAC address of the target TPCM device.
[0028] In an optional embodiment, the access control whitelist aging time policy includes:
[0029] In response to the target TPCM device disconnecting from the secure and trusted switch, the retention time of the first identity information and the second identity information of the target TPCM device in the access control whitelist is determined;
[0030] Determine whether the retention time exceeds the preset aging time threshold range; if so, delete the first identity information and second identity information of the target TPCM device from the access control whitelist.
[0031] In an optional embodiment, the target TPCM device and other TPCM devices each include an SM9 functional module. The target TPCM device generates a user signature private key based on the user signature public key and the SM9 functional module. The target TPCM device and other TPCM devices each store a signature master private key, a signature master public key, and signature parameters. The user signature public key of the target TPCM device includes the validity date of the target TPCM device and the target TPCM device's first identity information.
[0032] In an optional embodiment, the signature verification device verifies the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device, including:
[0033] The target TPCM device sends an access request to the signature verification device through the secure and trusted switch, wherein the access request includes the first identity information of the target TPCM device;
[0034] The signature verification device parses the access request information and verifies whether the first identity information of the target TPCM device is in the access whitelist of the signature verification device. If not, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If yes, the signature verification device sends a signature request information to the target TPCM device through the secure and trusted switch.
[0035] The target TPCM device performs a signature based on the signature request information, combined with the SM9 function module of the target TPCM device and the user signature private key of the target TPCM device, to obtain the signature of the target TPCM device.
[0036] The target TPCM device sends the signature to the signature verification device through the secure and trusted switch;
[0037] The signature verification device verifies the signature based on the user signature public key of the target TPCM device and the SM9 function module of the signature verification device. If the signature verification fails, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If the signature verification succeeds, the target TPCM device is allowed to access the signature verification device through the secure and trusted switch.
[0038] In an optional embodiment, the signature verification device verifies the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device, including:
[0039] The target TPCM device sends an access request to the signature verification device through the secure and trusted switch, wherein the access request includes the first identity information of the target TPCM device;
[0040] The signature verification device parses the access request information and verifies whether the first identity information of the target TPCM device is in the access whitelist of the signature verification device. If not, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If yes, the signature verification device sends a signature request information to the target TPCM device through the secure and trusted switch.
[0041] The target TPCM device performs a signature based on the signature request information, combined with the SM9 function module of the target TPCM device and the user signature private key of the target TPCM device, to obtain the signature of the target TPCM device.
[0042] The target TPCM device sends the signature to the signature verification device through the secure and trusted switch;
[0043] The signature verification device verifies the signature based on the user signature public key of the target TPCM device and the SM9 function module of the signature verification device. If the signature verification fails, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If the signature verification succeeds, the target TPCM device is allowed to access the signature verification device through the secure and trusted switch.
[0044] Secondly, this invention proposes a TPCM device access device based on a secure and trusted switch, applied to a secure and trusted switch used in an industrial control system. The industrial control system further includes a security management platform, a target TPCM device, and multiple other TPCM devices connected to the secure and trusted switch. The device comprises:
[0045] The access request module is used to respond to the access request information sent by the target TPCM device and send a request to the target TPCM device to send trusted report information.
[0046] The trusted report evaluation module is used to send the trusted report to the security management platform in response to the trusted report sent by the target TPCM device, so that the security management platform can evaluate the trusted report;
[0047] The first information sending module is configured to, in response to the assessment pass information sent by the security management platform, send the first identity information of the target TPCM device to the signature verification device; and send information to the target TPCM device to send the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device verifies the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device; wherein, the signature verification device is one of a plurality of other TPCM devices;
[0048] The signature verification module is used to update the access control whitelist in response to the signature verification information sent by the signature verification device, based on the first identity information and the second identity information of the target TPCM device; the access control whitelist is stored in the secure and trusted switch;
[0049] The trusted policy module is used to execute the trusted policy based on the target TPCM device in response to the trusted policy sent by the security management platform; the trusted policy includes an access frequency policy, a communication relationship control policy, and an access control whitelist aging time policy.
[0050] The beneficial effects of the technical solution provided by the embodiments of the present invention are as follows: The TPCM device access method and apparatus of the secure and trusted switch of the present invention forwards the trust report sent by the target TPCM device requesting access to the security management platform through the secure and trusted switch. The security management platform verifies the trust report. When the verification is successful, the secure and trusted switch sends the first identity information of the target TPCM device to the signature verification device, and sends the information of sending the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device performs signature verification based on the first identity information and the identity authentication information. After the signature verification is successful, the access control whitelist is updated. When the target TPCM device successfully accesses the system, the access frequency, communication relationship, and aging time of the target TPCM device are monitored according to the trust policy issued by the security management platform. The present invention uses a secure and trusted switch to execute the access method and apparatus for the target TPCM device. The secure and trusted switch can identify the communication relationship, establish a whitelist, and identify abnormal attacks based on the access frequency by executing the trust policy, thereby improving the security of the industrial control system and alleviating the resource occupation of the security management platform. The present invention can realize the access of the target TPCM device to the secure and trusted switch without the participation of a third party, realizing decentralization, convenient implementation, and economic practicality. Attached Figure Description
[0051] Figure 1 This is a flowchart illustrating the TPCM device access method based on a secure and trusted switch provided in an embodiment of the present invention.
[0052] Figure 2 This is a schematic diagram of a system topology provided in an embodiment of the present invention;
[0053] Figure 3 This is a schematic diagram of a user identity authentication process method provided in an embodiment of the present invention;
[0054] Figure 4 This is a schematic diagram of a node access authentication principle provided by an embodiment of the present invention.
[0055] Figure 5 This is a system schematic diagram of a TPCM device access device based on a secure and reliable switch, provided in an embodiment of the present invention.
[0056] In the diagram: 21-Secure and Trusted Switch; 22-Security Management Terminal; 23-Target TPCM Device; 24-Signature Verification Device; 25-TPCM Module; 110-Access Request Module; 120-Trust Report Evaluation Module; 130-First Information Sending Module; 140-Signature Verification Pass Module; 150-Trust Policy Module. Detailed Implementation
[0057] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0058] This invention provides a method for accessing TPCM devices based on a secure and trusted switch. This method is applied to a secure and trusted switch, which is used in an industrial control system. The industrial control system also includes a security management platform, a target TPCM device, and multiple other TPCM devices, all connected to the secure and trusted switch. Figure 2 As shown, the secure and trusted switch and the nodes in the system together form a local area network. The nodes can be industrial embedded controllers or host computers of industrial control systems. The TPCM device can be an industrial embedded controller or a host computer. These TPCM devices integrate TPCM (Trusted Platform Control Module), which is a core hardware module integrated in the trusted computing platform. It is mainly used to establish and protect the source of trust, and provide functions such as integrity measurement, secure storage, trusted reporting, cryptographic services, trust chain transmission, protection policy management and active monitoring for trusted computing, so as to ensure the trustworthiness and security of the system.
[0059] This embodiment combines a secure and trusted switch with the identity authentication and access authentication functions of a TPCM to achieve identity authentication and access authentication for the target device. When a new node n connects to the industrial control system, the secure and trusted switch and the designated node already existing in the system (i.e., the signature verification device mentioned below) need to participate in the authentication. The specific processing flow is as follows: Figure 1 As shown in steps S110-S150, the node access authentication principle is as follows: Figure 3 As shown.
[0060] Step S110: In response to the access request information sent by the target TPCM device, send a request to the target TPCM device to send trusted report information.
[0061] Specifically, the target TPCM device sends an access request to the secure and trusted switch. In response to the access request, the secure and trusted switch sends a request to the target TPCM device to send a trust report. The target TPCM device, in response to the request to send a trust report, sends a trust report to the secure and trusted switch.
[0062] A Trusted Report refers to information generated using Trusted Computing 3.0 technology. Trusted Computing 3.0, with proactive immunity as its core concept, achieves full-process measurability, controllability, and interference-free operation through a dual-system architecture and proactive trusted monitoring mechanisms, thereby ensuring the security and trustworthiness of information systems. In the Trusted Computing 3.0 architecture, the "Trusted Report" is a crucial component, responsible for providing detailed information about the system's trusted state. This detailed information is generated by the TPCM module in the TPCM device and provided based on system metrics and trust chain verification. The Trusted Report can include the following information: whether the firmware has been verified; the trusted state is updated when the target runs; and when an attack on the TPCM device or code tampering is detected, information about the attack and code tampering is recorded.
[0063] It should be noted that before the target TPCM device is connected, its ID (i.e., the first identity information below) is manually configured on the secure and trusted switch. In this embodiment, the target TPCM device is connected to node 1, and the first identity information is represented by ID1. Here, ID refers to the unique identifier of the IPCM. Each TPCM device has an ID similar to an ID card after leaving the factory. The unique identifier of the target TPCM device can be its factory serial number, chip serial number, and other unique identifiers, or it can be a combination of these identifiers.
[0064] Step S120: In response to the trusted report sent by the target TPCM device, the trusted report is sent to the security management platform so that the security management platform can evaluate the trusted report.
[0065] In this step, the secure and trusted switch forwards the trust report to the security management platform, which then evaluates the trust report. If the evaluation passes, it indicates that the target TPCM device is secure; if the evaluation fails, it indicates that the target TPCM device is insecure and may be vulnerable to malicious attacks. In this case, the connection between the secure and trusted switch and the target TPCM device must be disconnected.
[0066] In step S130, in response to the assessment pass information sent by the security management platform, the first identity information of the target TPCM device is sent to the signature verification device; and the signature verification device is sent to the target TPCM device to send the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device performs signature verification on the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device; wherein, the signature verification device is one of a plurality of other TPCM devices.
[0067] In one possible implementation, after the security management platform approves the trusted report, it sends approval information to the secure and trusted switch. The secure and trusted switch then forwards the approval information to the target TPCM device. Simultaneously, it sends a message to the target TPCM device indicating that its authentication information will be sent to the signature verification device. The target TPCM device then sends its authentication information to the signature verification device. At the same time, the secure and trusted switch also sends the target TPCM device's initial identity information to the signature verification device. The signature verification device then verifies the signature of the target TPCM device based on the received signature verification information and the initial identity information.
[0068] The signature verification process includes the following steps (1)-(5). The following explanation is based on the example of the target TPCM device being connected to node 1 of the secure and trusted switch and the signature verification device being connected to node n of the secure and trusted switch.
[0069] (1) The target TPCM device of node 1 sends access request information to the signature verification device of node n through a secure and trusted switch. The access request information includes the first identity information of the target TPCM device, namely ID1.
[0070] (2) The signature verification device of node 2 parses the access request information, parses the first identity information ID1 of the target TPCM device in node 1, and verifies whether the first identity information ID1 of the target TPCM device is in the access whitelist of the signature verification device. If not, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch; if so, the signature verification device sends the signature request information to the target TPCM device through the secure and trusted switch.
[0071] (3) After receiving the signature request information from node n, the target TPCM device of node 1 uses the SM9 function module of the target TPCM device and the user signature private key of the target TPCM device to sign the random number, thereby obtaining the signature of the target TPCM device.
[0072] Here, the TPCM in both the target TPCM device and the signature verification device integrates an SM9 functional module. The SM9 functional block has the functions of generating and verifying SM9 digital signatures. Before the TPCM device leaves the factory, the same signature master private key ks, signature master public key Ppub-s, and signature parameters are pre-set in the TPCM and secretly stored, never to be exported, thus ensuring the security of the core keys through hardware.
[0073] The target TPCM device generates a user-signed private key using the SM9 functional module and the master private key, based on the user-signed public key. The user-signed public key includes the target TPCM device's expiration date, primary identification information, and other data. This other data may include the MAC address, device type, etc. If the expiration date changes, a new user-signed public key is generated, and the user-signed private key is updated and saved based on the updated public key and the SM9 functional module.
[0074] (4) The target TPCM device of node 1 sends the signature to the signature verification device of node n through a secure and trusted switch.
[0075] (5) The signature verification device of node n performs signature verification based on the user signature public key of the target TPCM device and the SM9 function module of the signature verification device. If the signature verification fails, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If the signature verification passes, the target TPCM device is allowed to access the signature verification device through the secure and trusted switch.
[0076] The above identity verification process is as follows: Figure 3 As shown, it can be summarized into the following steps 1-5.
[0077] Step 1: The target TPCM device sends an access request carrying ID1 to the signature verification device.
[0078] Step 2: Verify whether ID1 is in the access control whitelist.
[0079] Step 3: The target TPCM device signs the random number using the user's signing private key ds1.
[0080] Step 4: The facial TPCM device sends the signature to the signature verification device.
[0081] Step 5: The signature verification device uses the user's signature public key ps1 to verify the signature.
[0082] In step S140, in response to the signature verification pass information sent by the signature verification device, the access control whitelist is updated according to the first identity information and the second identity information of the target TPCM device; the access control whitelist is stored in the secure and trusted switch.
[0083] When the signature verification is successful, the signature verification device sends a signature verification pass message to the secure and trusted switch. The secure and trusted switch updates the access control whitelist based on the signature verification pass message, and the target TPCM device on node 1 successfully connects to the secure and trusted switch.
[0084] When signature verification fails, the signature verification device sends a signature failure message to the secure and trusted switch and deletes the ID1 information of node 1. In response to the signature failure message sent by the signature verification device, the secure and trusted switch sends a first alarm message to the target TPCM device, which includes access failure information.
[0085] The access authentication process described in steps S110-S140 above is as follows: Figure 4 As shown, it can be summarized into the following steps 1-4.
[0086] Step 1: Configure ID1 of the target TPCM device on node 1.
[0087] Step 2: Send the ID1 of the target TPCM device to the signature verification device of node n.
[0088] Step 3: Receive authentication feedback sent by the node verification device.
[0089] Step 4: Distribute the ID1 of the target TPCM device to each node.
[0090] The above is the access control process for the target TPCM device to access the secure and trusted switch for the first time. When the target TPCM device that has been connected disconnects and attempts to reconnect, the secure and trusted switch does not need to manually configure the first identity information again.
[0091] After the target TPCM device is connected, the secure and trusted switch executes the trusted policy to monitor the access frequency, communication relationship, etc. of the target TPCM, as shown in step S150.
[0092] Step S150: In response to the trusted policy based on the target TPCM device sent by the security management platform, execute the trusted policy; the trusted policy includes access frequency policy, communication relationship control policy and access control whitelist aging time policy.
[0093] The access frequency policy includes performing the following steps a1-a3 after responding to the access request information sent by the target TPCM device.
[0094] Step a1: Determine the number of times the target TPCM device will be connected.
[0095] Step a2: Determine the access frequency of the target TPCM device based on the number of access attempts.
[0096] Step a3: Determine whether the access frequency exceeds the preset access frequency threshold range. If yes, disconnect the target TPCM device from the secure and trusted switch, generate a second alarm message, and send the second alarm message to the security management platform. If no, continue to execute the step of sending a request to the target TPCM device to send trusted report information.
[0097] Specifically, after a target device successfully connects for the first time, there may be instances of disconnection and reconnection. The secure and trusted switch will perform a trust measurement and control on the access frequency of a device based on the trust policy of the security management platform. The preset access frequency threshold can be defined as m times / minute. If the number of access attempts (successful + failed) of device n exceeds m times / minute, steps S110-S150 of the above process will not be entered. Instead, the target device's ID (i.e., ID1) will be directly removed from the access control whitelist node, the device connection will be disconnected, a second alarm message will be generated, and the information will be reported to the security management platform. Because performing trust report assessments and signature verification consumes resources, frequent access attempts will lead to increased computational resource consumption on the security management platform, other devices, and the switch, as well as bandwidth usage. This may indicate a fault in the node device itself or that it has been attacked. This embodiment first determines the number of access attempts of the target TPCM device, then determines the access frequency, and compares the access frequency with the preset access frequency threshold range. When the frequency exceeds this range, an alarm is triggered.
[0098] The communication relationship control strategy includes the following steps b1-b2.
[0099] Step b1: Obtain the communication data of the target TPCM device, and determine the first communication relationship of the target TPCM device based on the communication data; the first communication relationship is the communication relationship between the target TPCM device and other devices connected to the secure and trusted switch. Other devices include multiple other TPCM devices.
[0100] Step b2: Determine whether the first communication relationship satisfies the pre-stored preset communication relationship. If not, prevent the target TPCM device from communicating with other devices, generate a third alarm message, and send the third alarm message to the security management platform.
[0101] Specifically, in actual business systems, the data interaction between devices follows established rules. For example, if there are three devices, a, b, and c, their communication relationship might be that a sends data to b, and b sends data to c—a definite relationship. While the target TPCM device can access the system, violating this communication relationship is considered an anomaly, and the secure and trusted switch will block it and send an alarm to the security management platform. Therefore, in the communication relationship control strategy of this embodiment, the communication relationship of the target TPCM device is first determined, then the communication relationship between the target TPCM device and other devices is determined, and finally, an alarm is triggered based on the communication relationship. Other devices refer to devices connected to the secure and trusted switch (including other TPCM devices).
[0102] The access control whitelist aging time policy includes the following steps c1-c2.
[0103] Step c1: In response to the target TPCM device disconnecting from the secure and trusted switch, determine the retention time of the target TPCM device's first identity information and second identity information in the access control whitelist.
[0104] Step c2: Determine whether the retention time exceeds the preset aging time threshold; if so, delete the first and second identity information of the target TPCM device in the access control whitelist.
[0105] Specifically, a secure and trusted switch maintains an access control whitelist, which includes the IDs and MAC addresses of verified connected devices. If the access control whitelist does not delete the device's ID and MAC address information after a device disconnects, it will grow indefinitely over time, rendering the retained information meaningless. Therefore, the secure and trusted management platform includes access control whitelist aging time information in its trusted policies. This embodiment determines the target TPCM device's access control whitelist aging time by determining the retention time of the target TPCM device's first identity information (ID) and second identity information (MAC address) in the access control whitelist. This event is then compared with a preset aging time threshold range to determine whether the target TPCM device's access control whitelist aging time has exceeded the range.
[0106] The trust strategy also includes a dynamic trust measurement strategy; the dynamic trust measurement strategy includes the following steps d1-d2.
[0107] Step d1: Obtain the current measurement information of the target TPCM device.
[0108] Step d2: Perform a trusted measurement on the current information to be measured according to the trusted verification model; if the measurement passes, return to the step of obtaining the current information to be measured from the TPCM device; if the measurement fails, disconnect the connection between the secure and trusted switch and the TPCM device.
[0109] The trusted verification model is used to characterize the communication characteristics between the TPCM device and other devices. The trusted verification model includes a logical combination of one or more sub-verification models. The communication characteristics include communication relationship, data bandwidth, communication duration, communication direction and data packet size. The trusted verification model includes a logical combination of one or more sub-verification models, such as long-term bandwidth sub-verification model, burst bandwidth sub-verification model, high bandwidth duration sub-verification model and high bandwidth occurrence frequency sub-verification model.
[0110] It should be noted that before performing dynamic trust measurement, the threshold range of each sub-verification model needs to be determined in advance, i.e., the threshold line of the trust verification model needs to be determined. (The threshold line is composed of the first threshold range and the fourth threshold range. When configuring the threshold line, considering that the engineer station is usually in monitoring mode and the amount of data is small, a large amount of data will only be sent when engineering configuration or firmware upgrade. Since the modification of engineering configuration and firmware is definitely infrequent, the threshold line can be set as follows: long-term bandwidth is less than the first threshold, burst bandwidth increases, high bandwidth duration is less than the second threshold, and the number of high bandwidth occurrences per unit time is less than the third threshold.)
[0111] Since a trusted verification model may consist of a logical combination of multiple sub-verification models, the principle of performing trusted measurement on the current information to be measured based on the trusted verification model is to first calculate the values of each sub-verification model using the current information to be measured. For example, in the burst bandwidth sub-verification model, the burst bandwidth value is calculated using the current information to be measured. Some sub-verification models need to record and store the information to be measured for a certain duration, such as the long-term bandwidth sub-verification model and the high-bandwidth duration sub-verification model. The long-term bandwidth sub-verification model needs to record the bandwidth for a preset duration and then calculate the bandwidth for that preset duration; the high-bandwidth duration sub-verification model needs to record the duration for which the bandwidth meets a preset bandwidth threshold and obtain the duration value.
[0112] Then, threshold judgments are applied to the values of each sub-validation model. For example, whether the long-term bandwidth value obtained from the long-term bandwidth sub-validation model is less than the first threshold range, whether the high-bandwidth duration value obtained from the high-bandwidth duration sub-validation model is less than the second threshold range, whether the high-bandwidth occurrence frequency value obtained from the high-bandwidth occurrence frequency sub-model is less than the third threshold range, and whether the burst bandwidth value obtained from the burst bandwidth sub-validation model is greater than the fourth threshold range. If any one of these exceeds the threshold range, the measurement fails; if all of them meet the threshold range, the measurement passes.
[0113] In some possible embodiments, the trust policy also includes a key management policy to manage the keys of the TPCM device. The key management policy includes a key update frequency policy, a key update permission policy, a forced key update policy, and a primary / backup key policy. In this embodiment, the TPCM device refers to a device with TPCM connected to a trusted switch, including the target TPCM device and multiple other TPCM devices.
[0114] Specifically, the key includes the user-signed public key and the user-signed private key of the TPCM device.
[0115] The key update frequency strategy includes the following steps (11)-(13).
[0116] (11) Obtain the updated user signature public key sent by the TPCM device.
[0117] (12) Determine the key update frequency of the TPCM device within a preset first time period based on the updated user signature public key.
[0118] The secure and trusted switch records the number of updates to the TPCM device. When the user signature is updated, the update count is updated again, and then the update frequency value is calculated. Alternatively, the secure and trusted switch records the update frequency of the TPCM device, and when the user signature is updated, the update frequency value is updated.
[0119] (13) Determine whether the key update frequency exceeds the preset key update frequency threshold. If so, send a key update disallowed message to the TPCM device and an alarm message to the security management terminal.
[0120] Based on a preset key update frequency threshold, such as n times / day, it is determined whether the current key update frequency exceeds the threshold. If it exceeds the threshold, it indicates that the key update is too frequent. The secure and trusted switch will then refuse the TPCM device from updating the key and generate an alarm, which will be reported to the security management terminal.
[0121] In actual industrial control systems, when the TPCM device is an embedded device such as a PLC controller or DCS controller, it is sometimes necessary to ensure that the TPCM device operates continuously and without interruption (for example, when the device is connected to a secure and trusted switch). In this scenario, key updates may affect the access and communication status of the TPCM device. Therefore, for such devices, a key update permission policy needs to be implemented to set the TPCM device to not allow key updates. Therefore, the key update permission policy includes the following steps (21).
[0122] (21) When the TPCM device runs continuously without interruption within a preset time period, send a key update disallowed message to the TPCM device within the preset time period to ensure the continuity of the TPCM device's operating status.
[0123] When the key update permission policy is executed, if it is set to disallow key updates, and the TPCM device attempts to update, the secure and trusted switch will refuse the update and generate an alarm message, which will be reported to the security management terminal.
[0124] When the equipment is shut down or under maintenance, and a key update is indeed required, a forced key update policy is issued by the security management terminal. For example, if the TPCM equipment is under maintenance and a key update is performed once a year, the security management terminal will initiate a forced key update policy, which includes the following steps (31)-(32).
[0125] (31) Receive the first mandatory key update information issued by the security management terminal;
[0126] (32) Send the second forced key update information to the TPCM device according to the first forced key update information, so that the TPCM device can update the key according to the second forced key update information.
[0127] The forced key update policy is initiated by the security management terminal. Therefore, the first forced key update information and the second forced key update information can be the same, that is, the secure and trusted switch forwards the forced key update information to the target terminal.
[0128] For high-availability devices such as PLC controllers and DCS controllers, in order to ensure the continuity of device operation, a primary / backup key policy can be issued by the security management terminal to continue to save the original key. This ensures that in special circumstances such as key update failure, the original key can be quickly switched to, avoiding the lack of available keys due to key update failure. This embodiment lists three primary / backup key policies. The first primary / backup key policy includes the following steps (41).
[0129] (41) In response to the updated user signature public key sent by the TPCM device, the current user signature public key is stored as a backup user signature public key, or the current user signature public key is sent to the security management terminal so that the security management terminal stores the user signature public key, or the information of storing the current user signature public key is sent to the TPCM device. Specifically, the method of this embodiment aims to illustrate that the original key can be stored as a backup key in a secure and trusted switch, a security management terminal, or a TPCM device.
[0130] The second primary / backup key strategy includes the following steps (51), which are intended to explain that when the key update fails, the original key is sent to the TPCM device as a backup key.
[0131] (51) In response to the key update failure message sent by the TPCM device, the backup user signature public key is sent to the TPCM device so that the TPCM device can use the backup user signature public key for security protection.
[0132] The third primary / backup key strategy includes the following steps (61) to illustrate that in scenarios where key updates are required quickly, only primary / backup key switching information can be sent to achieve rapid key switching without going through the process of generating and distributing new keys, thus saving computing resources and network bandwidth.
[0133] (61) Send primary / backup key switching information to the TPCM device so that the TPCM device switches to the backup user signature public key for security protection.
[0134] The key management strategy in this embodiment enables scientific management of the keys of node devices, ensuring that the devices can operate securely and reliably before, during, and after key updates.
[0135] It should also be noted that, in addition to triggering the trusted policy in response when the security management platform sends a trusted policy in response, the execution time of each trusted policy can also be set to execute the trusted policy in response periodically.
[0136] In summary, the TPCM device access method based on a secure and trusted switch in this embodiment uses a secure and trusted switch to implement the method. The secure and trusted switch can identify communication relationships and establish whitelists by executing trusted policies, and can also identify abnormal attacks based on access frequency, thereby improving the security of the industrial control system and alleviating the resource consumption of the security management platform. It can also perform dynamic trust measurement on access devices, thereby further improving the security of the industrial control system. Furthermore, it can scientifically and effectively manage keys to ensure that devices can operate securely and reliably before, during, and after key updates.
[0137] Furthermore, this embodiment is simple to manage, using the SM9 algorithm based on the IBC system to implement user authentication, reducing the complexity of public key management and certificate management based on PKI systems. User authentication access in this embodiment requires no third-party participation; nodes can automatically update keys. From this perspective, it achieves decentralization, is easy to implement, and is economical and practical. In this embodiment, in the industrial embedded controller, the signing master private key, signing master public key, and parameters are all pre-set in the TPCM at the factory, secretly stored, and never exported, ensuring the security of the core keys through hardware.
[0138] See Figure 5This embodiment provides a TPCM device access device based on a secure and trusted switch. The secure and trusted switch is applied to an industrial control system, which also includes a security management platform, a target TPCM device, and multiple other TPCM devices connected to the secure and trusted switch. The device includes an access request module 110, a trust report evaluation module 120, a first information sending module 130, a signature verification module 140, and a trust policy module 150. The access request module 110, in response to an access request from the target TPCM device, sends a request to the target TPCM device to send a trust report. The trust report evaluation module 120, in response to the trust report sent by the target TPCM device, sends the trust report to the security management platform so that the security management platform can evaluate the trust report. The first information sending module 130 is used to send the first identity information of the target TPCM device to the signature verification device in response to the evaluation pass information sent by the security management platform; and to send the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device can verify the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device; wherein, the signature verification device is one of a plurality of other TPCM devices. The signature verification pass module 140 is used to update the access control whitelist based on the first identity information and the second identity information of the target TPCM device in response to the signature verification pass information sent by the signature verification device; the access control whitelist is stored in the secure trusted switch. The trusted policy module 150 is used to execute the trusted policy based on the target TPCM device in response to the trusted policy sent by the security management platform; the trusted policy includes an access frequency policy, a communication relationship control policy, and an access control whitelist aging time policy.
[0139] In a possible embodiment, the device of this embodiment further includes a signature failure module, which is used to send a first alarm message to the target TPCM device in response to the signature failure information sent by the signature verification device. The first alarm message includes access failure information.
[0140] In a possible embodiment, the access frequency policy includes a determination module, an access frequency module, and a second alarm information module connected to the access request module. The determination module determines the number of times the target TPCM device will access the network. The access frequency module determines the access frequency of the target TPCM device based on the number of accesses. The second alarm information module determines whether the access frequency exceeds a preset access frequency threshold. If it does, the connection between the target TPCM device and the secure and trusted switch is disconnected, a second alarm information is generated, and the second alarm information is sent to the security management platform. If not, the step of sending a request to the target TPCM device to send trusted report information continues.
[0141] In a possible embodiment, the communication relationship control strategy includes a communication data acquisition module and a first communication relationship determination module. The communication data acquisition module acquires communication data of the target TPCM device and determines a first communication relationship of the target TPCM device based on the communication data. The first communication relationship is the communication relationship between the target TPCM device and other devices connected to the secure and trusted switch; these other devices include multiple other TPCM devices. The first communication relationship determination module determines whether the first communication relationship satisfies a pre-stored preset communication relationship. If not, it prevents the target TPCM device from communicating with other devices, generates a third alarm message, and sends the third alarm message to the security management platform.
[0142] In a possible embodiment, the first identity information of the target TPCM device includes the factory serial number and / or chip serial number of the target TPCM device; the second identity information of the target TPCM device includes the MAC address of the target TPCM device.
[0143] In a possible embodiment, the access control whitelist aging-out policy includes a retention time determination module and a retention time judgment module. The retention time determination module determines the retention time of the target TPCM device's first and second identity information in the access control whitelist in response to the target TPCM device disconnecting from the secure and trusted switch. The retention time judgment module determines whether the retention time exceeds a preset aging-out time threshold; if so, it deletes the target TPCM device's first and second identity information from the access control whitelist.
[0144] In a possible embodiment, the target TPCM device and other TPCM devices each include an SM9 functional module. The target TPCM device generates a user signature private key based on the user signature public key and the SM9 functional module. The target TPCM device and other TPCM devices each store a signature master private key, a signature master public key, and signature parameters. The user signature public key of the target TPCM device includes the validity date of the target TPCM device and the first identity information of the target TPCM device.
[0145] In a possible embodiment, the signature verification module 140 includes an access request sending module, a parsing module, a signature generation module, a signature sending module, and a signature verification module. The access request sending module is used by the target TPCM device to send access request information to the signature verification device through a secure and trusted switch. The access request information includes the target TPCM device's first identity information. The parsing module is used by the signature verification device to parse the access request information and verify whether the target TPCM device's first identity information is in the signature verification device's access whitelist. If not, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch; if so, the signature verification device sends a signature request to the target TPCM device through the secure and trusted switch. The signature generation module is used by the target TPCM device to sign the signature based on the signature request information, combining the target TPCM device's SM9 function module and the target TPCM device's user signature private key. The signature sending module is used by the target TPCM device to send the signature to the signature verification device through the secure and trusted switch. The signature verification module is used by the signature verification device to verify the signature based on the user signature public key of the target TPCM device and the SM9 function module of the signature verification device. If the signature verification fails, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If the signature verification succeeds, the target TPCM device is allowed to access the signature verification device through the secure and trusted switch.
[0146] In a possible embodiment, the trust policy further includes a dynamic trust measurement policy; the dynamic trust measurement policy includes a current information to be measured acquisition module and a trust measurement module. The current information to be measured acquisition module is used to acquire the current information to be measured of the target TPCM device. The trust measurement module is used to perform trust measurement on the current information to be measured according to the trust verification model; when the measurement passes, it returns to the step of acquiring the current information to be measured of the TPCM device; when the measurement fails, it disconnects the connection between the secure and trusted switch and the TPCM device. The trust verification model is used to characterize the communication characteristics between the TPCM device and other devices; the trust verification model includes a logical combination of one or more sub-verification models; the communication characteristics include communication relationship, data bandwidth, communication duration, communication direction, and data packet size; the trust verification model includes a logical combination of one or more sub-verification models among the following: long-term bandwidth sub-verification model, burst bandwidth sub-verification model, high bandwidth duration sub-verification model, and high bandwidth occurrence frequency sub-verification model per unit time.
[0147] As is known from common technical knowledge, this invention can be implemented through other embodiments that do not depart from its spirit or essential characteristics. Therefore, the disclosed embodiments described above are merely illustrative in all respects and are not the only ones. All modifications within the scope of this invention or its equivalents are included in this invention.
Claims
1. A method for accessing TPCM devices based on a secure and trusted switch, characterized in that, The method, applied to a secure and trusted switch used in an industrial control system, includes a security management platform, a target TPCM device, and multiple other TPCM devices connected to the secure and trusted switch. In response to the access request information sent by the target TPCM device, a request to send trusted report information is sent to the target TPCM device; In response to a trusted report sent by the target TPCM device, the trusted report is sent to the security management platform so that the security management platform can evaluate the trusted report; In response to the assessment pass information sent by the security management platform, the first identity information of the target TPCM device is sent to the signature verification device; and the signature verification device is sent information to the target TPCM device to send the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device verifies the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device; wherein, the signature verification device is one of a plurality of other TPCM devices; In response to the signature verification pass information sent by the signature verification device, the access control whitelist is updated according to the first identity information and the second identity information of the target TPCM device; the access control whitelist is stored in the secure and trusted switch; In response to the trusted policy based on the target TPCM device sent by the security management platform, the trusted policy is executed; the trusted policy includes an access frequency policy, a communication relationship control policy, and an access control whitelist aging time policy.
2. The TPCM device access method based on a secure and trusted switch according to claim 1, characterized in that, The method further includes: In response to the signature verification failure information sent by the signature verification device, a first alarm message is sent to the target TPCM device, the first alarm message including access failure information.
3. The TPCM device access method based on a secure and trusted switch according to claim 1, characterized in that, The access frequency strategy includes: After the step of responding to the access request information sent by the target TPCM device, the following steps are performed: Determine the number of times the target TPCM device will be accessed; The access frequency of the target TPCM device is determined based on the number of accesses. If the access frequency exceeds a preset access frequency threshold range, the connection between the target TPCM device and the secure and trusted switch is disconnected, a second alarm message is generated, and the second alarm message is sent to the security management platform; otherwise, the step of sending a request to the target TPCM device to send a trusted report message continues.
4. The TPCM device access method based on a secure and trusted switch according to claim 1, characterized in that, The communication relationship control strategy includes: Acquire communication data of the target TPCM device, and determine a first communication relationship of the target TPCM device based on the communication data; the first communication relationship is the communication relationship between the target TPCM device and other devices connected to the secure and trusted switch, the other devices including multiple other TPCM devices; Determine whether the first communication relationship satisfies the pre-stored preset communication relationship. If not, prevent the target TPCM device from communicating with other devices, generate a third alarm message, and send the third alarm message to the security management platform.
5. The TPCM device access method based on a secure and trusted switch according to claim 1, characterized in that, The first identity information of the target TPCM device includes the factory serial number and / or chip serial number of the target TPCM device; the second identity information of the target TPCM device includes the MAC address of the target TPCM device.
6. The TPCM device access method based on a secure and trusted switch according to claim 5, characterized in that, The access control whitelist aging time policy includes: In response to the target TPCM device disconnecting from the secure and trusted switch, the retention time of the first identity information and the second identity information of the target TPCM device in the access control whitelist is determined; Determine whether the retention time exceeds the preset aging time threshold range; if so, delete the first identity information and second identity information of the target TPCM device from the access control whitelist.
7. The TPCM device access method based on a secure and trusted switch according to claim 1, characterized in that, The target TPCM device and other TPCM devices each include an SM9 functional module. The target TPCM device generates a user signature private key based on the user signature public key and the SM9 functional module. The target TPCM device and other TPCM devices each store a signature master private key, a signature master public key, and signature parameters. The user signature public key of the target TPCM device includes the validity date of the target TPCM device and the first identity information of the target TPCM device.
8. The TPCM device access method based on a secure and trusted switch according to claim 7, characterized in that, The signature verification device verifies the signature of the target TPCM device based on the target TPCM device's first identity information and the target TPCM device's authentication information, including: The target TPCM device sends an access request to the signature verification device through the secure and trusted switch, wherein the access request includes the first identity information of the target TPCM device; The signature verification device parses the access request information and verifies whether the first identity information of the target TPCM device is in the access whitelist of the signature verification device. If not, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If yes, the signature verification device sends a signature request information to the target TPCM device through the secure and trusted switch. The target TPCM device performs a signature based on the signature request information, combined with the SM9 function module of the target TPCM device and the user signature private key of the target TPCM device, to obtain the signature of the target TPCM device. The target TPCM device sends the signature to the signature verification device through the secure and trusted switch; The signature verification device verifies the signature based on the user signature public key of the target TPCM device and the SM9 function module of the signature verification device. If the signature verification fails, the target TPCM device is prohibited from accessing the signature verification device through the secure and trusted switch. If the signature verification succeeds, the target TPCM device is allowed to access the signature verification device through the secure and trusted switch.
9. The TPCM device access method based on a secure and trusted switch according to claim 7, characterized in that, The trust strategy also includes a dynamic trust measurement strategy; The dynamic trust measurement strategy includes: Obtain the current measurement information of the target TPCM device; The current information to be measured is subjected to a trusted measurement based on the trusted verification model; if the measurement passes, the process returns to the step of obtaining the current information to be measured of the TPCM device; if the measurement fails, the connection between the secure and trusted switch and the TPCM device is disconnected. The trusted verification model is used to characterize the communication characteristics between the TPCM device and other devices; the trusted verification model includes a logical combination of one or more sub-verification models; the communication characteristics include communication relationship, data bandwidth, communication duration, communication direction, and data packet size; the trusted verification model includes a logical combination of one or more sub-verification models among the following: long-term bandwidth sub-verification model, burst bandwidth sub-verification model, high bandwidth duration sub-verification model, and high bandwidth occurrence frequency sub-verification model per unit time.
10. A TPCM device access device based on a secure and trusted switch, characterized in that, An application is made in a secure and trusted switch, which is used in an industrial control system. The industrial control system further includes a security management platform, a target TPCM device, and multiple other TPCM devices connected to the secure and trusted switch. The device includes: The access request module is used to respond to the access request information sent by the target TPCM device and send a request to the target TPCM device to send trusted report information. The trusted report evaluation module is used to send the trusted report to the security management platform in response to the trusted report sent by the target TPCM device, so that the security management platform can evaluate the trusted report; The first information sending module is configured to, in response to the assessment pass information sent by the security management platform, send the first identity information of the target TPCM device to the signature verification device; and send information to the target TPCM device to send the identity authentication information of the target TPCM device to the signature verification device, so that the signature verification device verifies the signature of the target TPCM device based on the first identity information and the identity authentication information of the target TPCM device; wherein, the signature verification device is one of a plurality of other TPCM devices; The signature verification module is used to update the access control whitelist in response to the signature verification information sent by the signature verification device, based on the first identity information and the second identity information of the target TPCM device; the access control whitelist is stored in the secure and trusted switch; The trusted policy module is used to execute the trusted policy based on the target TPCM device in response to the trusted policy sent by the security management platform; the trusted policy includes an access frequency policy, a communication relationship control policy, and an access control whitelist aging time policy.
Citation Information
Patent Citations
SM9 Joint Digital Signature Method and Apparatus
CN107438005B
A hierarchical signature method and system based on the SM9 digital signature algorithm
CN109951288B
Lightweight identity authentication method for electric power Internet of Things sensing terminal
CN111083131A
Host measurement method and device
CN110311917A
Safe and trusted gateway system, control method, medium, equipment and terminal
CN116055254A