Trusted switch key management method, device and electronic equipment based on TPCM
By adopting a TPCM-based trusted switch key management method, updating user signature public and private keys, and performing trusted verification and policy execution, the problem that traditional protection mechanisms in industrial control systems are unable to cope with new types of attacks is solved. This achieves the scientific nature of trusted control and key management of TPCM devices, and improves the security and stability of the system.
Patent Information
- Application Number
- CN202411146125.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-20
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-08-20
AI Technical Summary
Existing industrial control system security protection systems are unable to cope with advanced persistent threats, especially in core components such as PLC controllers, DCS controllers, and SIS. Traditional static protection mechanisms are ineffective in dealing with new attack methods, and there is a lack of trusted key management methods adapted to industrial control systems.
A TPCM-based trusted switch key management method is adopted. By scientifically managing and dynamically measuring the keys of TPCM devices, updating the user's signature public and private keys using the SM9 algorithm, and performing trusted verification and policy enforcement through a trusted switch, effective control of TPCM devices is achieved.
It enables trusted verification and scientific management of TPCM devices, ensures the security and efficiency of key updates, supports decentralized management, and improves the security and stability of industrial control systems.
Smart Images

Figure CN119172061B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of trusted key management, and specifically relates to a trusted switch key management method, device and electronic device based on TPCM. Background Technology
[0002] Industrial Control Systems (ICS) are widely used in over 80% of core areas, including hydropower dispatching, power grid monitoring, and oil and gas pipeline pressure control, and are of immeasurable value in maintaining the stable operation of national infrastructure. However, in recent years, with the rapid development of information technology, cyberattacks targeting ICS have become increasingly frequent, affecting multiple critical information infrastructure sectors such as energy, transportation, manufacturing, healthcare, and communications.
[0003] According to authoritative disclosures, at least 30% of representative industrial enterprises or organizations worldwide have reported suffering cyberattacks. Given the potential impact of unstated statistics, the actual percentage of attacks may be even higher. In particular, Advanced Persistent Threats (APTs) are malware specifically designed to target Industrial Security Systems (ICS). With their highly stealthy dissemination mechanisms and destructive capabilities, they can penetrate traditional isolation and protection strategies, rendering existing security systems inadequate.
[0004] Faced with this severe situation, strengthening information security research in industrial control systems (ICS), especially implementing efficient information security solutions for core components such as PLCs (Programmable Logic Controllers), DCSs (Distributed Control Systems), and SISs (Safety Instrumented Systems), has become an urgent need for the industry. With the widespread application of emerging technologies such as artificial intelligence, big data, the Internet of Things, cloud computing, and fully digital instrumentation and control systems, the industrial control network environment is becoming increasingly complex. Traditional static protection mechanisms are insufficient to effectively cope with new attack methods, and the security protection posture urgently needs transformation and upgrading.
[0005] Against this backdrop, my country has included industrial control systems within the scope of the Cybersecurity Classified Protection System (CPS 2.0). Technically, security strategies are evolving from layered, passive protection to a proactive, immune-based protection system based on a scientific security framework. In engineering practice, the focus is shifting from traditional computer information system protection to the construction of a proactive cyberspace defense system for new computing environments. Trusted verification, as one of the core security protection methods recommended by CPS 2.0, is of great significance for ensuring the security of critical nodes such as secure communication equipment and secure boundary devices.
[0006] Therefore, conducting in-depth research and building an active defense technology system and key technologies for industrial control systems that meet the needs, and carrying out large-scale application demonstrations in hot industries, is not only a key path to improve the overall protection capabilities of ICS, but also a choice to ensure the security of national production system infrastructure and maintain the stable development of society and economy.
[0007] Patent CN111083131A proposes a lightweight authentication method for power IoT sensing terminals. It ensures communication security through interactive verification of encrypted data and signature values, and alerts the terminal upon verification failure. Patent CN107579819B discloses an SM9 digital signature method and system. By having both parties jointly generate the signature, it ensures the security of the private key, enhances signature fairness and security, and ultimately outputs a successfully verified target digital signature. Patent CN107579819B also discloses an SM9 digital signature method and system. This method ensures the security of the private key, enhances signature fairness and security, and ultimately outputs a successfully verified target digital signature. Patent CN109951288B discloses a hierarchical signature method based on SM9. It manages keys through a tree structure, enabling secure signing and verification for users at different levels, maintaining a constant private key length, and ensuring efficient verification while guaranteeing security under the standard model.
[0008] Some of the aforementioned patents are based on proxy-based identity authentication and are applied in the Internet of Things industry. They involve research on the modification of the SM9 algorithm and the improvement of digital signature security, but do not target applications related to industrial control systems, nor do they involve trusted key management methods for industrial control systems. Summary of the Invention
[0009] To address the aforementioned issues, this invention proposes a trusted switch key management method, apparatus, and electronic device based on TPCM. This method enables trusted verification of TPCM devices in industrial control systems during the key distribution process, achieving effective trusted control over TPCM devices. The trusted strategy enables scientific key management and dynamic trusted measurement of TPCM devices.
[0010] In a first aspect, the present invention provides a key management method for a TPCM device. The TPCM device is applied to an industrial control system, which further includes a trusted switch, other devices, and a security management terminal. The TPCM device, the other devices, and the security management terminal are respectively connected to the trusted switch. The method is applied to the TPCM device and includes:
[0011] Obtain the key of the TPCM device, the key including a user signature public key and a user signature private key, the user signature public key including at least an expiration date;
[0012] Determine whether the validity date has been updated. If so, update the user signature public key according to the validity date, and update the user signature private key according to the updated user signature public key and the SM9 algorithm, and save it.
[0013] The updated user signature public key is sent to the security management terminal via a trusted switch, so that the security management terminal sends information to the trusted switch allowing the distribution of the updated user signature public key of the TPCM device to other devices; and
[0014] In response to a trusted policy sent by the trusted switch, the trusted policy is executed; or, in response to policy information generated based on the trusted policy sent by the trusted switch, the policy information is executed; wherein the trusted policy is sent by the security management terminal to the trusted switch, and the trusted policy includes a key management policy.
[0015] In an optional implementation, the key management policy includes a key update frequency policy, a key update permission policy, a forced key update policy, and a primary / backup key policy; the policy information includes key update information.
[0016] In an optional implementation, the trust policy further includes a dynamic trust measurement policy, and the policy information further includes the current measurement information of the TPCM device.
[0017] Secondly, the present invention provides a trusted switch key management method, wherein the trusted switch is applied to an industrial control system, the industrial control system further includes a TPCM device, other devices, and a security management terminal, the TPCM device, the other devices, and the security management terminal are respectively connected to the trusted switch, the TPCM device uses a key to protect the system, the key includes a user signature public key and a user signature private key, wherein the user signature public key includes at least an expiration date; the TPCM device updates the user signature public key according to the updated expiration date to obtain an updated user signature public key, and updates the user signature private key according to the updated user signature public key and the SM9 algorithm and saves it; the method is applied to a trusted switch, and the method includes:
[0018] In response to the updated user signature public key sent by the TPCM device, the updated user signature public key is sent to the security management terminal;
[0019] In response to the information sent by the security management terminal allowing the distribution of the updated user signature public key of the TPCM device to other devices, the updated user signature public key of the TPCM device is distributed to other devices;
[0020] In response to a trusted policy sent by the security management terminal, the trusted policy is executed, or the trusted policy is sent to the TPCM device, or policy information generated based on the trusted policy is sent to the TPCM device; wherein, the trusted policy includes a key management policy.
[0021] In an optional implementation, the key management policy includes a key update frequency policy, a key update permission policy, a forced key update policy, and a primary / backup key policy; the policy information includes key update information.
[0022] In an optional implementation, the key update information includes key update disallowed information, second forced key update information, key update disallowed information, storage of current user signature public key information, and master / slave key switching information;
[0023] The key update frequency strategy includes:
[0024] Obtain the updated user signature public key sent by the TPCM device;
[0025] The key update frequency of the TPCM device within a preset first time period is determined based on the updated user signature public key.
[0026] Determine whether the key update frequency exceeds a preset key update frequency threshold. If so, send a key update disallowed message to the TPCM device and an alarm message to the security management terminal.
[0027] The key update permission policy includes:
[0028] When the TPCM device is running continuously for a preset time period, a key update disallowed message is sent to the TPCM device during the preset time period to ensure the continuity of the TPCM device's operating status.
[0029] The mandatory key update strategy includes:
[0030] Receive the first mandatory key update information issued by the security management terminal;
[0031] The TPCM device is sent a second forced key update information according to the first forced key update information, so that the TPCM device can update the key according to the second forced key update information.
[0032] The primary / backup key policy includes:
[0033] In response to the updated user signature public key sent by the TPCM device, the current user signature public key is stored as a backup user signature public key, or the current user signature public key is sent to the security management terminal so that the security management terminal stores the user signature public key, or the information of storing the current user signature public key is sent to the TPCM device.
[0034] The primary / backup key policy also includes:
[0035] In response to the key update failure information sent by the TPCM device, the backup user signature public key is sent to the TPCM device so that the TPCM device can use the backup user signature public key for security protection;
[0036] The primary / backup key policy also includes:
[0037] Send primary / backup key switching information to the TPCM device so that the TPCM device switches to the backup user signature public key for security protection.
[0038] In an optional implementation, the trust strategy further includes a dynamic trust measurement strategy, which includes:
[0039] Obtain the current measurement information of the TPCM device;
[0040] The current information to be measured is trusted according to the trusted verification model; when the measurement passes, the process returns to the step of obtaining the current information to be measured of the TPCM device; when the measurement fails, the connection between the trusted switch and the TPCM device is disconnected.
[0041] Thirdly, the present invention provides a TPCM device key management apparatus, wherein the TPCM device is applied to an industrial control system, the industrial control system further includes a trusted switch, other devices, and a security management terminal, the TPCM device, the other devices, and the security management terminal are respectively connected to the trusted switch, and the apparatus is applied to the TPCM device, the apparatus comprising:
[0042] The acquisition module is used to acquire the key of the TPCM device, the key including a user signature public key and a user signature private key, the user signature public key including at least an expiration date;
[0043] The judgment module is used to determine whether the validity date has been updated. If so, the user signature public key is updated according to the validity date, and the user signature private key is updated according to the updated user signature public key and the SM9 algorithm and then saved.
[0044] The first distribution module is used to send the updated user signature public key to the security management terminal through a trusted switch, so that the security management terminal sends information to the trusted switch allowing the updated user signature public key of the TPCM device to be distributed to the other devices.
[0045] The first trusted policy module is configured to execute the trusted policy in response to a trusted policy sent by the trusted switch, or to execute the policy information generated based on the trusted policy in response to policy information sent by the trusted switch; wherein the trusted policy is sent by the security management terminal to the trusted switch, and the trusted policy includes a key management policy.
[0046] Fourthly, the present invention provides a trusted switch key management device, wherein the trusted switch is applied to an industrial control system, the industrial control system further includes a TPCM device, other devices, and a security management terminal, the TPCM device, the other devices, and the security management terminal are respectively connected to the trusted switch, the TPCM device uses a key to protect the system, the key includes a user signature public key and a user signature private key, wherein the user signature public key includes at least an expiration date; the TPCM device updates the user signature public key according to the updated expiration date to obtain an updated user signature public key, and updates the user signature private key according to the updated user signature public key and the SM9 algorithm and saves it; the device is applied to a trusted switch, and the device includes:
[0047] The sending module is used to send the updated user signature public key to the security management terminal in response to the updated user signature public key sent by the TPCM device.
[0048] The second distribution module is used to distribute the updated user signature public key of the TPCM device to other devices in response to the information sent by the security management terminal that allows the updated user signature public key of the TPCM device to be distributed to other devices.
[0049] The second trusted policy module is used to respond to a trusted policy sent by the security management terminal, execute the trusted policy, or send the trusted policy to the TPCM device, or send policy information generated based on the trusted policy to the TPCM device; wherein, the trusted policy includes a key management policy.
[0050] Fifthly, the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described in any of the foregoing embodiments.
[0051] In a sixth aspect, the present invention provides a computer-readable medium having processor-executable non-volatile program code, the program code causing the processor to perform the method described in any of the foregoing embodiments.
[0052] The beneficial effects of the technical solution provided by the embodiments of the present invention are as follows: The TPCM-based trusted switch key management method, device, and electronic device of the present invention update the user signature public key and user signature private key after detecting an update to the validity date of the TPCM device; after the update, the user signature public key is sent to the security management terminal for verification; and after successful verification, the user signature public key is distributed to other devices using a trusted switch, thereby realizing trusted verification of the TPCM device and effective trusted control of the TPCM device; furthermore, the TPCM device can automatically update its key, achieving decentralization, convenient implementation, and economic practicality; the security management terminal of the present invention also issues trusted policies, and achieves scientific and effective management of keys through the key management policy in the trusted policy, ensuring that the TPCM device can operate securely and efficiently during and after key updates. Attached Figure Description
[0053] Figure 1 A flowchart illustrating the TPCM device key management method provided in an embodiment of the present invention;
[0054] Figure 2 This is a schematic diagram of the principle of an industrial control system;
[0055] Figure 3 This is a schematic diagram illustrating the key update principle provided in an embodiment of the present invention;
[0056] Figure 4 A flowchart illustrating the trusted switch key management method provided in an embodiment of the present invention;
[0057] Figure 5 This is a schematic diagram of the system principle of the TPCM device key management device provided in an embodiment of the present invention;
[0058] Figure 6 This is a schematic diagram of the system principle of the trusted switch key management device provided in an embodiment of the present invention;
[0059] Figure 7 A schematic diagram of the system principle of an electronic device provided in an embodiment of the present invention.
[0060] In the diagram: 110 - Acquisition module; 120 - Judgment module; 130 - First distribution module; 140 - First trusted policy module; 210 - Sending module; 220 - Second distribution module; 230 - Second trusted policy module; 21 - Trusted switch; 22 - Security management terminal; 23 - Industrial embedded controller; 24 - Host computer; 25 - TPCM module; 400 - Electronic device; 401 - Communication interface; 402 - Processor; 403 - Memory; 404 - Bus. Detailed Implementation
[0061] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0062] See Figure 1 This embodiment provides a TPCM device key management method. The industrial control system in this embodiment includes a trusted switch, a TPCM device, other devices, and a security management terminal. The TPCM device, other devices, and security management terminal are all connected to the trusted switch. The TPCM device and other devices act as nodes connected to the trusted switch. The TPCM device and other devices can be industrial embedded controllers or host computers. See also... Figure 2 The security management terminal 22, the trusted switch 21, and the nodes in the system together form a local area network. The nodes can be equipped with either an industrial embedded controller 23 or a host computer 24 from an industrial control system. Both the industrial embedded controller 23 and the host computer 24 have a TPCM module 25 (Trusted Platform Control Module) installed or have integrated the functions of the TPCM module 25, so as to implement the method of this embodiment through the TPCM module 25. The method of this embodiment is applied to a TPCM device and includes the following steps S110 to S140.
[0063] Step S110: Obtain the key of the TPCM device. The key includes a user-signed public key and a user-signed private key. The user-signed public key includes at least the expiration date.
[0064] Specifically, the keys in a TPCM device are typically stored in its own memory (e.g., in RAM). These keys include a user signing public key, a user signing private key, a master signing private key, a master signing public key, and parameters used to generate the user signing private key. The master signing private key, master signing public key, and parameters are all pre-installed and secretly stored in the TPCM device at the factory and are never exported, thus ensuring the security of the core keys through hardware. The user signing public key includes the TPCM device's ID (Identifier), validity date, and other data. The validity date refers to the deadline for updating the key; for example, a device might have a built-in validity date of December 30, 2024. Other data may include the MAC address (Media Access Control Address) and the chip serial number in the TPCM device.
[0065] Step S120: Determine whether the validity date has been updated. If so, update the user signature public key according to the validity date, and update the user signature private key according to the updated user signature public key and the SM9 algorithm (a token-based cryptography algorithm, abbreviated as IBC) and save it.
[0066] Specifically, when the validity period changes, the user signing public key is updated, thus forming a new user signing public key. See also Figure 3 The updated user signature public key is then used in the SM9 algorithm to generate the user signature private key (ds) by combining the signature master public key (Ppub-s), the signature master private key (ks), and the parameter (para), and is then secretly stored.
[0067] In step S130, the trusted report of the TPCM device and the updated user signature public key are sent to the security management terminal through the trusted switch so that the security management terminal can verify the trusted report. When the verification is successful, the security management terminal sends a message to the trusted switch that allows the updated user signature public key of the TPCM device to be distributed to other devices.
[0068] Specifically, this step involves distributing the key of the TPCM device connected to node n. After a key update, the TPCM device connected to node n sends its generated trust report and user signature public key to the trusted switch. The trusted switch then sends the trust report and the MAC address of node n to the security management terminal for verification. Before connecting to node n, the TPCM device has already registered its MAC address with the security management terminal. Now, the security management terminal verifies the validity of the MAC address and the trust report. After successful verification, it notifies the trusted switch, enabling the trusted switch to send the TPCM device's public key to other nodes.
[0069] Step S140: In response to the trusted policy sent by the trusted switch, execute the trusted policy; or, in response to the policy information generated based on the trusted policy sent by the trusted switch, execute the policy information.
[0070] Specifically, the trusted policy is sent from the security management terminal to the trusted switch; that is, the security management terminal issues trusted policies to the trusted switch. The trusted policy includes a key management policy and a trusted measurement policy. The key management policy is used to manage the keys of the devices connected to each node, and the trusted measurement policy is used to perform security and trusted measurement on the devices connected to each node.
[0071] More specifically, the key management policies include key update frequency policies, key update permission policies, forced key update policies, and primary / backup key policies; policy information includes key update information. The key update frequency policy limits the key update frequency of the TPCM device; the key update permission policy limits whether key updates to the TPCM device are permitted or not; the forced key update policy forces key updates to the TPCM device or prevents key updates; and the primary / backup key policy uses the TPCM device's key before the update as a backup key.
[0072] The Trust Measurement strategy ensures the continuous trustworthiness of access switch devices by dynamically measuring the trustworthiness of TPCM devices, effectively preventing malicious attacks on the network by access switch devices and improving the overall network security.
[0073] After a TPCM device registers with the security management terminal, the terminal sets a trust policy based on the device type and sends this policy to the trusted switch. The trusted switch then performs dynamic trust measurement on the TPCM device based on the trust policy, monitoring its network behavior and data transmission in real time. Any abnormal behavior detected is promptly isolated or triggers an alarm. Simultaneously, the switch periodically retrieves trust reports from the device and sends them to the security management terminal for adjudication.
[0074] In this embodiment, during the key distribution process, trusted verification of nodes is achieved through a security management platform and a trusted switch, enabling effective trusted control. Nodes can automatically update keys, thus achieving decentralization, ease of implementation, and cost-effectiveness. In the industrial embedded controller, the signature master private key, signature master public key, and parameters are all pre-set in the TPCM at the factory, secretly stored, and never exported, ensuring the security of the core keys through hardware.
[0075] See Figure 4This embodiment provides a trusted switch key management method, which is applied to a trusted switch. The method includes the following steps S210 to S230.
[0076] Step S210: In response to the updated user signature public key sent by the TPCM device, send the updated user signature public key to the security management terminal.
[0077] Specifically, after the user signature public key is updated, the TPCM device will send the updated user signature public key along with the trusted report to the security management terminal through the trusted switch.
[0078] Step S220: In response to the information sent by the security management terminal allowing the distribution of the updated user signature public key of the TPCM device to other devices, the updated user signature public key of the TPCM device is distributed to other devices.
[0079] Specifically, when the security management terminal verifies the trusted report, and the verification is successful, the trusted switch is allowed to send the user's signature public key of node n to each node. The trusted report refers to the information generated when the device starts up using Trusted Computing 3.0 technology. The trusted report may include the following information: whether the firmware has been verified; the trusted status is updated when the target runs; and when an attack or code tampering is detected on the TPCM device, information about the attack and code tampering is recorded.
[0080] Step S230: In response to the trusted policy sent by the security management terminal, execute the trusted policy, or send the trusted policy to the TPCM device, or send policy information generated based on the trusted policy to the TPCM device; wherein, the trusted policy includes a key management policy.
[0081] Specifically, some trusted policies require the trusted switch to execute and send policy information to the TPCM device; while other trusted policies require the TPCM device to execute, in which case the trusted switch may need to send feedback information to the security management terminal or the TPCM device.
[0082] The trust strategies in this embodiment include at least two categories: key management strategies and dynamic trust measurement strategies. Key management strategies include key update frequency strategies, key update permission strategies, forced key update strategies, and primary / backup key strategies; strategy information includes key update information.
[0083] When the keys of a TPCM device are frequently changed due to attacks, this situation not only severely consumes the TPCM device itself, but also affects the computing resources of trusted switches, security management terminals, and related devices, while also causing significant network bandwidth consumption. To address this problem, it is necessary to implement necessary restrictions on the key update frequency. In this scenario, the corresponding key update frequency policy should be communicated to and implemented by the trusted switch through the security management terminal to balance security requirements with the reasonable use of system resources. The key update frequency policy includes the following steps (11)-(13).
[0084] (11) Obtain the updated user signature public key sent by the TPCM device.
[0085] (12) Determine the key update frequency of the TPCM device within a preset first time period based on the updated user signature public key.
[0086] The trusted switch records the number of updates to the TPCM device. When the user signature is updated, the update count is updated again, and then the update frequency value is calculated. Alternatively, the trusted switch records the update frequency of the TPCM device, and when the user signature is updated, the update frequency value is updated.
[0087] (13) Determine whether the key update frequency exceeds the preset key update frequency threshold. If so, send a key update disallowed message to the TPCM device and an alarm message to the security management terminal.
[0088] Based on a preset key update frequency threshold, such as m times / day, it is determined whether the current key update frequency exceeds the threshold. If it exceeds the threshold, it indicates that the key update is too frequent. The trusted switch will then refuse the TPCM device from updating the key and generate an alarm, which will be reported to the security management terminal.
[0089] In actual industrial control systems, when the TPCM device is an embedded device such as a PLC controller or DCS controller, it is sometimes necessary to ensure that the TPCM device operates continuously and without interruption (for example, when the device is connected to a trusted switch). In this scenario, key updates may affect the access and communication status of the TPCM device. Therefore, for such devices, a key update permission policy needs to be implemented to set the TPCM device to not allow key updates. Therefore, the key update permission policy includes the following steps (21).
[0090] (21) When the TPCM device runs continuously without interruption within a preset time period, send a key update disallowed message to the TPCM device within the preset time period to ensure the continuity of the TPCM device's operating status.
[0091] When the key update permission policy is executed, if it is set to disallow key updates, and the TPCM device attempts to update, the trusted switch will refuse the update and generate an alarm message, which will be reported to the security management terminal.
[0092] When the equipment is shut down or under maintenance, and a key update is indeed required, a forced key update policy is issued by the security management terminal. For example, if the TPCM equipment is under maintenance and a key update is performed once a year, the security management terminal will initiate a forced key update policy, which includes the following steps (31)-(32).
[0093] (31) Receive the first mandatory key update information issued by the security management terminal;
[0094] (32) Send the second forced key update information to the TPCM device according to the first forced key update information, so that the TPCM device can update the key according to the second forced key update information.
[0095] The forced key update policy is initiated by the security management terminal. Therefore, the first forced key update information and the second forced key update information can be the same, that is, the trusted switch forwards the forced key update information to the target terminal.
[0096] For high-availability devices such as PLC controllers and DCS controllers, in order to ensure the continuity of device operation, a primary / backup key policy can be issued by the security management terminal to continue to save the original key. This ensures that in special circumstances such as key update failure, the original key can be quickly switched to, avoiding the lack of available keys due to key update failure. This embodiment lists three primary / backup key policies. The first primary / backup key policy includes the following steps (41).
[0097] (41) In response to the updated user signature public key sent by the TPCM device, the current user signature public key is stored as a backup user signature public key, or the current user signature public key is sent to the security management terminal so that the security management terminal stores the user signature public key, or the information of storing the current user signature public key is sent to the TPCM device. Specifically, the method of this embodiment aims to illustrate that the original key can be stored as a backup key in a trusted switch, a security management terminal, or a TPCM device.
[0098] The second primary / backup key strategy includes the following steps (51), which are intended to explain that when the key update fails, the original key is sent to the TPCM device as a backup key.
[0099] (51) In response to the key update failure message sent by the TPCM device, the backup user signature public key is sent to the TPCM device so that the TPCM device can use the backup user signature public key for security protection.
[0100] The third primary / backup key strategy includes the following steps (61) to illustrate that in scenarios where key updates are required quickly, only primary / backup key switching information can be sent to achieve rapid key switching without going through the process of generating and distributing new keys, thus saving computing resources and network bandwidth.
[0101] (61) Send primary / backup key switching information to the TPCM device so that the TPCM device switches to the backup user signature public key for security protection.
[0102] The key management strategy in this embodiment enables scientific management of the keys of node devices, ensuring that the devices can operate securely and reliably before, during, and after key updates.
[0103] Trusted policies also include trusted measurement policies executed by trusted switches. Dynamic trusted measurement policies include the following steps (71)-(72).
[0104] (71) Obtain the current measurement information of the TPCM device.
[0105] (72) Perform a trusted measurement on the current information to be measured according to the trusted verification model; if the measurement passes, return to step (71); if the measurement fails, disconnect the connection between the trusted switch and the TPCM device.
[0106] In industrial control systems, TPCM devices can be engineering workstations, operator workstations, or PLC controllers. This embodiment uses an engineering workstation as the TPCM device. The communication relationships of an engineering workstation are relatively simple, typically involving communication with PLC controllers within a fixed range (i.e., the aforementioned other devices). In this embodiment, the security management terminal can act as a trusted third-party adjudication system, responsible for formulating and issuing dynamic trust measurement strategies and adjudicating trust reports.
[0107] A trusted verification model is used to characterize the communication characteristics between TPCM devices and other devices; the trusted verification model includes a logical combination of one or more sub-verification models. Here, communication characteristics refer to features in the network behavior of TPCM devices, such as communication relationships, data bandwidth, communication duration, communication direction, and packet size. Communication relationships refer to the communication relationships between TPCM devices and other devices. "Logic" includes AND logic and OR logic; therefore, a logical combination can be either the first and second sub-verification models simultaneously satisfying their respective threshold ranges, or it can be that only two of the first, second, or third sub-verification models satisfy their respective threshold ranges.
[0108] Preferably, when the TPCM device is an engineering station in an industrial control system, and other devices are PLC controllers in the same system, the trusted verification model of the engineering station includes a logical combination of one or more sub-verification models, such as a long-term bandwidth sub-verification model, a burst bandwidth sub-verification model, a high bandwidth duration sub-verification model, and a high bandwidth occurrence frequency sub-verification model. In some possible embodiments, these sub-verification models all have threshold ranges; therefore, after obtaining the trusted verification model of the TPCM device sent by the security management terminal, it is also necessary to determine the threshold range corresponding to each sub-verification model to determine the threshold line of the trusted verification model.
[0109] When configuring threshold lines, considering that the engineer station is usually in monitoring mode and the amount of data is small, a large amount of data will only be sent when engineering configuration or firmware upgrade. Since the modification of engineering configuration and firmware is definitely infrequent, the threshold lines can be set as follows: long-term bandwidth is less than the first threshold, burst bandwidth increases, high bandwidth duration is less than the second threshold, and the number of high bandwidth occurrences per unit time is less than the third threshold.
[0110] The information to be measured is sent by the TPCM device to the trusted switch. The information to be measured refers to the communication characteristics of the TPCM device, such as the communication characteristics of the engineer station, including communication bandwidth and communication duration.
[0111] Since the trusted verification model comprises a logical combination of multiple sub-verification models, the values of each sub-verification model are calculated using the current information to be measured. For example, in the burst bandwidth sub-verification model, the burst bandwidth value is calculated using the current information to be measured. Some sub-verification models require recording and storing the information to be measured for a certain duration, such as the long-term bandwidth sub-verification model and the high-bandwidth duration sub-verification model. The long-term bandwidth sub-verification model needs to record the bandwidth for a preset duration and then calculate the bandwidth for that preset duration; the high-bandwidth duration sub-verification model needs to record the duration for which the bandwidth meets a preset bandwidth threshold and obtain the duration value.
[0112] The measurement is judged by a threshold line, which includes the threshold range corresponding to multiple sub-verification models. Each sub-verification model is judged to exceed the corresponding threshold range. If it does, the measurement fails; if it does not exceed the corresponding threshold range, the measurement passes. For example, whether the long-term bandwidth value obtained by the long-term bandwidth sub-verification model is less than the first threshold, whether the high bandwidth duration value obtained by the high bandwidth duration sub-verification model is less than the second threshold, whether the high bandwidth occurrence count value obtained by the high bandwidth occurrence count sub-verification model is less than the third threshold, and whether the burst bandwidth value obtained by the burst bandwidth sub-verification model is greater than the fourth threshold. If any of the above exceeds the threshold range, the measurement fails; if all of them meet the threshold range, the measurement passes. When the measurement fails, the connection between the trusted switch and the TPCM device is disconnected. When the measurement passes, return to (71) to continue dynamic measurement.
[0113] The dynamic trust measurement strategy in this embodiment can continuously measure the trustworthiness of the access device's behavior, effectively preventing malicious behavior and ensuring the security and trustworthiness of the entire industrial control network.
[0114] See Figure 5 This embodiment provides a TPCM device key management device. The industrial control system includes a trusted switch, a TPCM device, other devices, and a security management terminal. The TPCM device, other devices, and security management terminal are respectively connected to the trusted switch. The device is applied to the TPCM device and includes:
[0115] The acquisition module 110 is used to acquire the key of the TPCM device. The key includes a user signature public key and a user signature private key. The user signature public key includes at least the validity date.
[0116] The judgment module 120 is used to determine whether the validity date has been updated. If so, the user signature public key is updated according to the validity date, and the user signature private key is updated and saved according to the updated user signature public key and SM9 algorithm.
[0117] The first distribution module 130 is used to send the updated user signature public key to the security management terminal through the trusted switch, so that the security management terminal sends information to the trusted switch that allows the updated user signature public key of the TPCM device to be distributed to other devices.
[0118] The first trusted policy module 140 is used to execute a trusted policy in response to a trusted policy sent by a trusted switch, or to execute policy information based on a trusted policy sent by a trusted switch; wherein the trusted policy is sent by the security management terminal to the trusted switch, and the trusted policy includes a key management policy.
[0119] In optional embodiments, the key management policy includes a key update frequency policy, a key update permission policy, a forced key update policy, and a primary / backup key policy; the policy information includes key update information.
[0120] In an optional embodiment, the trust strategy further includes a dynamic trust measurement strategy.
[0121] See Figure 6 This embodiment provides a trusted switch key management device. The industrial control system includes a trusted switch, a TPCM device, other devices, and a security management terminal. The TPCM device, other devices, and security management terminal are respectively connected to the trusted switch. The TPCM device uses keys to protect the system. The keys include a user signature public key and a user signature private key, wherein the user signature public key includes at least an expiration date. The TPCM device updates the user signature public key according to the updated expiration date to obtain an updated user signature public key, and updates the user signature private key according to the updated user signature public key and the SM9 algorithm and saves it. The device is applied to the trusted switch and includes:
[0122] The sending module 210 is used to send the updated user signature public key to the security management terminal in response to the updated user signature public key sent by the TPCM device.
[0123] The second distribution module 220 is used to distribute the updated user signature public key of the TPCM device to other devices in response to the information sent by the security management terminal that allows the distribution of the updated user signature public key of the TPCM device to other devices.
[0124] The second trusted policy module 230 is used to respond to a trusted policy sent by the security management terminal, execute the trusted policy, or send the trusted policy to the TPCM device, or send policy information generated based on the trusted policy to the TPCM device; wherein, the trusted policy includes a key management policy.
[0125] In an optional embodiment, the key update information includes key update disallowed information, second forced key update information, key update disallowed information, storage of current user signature public key information, and master / slave key switching information;
[0126] The key update frequency policy includes a user signature public key module, an update frequency module, and an information sending module. The user signature public key module is used to obtain the updated user signature public key sent by the TPCM device. The update frequency module is used to determine the key update frequency of the TPCM device within a preset first time period based on the updated user signature public key. The information sending module is used to determine whether the key update frequency exceeds a preset key update frequency threshold; if so, it sends a key update disallowed message to the TPCM device and an alarm message to the security management terminal.
[0127] The key update permission policy includes a key update information module, which sends a key update disallowment message to the TPCM device within a preset time period when the TPCM device is running continuously for a preset time period, in order to ensure the continuity of the TPCM device's operating status.
[0128] The mandatory key update policy includes an information receiving module and a key update module. The information receiving module receives the first mandatory key update information from the security management terminal. The key update module sends a second mandatory key update information to the TPCM device based on the first mandatory key update information, so that the TPCM device can update its key according to the second mandatory key update information.
[0129] The primary / backup key policy includes a first storage module, which, in response to an updated user signature public key sent by the TPCM device, stores the current user signature public key as a backup user signature public key, or sends the current user signature public key to the security management terminal so that the security management terminal stores the user signature public key, or sends the information of storing the current user signature public key to the TPCM device.
[0130] The primary / backup key policy also includes a security protection module, which, in response to a key update failure message sent by the TPCM device, sends a backup user signature public key to the TPCM device so that the TPCM device can use the backup user signature public key for security protection.
[0131] The primary / backup key policy also includes a switchover information module. This module sends primary / backup key switchover information to the TPCM device, enabling the TPCM device to switch to the backup user signature public key for security protection.
[0132] In an optional embodiment, the trust policy further includes a dynamic trust measurement policy, which comprises a current information to be measured module and a trust measurement module. The current information to be measured module is used to obtain the current information to be measured of the TPCM device. The trust measurement is used to perform a trust measurement on the current information to be measured according to the trust verification model; when the measurement passes, the process returns to the step of obtaining the current information to be measured of the TPCM device; when the measurement fails, the connection between the trust switch and the TPCM device is disconnected.
[0133] The apparatus provided in the embodiments of this application has the same inventive concept as the method provided in the embodiments of this application. As long as the method can solve the technical problem, the apparatus can also solve the technical problem. This will not be elaborated here.
[0134] Reference Figure 7The present invention also provides an electronic device 400, including a communication interface 401, a processor 402, a memory 403, and a bus 404. The processor 402, the communication interface 401, and the memory 403 are connected through the bus 404. The memory 403 is used to store a computer program that supports the processor 402 in executing the above-described method. The processor 402 is configured to execute the program stored in the memory 403.
[0135] Optionally, embodiments of the present invention also provide a computer-readable medium having non-volatile program code executable by a processor 402, the program code causing the processor 402 to perform the methods as described in the above embodiments.
[0136] As is known from common technical knowledge, this invention can be implemented through other embodiments that do not depart from its spirit or essential characteristics. Therefore, the disclosed embodiments described above are merely illustrative in all respects and are not the only ones. All modifications within the scope of this invention or its equivalents are included in this invention.
Claims
1. A TPCM device key management method, characterized in that, The TPCM device is applied to an industrial control system, which further includes a trusted switch, other devices, and a security management terminal. The TPCM device, the other devices, and the security management terminal are respectively connected to the trusted switch. The method is applied to the TPCM device and includes: Obtain the key of the TPCM device, the key including a user signature public key and a user signature private key, the user signature public key including at least an expiration date; Determine whether the validity date has been updated. If so, update the user signature public key according to the validity date, and update the user signature private key according to the updated user signature public key and the SM9 algorithm, and save it. The updated user signature public key is sent to the security management terminal via a trusted switch, so that the security management terminal sends information to the trusted switch allowing the distribution of the updated user signature public key of the TPCM device to other devices; and In response to a trusted policy sent by the trusted switch, the trusted policy is executed; or, in response to policy information generated based on the trusted policy sent by the trusted switch, the policy information is executed; wherein the trusted policy is sent by the security management terminal to the trusted switch, and the trusted policy includes a key management policy.
2. The TPCM device key management method according to claim 1, characterized in that, The key management policy includes a key update frequency policy, a key update permission policy, a forced key update policy, and a primary / backup key policy; the policy information includes key update information.
3. The TPCM device key management method according to claim 1, characterized in that, The trust strategy also includes a dynamic trust measurement strategy.
4. A trusted switch key management method, characterized in that, A trusted switch is applied to an industrial control system, which further includes a TPCM device, other devices, and a security management terminal. The TPCM device, other devices, and security management terminal are respectively connected to the trusted switch. The TPCM device uses a key to protect the system's security. The key includes a user signature public key and a user signature private key, wherein the user signature public key includes at least an expiration date. The TPCM device updates the user signature public key according to the updated expiration date to obtain an updated user signature public key, and updates the user signature private key according to the updated user signature public key and the SM9 algorithm, and saves it. This method is applied to the trusted switch and includes: In response to the updated user signature public key sent by the TPCM device, the updated user signature public key is sent to the security management terminal; In response to the information sent by the security management terminal allowing the distribution of the updated user signature public key of the TPCM device to other devices, the updated user signature public key of the TPCM device is distributed to other devices; In response to a trusted policy sent by the security management terminal, the trusted policy is executed, or the trusted policy is sent to the TPCM device, or policy information generated based on the trusted policy is sent to the TPCM device; wherein, the trusted policy includes a key management policy.
5. The trusted switch key management method according to claim 4, characterized in that, The key management policy includes a key update frequency policy, a key update permission policy, a forced key update policy, and a primary / backup key policy; the policy information includes key update information.
6. The trusted switch key management method according to claim 5, characterized in that, The key update information includes key update disallowed information, second forced key update information, key update disallowed information, storage of the current user's signature public key information, and master / slave key switching information; The key update frequency strategy includes: Obtain the updated user signature public key sent by the TPCM device; The key update frequency of the TPCM device within a preset first time period is determined based on the updated user signature public key. Determine whether the key update frequency exceeds a preset key update frequency threshold. If so, send a key update disallowed message to the TPCM device and an alarm message to the security management terminal. The key update permission policy includes: When the TPCM device is running continuously for a preset time period, a key update disallowed message is sent to the TPCM device during the preset time period to ensure the continuity of the TPCM device's operating status. The mandatory key update strategy includes: Receive the first mandatory key update information issued by the security management terminal; The TPCM device is sent a second forced key update information according to the first forced key update information, so that the TPCM device can update the key according to the second forced key update information. The primary / backup key policy includes: In response to the updated user signature public key sent by the TPCM device, the current user signature public key is stored as a backup user signature public key, or the current user signature public key is sent to the security management terminal so that the security management terminal stores the user signature public key, or the information of storing the current user signature public key is sent to the TPCM device. The primary / backup key policy also includes: In response to the key update failure information sent by the TPCM device, the backup user signature public key is sent to the TPCM device so that the TPCM device can use the backup user signature public key for security protection; The primary / backup key policy also includes: Send primary / backup key switching information to the TPCM device so that the TPCM device switches to the backup user signature public key for security protection.
7. The trusted switch key management method according to claim 5, characterized in that, The trusted policy further includes a dynamic trusted measurement policy, and the execution of the trusted policy in response to the trusted policy sent by the security management terminal includes: Obtain the current measurement information of the TPCM device; The current information to be measured is subjected to a trust measurement according to the dynamic trust measurement strategy; when the measurement passes, the process returns to the step of obtaining the current information to be measured of the TPCM device; when the measurement fails, the connection between the trusted switch and the TPCM device is disconnected.
8. A TPCM device key management device, characterized in that, The TPCM device is applied to an industrial control system, which further includes a trusted switch, other devices, and a security management terminal. The TPCM device, the other devices, and the security management terminal are respectively connected to the trusted switch. The apparatus is applied to the TPCM device and includes: The acquisition module is used to acquire the key of the TPCM device, the key including a user signature public key and a user signature private key, the user signature public key including at least an expiration date; The judgment module is used to determine whether the validity date has been updated. If so, the user signature public key is updated according to the validity date, and the user signature private key is updated according to the updated user signature public key and the SM9 algorithm and then saved. The first distribution module is used to send the updated user signature public key to the security management terminal through a trusted switch, so that the security management terminal sends information to the trusted switch allowing the updated user signature public key of the TPCM device to be distributed to the other devices. The first trusted policy module is configured to execute the trusted policy in response to a trusted policy sent by the trusted switch, or to execute the policy information generated based on the trusted policy in response to policy information sent by the trusted switch; wherein the trusted policy is sent by the security management terminal to the trusted switch, and the trusted policy includes a key management policy.
9. A trusted switch key management device, characterized in that, The trusted switch is applied to an industrial control system, which further includes a TPCM device, other devices, and a security management terminal. The TPCM device, other devices, and security management terminal are respectively connected to the trusted switch. The TPCM device uses a key to protect the system, the key including a user signature public key and a user signature private key, wherein the user signature public key includes at least an expiration date. The TPCM device updates the user signature public key according to the updated expiration date to obtain an updated user signature public key, and updates the user signature private key according to the updated user signature public key and the SM9 algorithm, and saves it. The device is applied to the trusted switch and includes: The sending module is used to send the updated user signature public key to the security management terminal in response to the updated user signature public key sent by the TPCM device. The second distribution module is used to distribute the updated user signature public key of the TPCM device to other devices in response to the information sent by the security management terminal that allows the updated user signature public key of the TPCM device to be distributed to other devices. The second trusted policy module is used to respond to a trusted policy sent by the security management terminal, execute the trusted policy, or send the trusted policy to the TPCM device, or send policy information generated based on the trusted policy to the TPCM device; wherein, the trusted policy includes a key management policy.
10. An electronic device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method according to any one of claims 1-7.
Citation Information
Patent Citations
A method and system for generating SM9 digital signatures
CN107579819B
A hierarchical signature method and system based on the SM9 digital signature algorithm
CN109951288B
Secure and trusted starting method and system for generating random key based on TPCM
CN116707885A
Method for providing a firmware update of a device
US20190163465A1