Trusted industrial control system configuration screen security unlocking method and related device
Through multi-factor dynamic authentication and trusted computing technology, the security risks of the traditional industrial control system configuration screen unlocking method are solved, the security and stability of the configuration screen are achieved, the exclusivity of the configuration screen and the consistency of operation are ensured, and the security and operational efficiency of the industrial control system are improved.
Patent Information
- Application Number
- CN202411343323.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-09-25
AI Technical Summary
Traditional industrial control system configuration screen unlocking methods rely on simple user credentials for authentication, which poses security risks. Attackers can easily access and modify the configuration screen, affecting the security and stability of the industrial control system.
Adopting multi-factor dynamic authentication and trusted computing technology, users and devices are remotely verified through a trusted security center to build a trusted execution environment, ensuring the security and exclusivity of unlocking the configuration screen.
It improves the security and reliability of identity and device authentication, ensures the integrity and confidentiality of configuration screens, avoids multi-user operation conflicts, and records unlock operation details for security auditing and troubleshooting.
Smart Images

Figure CN119337347B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of industrial automation, and in particular to a method for securely unlocking a configuration screen of a trusted industrial control system and a related device. Background Art
[0002] Industrial control systems are the "nerve center" of industrial production, yet they face increasing security threats. Once these systems are attacked or operated incorrectly, they can lead to major production accidents, even threatening human life and social stability. Furthermore, screen configuration is a crucial component of industrial control systems. Users edit screens through screen configuration software, displaying the system's real-time operational status. Therefore, ensuring exclusive user access to the currently configured screen is crucial. Otherwise, duplicate or incorrect screen editing can occur, severely impacting the display quality of the industrial control system and affecting the quality of the system's monitoring.
[0003] Traditional methods for unlocking industrial control system configuration screens typically rely on simple user credentials (such as username and password) for authentication. However, this approach presents numerous security risks, such as credential leakage, password guessing, and identity theft. Once an attacker obtains the credentials of a legitimate user, they can easily access and modify the configuration screen, potentially damaging the industrial control system. Summary of the Invention
[0004] The purpose of the present invention is to provide a trusted industrial control system configuration screen security unlocking method and related devices to overcome the defects of the existing technology. The present invention uses trusted computing technology to ensure the communication security of the industrial control system and the exclusivity of the current user's configuration screen editing operations.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] The method for securely unlocking the configuration screen of a trusted industrial control system includes the following steps:
[0007] The user issues a security unlock command for the current configuration screen at the current operation station node;
[0008] The trusted security center performs multi-factor dynamic authentication verification on the security unlocking instruction and transmits the verification result back to the operation station node;
[0009] The operation station node receives the returned verification result. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked.
[0010] Furthermore, the multi-factor dynamic authentication verification specifically includes:
[0011] First-factor verification: The trusted platform module in the trusted security center performs remote user security verification on the user information. If the verification is successful, the user's authorization status is updated to authorized and the second-factor verification is initiated. Otherwise, the user's authorization status is updated to untrusted.
[0012] Second factor verification: The trusted platform module of the trusted security center performs remote device security verification on the operation station node. If the verification is successful, the device authorization status is updated to authorized, and the trusted security audit report is updated based on the trusted verification results; otherwise, the device authorization status is updated to untrusted.
[0013] Furthermore, the trusted security audit report is used to store the trusted verification results and detailed information of the unlocking operation. The trusted security center periodically initiates a trusted security check to the operation station node and dynamically updates the system trusted status based on the trusted security audit report. If the check result is untrusted, the trusted security audit report is updated and the authorization operation is stopped, and the process ends.
[0014] Furthermore, the secure unlocking of the current configuration screen specifically includes the following steps:
[0015] S31: querying a screen database according to the screen name of the current configuration screen to obtain a node name of the locked current configuration screen;
[0016] S32: If the node name of the locked current configuration screen obtained in S31 is consistent with the node name of the current operation station node, it means that the current configuration screen has been safely unlocked at the current operation station node, and the process ends; otherwise, a configuration screen unlocking application message is generated and sent to the node of the locked current configuration screen in S31, and S33 is executed;
[0017] The configuration screen unlock application message includes the current operation station node name and the screen name of the current configuration screen;
[0018] S33: The node that has locked the current configuration screen parses the configuration screen unlocking request message in S32 and pops up a screen unlocking inquiry window. If the node user that has locked the current configuration screen allows the screen to be unlocked, an unlocking permission response message is returned to the current operation station node; otherwise, an unlocking request rejection response message is returned to the current operation station node.
[0019] S34: The current operation station node parses the response message. If it is a response message allowing unlocking, it means that the current operation station node has completed the secure unlocking of the current configuration screen, and queries the screen database according to the screen name of the current configuration screen, and updates the node name of the locked current configuration screen in the screen database described in S31 with the current operation station node name described in S32 as the current operation station node. The process ends. Otherwise, it prompts that the screen unlocking fails and the process ends.
[0020] Trusted industrial control system configuration screen security unlocking system, including trusted security center and operation station node;
[0021] The trusted security center is used to receive the security unlocking instruction of the current configuration screen issued by the user at the current operation station node, perform multi-factor dynamic authentication verification on the security unlocking instruction, and transmit the verification result back to the operation station node;
[0022] The operation station node is used to receive the verification result and make a judgment. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked.
[0023] Furthermore, the multi-factor dynamic authentication verification specifically includes:
[0024] First-factor verification: The trusted platform module in the trusted security center performs remote user security verification on the user information. If the verification is successful, the user's authorization status is updated to authorized and the second-factor verification is initiated. Otherwise, the user's authorization status is updated to untrusted.
[0025] Second factor verification: The trusted platform module of the trusted security center performs remote device security verification on the operation station node. If the verification is successful, the device authorization status is updated to authorized, and the trusted security audit report is updated based on the trusted verification results; otherwise, the device authorization status is updated to untrusted.
[0026] Furthermore, the trusted security audit report is used to store the trusted verification results and detailed information of the unlocking operation. The trusted security center periodically initiates a trusted security check to the operation station node and dynamically updates the system trusted status based on the trusted security audit report. If the check result is untrusted, the trusted security audit report is updated and the authorization operation is stopped, and the process ends.
[0027] Furthermore, the secure unlocking of the current configuration screen specifically includes the following steps:
[0028] S31: querying a screen database according to the screen name of the current configuration screen to obtain a node name of the locked current configuration screen;
[0029] S32: If the node name of the locked current configuration screen obtained in S31 is consistent with the node name of the current operation station node, it means that the current configuration screen has been safely unlocked at the current operation station node, and the process ends; otherwise, a configuration screen unlocking application message is generated and sent to the node of the locked current configuration screen in S31, and S33 is executed;
[0030] The configuration screen unlock application message includes the current operation station node name and the screen name of the current configuration screen;
[0031] S33: The node that has locked the current configuration screen parses the configuration screen unlocking request message in S32 and pops up a screen unlocking inquiry window. If the node user that has locked the current configuration screen allows the screen to be unlocked, an unlocking permission response message is returned to the current operation station node; otherwise, an unlocking request rejection response message is returned to the current operation station node.
[0032] S34: The current operation station node parses the response message. If it is a response message allowing unlocking, it means that the current operation station node has completed the secure unlocking of the current configuration screen, and queries the screen database according to the screen name of the current configuration screen, and updates the node name of the locked current configuration screen in the screen database described in S31 with the current operation station node name described in S32 as the current operation station node. The process ends. Otherwise, it prompts that the screen unlocking fails and the process ends.
[0033] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method for securely unlocking a configuration screen of a trusted industrial control system when executing the computer program.
[0034] A computer storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method for securely unlocking a configuration screen of a trusted industrial control system.
[0035] Compared with the prior art, the present invention has the following beneficial technical effects:
[0036] The method of the present invention utilizes multi-factor dynamic authentication and verification to enhance the security and reliability of identity and device verification. Furthermore, the method incorporates trusted computing technology to protect the unlocking process of the configuration screen by establishing a trusted execution environment. In this environment, only authorized and verified operations can be executed, thereby ensuring the integrity and confidentiality of the configuration screen. Even if an attacker gains access to the industrial control system, they cannot perform unauthorized modifications or unlock operations on the configuration screen.
[0037] In industrial control systems, multiple users may access or modify the same configuration screen simultaneously, which can lead to operational conflicts and data inconsistencies. The present invention uses an exclusive unlocking mechanism to ensure that only one user can access and control the configuration screen at a given time, avoiding the problem of multiple users operating simultaneously. This ensures that each user's operations can proceed as expected, ensuring operational consistency and system stability. This exclusive working environment helps improve user operational efficiency and accuracy, especially in industrial control scenarios that require fast response or high precision.
[0038] Furthermore, through exclusive unlocking, the industrial control system can record detailed information about each unlock operation, including the time, user identity, and operation content. This information is extremely valuable for security audits and troubleshooting of the industrial control system. Administrators can analyze these records to identify potential security threats or operational anomalies and take timely action to address them. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings in the specification are used to provide further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0040] Figure 1 This is a flow chart of a method for securely unlocking a configuration screen of a trusted industrial control system according to the present invention;
[0041] Figure 2 This is a structural diagram of the secure unlocking system for the configuration screen of a trusted industrial control system according to the present invention. DETAILED DESCRIPTION
[0042] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0043] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0044] Example 1
[0045] See also Figure 1 The present invention provides a method for securely unlocking a configuration screen of a trusted industrial control system, comprising the following steps:
[0046] The user issues a security unlock command for the current configuration screen at the current operation station node;
[0047] The trusted security center performs multi-factor dynamic authentication verification on the security unlocking instruction and transmits the verification result back to the operation station node;
[0048] The operation station node receives the returned verification result. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked.
[0049] The method of the present invention utilizes multi-factor dynamic authentication and verification to enhance the security and reliability of identity and device verification. Furthermore, the method incorporates trusted computing technology to protect the unlocking process of the configuration screen by establishing a trusted execution environment. In this environment, only authorized and verified operations can be executed, thereby ensuring the integrity and confidentiality of the configuration screen. Even if an attacker gains access to the industrial control system, they cannot perform unauthorized modifications or unlock operations on the configuration screen.
[0050] Example 2
[0051] The present invention provides a method for securely unlocking a configuration screen of a trusted industrial control system, comprising the following steps:
[0052] Step 1: The user issues a security unlock command for the current configuration screen at the current operation station node;
[0053] Step 2: The trusted security center performs a multi-factor dynamic authentication check on the security unlock instruction and transmits the verification result back to the operation station node; the multi-factor dynamic authentication check specifically includes:
[0054] First-factor verification: The trusted platform module in the trusted security center performs remote user security verification on the user information. If the verification is successful, the user's authorization status is updated to authorized and the second-factor verification is initiated. Otherwise, the user's authorization status is updated to untrusted.
[0055] Second factor verification: The trusted platform module of the trusted security center performs remote device security verification on the operation station node. If the verification is successful, the device authorization status is updated to authorized, and the trusted security audit report is updated based on the trusted verification results; otherwise, the device authorization status is updated to untrusted.
[0056] This invention improves the security and reliability of identity and device verification by employing multi-factor dynamic authentication. Furthermore, the method incorporates trusted computing technology, building a trusted execution environment to protect the configuration screen unlocking process. In this environment, only authorized and verified operations can be executed, thus ensuring the integrity and confidentiality of the configuration screen. Even if an attacker gains access to the industrial control system, they cannot perform unauthorized modifications or unlock operations on the configuration screen.
[0057] Among them, the trusted security audit report is used to store the trusted verification results and detailed information of the unlocking operation. The trusted security center periodically initiates a trusted security check to the operation station node, and dynamically updates the system trusted status according to the trusted security audit report. If the verification result is untrustworthy, the trusted security audit report is updated and the authorization operation is stopped, and the process ends.
[0058] Step 3: The operation station node receives the returned verification result. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked. The secure unlocking of the current configuration screen specifically includes the following steps:
[0059] S31: querying a screen database according to the screen name of the current configuration screen to obtain a node name of the locked current configuration screen;
[0060] S32: If the node name of the locked current configuration screen obtained in S31 is consistent with the node name of the current operation station node, it means that the current configuration screen has been safely unlocked at the current operation station node, and the process ends; otherwise, a configuration screen unlocking application message is generated and sent to the node of the locked current configuration screen in S31, and S33 is executed;
[0061] The configuration screen unlock application message includes the current operation station node name and the screen name of the current configuration screen;
[0062] S33: The node that has locked the current configuration screen parses the configuration screen unlocking request message in S32 and pops up a screen unlocking inquiry window. If the node user that has locked the current configuration screen allows the screen to be unlocked, an unlocking permission response message is returned to the current operation station node; otherwise, an unlocking request rejection response message is returned to the current operation station node.
[0063] S34: The current operation station node parses the response message. If it is a response message allowing unlocking, it means that the current operation station node has completed the secure unlocking of the current configuration screen, and queries the screen database according to the screen name of the current configuration screen, and updates the node name of the locked current configuration screen in the screen database described in S31 with the current operation station node name described in S32 as the current operation station node. The process ends. Otherwise, it prompts that the screen unlocking fails and the process ends.
[0064] The present invention uses an exclusive unlocking mechanism to ensure that only one user can access and control the configuration screen at a given time, avoiding the problem of multiple users operating simultaneously. In this way, each user's operations can be carried out as expected, ensuring the consistency of operations and the stability of the system. This exclusive working environment helps to improve the user's operating efficiency and accuracy, especially in industrial control scenarios that require fast response or high precision. In addition, through exclusive unlocking, the industrial control system can record detailed information on each unlocking operation, including operation time, user identity, operation content, etc. This information is very valuable for security audits and troubleshooting of industrial control systems. Administrators can analyze these records to discover potential security threats or operational anomalies and take appropriate measures to deal with them in a timely manner.
[0065] Example 3
[0066] See also Figure 2 , the present invention provides a trusted industrial control system configuration screen security unlocking system, including a trusted security center and an operation station node;
[0067] The trusted security center is used to receive the security unlock instruction for the current configuration screen issued by the user at the current operation station node, perform multi-factor dynamic authentication verification on the security unlock instruction, and return the verification result to the operation station node; the multi-factor dynamic authentication verification specifically includes:
[0068] First-factor verification: The trusted platform module in the trusted security center performs remote user security verification on the user information. If the verification is successful, the user's authorization status is updated to authorized and the second-factor verification is initiated. Otherwise, the user's authorization status is updated to untrusted.
[0069] Second factor verification: The trusted platform module of the trusted security center performs remote device security verification on the operation station node. If the verification is successful, the device authorization status is updated to authorized, and the trusted security audit report is updated based on the trusted verification results; otherwise, the device authorization status is updated to untrusted.
[0070] Among them, the trusted security audit report is used to store the trusted verification results and detailed information of the unlocking operation. The trusted security center periodically initiates a trusted security check to the operation station node, and dynamically updates the system trusted status according to the trusted security audit report. If the verification result is untrustworthy, the trusted security audit report is updated and the authorization operation is stopped, and the process ends.
[0071] The operation station node is used to receive the verification result and make a judgment. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked, specifically including the following steps:
[0072] S31: querying a screen database according to the screen name of the current configuration screen to obtain a node name of the locked current configuration screen;
[0073] S32: If the node name of the locked current configuration screen obtained in S31 is consistent with the node name of the current operation station node, it means that the current configuration screen has been safely unlocked at the current operation station node, and the process ends; otherwise, a configuration screen unlocking application message is generated and sent to the node of the locked current configuration screen in S31, and S33 is executed;
[0074] The configuration screen unlock application message includes the current operation station node name and the screen name of the current configuration screen;
[0075] S33: The node that has locked the current configuration screen parses the configuration screen unlocking request message in S32 and pops up a screen unlocking inquiry window. If the node user that has locked the current configuration screen allows the screen to be unlocked, an unlocking permission response message is returned to the current operation station node; otherwise, an unlocking request rejection response message is returned to the current operation station node.
[0076] S34: The current operation station node parses the response message. If it is a response message allowing unlocking, it means that the current operation station node has completed the secure unlocking of the current configuration screen, and queries the screen database according to the screen name of the current configuration screen, and updates the node name of the locked current configuration screen in the screen database described in S31 with the current operation station node name described in S32 as the current operation station node. The process ends. Otherwise, it prompts that the screen unlocking fails and the process ends.
[0077] Example 4
[0078] The present invention also provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for securely unlocking the configuration screen of the trusted industrial control system are implemented.
[0079] Example 5
[0080] The present invention also provides a computer storage medium, wherein the computer storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for securely unlocking the configuration screen of a trusted industrial control system are implemented.
[0081] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0082] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0083] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0084] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit its scope of protection. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that after reading the present invention, those skilled in the art may still make various changes, modifications or equivalent substitutions to the specific implementation methods of the invention, but these changes, modifications or equivalent substitutions are all within the scope of protection of the pending claims of the invention.
Claims
1. A method for securely unlocking the configuration screen of a trusted industrial control system, characterized in that: The following steps are involved: The user issues a security unlock command for the current configuration screen at the current operation station node; The trusted security center performs multi-factor dynamic authentication verification on the security unlocking instruction and transmits the verification result back to the operation station node; The multi-factor dynamic authentication verification specifically includes: First-factor verification: The trusted platform module in the trusted security center performs remote user security verification on the user information. If the verification is successful, the user's authorization status is updated to authorized and the second-factor verification is initiated. Otherwise, the user's authorization status is updated to untrusted. Second factor verification: The trusted platform module of the trusted security center performs remote device security verification on the operation station node. If the verification is successful, the device authorization status is updated to authorized, and the trusted security audit report is updated based on the trusted verification result; otherwise, the device authorization status is updated to untrusted; The operation station node receives the returned verification result. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked. The secure unlocking of the current configuration screen specifically includes the following steps: S31: querying a screen database according to the screen name of the current configuration screen to obtain a node name of the locked current configuration screen; S32: If the node name of the locked current configuration screen obtained in S31 is consistent with the node name of the current operation station node, it means that the current configuration screen has been safely unlocked at the current operation station node, and the process ends; otherwise, a configuration screen unlocking application message is generated and sent to the node of the locked current configuration screen in S31, and S33 is executed; The configuration screen unlock application message includes the current operation station node name and the screen name of the current configuration screen; S33: The node that has locked the current configuration screen parses the configuration screen unlocking request message in S32 and pops up a screen unlocking inquiry window. If the node user that has locked the current configuration screen allows the screen to be unlocked, an unlocking permission response message is returned to the current operation station node; otherwise, an unlocking request rejection response message is returned to the current operation station node. S34: The current operation station node parses the response message. If it is a response message allowing unlocking, it means that the current operation station node has completed the secure unlocking of the current configuration screen, and queries the screen database according to the screen name of the current configuration screen, and updates the node name of the locked current configuration screen in the screen database described in S31 with the current operation station node name described in S32 as the current operation station node. The process ends. Otherwise, it prompts that the screen unlocking fails and the process ends.
2. The method for securely unlocking the configuration screen of a trusted industrial control system according to claim 1, characterized in that: The trusted security audit report is used to store the trusted verification results and detailed information of the unlocking operation. The trusted security center periodically initiates a trusted security check to the operation station node and dynamically updates the system trusted status based on the trusted security audit report. If the check result is untrustworthy, the trusted security audit report is updated and the authorization operation is stopped, and the process ends.
3. Trusted industrial control system configuration screen security unlocking system, characterized by: Includes trusted security center and operation station nodes; The trusted security center is used to receive the security unlocking instruction of the current configuration screen issued by the user at the current operation station node, perform multi-factor dynamic authentication verification on the security unlocking instruction, and transmit the verification result back to the operation station node; The multi-factor dynamic authentication verification specifically includes: First-factor verification: The trusted platform module in the trusted security center performs remote user security verification on the user information. If the verification is successful, the user's authorization status is updated to authorized and the second-factor verification is initiated. Otherwise, the user's authorization status is updated to untrusted. Second factor verification: The trusted platform module of the trusted security center performs remote device security verification on the operation station node. If the verification is successful, the device authorization status is updated to authorized, and the trusted security audit report is updated based on the trusted verification result; otherwise, the device authorization status is updated to untrusted; The operation station node is used to receive the verification result and make a judgment. If the verification fails, the process ends; otherwise, the current configuration screen is securely unlocked. The secure unlocking of the current configuration screen specifically includes the following steps: S31: querying a screen database according to the screen name of the current configuration screen to obtain a node name of the locked current configuration screen; S32: If the node name of the locked current configuration screen obtained in S31 is consistent with the node name of the current operation station node, it means that the current configuration screen has been safely unlocked at the current operation station node, and the process ends; otherwise, a configuration screen unlocking application message is generated and sent to the node of the locked current configuration screen in S31, and S33 is executed; The configuration screen unlock application message includes the current operation station node name and the screen name of the current configuration screen; S33: The node that has locked the current configuration screen parses the configuration screen unlocking request message in S32 and pops up a screen unlocking inquiry window. If the node user that has locked the current configuration screen allows the screen to be unlocked, an unlocking permission response message is returned to the current operation station node; otherwise, an unlocking request rejection response message is returned to the current operation station node. S34: The current operation station node parses the response message. If it is a response message allowing unlocking, it means that the current operation station node has completed the secure unlocking of the current configuration screen, and queries the screen database according to the screen name of the current configuration screen, and updates the node name of the locked current configuration screen in the screen database described in S31 with the current operation station node name described in S32 as the current operation station node. The process ends. Otherwise, it prompts that the screen unlocking fails and the process ends.
4. The trusted industrial control system configuration screen security unlocking system according to claim 3, characterized in that: The trusted security audit report is used to store the trusted verification results and detailed information of the unlocking operation. The trusted security center periodically initiates a trusted security check to the operation station node and dynamically updates the system trusted status based on the trusted security audit report. If the check result is untrustworthy, the trusted security audit report is updated and the authorization operation is stopped, and the process ends.
5. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method for securely unlocking the configuration screen of a trusted industrial control system as described in any one of claims 1 to 2 are implemented.
6. A computer storage medium storing a computer program, wherein: When the computer program is executed by a processor, the steps of the method for securely unlocking the configuration screen of a trusted industrial control system as claimed in any one of claims 1 to 2 are implemented.
Citation Information
Patent Citations
Remote checking method of operation circuit
CN101752909A
Credible DCS upper computer data configuration verification and release method and system
CN117195240A