A trusted function installation method and related device for a trusted DCS system

CN119396421BActive Publication Date: 2025-09-09XIAN THERMAL POWER RES INST CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411446755.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-16
Publication Date
2025-09-09
Estimated Expiration
2044-10-16

AI Technical Summary

Technical Problem

[0005]本发明的目的在于提供一种可信DCS系统可信功能安装方法与相关装置,以解决现有技术中DCS系统可信功能安装部署速度慢,安装效果不理想的技术问题

Benefits of technology

[0031] The present invention discloses a method for installing trusted functions of a trusted DCS system and related devices. First, the client and the host computer are connected via SSH. Then, the client sends an automatic installation instruction to the host computer. The host computer automatically installs the trusted function components and feeds back the execution result of the installation instruction to the client. The client generates a trusted function installation and deployment report based on the execution result of the installation instruction to complete the installation. The present invention proposes a one-click installation method for the trusted function of the host computer of a trusted DCS system based on Python. The method uses Python to develop an executable program under the Linux system and encapsulates a Python script. By executing the program or script, the terminal establishes an SSH connection with the trusted host computer to automatically install the trusted function components. The present invention can effectively improve the installation and deployment speed and installation and deployment quality. If there are problems with the installation and configuration files, they can be discovered earlier. At the same time, the trusted function can also be tested, which can significantly reduce the installation and deployment cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119396421B_ABST
    Figure CN119396421B_ABST
Patent Text Reader

Abstract

The present invention discloses a trusted function installation method and related devices for a trusted DCS system, belonging to the technical field of DCS systems. The method first connects a client and a host computer via SSH. The client then sends an automatic installation instruction to the host computer, which then automatically installs the trusted function component and feeds back the results of the installation instruction execution to the client. The client then generates a trusted function installation and deployment report based on the installation instruction execution results, completing the installation. The present invention can effectively improve installation and deployment speed and quality, allowing earlier detection of installation and configuration file problems. It can also verify trusted functions, significantly reducing installation and deployment costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of DCS systems, and relates to a trusted function installation method of a trusted DCS system and related devices. Background Art

[0002] In today's highly information-based and digitalized world, the security and trustworthiness of industrial control systems (ICs) have become crucial elements for ensuring stable production operations and preventing external attacks and internal errors. Distributed control systems (DCSs) are core infrastructure in industrial automation, and their host computers, the central interface for human-machine interaction, not only carry out crucial functions such as data monitoring and command issuance but also directly impact the overall system's trustworthiness and security. Therefore, developing and integrating a comprehensive suite of host computer trust enhancements is crucial for improving the overall protection of DCS systems. Trust enhancements for the host computer of a trusted DCS system integrate a series of advanced security technologies and components to build a comprehensive, multi-layered trust protection system from the underlying layer to the application layer. This system not only strengthens the system's anti-tampering and anti-spoofing capabilities but also provides an intuitive and easy-to-use visual management interface, enabling system administrators to monitor the system's security status in real time and quickly respond to potential threats.

[0003] The trusted DCS system's host computer trust enhancement function integrates a trusted client, a trusted agent, a trusted enhancement module, and a trusted management platform, providing the host computer with enhanced trust and a visual trusted function management interface. The trusted client serves as the first line of defense for user access to the system. It ensures that only authorized users can access the system through identity authentication and behavior auditing. It also supports encrypted communication protocols to ensure secure data transmission between users and the host computer. Using integrated intelligent analysis algorithms, the trusted client automatically identifies and blocks abnormal login attempts, effectively defending against brute force attacks. The trusted agent, deployed between the host computer and field control devices, is responsible for data filtering, verification, and forwarding. It utilizes advanced encryption technology and data integrity verification mechanisms to ensure data is not tampered with or stolen during transmission. Furthermore, the trusted agent monitors device operating status, promptly identifying and reporting abnormal behavior, providing an additional layer of security. The trusted enhancement module is the core of the host computer trust enhancement function. It integrates multiple security hardening technologies, such as code signature verification, memory protection, and process isolation, to prevent malware, viruses, and unauthorized programs from invading the host computer system. Furthermore, the Trusted Enhancement Module supports dynamic security policy adjustments, automatically adjusting security policies based on system operating status and threat intelligence, enabling flexible responses to various security challenges. The Trusted Management Platform component serves as the centralized management hub for the entire Trusted Enhancement feature. The Trusted Management Platform provides a rich set of visualization tools and management interfaces. System administrators can use this platform to monitor the security status of the host computer in real time, view security logs, configure security policies, and more. The platform also supports remote management and automated operations and maintenance, significantly reducing the complexity and cost of system maintenance. Furthermore, it boasts powerful report generation capabilities, automatically generating security audit reports to support system security assessments and compliance checks.

[0004] The existing trusted host computer uses the Kylin operating system on the ARM platform. When deploying trusted components in this system, the programs and files of each component need to be manually copied and deployed. The deployment speed is slow and many files need to be copied. If the host computers are installed in batches, the project time will be extended and the cost will exceed the plan. Summary of the Invention

[0005] The purpose of the present invention is to provide a trusted function installation method and related devices for a trusted DCS system, so as to solve the technical problems in the prior art of slow installation and deployment of trusted functions of DCS systems and unsatisfactory installation effects.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] In a first aspect, the present invention provides a method for installing a trusted function of a trusted DCS system, comprising the following steps:

[0008] Connect the client and the trusted DCS system host computer via SSH;

[0009] After the connection is successful, the client sends an automatic installation instruction to the host computer to install the trusted function;

[0010] The client receives the installation instruction execution results fed back by the host computer, and generates a trusted function installation deployment report based on the installation instruction execution results to complete the DCS system trusted function installation.

[0011] Furthermore, after the connection is successful, the client sends an automatic installation instruction to the host computer to install the trusted function, which specifically includes: detecting the connection status between the client and the host computer, if the connection status is failed, reconnecting; if the connection status is successful, sending an automatic installation instruction to the host computer to install the trusted function.

[0012] Furthermore, the specific content of the automatic installation instruction is:

[0013] Collect host computer system environment information;

[0014] Configure the conf file according to the system environment information;

[0015] According to the conf file, put the functional files into the specified directory in the order of component dependencies, start the local service in the order of component dependencies, and initialize the local trust policy;

[0016] Verify the local trusted function services and trusted policies of the host computer, and produce the results of the installation instruction execution.

[0017] Furthermore, the order of component dependency is: trusted management platform component>trusted enhancement module component>trusted proxy component>trusted client component.

[0018] Furthermore, the functional files include executable files, dynamic library files, kernel files and configuration files.

[0019] Furthermore, the client receives the installation instruction execution result fed back by the host computer, and generates a trusted function installation deployment report according to the installation instruction execution result, completing the steps of the DCS system trusted function installation, which specifically include:

[0020] Determine whether the installation is successful based on the results of the installation command execution, and record the success or failure log;

[0021] Storing the success or failure logs in the database;

[0022] After the entire trusted function is installed, an installation and deployment report is output based on the logs in the database.

[0023] Furthermore, the output format of the installation and deployment report is HTML format.

[0024] In a second aspect, the present invention provides a trusted function installation system for a trusted DCS system, comprising:

[0025] Connection module, used to connect the client and the trusted DCS system host computer through SSH;

[0026] The installation module is used to send automatic installation instructions to the host computer after successful connection to install trusted functions;

[0027] The feedback module is used to receive the installation instruction execution results fed back by the host computer, and generate a trusted function installation deployment report based on the installation instruction execution results to complete the DCS system trusted function installation.

[0028] In a third aspect, the present invention provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.

[0029] In a fourth aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0030] Compared with the prior art, the present invention has the following beneficial effects:

[0031] The present invention discloses a method for installing trusted functions of a trusted DCS system and related devices. First, the client and the host computer are connected via SSH. Then, the client sends an automatic installation instruction to the host computer. The host computer automatically installs the trusted function components and feeds back the execution result of the installation instruction to the client. The client generates a trusted function installation and deployment report based on the execution result of the installation instruction to complete the installation. The present invention proposes a one-click installation method for the trusted function of the host computer of a trusted DCS system based on Python. The method uses Python to develop an executable program under the Linux system and encapsulates a Python script. By executing the program or script, the terminal establishes an SSH connection with the trusted host computer to automatically install the trusted function components. The present invention can effectively improve the installation and deployment speed and installation and deployment quality. If there are problems with the installation and configuration files, they can be discovered earlier. At the same time, the trusted function can also be tested, which can significantly reduce the installation and deployment cost. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0033] Figure 1 is a flow chart of the method of the present invention;

[0034] Figure 2 is a schematic diagram of the system of the present invention;

[0035] Figure 3 This is a diagram of the overall process framework of the method according to the embodiment of the present invention;

[0036] Figure 4 It is a schematic diagram of the computer device structure of the present invention. DETAILED DESCRIPTION

[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0038] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0039] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0040] In the description of the embodiments of the present invention, it should be noted that if the terms "upper," "lower," "horizontal," "inner," etc. appear, the orientation or positional relationship indicated is based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship in which the inventive product is typically placed when in use. These terms are merely for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on the present invention. In addition, the terms "first," "second," etc. are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0041] In addition, if the term "horizontal" appears, it does not mean that the component must be absolutely horizontal, but can be slightly tilted. For example, "horizontal" only means that its direction is more horizontal than "vertical", and does not mean that the structure must be completely horizontal, but can be slightly tilted.

[0042] In the description of the embodiments of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to internal connections between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0043] The present invention is described in further detail below with reference to the accompanying drawings:

[0044] See also Figure 1 The embodiment of the present invention discloses a method for installing a trusted function of a trusted DCS system, which is characterized by comprising the following steps:

[0045] S1, connect the client and the trusted DCS system host computer through SSH;

[0046] S2, after the connection is successful, the client sends an automatic installation command to the host computer to install the trusted function;

[0047] Detect the connection status between the client and the host computer. If the connection status is failed, reconnect; if the connection status is successful, send an automatic installation instruction to the host computer to install the trusted function.

[0048] The specific contents of the automatic installation instructions are:

[0049] 1) Collect host computer system environment information;

[0050] 2) Configure the conf file according to the system environment information;

[0051] 3) According to the conf file, place all functional files (executable files, dynamic library files, kernel files, and configuration files) in the specified directory in the order of component dependencies, start local services in the order of component dependencies, and initialize the local trusted policy;

[0052] 4) Verify the local trusted function services and trusted policies of the host computer, and produce the execution results of the installation instructions.

[0053] The order of component dependency is: trusted management platform component > trusted enhancement module component > trusted agent component > trusted client component.

[0054] S3, the client receives the installation instruction execution result fed back by the host computer, and generates a trusted function installation deployment report based on the installation instruction execution result, completing the DCS system trusted function installation.

[0055] S301, determining whether the installation is successful based on the result of executing the installation instruction, and recording a success log or a failure log;

[0056] S302, storing the determination success log or the determination failure log in a database;

[0057] S303: After the entire trusted function is installed, an installation deployment report is output based on the log in the database.

[0058] See also Figure 2 The embodiment of the present invention discloses a trusted function installation system for a trusted DCS system, comprising a connection module, an installation module, and a feedback module. The connection module is used to connect a client to a trusted DCS system host computer via SSH; the installation module can detect the connection status between the client and the host computer, and if the connection status is failed, reconnect; if the connection status is successful, an automatic installation instruction is sent to the host computer to install the trusted function. The feedback module can determine whether the installation is successful based on the execution result of the installation instruction, and record a success log or a failure log; store the success log or the failure log in a database; and output an installation deployment report based on the log in the database after the entire trusted function installation is completed.

[0059] Example:

[0060] See also Figure 3 This embodiment discloses a method for installing a trusted function of a trusted DCS system, comprising the following steps:

[0061] 1) Execute the Python one-click installation script or program in the terminal and connect to the host computer of the domestically produced trusted DCS system via SSH.

[0062] 2) Reconnect when connection fails, and send automatic installation execution instructions to the host computer after connection is successful.

[0063] 3) The automatic installation instructions include:

[0064] a. Collect system environment information such as local IP, kernel version, etc.

[0065] b. Automatically configure the conf file based on system environment information (network card IP address).

[0066] c. Place executable files, dynamic library files, kernel files, configuration files, and other functional files into the designated directory in the order of component dependencies (trusted management platform -> trusted enhancement module -> trusted agent -> trusted client), start local services in the order of component dependencies, and initialize the local trusted policy.

[0067] d. Verify the local trusted function services and trusted policies of the host computer in step c.

[0068] It's important to note that executable files, dynamic library files, kernel files, and configuration files play different roles in computer systems, collectively supporting the normal operation of the system and the diverse needs of users. An executable file is a file that can be directly loaded and executed by the operating system. This type of file contains an encoded sequence of instructions that, when triggered (such as a user double-clicking a file icon), the system can directly execute these instructions. A dynamic link library (DLL) is a library file that is dynamically loaded into memory by the system when a program is running. It contains code and data that can be shared by multiple programs. The kernel file is the core of the operating system, responsible for low-level tasks such as managing system resources, scheduling processes, and handling interrupts. In Linux systems, kernel files are typically named vmlinuz (compressed version) or vmlinux (uncompressed version). A configuration file is a computer file used to store program or system parameters and initial settings. It allows users or administrators to customize program or system configurations based on their specific needs.

[0069] 4) The terminal database receives the execution results of each instruction returned by the host computer and saves the results in the database.

[0070] 5) After the entire automated one-click installation is completed, an installation and deployment report in HTML format is output.

[0071] In one embodiment of the present invention, a computer device is provided. Figure 4The computer device includes a processor and a memory, wherein the memory is used to store a computer program, wherein the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the trusted function installation method of the trusted DCS system.

[0072] The present invention also provides a storage medium, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in a computer device, used to store programs and data. It is understood that the computer-readable storage medium herein can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides storage space, which stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for being loaded and executed by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium herein can be a high-speed RAM memory or a non-volatile memory, such as at least one disk storage device. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the trusted function installation method for a trusted DCS system in the above-mentioned embodiment.

[0073] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0074] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0075] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0076] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for installing a trusted function of a trusted DCS system, characterized in that: The following steps are involved: Connect the client and the trusted DCS system host computer via SSH; After the connection is successful, the client sends an automatic installation instruction to the host computer to install the trusted function; The client receives the installation instruction execution results fed back by the host computer, and generates a trusted function installation deployment report based on the installation instruction execution results, completing the DCS system trusted function installation; The specific content of the automatic installation instruction is: Collect host computer system environment information; Configure the conf file according to the system environment information; According to the conf file, put the function files into the specified directory in the order of trusted function component dependencies, start the local service in the order of trusted function component dependencies, and initialize the local trusted policy; The functional files include executable files, dynamic library files, kernel files and configuration files; Verify the local trusted function services and trusted policies of the host computer, and produce the results of the installation instruction execution.

2. A trusted function installation method for a trusted DCS system according to claim 1, characterized in that: After the connection is successful, the client sends an automatic installation instruction to the host computer to install the trusted function, which specifically includes: detecting the connection status between the client and the host computer, if the connection status is failed, reconnecting; if the connection status is successful, sending an automatic installation instruction to the host computer to install the trusted function.

3. The method for installing a trusted function of a trusted DCS system according to claim 1, characterized in that: The dependency order of the trusted functional components is: trusted management platform component > trusted enhancement module component > trusted agent component > trusted client component.

4. The method for installing a trusted function of a trusted DCS system according to claim 1, characterized in that: The client receives the installation instruction execution result fed back by the host computer, and generates a trusted function installation deployment report according to the installation instruction execution result, completing the steps of the DCS system trusted function installation, specifically including: Determine whether the installation is successful based on the results of the installation command execution, and record the success or failure log; Storing the success or failure logs in the database; After the entire trusted function is installed, an installation and deployment report is output based on the logs in the database.

5. A trusted function installation method for a trusted DCS system according to claim 4, characterized in that: The output format of the installation and deployment report is HTML format.

6. A trusted function installation system for a trusted DCS system, characterized in that: A method for installing a trusted function of a trusted DCS system according to any one of claims 1 to 5, comprising: Connection module, used to connect the client and the trusted DCS system host computer through SSH; The installation module is used to send automatic installation instructions to the host computer after successful connection to install trusted functions; The feedback module is used to receive the installation instruction execution results fed back by the host computer, and generate a trusted function installation deployment report based on the installation instruction execution results to complete the DCS system trusted function installation.

7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Construction method and construction system of publishing system of embedded system

    CN116501340A

  • Deployment method, system and device of trusted DCS upper computer system and storage medium

    CN117055501A