A network security transmission method for accessing a power information intranet and related equipment
By establishing control security channels and data security channels within the power information intranet and using pre-shared keys for data encryption, the problem of poor network transmission security for IoT terminals accessing the power information intranet is solved, achieving secure data transmission and efficient system protection.
Patent Information
- Application Number
- CN202510111245.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2045-01-23
AI Technical Summary
In existing technologies, the network transmission security of IoT terminals accessing the power information intranet is poor, posing risks of data leakage and tampering, which affects the stable operation of the power system.
By establishing a secure control channel to exchange parameters and perform authentication with the security agent module, and using a pre-shared key to establish a secure data channel, encrypted data transmission is ensured, including negotiation of encryption protocols, key management, and authentication protocols.
It achieves secure protection of data within the power information intranet, reduces the risk of spoofing attacks, ensures the legality and integrity of data transmission, and improves the security and flexibility of the system.
Smart Images

Figure CN119892478B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security transmission method and related equipment for accessing the power information intranet. Background Technology
[0002] With the rapid development and continuous expansion of IoT technology, IoT terminals have become an indispensable part of modern power systems. They are widely distributed in all aspects of power generation, transmission, transformation, distribution, and consumption, enabling real-time monitoring, data acquisition, and remote control of the power system's operating status. The data interaction between these IoT terminals and the power information intranet not only greatly improves the intelligence level of the power system but also promotes the optimal allocation and efficient utilization of power resources.
[0003] However, with the increasing frequency of data interaction, the complexity and uncertainty of the network environment are also increasing. Security threats in cyberspace are becoming increasingly severe, including but not limited to malicious attacks by hackers, illegal theft and alteration of data, and the spread and proliferation of viruses. These security threats may not only lead to the leakage or destruction of important data within the power information intranet, but may also seriously affect the stable operation of the power system, and even trigger large-scale power outages and other serious consequences, posing a huge threat to national security, social stability, and people's lives.
[0004] Therefore, ensuring secure and efficient data transmission for IoT terminals during their access to the power information intranet has become a critical issue that the power industry urgently needs to address. Summary of the Invention
[0005] In order to overcome the defects of the prior art, the purpose of this invention is to provide a network security transmission method and related equipment for accessing the power information intranet, so as to solve the technical problem of poor network transmission security in the prior art.
[0006] This invention is achieved through the following technical solution:
[0007] In a first aspect, the present invention provides a secure transmission method for accessing a power information intranet, comprising:
[0008] Receive an access request sent by the security proxy module, and establish a control security channel for interaction with the security proxy module based on the access request;
[0009] Within the control security channel, parameters are exchanged with the security agent module, and the exchanged parameters are authenticated to obtain the authentication result;
[0010] Based on the authentication result, a pre-shared key for data encryption is exchanged with the security agent module, and a secure data channel is established according to the pre-shared key for data encryption.
[0011] The data security channel processes the received SSL data packets and transmits them securely through the data security channel.
[0012] Preferably, the system receives an access request from the security proxy module and establishes a control security channel for interaction with the security proxy module based on the access request. The establishment process is as follows:
[0013] Receive access requests sent by the security proxy module, wherein the request includes the identity information of the security proxy module, the type of service requested for access, and security requirements;
[0014] Verify the received request and obtain the verification result;
[0015] Based on the verification results, establish the protocol used for interaction with the security agent module, and establish a control security channel based on the protocol used, including encryption protocol, key management protocol and authentication protocol.
[0016] Preferably, parameters are exchanged with the security agent module within the control security channel, and the exchanged parameters are authenticated to obtain an authentication result. The authentication process is as follows:
[0017] Exchange initialization parameters and business parameters with the security proxy module;
[0018] The initialization parameters and business parameters are subjected to integrity verification and identity authentication.
[0019] If both integrity verification and identity authentication pass, the authentication is successful and communication services can proceed; otherwise, the authentication fails and communication is terminated.
[0020] Furthermore, in integrity verification, the integrity of the parameters is determined by calculating the hash value of the parameters or the message authentication code; in identity authentication, identity is determined by digital signature and certificate verification methods.
[0021] Preferably, a pre-shared key for data encryption is exchanged with the security agent module based on the authentication result, wherein the pre-shared key is the same key confirmed by the security agent module.
[0022] Preferably, the data security channel processes the received SSL data packets as follows:
[0023] The data security channel first receives SSL encrypted data packets transmitted from external networks or data sources;
[0024] Verify the integrity of SSL packets and authenticate identity;
[0025] SSL packets are decrypted using the AES algorithm via the key in the SSL / TLS protocol;
[0026] The decrypted data is parsed to extract specific application layer data. The parsing process includes data format identification and field extraction.
[0027] The extracted data is processed, including data format conversion and data content cleaning.
[0028] Preferably, the processed SSL data is transmitted securely through a data security channel using a one-way isolation method.
[0029] Secondly, the present invention provides a network security transmission system for accessing the power information intranet, including...
[0030] The control security channel establishment module is used to receive access requests sent by the security proxy module and establish a control security channel for interaction with the security proxy module based on the access requests.
[0031] The authentication module is used to exchange parameters with the security agent module within the control security channel, and to authenticate the exchanged parameters to obtain the authentication result.
[0032] The pre-shared key data security channel establishment module is used to exchange a pre-shared key for data encryption with the security agent module based on the authentication result, and to establish a data security channel according to the pre-shared key for data encryption.
[0033] The data transmission module is used to process the received SSL data packets through the data security channel and transmit them securely through the data security channel.
[0034] Thirdly, the present invention also provides a mobile terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the network security transmission method for accessing the power information intranet as described above.
[0035] Fourthly, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the network security transmission method for accessing the power information intranet as described above.
[0036] Compared with the prior art, the present invention has the following beneficial technical effects:
[0037] This invention provides a secure data transmission method for accessing a power information intranet. By establishing a secure data channel and using a pre-shared key for data encryption, it ensures that data during transmission is not stolen or spied on by unauthorized third parties, effectively protecting the security of sensitive data within the power information intranet. Exchanging parameters and performing rigorous authentication with the security agent module within the control security channel not only verifies the identities of both parties but also ensures the legitimacy and credibility of subsequent communications, reducing the risk of impersonation attacks. By establishing control and data security channels in stages, hierarchical protection of the communication process is achieved. The control security channel is used for negotiating and authenticating security parameters, while the data security channel focuses on the transmission of encrypted data. This layered design improves the overall system's security and flexibility.
[0038] Furthermore, this invention supports the reception and processing of SSL data packets and their transmission through a secure data channel. This means that even in complex and ever-changing network environments, data security and integrity can be guaranteed, meeting the high-security communication requirements of the power information intranet.
[0039] Furthermore, this invention reduces the complexity of system management and maintenance through standardized secure channel establishment and data encryption processes. Simultaneously, the use of mechanisms such as pre-shared keys facilitates key updates and management when necessary, ensuring the long-term secure and stable operation of the system. Attached Figure Description
[0040] Figure 1 This is a flowchart of a network security transmission method for accessing the power information intranet in an embodiment of the present invention;
[0041] Figure 2 This is a structural diagram of a network security transmission system for accessing the power information intranet in an embodiment of the present invention;
[0042] In the diagram: 1-Secure channel establishment module; 2-Authentication module; 3-Pre-shared key data secure channel establishment module; 4-Data transmission module. Detailed Implementation
[0043] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0044] The present invention will now be described in further detail with reference to the accompanying drawings:
[0045] The purpose of this invention is to provide a secure transmission method and related equipment for accessing the power information intranet, so as to solve the technical problem of poor network transmission security in the prior art.
[0046] See Figure 1 In one embodiment of the present invention, a method for secure transmission of information over a power information intranet is provided, comprising:
[0047] Step 1: Receive the access request sent by the security proxy module, and establish a control security channel for interaction with the security proxy module based on the access request;
[0048] Specifically, the system receives access requests from the security proxy module and establishes a control security channel for interaction with the security proxy module based on the access requests. The establishment process is as follows:
[0049] Receive access requests sent by the security proxy module, wherein the request includes the identity information of the security proxy module, the type of service requested for access, and security requirements;
[0050] Verify the received request and obtain the verification result;
[0051] Based on the verification results, establish the protocol used for interaction with the security agent module, and establish a control security channel based on the protocol used, including encryption protocol, key management protocol and authentication protocol.
[0052] In this embodiment, the system receives an access request from the security proxy module. The request includes the identity information of the security proxy module, the type of service requested for access, and security requirements.
[0053] The system verifies the identity information in the received access request. This typically involves checking the validity of the certificate and the correctness of the digital signature to ensure the authenticity and reliability of the security proxy module's identity.
[0054] Based on the verification results and the security requirements in the access request, the system will select a suitable protocol to establish a secure control channel. These protocols include:
[0055] Encryption protocols: used to ensure the confidentiality of data transmitted in the channel, such as TLS / SSL protocols.
[0056] Key management protocol: used to negotiate and manage encryption keys, ensuring the security and validity of the keys.
[0057] Authentication protocol: Used to authenticate the identities of the two communicating parties, ensuring that the identities of both parties are true and reliable.
[0058] Finally, based on the selected protocol, the system and the security agent module begin establishing a secure control channel. This process typically includes steps such as key negotiation, authentication, and encrypted communication to ensure the security and reliability of the channel.
[0059] Step 2: Exchange parameters with the security agent module within the control security channel, and authenticate the exchanged parameters to obtain the authentication result;
[0060] Specifically, the authentication process is as follows:
[0061] Exchange initialization parameters and business parameters with the security proxy module;
[0062] The initialization parameters and business parameters are subjected to integrity verification and identity authentication.
[0063] If both integrity verification and identity authentication pass, the authentication is successful and communication services can proceed; otherwise, the authentication fails and communication is terminated.
[0064] Specifically, integrity verification determines the integrity of parameters by calculating their hash value or message authentication code; identity authentication determines identity through digital signatures and certificate verification.
[0065] Specifically, integrity verification of the exchanged initialization and service parameters is a crucial step to ensure that these parameters have not been tampered with during transmission. This is achieved by calculating the hash value of the parameter (such as MD5, SHA-256, etc.) and comparing it with the received hash value. If the hash values match, it indicates that the parameter has remained intact during transmission; otherwise, tampering may have occurred.
[0066] After integrity verification, both parties need to authenticate their identities. This typically involves using security mechanisms such as digital certificates and digital signatures to verify each other's identities. For example, a security proxy module might provide its digital certificate to the system, which then verifies the validity of the certificate (e.g., by checking the certificate chain, certificate revocation list, etc.) to confirm the security proxy module's identity. Alternatively, the system can request a digital signature from the security proxy module to verify its identity and further confirm its identity by verifying the signature's correctness.
[0067] Step 3: Based on the authentication result, exchange a pre-shared key for data encryption with the security agent module, and establish a secure data channel according to the pre-shared key for data encryption;
[0068] Specifically, after completing the parameter exchange and authentication process within the secure control channel, the system determines whether to continue communication with the security proxy module based on the authentication result. Only when the authentication result is successful will the subsequent pre-shared key exchange step proceed.
[0069] To securely exchange pre-shared keys, a key exchange protocol is used between the system and the security agent module. This protocol ensures that the keys are not eavesdropped on or tampered with during the exchange. Common key exchange protocols include the Diffie-Hellman (DH) protocol and RSA key exchange.
[0070] According to the key negotiation protocol, the system and the security agent module will jointly generate a pre-shared key, or one party will generate a key and distribute it to the other party in a secure manner. This pre-shared key will serve as the basis for subsequent data encryption.
[0071] During the establishment of the secure data channel, after obtaining the pre-shared key, the system and the security agent module negotiate and select a suitable encryption protocol to establish the secure data channel. This encryption protocol will be used to protect the confidentiality, integrity, and availability of the data transmitted through the channel. Once the secure data channel is successfully established, all communication between the system and the security agent module will be conducted through this channel, and all transmitted data will be encrypted and decrypted using the pre-shared key. In this way, even if data is intercepted during transmission, it cannot be decrypted and read by unauthorized third parties.
[0072] Step 4: The data security channel processes the received SSL data packets and transmits them securely through the data security channel.
[0073] Specifically, the data security channel processes the received SSL data packets as follows:
[0074] The data security channel first receives SSL encrypted data packets transmitted from external networks or data sources;
[0075] Verify the integrity of SSL packets and authenticate identity;
[0076] SSL packets are decrypted using the AES algorithm via the key in the SSL / TLS protocol;
[0077] The decrypted data is parsed to extract specific application layer data. The parsing process includes data format identification and field extraction.
[0078] The extracted data is processed, including data format conversion, data content cleaning, removal of invalid data, correction of erroneous data, and conversion of data format.
[0079] In the SSL packet integrity verification and authentication process, the data security channel performs integrity checks on received SSL packets. This is typically achieved by verifying the packet's hash value (such as MD5, SHA-256, etc.) to ensure the packet has not been tampered with during transmission. Simultaneously, the data security channel also performs authentication on the packets. This involves verifying the sender's identity, ensuring the packet was sent by a legitimate sender. In the SSL / TLS protocol, this is usually achieved by verifying digital certificates and signatures.
[0080] In the SSL / TLS protocol, after the SSL data packet passes verification using the AES algorithm, the secure data channel uses the pre-shared key negotiated in the SSL / TLS protocol to decrypt the SSL data packet. AES is a symmetric encryption algorithm used for encrypting and decrypting data. However, the SSL / TLS protocol actually combines both symmetric and asymmetric encryption technologies. During the handshake phase, both parties use asymmetric encryption (such as RSA) to negotiate a symmetric encryption key, which is then used for encryption and decryption during data transmission.
[0081] The decrypted data is an encrypted form of application-layer data. The data security channel needs to parse it to extract the specific application-layer data. The parsing process includes identifying the data format and extracting fields.
[0082] The extracted data undergoes processing, including data format conversion and data cleaning. Data format conversion involves transforming the extracted data to suit different application scenarios or system requirements. Data cleaning includes removing invalid data, correcting erroneous data, and converting data formats to ensure data accuracy and usability. These operations help improve the efficiency and quality of subsequent data processing and applications.
[0083] Specifically, in this embodiment, the processed SSL data is transmitted securely through a data security channel using a one-way isolation method.
[0084] In this embodiment, the unidirectional isolation method ensures that data can only flow in one direction, typically from a low-security-level area to a high-security-level area, effectively preventing potential network attacks and data leaks. In a secure data channel, this means that processed SSL data can only be transmitted unidirectionally from one secure area (such as an external network) to another area with a higher security level (such as an internal network).
[0085] One-way isolation can be achieved through physical means (such as one-way gateways) or logical means (such as software-implemented one-way data transmission protocols). Physical isolation typically involves using specialized hardware to ensure the one-way nature of the data flow; while logical isolation relies on software algorithms and protocols to simulate one-way data flow.
[0086] In summary, this invention provides a secure data transmission method for accessing the power information intranet. By establishing a secure data channel and using a pre-shared key for data encryption, it ensures that data during transmission is not stolen or spied on by unauthorized third parties, effectively protecting the security of sensitive data within the power information intranet. Exchanging parameters and performing rigorous authentication with the security agent module within the control security channel not only verifies the identities of both parties but also ensures the legitimacy and credibility of subsequent communications, reducing the risk of impersonation attacks. By establishing control and data security channels in stages, hierarchical protection of the communication process is achieved. The control security channel is used for negotiating and authenticating security parameters, while the data security channel focuses on the transmission of encrypted data. This layered design improves the overall system's security and flexibility.
[0087] Example 2
[0088] according to Figure 2 As shown, this embodiment provides a network security transmission system for accessing the power information intranet, including a control security channel establishment module 1, an authentication module 2, a pre-shared key data security channel establishment module 3, and a data transmission module 4;
[0089] The control security channel establishment module 1 is used to receive access requests sent by the security proxy module and establish a control security channel for interaction with the security proxy module according to the access requests;
[0090] The authentication module 2 is used to exchange parameters with the security agent module within the control security channel, and to authenticate the exchanged parameters to obtain the authentication result;
[0091] The pre-shared key data security channel establishment module 3 is used to exchange a pre-shared key for data encryption with the security agent module based on the authentication result, and to establish a data security channel according to the pre-shared key for data encryption.
[0092] The data transmission module 4 is used to process the received SSL data packets through the data security channel and transmit them securely through the data security channel.
[0093] Example 3
[0094] The present invention also provides a mobile terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, such as a network security transmission program for accessing the power information intranet.
[0095] When the processor executes the computer program, it implements the steps of the above-described method for secure transmission of data into the power information intranet, for example:
[0096] Receive an access request sent by the security proxy module, and establish a control security channel for interaction with the security proxy module based on the access request;
[0097] Within the control security channel, parameters are exchanged with the security agent module, and the exchanged parameters are authenticated to obtain the authentication result;
[0098] Based on the authentication result, a pre-shared key for data encryption is exchanged with the security agent module, and a secure data channel is established according to the pre-shared key for data encryption.
[0099] The data security channel processes the received SSL data packets and transmits them securely through the data security channel.
[0100] Alternatively, when the processor executes the computer program, it implements the functions of each module in the above system, for example:
[0101] The control security channel establishment module 1 is used to receive access requests sent by the security proxy module and establish a control security channel for interaction with the security proxy module according to the access requests;
[0102] The authentication module 2 is used to exchange parameters with the security agent module within the control security channel, and to authenticate the exchanged parameters to obtain the authentication result;
[0103] The pre-shared key data security channel establishment module 3 is used to exchange a pre-shared key for data encryption with the security agent module based on the authentication result, and to establish a data security channel according to the pre-shared key for data encryption.
[0104] The data transmission module 4 is used to process the received SSL data packets through the data security channel and transmit them securely through the data security channel.
[0105] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the mobile terminal.
[0106] For example, the computer program can be divided into a control secure channel establishment module 1, an authentication module 2, a pre-shared key data secure channel establishment module 3, and a data transmission module 4;
[0107] The specific functions of each module are as follows:
[0108] The control security channel establishment module 1 is used to receive access requests sent by the security proxy module and establish a control security channel for interaction with the security proxy module according to the access requests;
[0109] The authentication module 2 is used to exchange parameters with the security agent module within the control security channel, and to authenticate the exchanged parameters to obtain the authentication result;
[0110] The pre-shared key data security channel establishment module 3 is used to exchange a pre-shared key for data encryption with the security agent module based on the authentication result, and to establish a data security channel according to the pre-shared key for data encryption.
[0111] The data transmission module 4 is used to process the received SSL data packets through the data security channel and transmit them securely through the data security channel.
[0112] The mobile terminal can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. The mobile terminal may include, but is not limited to, a processor and memory.
[0113] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the mobile terminal, connecting various parts of the mobile terminal via various interfaces and lines.
[0114] The memory can be used to store the computer program and / or module. The processor implements various functions of the mobile terminal by running or executing the computer program and / or module stored in the memory and calling the data stored in the memory.
[0115] The memory may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function (such as sound playback, image playback, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). Furthermore, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disks, RAM, plug-in hard disks, SmartMediaCards (SMC), Secure Digital (SD) cards, FlashCards, at least one disk storage device, flash memory device, or other volatile solid-state storage devices.
[0116] Example 4
[0117] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the method for secure transmission of data into a power information intranet.
[0118] If the modules / units integrated in the mobile terminal are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0119] Based on this understanding, all or part of the processes in the above-described method can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of the above-described method for secure transmission of data into the power information intranet. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms.
[0120] The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0121] It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the content as required by the legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium may not include electrical carrier signals and telecommunication signals.
[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A method for secure transmission of data into a power information intranet, characterized in that: include: Receive an access request sent by the security proxy module, and establish a control security channel for interaction with the security proxy module based on the access request; Within the control security channel, parameters are exchanged with the security agent module, and the exchanged parameters are authenticated to obtain the authentication result; Within the control security channel, parameters are exchanged with the security agent module, and the exchanged parameters are authenticated to obtain the authentication result. The authentication process is as follows: Exchange initialization parameters and business parameters with the security proxy module; The initialization parameters and business parameters are subjected to integrity verification and identity authentication. If both integrity verification and identity authentication pass, the authentication is successful and communication services can proceed; otherwise, the authentication fails and communication is terminated. In integrity verification, the integrity of the parameters is determined by calculating the hash value of the parameters or the message authentication code; in identity authentication, identity is determined by digital signature and certificate verification methods. Based on the authentication result, a pre-shared key for data encryption is exchanged with the security agent module, and a secure data channel is established according to the pre-shared key for data encryption. The data security channel processes the received SSL data packets and transmits them securely through the data security channel.
2. The network security transmission method for accessing the power information intranet according to claim 1, characterized in that, The system receives an access request from the security proxy module and establishes a control security channel for interaction with the security proxy module based on the access request. The establishment process is as follows: Receive access requests sent by the security proxy module, wherein the request includes the identity information of the security proxy module, the type of service requested for access, and security requirements; Verify the received request and obtain the verification result; Based on the verification results, establish the protocol used for interaction with the security agent module, and establish a control security channel based on the protocol used, including encryption protocol, key management protocol and authentication protocol.
3. The network security transmission method for accessing the power information intranet according to claim 1, characterized in that, Based on the authentication result, a pre-shared key for data encryption is exchanged with the security agent module, wherein the pre-shared key is the same key confirmed by the security agent module.
4. A network security transmission method for accessing the power information intranet according to claim 1, characterized in that, The data security channel processes the received SSL data packets as follows: The data security channel first receives SSL data packets transmitted from external networks or data sources; Verify the integrity of SSL packets and authenticate identity; SSL packets are decrypted using the AES algorithm via the key in the SSL / TLS protocol; The decrypted data is parsed to extract specific application layer data. The parsing process includes data format identification and field extraction. The extracted data is processed, including data format conversion and data content cleaning.
5. A network security transmission method for accessing the power information intranet according to claim 1, characterized in that, The processed SSL data packets are transmitted securely through a data security channel using a one-way isolation method.
6. A network security transmission system for accessing the power information intranet, characterized in that, include The control security channel establishment module (1) is used to receive the access request sent by the security agent module and establish a control security channel for interaction with the security agent module according to the access request; The authentication module (2) is used to exchange parameters with the security agent module in the control security channel and to authenticate the exchanged parameters to obtain the authentication result; The pre-shared key data security channel establishment module (3) is used to exchange a pre-shared key for data encryption with the security agent module based on the authentication result, and to establish a data security channel according to the pre-shared key for data encryption. The data transmission module (4) is used to process the received SSL data packets through the data security channel and transmit them through the data security channel for network security.
7. A mobile terminal, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the network security transmission method for accessing the power information intranet as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the network security transmission method for accessing the power information intranet as described in any one of claims 1-5.
Citation Information
Patent Citations
Front safety system for guaranteeing information safety
CN102487378A
Energy interconnection power distribution network intelligent distribution transformer terminal safety access framework and application
CN111884995A