Heartbeat uploading method, system and equipment for trusted thermal power DCS (Distributed Control System) controller

By using the heartbeat upload method in the DCS control system, the connection status between the trusted agent and the DCS controller is monitored in real time, which solves the problem of difficulty in discovering trusted problems in time in the existing system, and improves the reliability and stability of the system.

CN119937486AActive Publication Date: 2025-05-06XIAN THERMAL POWER RES INST CO LTD +1
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510077586.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-06
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

When monitoring and managing thermal power plants, it is difficult to detect the connection status between the trusted agent and the DCS controller in real time, resulting in the failure to detect potential trustworthy problems in a timely manner, affecting the reliability and stability of the system.

Method used

The heartbeat up-sending method is adopted, and the heartbeat message is sent to the DCS controller regularly through the trusted agent and a trusted related service status is attached. The DCS controller sends this information to the trusted management center to monitor and manage the connection and trusted status of the system in real time.

Benefits of technology

Real-time detection of the connection status of the trusted agent and the DCS controller is realized, potential trustworthy problems are discovered in a timely manner, and the reliability and stability of the system are improved. At the same time, the data transmission channel of the original DCS controller is effectively utilized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119937486A_ABST
    Figure CN119937486A_ABST
Patent Text Reader

Abstract

A heartbeat uploading method, system and device for a trusted thermal power DCS controller, and the method comprises the steps: a trusted agent sends a heartbeat message to the DCS controller regularly to indicate that the trusted agent is in a normal working state; the trusted agent obtains a trusted related service state and attaches the obtained trusted related service state to a heartbeat message; the DCS controller returns heartbeat message confirmation to the trusted agent; and the DCS controller sends the heartbeat message added with the credible related service state to the credible management center, and the credible management center carries out centralized management and control on the DCS controller. And if the trusted management center does not receive the heartbeat message added with the trusted related service state within the preset time, judging that the trusted service of the DCS controller fails or is abnormal, and performing corresponding processing. According to the invention, the connection state between the trusted agent and the DCS controller can be detected in real time, and potential trusted problems can be found in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of DCS controllers, and in particular relates to a heartbeat uploading method, system and equipment for a reliable thermal power DCS controller. Background Art

[0002] In the thermal power industry, the Distributed Control System (DCS) plays a vital role. It is widely used in the control of boilers, steam turbines, generators and other auxiliary equipment, greatly promoting the automation level of thermal power units. Through highly integrated software and hardware design, the DCS system realizes comprehensive monitoring, control and optimization of the production process of thermal power plants, significantly improving the safety, reliability and economy of the units.

[0003] The DCS system distributes the control functions to various control stations, and each control station is responsible for the control tasks of a part of the equipment, thus achieving risk dispersion. At the same time, the various control stations are connected through a high-speed communication network to realize centralized processing and display of information, which is convenient for operators to carry out unified management and monitoring. At the same time, the DCS system adopts redundant configuration, including controller redundancy, power supply redundancy, communication redundancy, etc., to ensure seamless switching in the event of a local failure in the system, and to ensure the continuous and stable operation of the system. In addition, the system also has self-diagnosis and fault alarm functions, which can detect and deal with potential problems in a timely manner. Since the DCS system adopts a modular design, it can be flexibly configured and expanded according to the actual needs of the thermal power plant. With the expansion of the scale of the thermal power plant or the update and upgrade of equipment, it is easy to add control stations or upgrade software to meet new control needs.

[0004] In the thermal power industry, the DCS system collects various parameters of the boiler (such as temperature, pressure, flow, etc.) to accurately control the combustion process of the boiler to ensure the safe and stable operation of the boiler. At the same time, by optimizing the combustion strategy, the thermal efficiency of the boiler is improved and pollutant emissions are reduced. The DCS system monitors and controls key parameters such as the speed, load, and temperature of the steam turbine in real time to ensure that the steam turbine operates under the best working conditions. In addition, the system also has safety protection functions such as overspeed protection and vibration monitoring to ensure the safe operation of the steam turbine. The DCS system achieves precise control of the generator output power by adjusting parameters such as the excitation current and voltage of the generator. At the same time, the system also has functions such as grid connection control and decoupling control to ensure the safe and stable connection between the generator and the power grid. The DCS system is also responsible for controlling auxiliary equipment such as feed water pumps, circulating water pumps, and fans in thermal power plants to ensure that these equipment can operate according to the predetermined process flow and control strategy, providing a stable operating environment and conditions for thermal power units. When the DCS system is working, the trusted management center needs to fully and real-time understand the connection status of all unit controllers, so as to more accurately provide security services to the managed unit controllers and display trusted security policies and status. Summary of the invention

[0005] The purpose of the present invention is to provide a heartbeat uploading method, system and device for a trusted thermal power DCS controller to address the problems in the above-mentioned prior art, detect the connection status between the trusted agent and the DCS controller in real time, discover potential trusted problems in time, and improve the reliability and stability of the system.

[0006] In order to achieve the above object, the present invention has the following technical solutions: In a first aspect, a heartbeat sending method for a trusted thermal power DCS controller is provided, comprising: The trusted agent periodically sends heartbeat messages to the DCS controller to indicate that the trusted agent is in normal working state; The trusted agent obtains the trusted related service status and attaches the obtained trusted related service status to the heartbeat message; The DCS controller returns a heartbeat message confirmation to the trusted agent; The DCS controller sends a heartbeat message with the status of the trusted related services to the trusted management center, and the trusted management center centrally controls the DCS controller; The trust-related service status includes a statically trusted overall trust state, and the steps of obtaining the statically trusted overall trust state include: Check whether static trusted applications are enabled; If it is not enabled, the overall trust status of static trust is determined to be untrustworthy; If static trusted applications are enabled, check whether static trusted policies are configured for key files that need to be protected; If the static trust policy is not configured, the overall trust status of the static trust policy is determined to be untrustworthy; If a static trusted policy is configured, a hash algorithm is used to calculate the first hash value of each key file in each heartbeat cycle, and the first hash value and the second hash value of each of the key files are compared. When the first hash value and the second hash value of at least one of the key files are different, the overall trusted state of the static trusted system is determined to be untrustworthy; when the first hash value and the second hash value of each of the key files are the same, the overall trusted state of the static trusted system is determined to be trusted; wherein the second hash value of the key file is a hash value calculated by using the hash algorithm for the key file using a trusted computing module TPM during the process of configuring a static trusted policy for the key file.

[0007] As a preferred solution, the trust-related service status also includes a dynamic and trusted overall trust status, and the step of obtaining the dynamic and trusted overall trust status includes: Check whether dynamic trusted applications are enabled; If it is not enabled, the overall trusted state of the dynamic trusted system is determined to be untrusted; If dynamic trusted applications are enabled, check whether the application files to be protected are configured with dynamic trusted policies; If the dynamic trust policy is not configured, the overall trust status of the dynamic trust is determined to be untrustworthy; If a dynamic trusted policy is configured, then in the life cycle of each process of the dynamic trusted application, according to the pre-configured measurement period, the trusted computing module TPM is used to adopt the hash algorithm to calculate the third hash value of the memory code segment of the process of the dynamic trusted application, and the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application are compared. When the third hash value and the fourth hash value of the memory code segment of at least one process are different, the process is determined to be untrustworthy, and the dynamic trusted overall trusted state is determined to be untrustworthy. When the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application are the same, the dynamic trusted overall trusted state is determined to be trusted; wherein the fourth hash value of the memory code segment of the process is the hash value of the memory code segment of the process calculated by the trusted computing module TPM and the hash algorithm during the process of starting the state trusted application configured with the dynamic trusted policy.

[0008] As a preferred solution, the trusted-related service status also includes the static trusted security service running status, the dynamic trusted security service running status, the unknown program immune security service running status, the process trusted security service running status, the application's access control security running status and the number of dynamically trusted untrusted processes.

[0009] As a preferred solution, the trusted agent periodically polls to obtain various trusted-related service states.

[0010] As a preferred solution, the trusted agent attaches the acquired trusted related service status to the heartbeat message to form a heartbeat packet and then sends it to the DCS controller.

[0011] As a preferred solution, the DCS controller sends the heartbeat packet to the trusted management center through an existing communication channel.

[0012] As a preferred solution, the trusted agent appends the acquired trusted-related service status to the heartbeat message at a set time interval.

[0013] As a preferred solution, if the trusted management center does not receive a heartbeat message with a trusted related service status attached within a preset time, it determines that the trusted service of the DCS controller fails or is abnormal, and performs corresponding processing.

[0014] In a second aspect, a heartbeat uploading system for a trusted thermal power DCS controller is provided, including: A heartbeat message sending module is used for the trusted agent to periodically send heartbeat messages to the DCS controller to indicate that the trusted agent is in a normal working state; A trusted related service status appending module is used for the trusted agent to obtain the trusted related service status and append the obtained trusted related service status to the heartbeat message; Heartbeat message confirmation module, used for the DCS controller to return the heartbeat message confirmation to the trusted agent; A DCS controller message sending module is used for the DCS controller to send a heartbeat message with a trusted related service status to a trusted management center, and the trusted management center performs centralized control over the DCS controller; The trust-related service status includes a statically trusted overall trust state, and the trust-related service status additional module includes: A first detection module, used to detect whether a static trusted application is enabled; A first determination module, configured to determine, if not enabled, that the overall trust state of static trust is untrustworthy; The second detection module is used to detect whether the key files to be protected are configured with a static trusted policy if the static trusted application is enabled; A second determination module is used to determine that the overall trust state of static trust is untrustworthy if the static trust policy is not configured; The third determination module is used to, if a static trusted policy is configured, use a hash algorithm to calculate the respective first hash value for each key file in each heartbeat cycle, compare the first hash value and the second hash value of each of the key files, and determine that the overall trusted state of the static trusted system is untrustworthy when the first hash value and the second hash value of at least one of the key files are different, and determine that the overall trusted state of the static trusted system is trusted when the first hash value and the second hash value of each of the key files are the same; wherein the second hash value of the key file is a hash value calculated by using the hash algorithm for the key file using a trusted computing module TPM in the process of configuring a static trusted policy for the key file.

[0015] According to a third aspect, an electronic device is provided, including: a memory storing at least one instruction; and The processor executes the instructions stored in the memory to implement the heartbeat sending method for a trusted thermal power DCS controller as described in the first aspect.

[0016] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the heartbeat uploading method for a trusted thermal power DCS controller as described in the first aspect is implemented.

[0017] Compared with the prior art, the present invention has at least the following beneficial effects: The trusted agent periodically sends a heartbeat message to the DCS controller to indicate that the trusted agent is in a normal working state. At the same time, the trusted agent obtains the trusted related service status, and attaches the obtained trusted related service status to the heartbeat message and sends it to the DCS controller. The DCS controller then sends the heartbeat message attached with the trusted related service status to the trusted management center, thereby detecting the connection status between the trusted agent and the DCS controller in real time, timely discovering potential trusted problems, and improving the reliability and stability of the system. At the same time, the heartbeat message attached with the trusted related service status can also be used for auditing and logging, helping system administrators to better understand the operation of the system. Through the method of the present invention, the original DCS controller data transmission channel can be effectively utilized, and the domestic trusted management center can obtain the security and trusted status of the DCS controller in a timely manner while obtaining the connection status and operation status of each DCS controller, thereby improving the safety and controllability of the entire thermal power control system. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 A flowchart of a heartbeat uploading method for a trusted thermal power DCS controller according to an embodiment of the present invention; Figure 2 A schematic diagram of the principle of a heartbeat uploading method for a trusted thermal power DCS controller according to an embodiment of the present invention. DETAILED DESCRIPTION

[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, ordinary technicians in this field can also obtain other embodiments without making creative work.

[0021] See also Figure 1-2 In order for the trusted management center to fully and in real time understand the connection status of all unit DCS controllers, and to more accurately provide security services to the managed unit DCS controllers, and to display trusted security policies and status, the DCS controllers need to regularly report their own status. The embodiment of the present invention proposes a heartbeat transmission method for a trusted thermal power DCS controller, which mainly includes the following steps: S1. The trusted agent periodically sends heartbeat messages to the DCS controller to indicate that the trusted agent is in normal working state; S2. The trusted agent obtains the trusted related service status and attaches the obtained trusted related service status to the heartbeat message; S3, the DCS controller returns a heartbeat message confirmation to the trusted agent; S4. The DCS controller sends a heartbeat message with the trusted related service status attached to the trusted management center, and the trusted management center centrally controls the DCS controller; The trust-related service status includes a statically trusted overall trust state, and the steps of obtaining the statically trusted overall trust state include: Check whether static trusted applications are enabled; If it is not enabled, the overall trust status of static trust is determined to be untrustworthy; If static trusted applications are enabled, check whether static trusted policies are configured for key files that need to be protected; If the static trust policy is not configured, the overall trust status of the static trust policy is determined to be untrustworthy; If a static trusted policy is configured, a hash algorithm is used to calculate the first hash value of each key file in each heartbeat cycle, and the first hash value and the second hash value of each of the key files are compared. When the first hash value and the second hash value of at least one of the key files are different, the overall trusted state of the static trusted system is determined to be untrustworthy; when the first hash value and the second hash value of each of the key files are the same, the overall trusted state of the static trusted system is determined to be trusted; wherein the second hash value of the key file is a hash value calculated by using the hash algorithm for the key file using a trusted computing module TPM during the process of configuring a static trusted policy for the key file.

[0022] A trusted agent is a subject that all entities trust in information system security. It is usually responsible for generating or distributing keys, arbitrating disputes, etc. In a zero-trust architecture, a trusted agent is a key component of the data plane, responsible for intercepting access requests and performing authentication and dynamic authorization. The trusted agent is the policy execution point for dynamic access control capabilities, and works with the dynamic access control engine to authenticate and dynamically authorize all access requests.

[0023] Trusted proxies can easily adapt to application scenarios where certain resources have a large amount of IP address information and the IP addresses are not fixed, providing trusted access for untrusted external network users and a trusted security barrier for internal network resources. Trusted proxies play an important role in information system security and zero-trust architecture, and are key components to ensure secure business access and data security.

[0024] In a possible implementation manner, the trust-related service status also includes a dynamically trusted overall trust status, and the step of obtaining the dynamically trusted overall trust status includes: Check whether dynamic trusted applications are enabled; If it is not enabled, the overall trusted state of the dynamic trusted system is determined to be untrusted; If dynamic trusted applications are enabled, check whether the application files to be protected are configured with dynamic trusted policies; If the dynamic trust policy is not configured, the overall trust status of the dynamic trust is determined to be untrustworthy; If a dynamic trusted policy is configured, then in the life cycle of each process of the dynamic trusted application, according to the pre-configured measurement period, the trusted computing module TPM is used to adopt the hash algorithm to calculate the third hash value of the memory code segment of the process of the dynamic trusted application, and the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application are compared. When the third hash value and the fourth hash value of the memory code segment of at least one process are different, the process is determined to be untrustworthy, and the dynamic trusted overall trusted state is determined to be untrustworthy. When the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application are the same, the dynamic trusted overall trusted state is determined to be trusted; wherein the fourth hash value of the memory code segment of the process is the hash value of the memory code segment of the process calculated by the trusted computing module TPM and the hash algorithm during the process of starting the state trusted application configured with the dynamic trusted policy.

[0025] In a possible implementation manner, the trust-related service status further includes: The running status of statically trusted security services, the running status of dynamically trusted security services, the running status of unknown program immunity security services, the running status of process trusted security services, the running status of application access control security services, and the number of dynamically trusted untrusted processes.

[0026] Furthermore, the static trusted security service running state usually refers to ensuring that the system is in a secure and trusted initial state through a series of predefined, tamper-proof security mechanisms when or before the system starts. This includes starting the trusted code from the trusted module and gradually verifying the integrity of the system loading code, the operating system kernel, other parts of the operating system, and upper-level applications. If all links pass the verification, the system enters a static trusted state. In this state, the system and services are running based on preset security policies and mechanisms.

[0027] The dynamic and trusted security service operation status is to continuously monitor the integrity and security of the system and services through real-time and dynamic security mechanisms after the system is started. This includes but is not limited to checking the legitimacy of running programs, verifying the integrity of newly installed or newly running programs, and monitoring the use of system resources. The dynamic trusted mechanism can adapt to the dynamic changes in the system operation status and promptly detect and respond to potential security threats.

[0028] The unknown program immune security service running state means that the system has the ability to identify and intercept unknown programs to prevent the invasion of malware. This is usually achieved through various means such as blacklists, whitelists, and behavioral analysis. When the unknown program immune security service is running, the system can identify unverified or risky programs and prevent them from executing or accessing sensitive resources.

[0029] The trusted process security service operation state emphasizes the verification and management of the trustworthiness of each process in the system. This includes checking the source, integrity, and whether the behavior of the process is in line with expectations. In the trusted process security service operation state, the system can ensure that only trusted processes can access sensitive resources or perform key operations, thereby improving the overall security of the system.

[0030] The access control security operation state of an application refers to the system's strict management and control of application access rights. This includes access control policies based on user identity, role, permissions, and other factors, as well as access auditing and monitoring of sensitive resources and operations. When the access control security operation state of an application is in place, the system can ensure that the application's access behavior complies with security policies and prevent security issues such as unauthorized access and data leakage.

[0031] The statically trusted overall trust state is a comprehensive and integrated trust state achieved when or before the system is started. It covers the static trustworthiness of each component of the system (including hardware, software, services, etc.) and is the basis for the subsequent safe and stable operation of the system. In the statically trusted overall trust state, the various components of the system verify and rely on each other through the trust chain mechanism, forming a safe and trustworthy whole.

[0032] The overall trust state of dynamic trust is a comprehensive trust state that the system maintains continuously during operation. It relies on the real-time monitoring and adjustment of the system state by the dynamic trust mechanism to ensure that the system can maintain a safe and trustworthy operation state in the face of various dynamic changes. The overall trust state of dynamic trust not only focuses on the current security state of the system, but also focuses on the system's response and recovery capabilities to potential security threats.

[0033] The number of dynamically trusted untrusted processes refers to the number of processes that are identified as untrusted or have security risks when the system's dynamically trusted security services are running. This number changes dynamically and depends on the results of the system's real-time monitoring and detection. When the system finds an untrusted process, it will take corresponding security measures (such as isolation, deletion, etc.) to eliminate the threat and update the statistics of the number of untrusted processes. However, since there is currently no direct access to real-time system data, it is impossible to give a specific number of untrusted processes. In actual applications, this information is usually provided by the system's security monitoring and auditing tools.

[0034] The above states are important components of system security services, and together they form the cornerstone of system security and reliability. In practical applications, it is necessary to reasonably configure and optimize these security service states according to specific security requirements and system environment.

[0035] In a possible implementation, the trusted agent periodically polls to obtain various trusted-related service states.

[0036] In a possible implementation, the trusted agent attaches the acquired trusted-related service status to a heartbeat message to form a heartbeat packet and then sends it to the DCS controller.

[0037] Furthermore, the DCS controller sends the heartbeat packet to the trusted management center through the existing communication channel.

[0038] Trusted Management Center (TMC) plays a vital role in the field of information security. It is usually a comprehensive management platform responsible for managing and maintaining the trustworthiness, security and stability of the entire system. The basic idea of ​​the Trusted Management Center is to create a secure trust root, and start from this trust root, measure one level at a time, and trust one level at a time, so as to build a complete trust chain from hardware to operating system and then to application system. This trust chain ensures that every link of the system from startup to operation is in a trusted state. The main functions of the Trusted Management Center include trusted node management, application management, policy management and audit management. The specific contents of each function are as follows: Trusted node management refers to managing the status of all trusted verification nodes in the system to ensure that they operate in accordance with the established security policies. Application management refers to providing full-process management such as signing, publishing, updating, issuing and verifying application software, reducing the difficulty of system operation and maintenance and improving the ease of use of the platform. Policy management refers to the formulation and implementation of security policies, including access control, data encryption, behavior auditing, etc., to ensure the consistency and effectiveness of system security policies. Audit management refers to receiving and processing audit log information from each node to provide data support for the investigation and analysis of security incidents.

[0039] In a trusted network architecture, the trusted management center usually exists as a core component, responsible for the trustworthiness management and security policy execution of the entire network. It works closely with other network devices (such as trusted switches, trusted servers, etc.) to jointly build a secure and trusted network environment. Specific functions include: (1) Authentication and authorization: Authentication and authorization of devices accessing the network to ensure that only legitimate devices can access network resources. (2) Security policy execution: According to the preset security policies, the network traffic, data, behavior, etc. are monitored and managed to prevent the spread of security threats. (3) Log audit and response: Collect and analyze security event logs in the network to promptly discover and respond to potential security threats.

[0040] The technical implementation of a trusted management center usually involves multiple aspects, including: hardware security module (HSM), trusted computing platform (TCP), security policy engine, etc. These technical components work together to ensure that the trusted management center can operate efficiently and reliably. However, in actual applications, the trusted management center also faces some challenges, including: as the scale of the system expands and the functions increase, the complexity and operation and maintenance difficulty of the trusted management center will also increase accordingly. The increasing diversity and complexity of network security threats have put forward higher requirements on the security protection capabilities of the trusted management center. In addition, there may be compatibility and interoperability issues between trusted management centers of different manufacturers, affecting the overall performance and security of the system.

[0041] In summary, the trusted management center is an important part of the information security field. It ensures that every link of the system from startup to operation is in a trusted state by building a trust chain, executing security policies, managing audit logs, and other means.

[0042] In a possible implementation, the trusted agent appends the acquired trusted-related service status to the heartbeat message at a set time interval. The time interval set in the embodiment of the present invention is 5 seconds.

[0043] In step S3, after the DCS controller receives the heartbeat message with the trusted related service status sent by the trusted agent, it returns the heartbeat message ACK (Acknowledgment) to the trusted agent. ACK stands for "confirmation" or "response". The ACK signal or message is used to confirm the successful reception or processing of data. In various communication protocols, such as TCP / IP (Transmission Control Protocol / Internet Protocol), the ACK mechanism is a key part to ensure reliable data transmission.

[0044] In the TCP protocol, ACK is used to confirm the reception of a TCP segment or packet. When a TCP segment is successfully received and error-checked, the receiver will send an ACK to the sender to inform it of the sequence number of the last successfully received TCP segment. This mechanism ensures reliable data transmission because the sender will wait for the arrival of the ACK to confirm that the data has been correctly received by the receiver. If the ACK is not received, the sender may resend the data.

[0045] The main function of ACK is to confirm the successful reception of data. This helps the sender know when it can continue to send new data, or whether it needs to resend unconfirmed data. At the same time, through ACK, the receiver can tell the sender the size of its receive buffer, thereby controlling the sender's sending rate and avoiding network congestion. In addition, if the sender does not receive the expected ACK, it may think that the data is lost or damaged during transmission and take corresponding recovery measures, such as resending the data.

[0046] In TCP, ACK is sent automatically without explicit request from upper layer applications. Whenever TCP receives a TCP segment and the segment passes all error checks (such as checksum verification), the receiver sends an ACK with the acknowledgment number set to the sequence number in the received TCP segment plus 1.

[0047] To improve network efficiency, TCP implementations often use a delayed ACK mechanism. This means that the receiver will not immediately send an ACK for each received TCP segment, but will wait for a short period of time (usually 200 milliseconds) to see if more TCP segments arrive. If so, it can merge these ACKs into one, thereby reducing the number of ACKs on the network. However, if no more TCP segments arrive during this time, or if data that requires an immediate response (such as a FIN packet) is received, the receiver will send a delayed ACK.

[0048] ACK is an important mechanism in computer communications and network protocols to ensure reliable data transmission. By confirming the successful receipt of data, ACK helps maintain synchronization between the sender and receiver and promotes efficient and reliable data transmission.

[0049] Furthermore, if the trusted management center does not receive a heartbeat message with the trusted related service status attached within a preset time, it determines that the trusted service of the DCS controller fails or is abnormal, and performs corresponding processing.

[0050] Through the method of the present invention, the connection status between the trusted agent and the DCS controller can be detected in real time, potential trusted problems can be discovered in time, the reliability and stability of the system can be improved, and the data transmission channel of the original DCS controller can be effectively utilized. At the same time, the domestic trusted management center can obtain the security and trusted status of the DCS controller in time while obtaining the connection status and operation status of each DCS controller, thereby improving the safety and controllability of the entire thermal power control system. At the same time, the heartbeat message with the trusted status can also be used for auditing and logging, helping system administrators to better understand the operation of the system.

[0051] Another embodiment of the present invention further provides a heartbeat transmission system for a trusted thermal power DCS controller, comprising: A heartbeat message sending module is used for the trusted agent to periodically send heartbeat messages to the DCS controller to indicate that the trusted agent is in a normal working state; A trusted related service status appending module is used for the trusted agent to obtain the trusted related service status and append the obtained trusted related service status to the heartbeat message; Heartbeat message confirmation module, used for the DCS controller to return the heartbeat message confirmation to the trusted agent; A DCS controller message sending module is used for the DCS controller to send a heartbeat message with a trusted related service status to a trusted management center, and the trusted management center performs centralized control over the DCS controller; The trust-related service status includes a statically trusted overall trust state, and the trust-related service status additional module includes: A first detection module, used to detect whether a static trusted application is enabled; A first determination module, configured to determine, if not enabled, that the overall trust state of static trust is untrustworthy; The second detection module is used to detect whether the key files to be protected are configured with a static trusted policy if the static trusted application is enabled; A second determination module is used to determine that the overall trust state of static trust is untrustworthy if the static trust policy is not configured; The third determination module is used to, if a static trusted policy is configured, use a hash algorithm to calculate the respective first hash value for each key file in each heartbeat cycle, compare the first hash value and the second hash value of each of the key files, and determine that the overall trusted state of the static trusted system is untrustworthy when the first hash value and the second hash value of at least one of the key files are different, and determine that the overall trusted state of the static trusted system is trusted when the first hash value and the second hash value of each of the key files are the same; wherein the second hash value of the key file is a hash value calculated by using the hash algorithm for the key file using a trusted computing module TPM in the process of configuring a static trusted policy for the key file.

[0052] In a possible implementation manner, the trust-related service status further includes a dynamically trusted overall trust status, and the trust-related service status additional module further includes: A third detection module is used to detect whether the dynamic trusted application is enabled; A fourth determination module, for determining that the dynamic trusted overall trusted state is untrusted if it is not enabled; A fourth detection module, for detecting whether a dynamic trusted application is configured with a dynamic trusted policy for an application file to be protected if a dynamic trusted application is enabled; A fifth determination module, configured to determine that the dynamic trusted overall trusted state is untrusted if the dynamic trusted policy is not configured; The sixth determination module is used for, if a dynamic trusted policy is configured, then in the life cycle of the process of each dynamic trusted application, according to a pre-configured measurement period, using the trusted computing module TPM, adopting the hash algorithm, calculating the third hash value of the memory code segment of the process of the dynamic trusted application, comparing the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application, and when the third hash value of the memory code segment of at least one process is different from the fourth hash value, determining that the process is untrustworthy, and determining that the dynamic trusted overall trusted state is untrustworthy, and when the third hash value of the memory code segment of each process of the dynamic trusted application is the same as the fourth hash value, determining that the dynamic trusted overall trusted state is trusted; wherein the fourth hash value of the memory code segment of the process is the hash value of the memory code segment of the process calculated using the trusted computing module TPM and the hash algorithm during the process of starting the state trusted application configured with a dynamic trusted policy.

[0053] Another embodiment of the present invention further provides an electronic device, comprising: a memory storing at least one instruction; and a processor executing the instruction stored in the memory to implement the heartbeat uploading method for a trusted thermal power DCS controller described in an embodiment of the present invention.

[0054] Another embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the heartbeat uploading method for a trusted thermal power DCS controller described in an embodiment of the present invention is implemented.

[0055] Exemplarily, the instructions stored in the memory may be divided into one or more modules / units, which are stored in a computer-readable storage medium and executed by the processor to complete the heartbeat uploading method for a trusted thermal power DCS controller according to an embodiment of the present invention. The one or more modules / units may be a series of computer-readable instruction segments capable of completing specific functions, which are used to describe the execution process of the computer program in the server.

[0056] The electronic device may be a computing device such as a smart phone, a notebook, a PDA, and a cloud server. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art will appreciate that the electronic device may also include more or fewer components, or a combination of certain components, or different components, for example, the electronic device may also include an input / output device, a network access device, a bus, etc.

[0057] The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0058] The memory may be an internal storage unit of the server, such as a hard disk or memory of the server. The memory may also be an external storage device of the server, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the server. Furthermore, the memory may include both an internal storage unit of the server and an external storage device. The memory is used to store the computer-readable instructions and other programs and data required by the server. The memory may also be used to temporarily store data that has been output or is to be output.

[0059] It should be noted that the information interaction, execution process and other contents between the above-mentioned module units are based on the same concept as the method embodiment. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0060] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0061] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal and software distribution medium. For example, a USB flash drive, a mobile hard disk, a disk or an optical disk.

[0062] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0063] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A heartbeat uploading method for a trusted thermal power distributed control system DCS controller, characterized in that: include: The trusted agent periodically sends heartbeat messages to the DCS controller to indicate that the trusted agent is in normal working state; The trusted agent obtains the trusted related service status and attaches the obtained trusted related service status to the heartbeat message; The DCS controller returns a heartbeat message confirmation to the trusted agent; The DCS controller sends a heartbeat message with the status of the trusted related services to the trusted management center, and the trusted management center centrally controls the DCS controller; The trust-related service status includes a statically trusted overall trust state, and the steps of obtaining the statically trusted overall trust state include: Check whether static trusted applications are enabled; If it is not enabled, the overall trust status of static trust is determined to be untrustworthy; If static trusted applications are enabled, check whether static trusted policies are configured for key files that need to be protected; If the static trust policy is not configured, the overall trust status of the static trust policy is determined to be untrustworthy; If a static trusted policy is configured, a hash algorithm is used to calculate the first hash value of each key file in each heartbeat cycle, and the first hash value and the second hash value of each of the key files are compared. When the first hash value and the second hash value of at least one of the key files are different, the overall trusted state of the static trusted system is determined to be untrustworthy; when the first hash value and the second hash value of each of the key files are the same, the overall trusted state of the static trusted system is determined to be trusted; wherein the second hash value of the key file is a hash value calculated by using the hash algorithm for the key file using a trusted computing module TPM during the process of configuring a static trusted policy for the key file.

2. According to claim 1, the heartbeat sending method for a trusted thermal power DCS controller is characterized in that: in, The trust-related service status also includes a dynamic trustworthy overall trustworthy status. The step of obtaining the dynamic trustworthy overall trustworthy status includes: Check whether dynamic trusted applications are enabled; If it is not enabled, the overall trusted state of the dynamic trusted system is determined to be untrusted; If dynamic trusted applications are enabled, check whether the application files to be protected are configured with dynamic trusted policies; If the dynamic trust policy is not configured, the overall trust status of the dynamic trust is determined to be untrustworthy; If a dynamic trusted policy is configured, then in the life cycle of each process of the dynamic trusted application, according to the pre-configured measurement period, the trusted computing module TPM is used to adopt the hash algorithm to calculate the third hash value of the memory code segment of the process of the dynamic trusted application, and the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application are compared. When the third hash value and the fourth hash value of the memory code segment of at least one process are different, the process is determined to be untrustworthy, and the dynamic trusted overall trusted state is determined to be untrustworthy. When the third hash value and the fourth hash value of the memory code segment of each process of the dynamic trusted application are the same, the dynamic trusted overall trusted state is determined to be trusted; wherein the fourth hash value of the memory code segment of the process is the hash value of the memory code segment of the process calculated by the trusted computing module TPM and the hash algorithm during the process of starting the state trusted application configured with the dynamic trusted policy.

3. The heartbeat sending method for a trusted thermal power DCS controller according to claim 1 is characterized in that: The trusted-related service status also includes the static trusted security service running status, the dynamic trusted security service running status, the unknown program immune security service running status, the process trusted security service running status, the application's access control security running status and the number of dynamically trusted untrusted processes.

4. The heartbeat sending method for a trusted thermal power DCS controller according to claim 3 is characterized in that: The trusted agent periodically polls to obtain various trusted related service states.

5. The heartbeat sending method for a trusted thermal power DCS controller according to claim 4 is characterized in that: The trusted agent attaches the acquired trusted related service status to the heartbeat message to form a heartbeat packet and then sends it to the DCS controller.

6. The heartbeat sending method for a trusted thermal power DCS controller according to claim 5 is characterized in that: The DCS controller sends the heartbeat packet to the trusted management center through the existing communication channel.

7. The heartbeat sending method for a trusted thermal power DCS controller according to claim 1 is characterized in that: The trusted agent appends the acquired trusted related service status to the heartbeat message at a set time interval.

8. The heartbeat sending method for a trusted thermal power DCS controller according to claim 1 is characterized in that: If the trusted management center does not receive the heartbeat message with the trusted related service status attached within a preset time, it determines that the trusted service of the DCS controller fails or is abnormal, and performs corresponding processing.

9. A heartbeat transmission system for a trusted thermal power DCS controller, characterized in that: include: A heartbeat message sending module is used for the trusted agent to periodically send heartbeat messages to the DCS controller to indicate that the trusted agent is in a normal working state; A trusted related service status appending module is used for the trusted agent to obtain the trusted related service status and append the obtained trusted related service status to the heartbeat message; Heartbeat message confirmation module, used for the DCS controller to return the heartbeat message confirmation to the trusted agent; A DCS controller message sending module is used for the DCS controller to send a heartbeat message with a trusted related service status to a trusted management center, and the trusted management center performs centralized control over the DCS controller; The trust-related service status includes a statically trusted overall trust state, and the trust-related service status additional module includes: A first detection module, used to detect whether a static trusted application is enabled; A first determination module, configured to determine, if not enabled, that the overall trust state of static trust is untrustworthy; The second detection module is used to detect whether the key files to be protected are configured with a static trusted policy if the static trusted application is enabled; A second determination module is used to determine that the overall trust state of static trust is untrustworthy if the static trust policy is not configured; The third determination module is used to, if a static trusted policy is configured, use a hash algorithm to calculate the respective first hash value for each key file in each heartbeat cycle, compare the first hash value and the second hash value of each of the key files, and determine that the overall trusted state of the static trusted system is untrustworthy when the first hash value and the second hash value of at least one of the key files are different, and determine that the overall trusted state of the static trusted system is trusted when the first hash value and the second hash value of each of the key files are the same; wherein the second hash value of the key file is a hash value calculated by using the hash algorithm for the key file using a trusted computing module TPM in the process of configuring a static trusted policy for the key file.

10. An electronic device, characterized in that: include: A memory storing at least one instruction; and The processor executes the instructions stored in the memory to implement the heartbeat sending method for a trusted thermal power DCS controller as described in any one of claims 1 to 8.

11. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the heartbeat uploading method for a trusted thermal power DCS controller is implemented as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Self-diagnostic method and device for communication of nuclear safety level DCS system

    CN109274553A

  • Time sequence database synchronization method, system and device and storage medium

    CN113434604A

  • Security protection method of DCS software server and computer equipment

    CN116405272A

  • DCS (Distributed Control System) controller and real-time synchronization method and system for trusted strategy and trusted state of DCS controller

    CN116880414A

  • DCS (Distributed Control System) controller credibility enhancement method, system, equipment and medium

    CN117075558A