Power monitoring system safety protection method and device of zero-trust architecture and medium
By combining SDP, IAM and MSG technologies with zero trust architecture in the power monitoring system, a multi-level security protection architecture is built, which solves the problems of insufficient data privacy and security and insufficient emergency response capabilities in the existing technology, and achieves efficient security protection of the power system.
Patent Information
- Application Number
- CN202510062283.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-06
AI Technical Summary
The existing zero-trust architecture is not sufficient in power monitoring systems to ensure data privacy and lacks strong emergency response and disaster recovery capabilities to respond to potential security incidents.
By combining the power monitoring system with three major technologies: zero-trust network access (SDP), identity and access management (IAM), and micro-isolation (MSG), we build a multi-level security protection architecture, including a software-defined boundary (SDP) control engine and gateway security authentication module, an access management IAM dynamic intelligent authorization decision-making module, and a resource data division module based on micro-isolation MSG.
It realizes comprehensive safety protection, effectively improves the overall security of the power system, can deal with modern complex security challenges, and protects critical power infrastructure from various cyber threats and attacks.
Smart Images

Figure CN119945762A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power system monitoring, and in particular to a power monitoring system security protection method, equipment and medium with a zero-trust architecture. Background Art
[0002] As a key national infrastructure, the power system ensures the normal daily life and work of the people, and is directly related to the country's economic lifeline and energy security. With the continuous development and digital transformation of modern power systems, power monitoring systems play a vital role in ensuring the stable operation of power infrastructure. However, the widespread application of information technology has made power monitoring systems face increasingly complex and diverse network security threats. Traditional security measures can no longer meet the current needs of power grid information security. It is necessary to introduce a new security architecture to ensure that key power monitoring systems are not affected by various network threats and to ensure the security of the stable operation of power monitoring systems. To this end, a new network security model called "zero trust" has emerged.
[0003] As a modern network security model, the core concept of Zero Trust architecture is to no longer trust any entity inside or outside the network, emphasizing "never trust, always verify". Zero Trust Architecture (ZTA) combines three major technical components: Software Defined Perimeter (SDP), Unified Identity and Access Management (IAM) and Micro-Segmentation (MSG). It can not only meet the requirements of network security protection and protect the data security of enterprises and users, but also balance the relationship between network security and power dispatching, and realize the security protection and architectural innovation of power monitoring systems. However, the power monitoring system needs to process a large amount of sensitive data, and the existing Zero Trust architecture is not enough to ensure the privacy and security of this data, and it also lacks strong emergency response and disaster recovery capabilities for potential security incidents. Summary of the invention
[0004] The purpose of the present invention is to propose a zero-trust architecture power monitoring system security protection method, equipment and medium in view of the problem that the application of zero-trust architecture in power monitoring system is insufficient to ensure data privacy security and lacks emergency response capabilities for potential security incidents. This method combines the power monitoring system with three major technologies: zero-trust network access (SDP), identity and access management (IAM), and micro-isolation (MSG), to unify the planning and construction of the power monitoring system and realize a zero-trust closed loop that integrates security and enterprise. This multi-level security protection can not only effectively improve the overall security of the power system, but also more effectively respond to modern complex security challenges.
[0005] The present invention provides a zero-trust architecture power monitoring system security protection method, comprising the following steps:
[0006] S1. Build a zero-trust power monitoring system security protection architecture:
[0007] The security protection architecture includes: software-defined boundary SDP control engine and gateway security authentication module, access management IAM dynamic intelligent authorization decision module, and resource data partitioning module based on micro-isolation MSG;
[0008] S2. Build the software-defined boundary SDP control engine and gateway security authentication module:
[0009] Build a software-defined perimeter SDP control engine and gateway security authentication module through multi-layer security connections between user-end devices and distributed secure connection cloud services, public cloud servers, SDP gateways, and private clouds / internal networks;
[0010] S3: Build an access management IAM dynamic intelligent authorization decision module:
[0011] Build an access management IAM dynamic intelligent authorization decision module through multi-factor authentication MFA management of users;
[0012] S4: Build a resource data partitioning module based on micro-isolation MSG:
[0013] By dividing the power monitoring network into different areas, a resource data partitioning module based on micro-isolation MSG is constructed;
[0014] S5: Verify the zero-trust power monitoring system security protection architecture:
[0015] The effectiveness of the zero-trust power monitoring system security protection architecture is verified through SPA simulation experiments and power equipment fault identification experiments.
[0016] A storage medium stores instructions and data for implementing a zero-trust architecture power monitoring system security protection method.
[0017] A power monitoring system security protection device with a zero-trust architecture comprises: a processor and a storage medium; the processor loads and executes instructions and data in the storage medium to implement a power monitoring system security protection method with a zero-trust architecture.
[0018] The beneficial effects provided by the present invention are: realizing a comprehensive security protection method and providing multi-level security protection, including: zero-trust power monitoring system protection system construction; SDP power monitoring system security protection method; power monitoring system IAM method; power monitoring system agent MSG method; experimental verification stage. Based on the zero-trust power monitoring system security architecture, by combining the power monitoring system with the three major technologies of zero-trust SDP+IAM+MSG, a comprehensive security protection solution is formed and multi-level security protection is provided. This method effectively improves the overall security of the power system, can cope with modern complex security challenges, and protect critical power infrastructure from various network threats and attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic flow chart of the method of the present invention;
[0020] Figure 2 This is a schematic diagram of the construction process of the software-defined boundary SDP control engine and gateway security authentication module;
[0021] Figure 3 This is a schematic diagram of the construction process of the access management IAM dynamic intelligent authorization decision module;
[0022] Figure 4 This is a schematic diagram of the resource data partitioning module construction process based on micro-isolation MSG;
[0023] Figure 5 It is a schematic diagram of the overall architecture of the method of the present invention;
[0024] Figure 6 It is a working schematic diagram of the hardware device of the present invention. DETAILED DESCRIPTION
[0025] To make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be further described below with reference to the accompanying drawings.
[0026] Before formally describing the present invention, the scheme of the present invention is first generally described for easy understanding.
[0027] Please refer to Figure 1 , Figure 1 It is a schematic flow diagram of the method of the present invention.
[0028] The present invention provides a zero-trust architecture power monitoring system security protection method, comprising the following steps:
[0029] S1. Build a zero-trust power monitoring system security protection architecture;
[0030] The security protection architecture includes: software-defined boundary SDP control engine and gateway security authentication module, access management IAM dynamic intelligent authorization decision module, and resource data partitioning module based on micro-isolation MSG;
[0031] It should be noted that the zero-trust power monitoring system described in the present invention includes a series of hardware devices and security components. For better explanation, the present invention elaborates on the hardware devices and security components as follows:
[0032] Hardware devices include: unprivileged network managed devices and public network managed devices.
[0033] Specifically, unprivileged network managed devices refer to devices that are connected to unprivileged networks (such as corporate intranets) and managed; public network managed devices refer to devices that are connected and managed through public networks (such as the Internet). These devices need to undergo strict authentication and authorization to ensure that their access requests are legitimate.
[0034] Security components include: protocol and access agent, single sign-on, core components, power monitoring equipment database, certificate issuer, trust interface and user database. Specifically:
[0035] Protocol refers to the managed devices of unprivileged networks and public networks communicating with the system through specific network protocols;
[0036] Access proxy means that the access proxy is responsible for receiving and processing access requests from these devices and performing identity authentication and authorization.
[0037] Single sign-on (SSO) means that users only need to authenticate once to access multiple system resources, thereby simplifying the user experience and enhancing security.
[0038] Core components: Core components are the key parts of the zero trust architecture and include the following modules:
[0039] (1) Policy Decision Point (PDP): Responsible for determining whether to allow or deny an access request based on the decision of the policy engine.
[0040] (2) Policy engine: Evaluates access requests and generates access decisions based on user identity, device status, and other contextual information.
[0041] (3) Policy management: Define and manage security policies to ensure that the policies meet security requirements and business needs.
[0042] (4) Policy Enforcement Point (PEP): The decision point at which the policy is implemented to actually control access to resources.
[0043] Power monitoring equipment database: stores the information and status of all power monitoring equipment.
[0044] Certificate issuer: Responsible for generating and managing digital certificates for device and user authentication.
[0045] Trust interface: Provides trust assessment data for devices and users to ensure that only trusted devices and users can access the system.
[0046] User database: stores user identity information and permission information.
[0047] It should be noted that after the device is connected, the unprivileged network managed device and the public network managed device communicate with the system through the network protocol, and the device sends an access request to the access agent;
[0048] Secondly, in the authentication and authorization phase, the access agent receives the access request and authenticates the device through the RADIUS protocol or other authentication mechanisms. After the authentication is passed, the device or user enters the single sign-on (SSO) process and can access multiple resources after one authentication.
[0049] Secondly, in the policy evaluation and decision phase, the access request enters the core component, the policy engine evaluates the request based on the predefined policy and current context information, and the policy decision point decides whether to allow access based on the evaluation result of the policy engine;
[0050] Secondly, entering the access control stage, the policy execution point implements the decision of the policy decision point to control the access of equipment or users to resources. Approved access requests can access the information in the power monitoring equipment database to perform monitoring and control operations.
[0051] Finally, it enters the continuous monitoring and trust assessment phase. The system continuously monitors all access and operations through the trust interface to ensure compliance with the zero-trust security model. The certificate issuer manages the digital certificates of devices and users to ensure the security of identity authentication. The user database stores and manages user identity information and permission information.
[0052] S2. Build the software-defined boundary SDP control engine and gateway security authentication module:
[0053] Build a software-defined perimeter SDP control engine and gateway security authentication module through multi-layer security connections between user-end devices and distributed secure connection cloud services, public cloud servers, SDP gateways, and private clouds / internal networks;
[0054] Please refer to Figure 2 , Figure 2 It is a schematic diagram of the construction process of the software-defined boundary SDP control engine and gateway security authentication module.
[0055] It should be noted that before explaining the software-defined boundary SDP control engine and gateway security authentication module, a preliminary explanation of the relevant equipment and components involved is first given as follows.
[0056] The software-defined border SDP control engine and gateway security authentication module include the following devices and components:
[0057] User side: The user initiates an access request through the user side device and connects to the system;
[0058] Connecting to cloud services: This is an intermediate layer that is responsible for processing the access request from the user side and performing preliminary verification and forwarding. It ensures that the request from the user side can correctly reach the target server or gateway;
[0059] Public cloud server: Connecting to cloud services can forward user requests to public cloud servers to handle public cloud-related tasks and services;
[0060] SDP Gateway (Software-Defined Perimeter): This is a key component in the zero-trust architecture. The SDP Gateway is responsible for establishing a secure connection between the user end and the private cloud or internal network, ensuring that only authenticated users can access internal resources.
[0061] Connecting to private cloud / internal network: The SDP gateway forwards authenticated client requests to the private cloud or internal network to handle access to internal systems and services.
[0062] Therefore, in step S2, the working process of the software-defined boundary SDP control engine and the gateway security authentication module is as follows:
[0063] S21, the user terminal device initiates an access request through the network. The user terminal device initiates an access request through the network and connects to the cloud service;
[0064] S23: In the connection cloud service request processing phase, the connection cloud service receives the request from the user, performs preliminary verification and processing, and forwards the request to the public cloud server or SDP gateway according to the request type and target;
[0065] S24: Request forwarding to the public cloud server or SDP gateway stage. If the target of the request is a public cloud resource, the connected cloud service forwards the request to the public cloud server; if the request needs to access private cloud or internal network resources, the connected cloud service forwards the request to the SDP gateway.
[0066] S25: SDP gateway verification and connection phase: The SDP gateway receives the request from the cloud service for further verification. The SDP gateway strictly verifies the user's identity and the legitimacy of the request based on the zero-trust principle. After the verification is passed, the SDP gateway establishes a secure connection and forwards the request to the target resource in the private cloud or internal network.
[0067] S26: Access to private cloud / internal network stage, the request is verified by the SDP gateway, and the resources in the private cloud or internal network are securely accessed to perform the required tasks or operations.
[0068] As an example, the overall workflow of the software-defined boundary SDP control engine and the gateway security authentication module is as follows:
[0069] The user end (such as the front-end device in the power monitoring system) first establishes a connection with the distributed secure connection cloud service through the secure connection module. The distributed secure connection cloud service acts as an intermediate layer, responsible for verifying the identity of the user end device and ensuring that its connection is secure and reliable. Once the user end device passes the identity authentication of the distributed secure connection cloud service, it will establish a connection with the public cloud server. The public cloud server stores and processes a large amount of data required by the power monitoring system, such as historical power usage data, real-time monitoring data, and analysis reports; the user end device establishes a secure connection with the SDP (software defined perimeter) gateway through the public cloud server. After the SDP gateway successfully verifies the identity of the user end device, it connects the device to the private cloud or internal network. By connecting the cloud service and the SDP gateway to work together, strict verification and secure forwarding of user requests are achieved to ensure the security and reliability of the system.
[0070] S3: Build an access management IAM dynamic intelligent authorization decision module:
[0071] Build an access management IAM dynamic intelligent authorization decision module through multi-factor authentication MFA management of users;
[0072] Please refer to Figure 3 , Figure 3 This is a schematic diagram of the construction process of the access management IAM dynamic intelligent authorization decision module;
[0073] For better explanation, the present invention explains the devices and components involved in the access management IAM dynamic intelligent authorization decision module in advance as follows:
[0074] Business Administrator: responsible for managing business-related operations and decisions;
[0075] Organization and personnel: including the management of current and former users;
[0076] Application administrator: responsible for managing application-related policies and permissions;
[0077] Working users: users who are still working and have the authority to access the system;
[0078] Resigned users: The access rights of users who have resigned need to be revoked;
[0079] Multi-factor authentication (MFA): Perform multi-factor authentication on users to improve system security;
[0080] Revocation of access rights: timely revoke access rights for users who have left the company or no longer need access;
[0081] Power Monitoring System: Core system used to monitor and control power facilities.
[0082] Application policy management: Manage application security policies, including password management, authentication management, and permission management.
[0083] The working process of the access management IAM dynamic intelligent authorization decision module in step S3 is as follows:
[0084] S31. Business administrators and application administrators are responsible for management at different levels. The organization and personnel modules manage basic user information and distinguish between active and resigned users.
[0085] S32, user authentication stage, in-service users authenticate their identities through multi-factor authentication (MFA);
[0086] It should be noted that multi-factor authentication ensures the authenticity of the user's identity and is verified through multiple methods such as passwords, fingerprints, and dynamic verification codes.
[0087] S33, application policy management stage, application administrators use the application policy management module to configure the system security, including password management, authentication management and authority management, to ensure system security and reasonable allocation of user rights;
[0088] S34, access and authority management stage, after being authenticated, the in-service users can access the power monitoring system; for the resigned users, the access rights are immediately revoked to ensure that they can no longer access system resources;
[0089] S35: During the power monitoring system access phase, authenticated and authorized users access the power monitoring system to perform routine monitoring and management operations.
[0090] Finally, the power monitoring system ensures that only authenticated and authorized users have access, maintaining the security and stability of the system.
[0091] As an example, the overall workflow of the access management IAM dynamic intelligent authorization decision module includes:
[0092] First, the user submits a registration application, which is approved by the business administrator and configured by the application administrator before undergoing multi-factor authentication to verify the identity. The system monitors the daily operations of in-service users in real time, adjusts permissions, and promptly handles abnormal behaviors. Upon receiving a notice of resignation, the application administrator immediately revokes the access rights of the resigned user and archives their data. Through password policies, multi-factor authentication, and permission management, passwords, authentication, and permission policies are regularly updated and reviewed to ensure system security and business continuity. The power monitoring system based on a zero-trust architecture ensures the security and reliability of the system through mechanisms such as business administrators, application administrators, organization and personnel management, as well as multi-factor authentication and access rights revocation. Through a strict authentication and authorization process, it is ensured that only verified users can access the power monitoring system, effectively preventing unauthorized access and potential security threats.
[0093] S4: Build a resource data partitioning module based on micro-isolation MSG:
[0094] By dividing the power monitoring network into different areas, a resource data partitioning module based on micro-isolation MSG is constructed;
[0095] Please refer to Figure 4 , Figure 4 This is a schematic diagram of the resource data partitioning module construction process based on micro-isolation MSG:
[0096] In order to better explain the present invention, the present invention describes the related devices and components involved in the resource data partitioning module based on micro-isolation MSG as follows:
[0097] Policy Engine: The policy engine is responsible for developing and enforcing security policies, managing network traffic and access control rules. It determines which communications are allowed and which are denied based on preset policies;
[0098] Policy Manager: The Policy Manager is the management and configuration interface of the Policy Engine. Administrators use the Policy Manager to define, modify, and deploy security policies and monitor the execution of policies.
[0099] User: Users include operators, maintenance personnel and managers of the power system. After being authenticated and authorized, they can access the power monitoring system and related data resources.
[0100] Power Monitoring System: The power monitoring system is the core component responsible for monitoring and controlling the operating status and parameters of power equipment. It interacts with users and data resources.
[0101] Proxy: The proxy is a key component of micro-segmentation and is located between the power monitoring system and data resources. The proxy controls and filters network traffic by applying the rules of the policy engine to ensure that only authenticated and authorized communications can pass.
[0102] Gateway: The gateway acts as a security barrier for internal and external communications at the boundary of the data platform. It applies the rules of the policy engine to verify and filter external and internal access requests.
[0103] Power data resources: Power data resources include real-time data, historical records, and analytical data of various power equipment. These data resources communicate securely with power monitoring systems and users through agents and gateways.
[0104] It should be noted that the working process of the resource data partitioning module based on micro-isolation MSG in step S4 is as follows:
[0105] S41, policy management and execution phase, administrators define and configure security policies through the policy manager; these policies are passed to the policy engine, which manages network traffic and access control in the data platform according to the configured policy rules;
[0106] S42, user access stage, the user authenticates himself through multi-factor authentication to ensure that only verified legitimate users can enter the system. After passing the authentication, the user sends an access request to the power monitoring system through the gateway;
[0107] S43, access control stage, the gateway performs preliminary verification of the user's access request to ensure compliance with the security rules of the policy engine, and the agent further verifies and controls network traffic to ensure that all communications comply with security policies and prevent unauthorized access;
[0108] S44, data interaction stage, after double verification by the gateway and the agent, legitimate access requests are allowed to enter the power monitoring system and power data resources; data is securely transmitted between the user, the power monitoring system and the power data resources to ensure that the data is not stolen or tampered with during the transmission process;
[0109] S45, real-time monitoring stage, the control platform monitors the operation of the data platform in real time, including network traffic, user behavior and system status; abnormal behavior is discovered in a timely manner through the security monitoring system, and once abnormal behavior is detected, it responds and processes according to the preset security policy.
[0110] As an example, the overall workflow of the resource data partitioning module based on micro-isolation MSG is as follows: The administrator defines and configures security policies through the policy manager. These policies are passed to the policy engine, which manages network traffic and access control in the data platform according to the configured policy rules. After the user is authenticated, he requests access to the power monitoring system through the gateway. The gateway and the agent verify and filter the user's access request according to the rules of the policy engine. The verified request accesses the power monitoring system and power data resources through the agent. Data is securely transmitted between users, power monitoring systems, and power data resources. The control platform monitors the operation of the data platform in real time to ensure the effective execution of policies and respond when abnormal behavior is found.
[0111] S5: Verify the zero-trust power monitoring system security protection architecture:
[0112] The effectiveness of the zero-trust power monitoring system security protection architecture is verified through SPA simulation experiments and power equipment fault identification experiments.
[0113] As an embodiment, the SPA simulation experiment in step S5 is specifically as follows:
[0114] S511: By authenticating and dynamically authorizing a single encrypted data packet, it ensures that only legitimate authenticated users can access system resources;
[0115] S512: The SPA function is simulated and verified by using the Fwknop open source tool. Fwknop and its related dependency packages are configured on the client and server. The firewall policy on the server denies all access to port 22 by default to simulate a strict zero-trust architecture. The client uses the nmap tool to perform port scanning to verify the service status.
[0116] S513: Use the nmap tool on the client to perform port scanning on the server to check the service status. The simulation results show that when an illegal request is made, the server does not respond to the nmap port 22 detection, which has the network stealth feature and reduces the attack surface.
[0117] S514: When the client directly performs port scanning, i.e., illegal requests, the server does not respond to the nmap port 22 detection, so the client cannot determine whether the service is enabled, indicating that this method has the network stealth feature and can effectively reduce the attack surface in the business network;
[0118] S515: The client sends a legitimate encrypted data packet and passes the identity authentication of the SPA authentication mechanism. After the authentication is successful, the client performs a port scan again. At this time, it can be detected that the server's port 22 is open and the SSH service is accessible. At this stage, the server firewall is dynamically updated, temporarily allowing the client to access port 22. Each new access request still needs to be re-authenticated.
[0119] S516: Security test analysis of distributed denial of service (DDoS) attacks. SYN flood attacks exhaust server resources by sending a large number of SYN request packets, causing the server to be unable to process normal connection requests. However, when the server is attacked, it does not interfere with the processing of legitimate traffic. The attack traffic is effectively identified and isolated outside the SPA authentication mechanism and does not enter the server.
[0120] As an example, in step S5, the power equipment fault identification experiment is specifically as follows:
[0121] S521. Using a machine predictive maintenance classification data set, the data set contains multi-dimensional sensor data related to power equipment failures; the target variables of the data set include two categories: whether there is a failure and the type of failure; by analyzing these data, the features related to different types of failures can be identified;
[0122] S522, use machine learning models such as logistic regression, k-nearest neighbor, random forest, LightGBM and XGBoost to train and predict the data set;
[0123] S523, SMOTE and upsampling data balancing strategies were used to improve model performance;
[0124] S524, evaluating the performance of each model and determining the best performing model;
[0125] S525, analyzing the average values of the features corresponding to different fault types, and finding out the features that have a significant impact on the power fault;
[0126] S526: Based on the analysis results, further optimize the fault identification method to improve the reliability and effectiveness of the power system.
[0127] Through observation, for power failure, speed is the main influencing factor of power failure, and its change trend is significantly higher than other fault types. Temperature has a smaller impact on power failure, although they are similar to other fault types in overall trend. Torque and tool wear time have a certain impact on power failure, but they are not the main factors. Through the detailed analysis of power failure, we can better understand which characteristics have a significant impact on power failure. This is of great significance for improving the reliability and effectiveness of power systems.
[0128] As a summary, please refer to Figure 5 , Figure 5 It is a schematic diagram of the overall architecture of the method of the present invention.
[0129] As an example, the overall workflow of the architecture is as follows:
[0130] Devices and users access through unprivileged networks or public networks, and users authenticate themselves through single sign-on. Next, the access agent uses the protocol to verify the identity of the device and user and check their certificates. The access request enters the core component, and the policy engine evaluates the request based on the predefined policy and current context information. Based on the evaluation results of the policy engine, the policy decision point decides whether to allow access, and the policy execution point implements the decision to allow or deny the access request. Approved access requests can access information in the power monitoring device database for monitoring and control operations. The system continuously monitors all access and operations to ensure compliance with the zero-trust security model. Any abnormal behavior will trigger a security response mechanism. The power monitoring system based on the zero-trust architecture uses strict authentication and access control to ensure that only authenticated and authorized users and devices can access system resources, thereby improving the security and reliability of the system. Through the coordinated work of the core components, the system can dynamically evaluate and respond to various security threats and protect the power monitoring infrastructure.
[0131] See also Figure 6 , Figure 6 It is a working diagram of the hardware device of an embodiment of the present invention, and the hardware device specifically includes: a power monitoring system security protection device 401 with a zero-trust architecture, a processor 402 and a storage medium 403.
[0132] A power monitoring system security protection device 401 with a zero-trust architecture: The power monitoring system security protection device 401 with a zero-trust architecture implements the power monitoring system security protection method with a zero-trust architecture.
[0133] Processor 402: The processor 402 loads and executes the instructions and data in the storage medium 403 to implement the power monitoring system security protection method of the zero-trust architecture.
[0134] Storage medium 403: The storage medium 403 stores instructions and data; the storage medium 403 is used to implement the security protection method of the power monitoring system with a zero-trust architecture.
[0135] The beneficial effects of the present invention are: a comprehensive security protection method is implemented and multi-level security protection is provided, including: construction of a zero-trust power monitoring system protection system; SDP power monitoring system security protection method; IAM method of power monitoring system; power monitoring system agent MSG method; experimental verification stage. Based on the zero-trust power monitoring system security architecture, by combining the power monitoring system with the three major technologies of zero-trust SDP+IAM+MSG, a comprehensive security protection solution is formed and multi-level security protection is provided. This method effectively improves the overall security of the power system, can cope with modern complex security challenges, and protect critical power infrastructure from various network threats and attacks.
[0136] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A zero-trust architecture power monitoring system security protection method, characterized by: The method comprises the following steps: S1. Build a zero-trust power monitoring system security protection architecture: The security protection architecture includes: software-defined boundary SDP control engine and gateway security authentication module, access management IAM dynamic intelligent authorization decision module, and resource data partitioning module based on micro-isolation MSG; S2. Build the software-defined boundary SDP control engine and gateway security authentication module: Build a software-defined perimeter SDP control engine and gateway security authentication module through multi-layer security connections between user-end devices and distributed secure connection cloud services, public cloud servers, SDP gateways, and private clouds / internal networks; S3: Build an access management IAM dynamic intelligent authorization decision module: Build an access management IAM dynamic intelligent authorization decision module through multi-factor authentication MFA management of users; S4: Build a resource data partitioning module based on micro-isolation MSG: By dividing the power monitoring network into different areas, a resource data partitioning module based on micro-isolation MSG is constructed; S5: Verify the zero-trust power monitoring system security protection architecture: The effectiveness of the zero-trust power monitoring system security protection architecture is verified through SPA simulation experiments and power equipment fault identification experiments.
2. The method for protecting the power monitoring system with a zero-trust architecture according to claim 1, characterized in that: In step S2, the working process of the software-defined boundary SDP control engine and the gateway security authentication module is as follows: S21, the user terminal device initiates an access request through the network. The user terminal device initiates an access request through the network and connects to the cloud service; S23: In the connection cloud service request processing phase, the connection cloud service receives the request from the user, performs preliminary verification and processing, and forwards the request to the public cloud server or SDP gateway according to the request type and target; S24: Request forwarding to the public cloud server or SDP gateway stage. If the target of the request is a public cloud resource, the connected cloud service forwards the request to the public cloud server; if the request needs to access private cloud or internal network resources, the connected cloud service forwards the request to the SDP gateway. S25: SDP gateway verification and connection phase: The SDP gateway receives the request from the cloud service for further verification. The SDP gateway strictly verifies the user's identity and the legitimacy of the request based on the zero-trust principle. After the verification is passed, the SDP gateway establishes a secure connection and forwards the request to the target resource in the private cloud or internal network. S26: Access to private cloud / internal network stage, the request is verified by the SDP gateway, and the resources in the private cloud or internal network are securely accessed to perform the required tasks or operations.
3. The method for protecting the security of a power monitoring system with a zero-trust architecture according to claim 1, characterized in that: The working process of the access management IAM dynamic intelligent authorization decision module in step S3 is as follows: S31. Business administrators and application administrators are responsible for management at different levels. The organization and personnel modules manage basic user information and distinguish between active and resigned users. S32, user authentication stage, in-service users authenticate their identities through multi-factor authentication (MFA); S33, application policy management stage, application administrators use the application policy management module to configure the system security, including password management, authentication management and authority management, to ensure system security and reasonable allocation of user rights; S34, access and authority management stage, after being authenticated, the on-the-job user accesses the power monitoring system; For users who have left the company, their access rights will be revoked immediately to ensure that they can no longer access system resources. S35: During the power monitoring system access phase, authenticated and authorized users access the power monitoring system to perform routine monitoring and management operations.
4. The method for protecting the security of a power monitoring system with a zero-trust architecture according to claim 1, wherein: The working process of the resource data partitioning module based on micro-isolation MSG in step S4 is as follows: S41, policy management and execution phase, administrators define and configure security policies through the policy manager; these policies are passed to the policy engine, which manages network traffic and access control in the data platform according to the configured policy rules; S42, user access stage, the user authenticates himself through multi-factor authentication to ensure that only verified legitimate users can enter the system. After passing the authentication, the user sends an access request to the power monitoring system through the gateway; S43, access control stage, the gateway performs preliminary verification of the user's access request to ensure compliance with the security rules of the policy engine, and the agent further verifies and controls network traffic to ensure that all communications comply with security policies and prevent unauthorized access; S44, data interaction stage, after double verification by the gateway and the agent, the legitimate access request is allowed to enter the power monitoring system and power data resources; Data is securely transmitted between users, power monitoring systems and power data resources to ensure that data is not stolen or tampered with during transmission; S45, real-time monitoring stage, the control platform monitors the operation of the data platform in real time, including network traffic, user behavior and system status; abnormal behavior is discovered in a timely manner through the security monitoring system, and once abnormal behavior is detected, it responds and processes according to the preset security policy.
5. The method for protecting the security of a power monitoring system with a zero-trust architecture according to claim 1, wherein: The SPA simulation experiment in step S5 is as follows: S511: By authenticating and dynamically authorizing a single encrypted data packet, it ensures that only legitimate authenticated users can access system resources; S512: The SPA function is simulated and verified by using the Fwknop open source tool. Fwknop and its related dependency packages are configured on the client and server. The firewall policy on the server denies all access to port 22 by default to simulate a strict zero-trust architecture. The client uses the nmap tool to perform port scanning to verify the service status; S513: Use the nmap tool on the client to perform port scanning on the server to check the service status. The simulation results show that when an illegal request is made, the server does not respond to the nmap port 22 detection, which has the network stealth feature and reduces the attack surface. S514: When the client directly performs port scanning, i.e., illegal requests, the server does not respond to the nmap port 22 detection, so the client cannot determine whether the service is enabled, indicating that this method has the network stealth feature and can effectively reduce the attack surface in the business network; S515: The client sends a legitimate encrypted data packet and passes the identity authentication of the SPA authentication mechanism. After the authentication is successful, the client performs a port scan again. At this time, it can be detected that the server's port 22 is open and the SSH service is accessible. At this stage, the server firewall is dynamically updated, temporarily allowing the client to access port 22. Each new access request still needs to be re-authenticated. S516: Security test analysis of distributed denial of service (DDoS) attacks. SYN flood attacks exhaust server resources by sending a large number of SYN request packets, causing the server to be unable to process normal connection requests. However, when the server is attacked, it does not interfere with the processing of legitimate traffic. The attack traffic is effectively identified and isolated outside the SPA authentication mechanism and does not enter the server.
6. The method for protecting the security of a power monitoring system with a zero-trust architecture according to claim 1, characterized in that: In step S5, the power equipment fault identification experiment is specifically as follows: S521. Using a machine predictive maintenance classification data set, the data set contains multi-dimensional sensor data related to power equipment failures; the target variables of the data set include two categories: whether there is a failure and the type of failure; by analyzing these data, the features related to different types of failures can be identified; S522, use logistic regression, k-nearest neighbor, random forest, LightGBM and XGBoost machine learning models to train and predict the data set; S523, SMOTE and upsampling data balancing strategies were used to improve model performance; S524, evaluating the performance of each model and determining the best performing model; S525, analyzing the average values of the features corresponding to different fault types, and finding out the features that have a significant impact on the power fault; S526: Based on the analysis results, further optimize the fault identification method to improve the reliability and effectiveness of the power system.
7. A storage medium, characterized in that: The storage medium stores instructions and data for implementing a zero-trust architecture power monitoring system security protection method as described in any one of claims 1 to 6.
8. A zero-trust architecture power monitoring system security protection device, characterized by: include: Processor and storage medium; the processor loads and executes instructions and data in the storage medium to implement a zero-trust architecture power monitoring system security protection method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Emotion analysis method and device based on domain information, equipment and storage medium
CN113672731A
SDP-based power internet of things and networking method
CN115189904A
Zero-trust security unified analysis and evaluation and trusted access method for Internet of Things
CN117240465A
Access control method and device, computer equipment and storage medium
CN117792753A
Construction method of intelligent power distribution network based on standard digital model
CN119093338A