Trusted network connection method and system of trusted DCS controller

By collecting and verifying the IP address, public key and fingerprint information of the connected devices on the trusted DCS controller, a multi-level verification mechanism is established, which solves the security risks caused by the open network connection of the trusted DCS controller, and achieves higher network security and reliability.

CN119966737APending Publication Date: 2025-05-09XIAN THERMAL POWER RES INST CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510161135.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Since the control part of the trusted DCS controller network is relatively open to the connection judgment of the external device network, illegal or risky external networks may be introduced, resulting in network security risks.

Method used

By collecting the reference values ​​of the IP address, public key and platform configuration register that allow the connected device to be collected on the trusted DCS controller, establishing a matrix table of the reference values ​​of the IP address, public key, platform configuration register and fingerprint information, and performing multi-level verification, including IP address whitelist verification, public key verification, platform configuration register reference value comparison and fingerprint information comparison, to ensure the trustworthiness of the device.

Benefits of technology

Effectively prevent unauthorized devices from accessing trusted DCS controllers, improve the security and reliability of network connection systems, and reduce the risk of external threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966737A_ABST
    Figure CN119966737A_ABST
Patent Text Reader

Abstract

The invention provides a trusted network connection method and system of a trusted DCS controller, and belongs to the technical field of network connection verification and control, and the method comprises the steps: collecting and forming an IP address white list of allowed connection equipment on the trusted DCS controller, and collecting and storing a public key of the allowed connection equipment and a reference value of a platform configuration register; fingerprint information is obtained through the disk ID of the allowed connection device, the MAC address of the network card and the endorsement key of the trusted computing module; and the trusted DCS controller verifies the IP address of the request connection equipment, the current value of the platform configuration register and the fingerprint information based on the connection request of the request connection equipment, confirms whether the request connection equipment is allowed to be connected or not, permits the connection if the verification is passed, and rejects the connection if any verification is not passed. According to the invention, the trusted DCS controller can be protected from external threats, and the security and reliability of the network are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of network connection verification and control, and in particular relates to a trusted network connection method and system for a trusted DCS controller. Background Art

[0002] At present, Linux systems, Windows systems, etc. have their own firewall security mechanisms. They can control internal and external network connections by configuring different firewall rules to protect the security of the system. However, there is a lack of a security mechanism similar to a firewall on the SylixOS system, which results in the system's network connection being in an open state. Any attacker can connect through the IP (Internet Protocol) address and port. Firewalls generally match and restrict network connections in the kernel through rules such as protocols, addresses, and ports. When a connection request that meets the rules arrives, the connection is allowed, and a connection request that does not meet the rules is rejected. At present, the trusted network connection method of the trusted DCS (Distributed Control System) controller combines the trusted computing function and the connection matching rules to match and verify the connection request connected to the trusted DCS controller. If the verification fails, the connection is rejected, and if it passes, the connection is allowed. However, since the control part of the current trusted DCS controller network is relatively open to the connection judgment of the external device network, some illegal or risky external networks may be introduced, which brings certain network security risks to the trusted DCS controller. Summary of the invention

[0003] The present invention provides a trusted network connection method and system for a trusted DCS controller, aiming to solve the problem that the control part of the current trusted DCS controller network is relatively open to the connection judgment of the external device network, which may lead to the introduction of some illegal or risky external networks, thus bringing certain network security risks to the trusted DCS controller.

[0004] In order to achieve the above object, the present invention adopts the following technical scheme: The present invention provides a trusted network connection method for a trusted DCS controller, comprising the following steps: S1. Collect the IP addresses of all devices that are allowed to connect on the trusted DCS controller to form an IP address whitelist, collect and store the public keys of the devices that are allowed to connect and the reference values ​​of the platform configuration registers; obtain fingerprint information through the disk ID of the device that is allowed to connect, the MAC address of the network card and the endorsement key of the trusted computing module, and record the fingerprint information on the trusted DCS controller; S2. Establish a matrix table of IP address, public key, base value of platform configuration register, and fingerprint information, and use IP address as key value to uniquely identify a device that is allowed to connect; S3. When the device requesting connection is waiting for connection, the trusted DCS controller determines based on the connection request whether the IP address of the device requesting connection is in the IP address whitelist, and then enters S4; if not, the connection request is rejected; S4, the trusted DCS controller performs trusted status verification, verifies and compares the public key of the device requesting connection and the current value of the platform configuration register based on the public key of the device allowed to connect and the reference value of the platform configuration register. If the signature verification and comparison are consistent, enter S5; otherwise, reject the connection request; S5. The device requesting connection sends the fingerprint information to the trusted DCS controller. The trusted DCS controller verifies the fingerprint information of the device requesting connection. If it is consistent with the fingerprint information recorded by the trusted DCS controller, the connection is allowed. If it is inconsistent, the connection request is rejected. Optionally, in S1, the trusted DCS controller collects the public keys of all devices allowed to connect and stores them as certificates in the public key storage directory of the DCS controller; obtains the fingerprint information of the device allowed to connect and stores it in the fingerprint library of the DCS controller.

[0005] Optionally, in S1, the reference value of the platform configuration register of the device allowed to be connected is collected and stored, specifically including: the trusted DCS controller sends a request to the device allowed to be connected, requiring the device allowed to be connected to send back the current value of the platform configuration register after signing, allowing the device to be connected to read the current value of the platform configuration register, using a private key to sign the current value of the platform configuration register, and then sending the signed current value of the platform configuration register to the trusted DCS controller. After the trusted DCS controller verifies the signature, the current value of the platform configuration register is used as the reference value of the platform configuration register of the device requesting to be connected, and the reference value of the platform configuration register is stored in the reference value directory of the DCS controller.

[0006] Furthermore, in S2, an IP address, a public key, a reference value of a platform configuration register, and fingerprint information are used to jointly identify a unique device that is allowed to connect.

[0007] Only when the IP address of the device requesting connection, the current value of the platform configuration register and the device fingerprint are verified, the device requesting connection is allowed to connect to the DCS controller. If any of the verifications fails, the connection is rejected.

[0008] Optionally, in S3, when a device requesting connection requests to connect to a trusted DCS controller, the trusted DCS controller parses the IP address of the device requesting connection and compares it with the IP addresses in the IP address whitelist; if the IP address of the device requesting connection is in the IP address whitelist, the next step of confirmation is performed; if not, the connection request is rejected.

[0009] Optionally, in S4, the trusted DCS controller sends a request to the connection requesting device, requiring the connection requesting device to send the current value of the platform configuration register to the trusted DCS controller; The device requesting the connection sends the current value of the platform configuration register signed by the private key; The trusted DCS controller uses the matrix table to find the IP address, public key and reference value of the platform configuration register of the device requesting connection, and uses the found public key to verify and compare the current value of the platform configuration register sent by the device requesting connection; if the verification and comparison are successful, the next step of verification is carried out; if unsuccessful, the connection request is rejected.

[0010] Optionally, in S5, the trusted DCS controller sends a request to the device requesting connection, requiring the device requesting connection to send the device's disk ID, the MAC address of the network card, and the endorsement key of the trusted computing module. The trusted DCS controller calculates the fingerprint information of the device requesting connection through an extended algorithm. The trusted DCS controller uses a matrix table to find the IP address and fingerprint information of the device requesting connection and compares them. If the comparison is successful, the connection is allowed, otherwise the connection request is rejected.

[0011] The present invention also provides a trusted network connection system for a trusted DCS controller, comprising a data configuration module, a building module, a judgment module, a first verification module and a second verification module, wherein: The data configuration module is used to collect and form a whitelist of IP addresses of devices that are allowed to connect on the trusted DCS controller, collect and store the public keys of devices that are allowed to connect and the reference values ​​of platform configuration registers; obtain the fingerprint information of the devices that are allowed to connect based on the disk ID, MAC address of the network card and the endorsement key of the trusted computing module of the devices that are allowed to connect, and record the fingerprint information on the trusted DCS controller; The establishment module is used to establish a matrix table of IP address, public key, base value of platform configuration register and fingerprint information, and use IP address as key value to uniquely identify a device that is allowed to connect; The judging module is used for, when the device requesting connection is waiting for connection, the trusted DCS controller judges based on the connection request whether the IP address of the device requesting connection is in the IP address whitelist, then enters S4; if not, then rejects the connection request; The first verification module is used for the trusted DCS controller to perform trusted state verification, and to verify and compare the public key of the device requesting connection and the current value of the platform configuration register based on the public key of the device allowing connection and the reference value of the platform configuration register. If the verification and comparison are consistent, then enter S5; otherwise, reject the connection request; The second verification module is used to request the connection device to send fingerprint information to the trusted DCS controller, and the trusted DCS controller verifies the fingerprint information of the connection request device. If they are consistent, the connection is allowed; if they are inconsistent, the connection request is rejected.

[0012] The present invention also provides a computer device, comprising a memory, a processor and a computer program stored and running on the memory, wherein the processor implements the steps of the trusted network connection method of the trusted DCS controller as described above when executing the computer program.

[0013] The present invention also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the trusted network connection method of the trusted DCS controller are implemented.

[0014] Compared with the prior art, the trusted network connection method and system of a trusted DCS controller of the present invention has the following beneficial effects: The present invention first establishes a basis for a trusted connection by configuring an IP address whitelist list of devices that are allowed to connect, collecting and storing the public keys of devices that are allowed to connect, and setting the reference values ​​of their platform configuration registers, and at the same time, calculates the fingerprint information of the device through the disk ID, the MAC address of the network card, and the endorsement key of the trusted computing module. When the device requesting connection initiates a connection request, first verify whether its IP address is in the IP address whitelist list configured on the trusted DCS controller, then verify the authenticity of the current value of the platform configuration register of the device requesting connection through the public key, and finally ensure that the network card, disk and trusted computing module of the device requesting connection have not been replaced through fingerprint information comparison, thereby ensuring the credibility of the device requesting connection. The present invention can effectively prevent unauthorized requesting devices from accessing the trusted DCS controller, verify and control the network connected to the trusted DCS controller, and only connections that meet expectations are allowed to access, and other connections are rejected, thereby effectively protecting the trusted DCS controller from external threats, improving the security and reliability of the network connection system, and having better practical significance. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The drawings in the specification are used to provide further understanding of the present invention and constitute a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0016] Figure 1A flow chart of a trusted network connection method for a trusted DCS controller according to the present invention; Figure 2 A structural schematic diagram of a trusted network connection system of a trusted DCS controller of the present invention; Figure 3 The figure is a schematic diagram of the structure of a computer device according to the present invention. DETAILED DESCRIPTION

[0017] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.

[0018] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0019] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.

[0020] In the description of the embodiments of the present invention, it should be noted that if the terms "upper", "lower", "horizontal", "inner", etc. indicate an orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of the invention is usually placed when in use, it is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention. In addition, the terms "first", "second", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.

[0021] In addition, if the term "horizontal" appears, it does not mean that the component must be absolutely horizontal, but can be slightly tilted. For example, "horizontal" only means that its direction is more horizontal than "vertical", which does not mean that the structure must be completely horizontal, but can be slightly tilted.

[0022] In the description of the embodiments of the present invention, it is also necessary to explain that, unless otherwise clearly specified and limited, the terms "set", "install", "connect", and "connect" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal connection of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0023] How to set a network connection method that only allows access to connections that meet expectations and rejects all other connections, thereby effectively protecting the trusted DCS controller from external threats and improving the security of the trusted DCS controller.

[0024] like Figure 1 As shown, the present invention provides a trusted network connection method for a trusted DCS controller, comprising the following steps: S1. Collect the IP addresses of all devices that are allowed to connect on the trusted DCS controller to form an IP address whitelist, collect and store the public keys of the devices that are allowed to connect and the reference values ​​of the platform configuration registers; obtain fingerprint information through the disk ID of the device that is allowed to connect, the MAC address of the network card and the endorsement key of the trusted computing module, and record the fingerprint information on the trusted DCS controller; S2. Establish a matrix table of IP address, public key, base value of platform configuration register and fingerprint information, and use IP address as key value to uniquely identify a device that is allowed to connect; S3. When the device requesting connection is waiting for connection, the trusted DCS controller determines based on the connection request whether the IP address of the device requesting connection is in the IP address whitelist, and then enters S4; if not, the connection request is rejected; S4, the trusted DCS controller performs trusted status verification, verifies and compares the public key of the device requesting connection and the current value of the platform configuration register based on the public key of the device allowed to connect and the reference value of the platform configuration register. If the signature verification and comparison are consistent, enter S5; otherwise, reject the connection request; S5. The device requesting connection sends the fingerprint information to the trusted DCS controller. The trusted DCS controller verifies the fingerprint information of the device requesting connection. If it is consistent with the fingerprint information recorded by the trusted DCS controller, the connection is allowed. If it is inconsistent, the connection request is rejected.

[0025] Only when the above S2~S5 are confirmed to be correct, the device requesting connection is allowed to connect to the trusted DCS controller and communicate normally. If any verification fails, the connection is rejected.

[0026] In the above steps, where: In S1, a whitelist of IP addresses of devices that are allowed to connect is configured on the trusted DCS controller, the public keys of devices that are allowed to connect are collected and stored, the base values ​​of platform configuration registers signed by the private keys of devices that are allowed to connect are collected and set, and fingerprint information of devices that are allowed to connect is collected. The fingerprint information of devices that are allowed to connect is obtained by calculation through the MAC address of the network card, the disk ID, and the endorsement key of the trusted computing module. The calculation algorithm of the fingerprint information is: hash (MAC address of the network card, disk ID, endorsement key), that is, the MAC address of the network card, the disk ID, and the endorsement key information are connected and then hashed to obtain the fingerprint hash value.

[0027] In S2, a matrix relationship among the IP address, the public key, the base value of the platform configuration register, and the fingerprint information is established, wherein the IP address is used as the unique primary key, and the public key certificate and fingerprint information of the device requesting connection can be found through the IP address.

[0028] In S3, when the device requesting connection is waiting for connection, the trusted DCS controller parses the IP address of the device requesting connection from the data packet of the connection request based on the connection request, and determines that if the IP address of the device requesting connection is in the IP address whitelist stored on the DCS controller, it means that the device is allowed to connect, and enters S4 for the next step of verification; if it is not in the IP address whitelist, the connection request is rejected; In S4, the trusted DCS controller verifies the trusted state of the connection requesting device, that is, performs trusted state verification, verifies and compares the current value of the platform configuration register signed by the connection requesting device based on the stored public key of the connection requesting device. If it fails, the connection is rejected. If it passes, it enters S5; S5. The trusted DCS controller performs fingerprint comparison by comparing the fingerprint information sent by the device requesting the connection with the stored fingerprint information. If the comparison is successful, the connection is allowed, otherwise the connection request is rejected. Specifically, the trusted DCS controller requires the device requesting the connection to send the MAC address of the network card, the disk ID, and the endorsement key of the trusted computing module. The trusted DCS controller obtains the fingerprint information of the device requesting the connection through the extended algorithm, and searches for the fingerprint information stored on the trusted DCS controller through the IP address. If the fingerprint information is found and verified to be consistent, the connection is allowed. If it is not found or the comparison is inconsistent, the connection request is rejected.

[0029] S2~S5 verify the information of the device requesting connection in three steps. If all the verifications are successful, it means that the device requesting connection is credible and authenticated, and the connection is allowed. That is, if the IP address, the current value of the platform configuration register, and the fingerprint information are successfully verified, the device requesting connection is allowed to establish a connection with the credible DCS controller and perform business interaction; if any of the verifications fail, the connection request is directly rejected.

[0030] In some embodiments, in S1, the IP addresses of all devices allowed to connect are recorded in the trusted DCS controller to form a whitelist of IP addresses of all devices allowed to connect. For example, the IP addresses of devices allowed to connect are collected and stored manually, and stored in the whitelist of IP addresses of devices allowed to connect of the trusted DCS controller. The MAC address, disk ID and endorsement key of the network card of the device allowed to connect are obtained, and the fingerprint information of the device allowed to connect is obtained through an extended algorithm, and stored in the fingerprint library of the trusted DCS controller.

[0031] And in S1, the public keys of all the devices allowed to connect are collected and stored as certificates in the public key storage directory of the trusted DCS controller. Collecting and storing the public keys of the devices allowed to connect specifically includes: the trusted DCS controller collects the public keys of all the devices allowed to connect, stores them as certificates on the trusted DCS controller, and establishes a corresponding relationship between the public keys and the IP addresses of the devices allowed to connect.

[0032] Collect and store the reference value of the platform configuration register of the device that is allowed to connect, specifically including: the trusted DCS controller sends a request to the device that is allowed to connect, requiring the device that is allowed to connect to send back the current value of the platform configuration register after signing with a private key, allowing the device to connect to read the current value of the platform configuration register, using the private key to sign the current value of the platform configuration register, and then sending the signed current value of the platform configuration register to the trusted DCS controller. After the trusted DCS controller verifies the signature, it uses the current value of the platform configuration register as the reference value of the platform configuration register of the device that is allowed to connect, and stores the reference value of the platform configuration register in the reference value directory of the DCS controller.

[0033] The trusted DCS controller sends a request to the device requesting connection, requiring the device requesting connection to send back the current value of its platform configuration register after signing with the private key, and the device requesting connection reads the current value of the platform configuration register, signs the current value of the platform configuration register with the private key, and then sends the signed current value of the platform configuration register to the trusted DCS controller; after the trusted DCS controller verifies the signature, it saves the current value of the platform configuration register signed with the private key as the platform configuration register baseline value of the device requesting connection.

[0034] In some implementations, in S2, a matrix relationship of the IP address, public key certificate, reference value of the platform configuration register, and fingerprint information of the device allowed to connect to the trusted DCS controller is established on the trusted DCS controller, and the three pieces of information together identify a unique device allowed to connect to the trusted DCS controller.

[0035] In some implementations, in S3, when a device requesting connection requests to connect to a trusted DCS controller, the trusted DCS controller parses the IP address of the device requesting connection and compares it with the IP addresses in the IP address whitelist stored on the trusted DCS controller. If the IP address of the device requesting connection is in the whitelist, the next step of confirmation is performed; if it is not in the IP address whitelist, the connection request is rejected.

[0036] In some implementations, in S4, the trusted DCS controller sends a request to the device requesting connection, requiring the device requesting connection to send the current value of the platform configuration register signed by the private key to the trusted DCS controller. The trusted DCS controller uses a matrix table to find the IP address, public key and reference value of the platform configuration register of the device requesting connection, and uses the found public key to verify and compare the current value of the platform configuration register sent by the device requesting connection; if the verification and comparison are successful, the next step of verification is performed; if unsuccessful, the connection is rejected.

[0037] In some implementations, in S5, the trusted DCS controller sends a request to the device requesting connection, requiring it to send the disk ID of the device requesting connection, the MAC address of the network card, and the endorsement key of the trusted computing module. The trusted DCS controller obtains the fingerprint information of the device requesting connection through an extended algorithm. The trusted DCS controller uses the matrix table established in S2 to find the IP address of the device requesting connection and performs a fingerprint information comparison. If the comparison is successful, the connection is allowed, otherwise the connection request is rejected.

[0038] Only when the IP address of the device requesting connection, the current value of the platform configuration register and the fingerprint information are verified, the device requesting connection is allowed to connect to the trusted DCS controller. If any of the verifications fails, the connection request is rejected.

[0039] Furthermore, in S1, the signature verification of the trusted DCS controller is specifically as follows: the trusted DCS controller uses the stored public key of the device requesting connection to verify the current value of the platform configuration register signed by the private key.

[0040] In S3, when the device requesting connection attempts to connect to the trusted DCS controller, the trusted DCS controller receives the connection request and resolves the IP address of the device requesting connection; In some implementations, in S4, the trusted status verification is specifically as follows: the trusted DCS controller sends a request to the requesting connection device, requiring it to provide the current value of each platform configuration register stored in the current trusted computing chip, requests the connecting device to read the current value of the platform configuration register, uses the private key to sign the current value of the platform configuration register, and then sends the signed current value of the platform configuration register to the trusted DCS controller.

[0041] After the trusted DCS controller verifies the current value of the platform configuration register, it compares the current value of the platform configuration register sent by the device requesting connection with the reference value of the platform configuration register stored in the trusted DCS controller. If they are consistent, the connection request of the device requesting connection is allowed; if they are inconsistent, the connection request of the device requesting connection is rejected.

[0042] In some embodiments, in S5, after the trusted DCS controller obtains the MAC address of the network card of the device requesting connection, the disk ID and the endorsement key of the trusted computing module, it calculates the fingerprint information of the device requesting connection through an extended algorithm and compares it with the fingerprint information stored in the trusted DCS controller. If they are inconsistent, the connection request of the device requesting connection is rejected.

[0043] The present invention discloses a trusted network connection method for a trusted DCS controller, which ensures the network connection security of the trusted DCS controller by constructing a multi-level verification mechanism. The present invention can preliminarily filter out illegal connection requests by configuring an IP address whitelist list of devices that are allowed to be connected, and only the devices that are requested to be connected in the IP address whitelist list are allowed to connect and perform subsequent verification; the present invention collects and stores the public keys of devices that are allowed to be connected, providing a basis for subsequent signature verification; the present invention collects the current value of the platform configuration register of the device that is allowed to be connected as a reference value for verification, ensuring that even if the configuration of the device that is requested to be connected is tampered with later, the abnormality can be found by comparing the reference value. The present invention calculates the fingerprint information of the device that is requested to be connected by the MAC (Media Access Control) of the network card of the device that is requested to be connected, the disk ID (Identity) and the endorsement key of the trusted computing module. When the network card, disk or trusted computing module of the device that is requested to be connected is replaced, it can be found by verifying the fingerprint information, ensuring that the original components of the device that is requested to be connected have not been replaced, thereby ensuring the security of the device that is requested to be connected. The present invention reduces the risk of illegal external devices accessing a trusted DCS controller to a large extent through triple verification of the IP address whitelist, the public key, the reference value of the platform configuration register, and the fingerprint information. The present invention can identify any abnormal changes in the configuration of the device requesting connection by setting the reference value of the platform configuration register, thereby enhancing the overall credibility of the system. In addition, the present invention allows the list of devices allowed to be connected to be flexibly configured, which is convenient for adjustment according to actual needs.

[0044] In a trusted network connection method of a trusted DCS controller of the present invention, the trusted DCS controller actively collects the public key of the device requesting connection and establishes a corresponding relationship with its IP address. This not only simplifies the public key search during the verification process, but also ensures the accurate matching of the public key and the device requesting connection. This reduces the time for public key search during the verification process, improves the verification efficiency, and reduces the risk of verification failure caused by incorrect public key matching during the verification process by establishing a corresponding relationship between the public key and the IP address, providing convenience for the centralized management and update of the public key.

[0045] The present invention provides a trusted network connection method for a trusted DCS controller. During the verification process, the trusted DCS controller uses the stored public key of the device requesting connection to verify the current value of the platform configuration register after the private key signature. The present invention utilizes the principle of public key cryptography, verifies the authenticity of the signature through the public key, and thus confirms the credibility of the current value of the platform configuration register. The present invention effectively prevents signature forgery and tampering through public key signature verification, and the signature verification process is fast and efficient, does not affect the overall performance of the system, and provides a high reliability guarantee for the signature verification process.

[0046] The present invention provides a trusted network connection method for a trusted DCS controller. During the verification process, the trusted DCS controller uses the stored fingerprint information of the corresponding allowed connection device to compare with the calculated fingerprint information of the request connection device, so as to confirm whether the network card, disk and trusted computing module components of the request connection device have been replaced. If replaced, it indicates that the request connection device is not trustworthy, thereby improving the vulnerability of single method verification.

[0047] In a trusted network connection method of a trusted DCS controller of the present invention, when a connection requesting device attempts to connect, the trusted DCS controller first parses the IP address in the connection request and performs verification. If the IP address is not in the IP address whitelist, the connection request is directly rejected. The present invention implements preliminary security filtering through simple IP address comparison, quickly filters out illegal connection requests through IP address comparison, reduces unnecessary verification processes, improves the efficiency of the system in processing connection requests, and records the event data of connection rejection, which is convenient for subsequent auditing and troubleshooting.

[0048] The present invention provides a trusted network connection method for a trusted DCS controller. In the trusted state verification process, the trusted DCS controller requires the device requesting connection to provide the signature values ​​of each platform configuration register stored in the current trusted computing chip. The present invention verifies the credibility of the current state of the device requesting connection by reusing the private key signature and public key signature verification technology, and can verify the current state of the device requesting connection in real time, ensuring that the device requesting connection is not tampered with during the connection process. Through the re-verification process, the security of the system is further enhanced, and the combined use of the private key signature and the public key signature verification provides a high reliability guarantee for the verification process.

[0049] In a trusted network connection method of a trusted DCS controller of the present invention, after the signature verification is passed, the trusted DCS controller compares the current value of the platform configuration register signed by the private key with the reference value. If the two are consistent, the connection is allowed; if they are inconsistent, the connection is rejected and the event data is recorded. The present invention ultimately determines the connection authority of the device by comparing the verification results. By comparing the verification results and the reference value, the consistency of the configuration of the device requesting connection is ensured. The connection decision made based on the comparison result is more accurate and reliable. The connection is rejected for the device requesting connection with inconsistent configuration, thereby improving the overall security of the system.

[0050] In addition, the present invention also provides a trusted network connection system for a trusted DCS controller, in which the policy configuration module is responsible for configuring the IP address whitelist of devices that are allowed to connect, collecting and managing the public key of the trusted computing chip of the connection object and the current value of the PCR (Platform Configuration Register). The policy configuration module is used to add, delete and query the IP address of the device that is allowed to connect. It is responsible for collecting, storing and updating the public key of the device that is allowed to connect, and establishing the corresponding relationship between the public key and the IP address. It sends a PCR value request to the device that is allowed to connect, receives and verifies the signed PCR value, and saves it as a reference value.

[0051] The connection request control module is responsible for processing the connection request of the device requesting connection, performing IP address verification and trusted status verification, and allowing or rejecting the connection based on the verification results. Query the policy configuration to verify whether the IP address of the device requesting connection is in the allowed list. Send a request to obtain the current value of the platform configuration register to the device requesting connection, receive and verify the current value of the platform configuration register after signing, and compare it with the reference value stored on the trusted DCS controller. Based on the verification results of the IP verification and the current value of the platform configuration register, decide whether to allow the device requesting connection to connect.

[0052] The following is a further detailed description of a trusted network connection method and system for a trusted DCS controller of the present invention.

[0053] The policy configuration function of the application layer in the present invention includes the configuration management of the policy and the collection and management of the benchmark values ​​of the connection objects. The policy configuration process is as follows: The trusted DCS controller is configured with the IP addresses of the devices that are allowed to connect, and the public keys produced by the trusted computing chips on all the devices that are allowed to connect are collected in advance as certificates. The public key certificates are stored on the trusted DCS controller, and a corresponding relationship between the public key certificates and the IP addresses is established.

[0054] A request is sent to the allowed connection device, requiring the allowed connection device to sign the current value of the platform configuration register of each measurement object stored in the trusted computing chip with a private key and send it to the trusted DCS controller as a reference value to be stored in the policy.

[0055] After receiving the request, the allowed connection device reads the current value of the platform configuration register of each measurement object from the trusted computing chip, then uses the private key in the chip to sign the current value of the platform configuration register and sends it to the trusted DCS controller. After receiving the data, the controller looks up the public key of the IP address of the connection requesting device and verifies the signature of the data. If the signature verification passes, it means that the current value of the platform configuration register comes from the corresponding connection requesting device, and the current value of the platform configuration register of the connection requesting device is saved as the reference value.

[0056] In the present invention, the request connection control function is specifically as follows: When a device that requests to connect requests to connect to a trusted DCS controller, the trusted DCS controller first resolves the IP address of the device that requests to connect, and confirms whether the IP address is in the IP address whitelist of the trusted DCS controller. If it is not in the IP address whitelist, the connection is directly rejected.

[0057] If the IP address verification is successful, a request is sent to the device requesting the connection, requiring it to send the current value of the platform configuration register signed with the private key for authentication.

[0058] After receiving the message, the trusted DCS controller uses the public key corresponding to the IP address and the reference value stored in the platform configuration register to verify the signature of the current value of the platform configuration register sent by the device requesting connection. After the signature verification is passed, the current value of the platform configuration register sent is compared with the reference value of the stored platform configuration register. If they are inconsistent, it means that the device requesting connection may have been tampered with and is untrustworthy, and the connection is rejected. If they are consistent, the connection request is allowed.

[0059] If the current value of the platform configuration register is verified, a request is sent to the device requesting connection, requiring it to send the MAC address of the network card, the disk ID, and the endorsement key of the trusted computing module to the trusted DCS controller. The trusted DCS controller calculates the fingerprint information of the device requesting connection based on this information through an extended algorithm, and compares it with the fingerprint information of the device requesting connection stored in the trusted DCS controller. If the comparison is consistent, the connection is allowed. If the comparison is inconsistent, the connection is rejected.

[0060] like Figure 2 As shown, the present invention also provides a trusted network connection system for a trusted DCS controller, including a data configuration module, a building module, a judgment module, a first verification module and a second verification module, for executing a trusted network connection method for a trusted DCS controller.

[0061] A trusted network connection method and system for a trusted DCS controller of the present invention can effectively solve the problem of open network connection of a trusted DCS controller. At the same time, combined with a trusted verification function, in addition to a simple control connection, it is also possible to confirm whether the connection object is trustworthy by verifying the trusted state of the connection object, thereby achieving the purpose of prohibiting arbitrary connection of external devices, improving the safety factor of the network, and improving the credibility and stability of the network, and having better practical significance.

[0062] like Figure 3 As shown, the present invention also provides a computer device, including a memory, a processor, and a computer program stored and running on the memory, and when the processor executes the computer program, the steps of the trusted network connection method of the trusted DCS controller as described above are implemented.

[0063] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Any ordinary technician in the industry can smoothly implement the present invention as shown in the specification and described above. However, any equivalent changes, modifications and evolutions made by technicians familiar with the profession without departing from the scope of the technical solution of the present invention using the technical content disclosed above are all equivalent embodiments of the present invention. At the same time, any equivalent changes, modifications and evolutions made to the above embodiments based on the essential technology of the present invention are still within the protection scope of the technical solution of the present invention.

Claims

1. A trusted network connection method for a trusted DCS controller, characterized in that: The steps include: S1. Collect the IP addresses of all devices allowed to connect on the trusted DCS controller to form an IP address whitelist, collect and store the public keys of the devices allowed to connect and the reference values ​​of the platform configuration registers; The fingerprint information is obtained by using the disk ID of the connected device, the MAC address of the network card, and the endorsement key of the trusted computing module, and the fingerprint information is recorded on the trusted DCS controller; S2. Establish a matrix table of IP address, public key, base value of platform configuration register, and fingerprint information, and use IP address as key value to uniquely identify a device that is allowed to connect; S3. When the device requesting connection is waiting for connection, the trusted DCS controller determines based on the connection request whether the IP address of the device requesting connection is in the IP address whitelist, and then enters S4; if not, the connection request is rejected; S4, the trusted DCS controller performs trusted status verification, verifies and compares the public key of the device requesting connection and the current value of the platform configuration register based on the public key of the device allowed to connect and the reference value of the platform configuration register. If the signature verification and comparison are consistent, enter S5; otherwise, reject the connection request; S5. The device requesting connection sends the fingerprint information to the trusted DCS controller. The trusted DCS controller verifies the fingerprint information of the device requesting connection. If it is consistent with the fingerprint information recorded by the trusted DCS controller, the connection is allowed. If it is inconsistent, the connection request is rejected.

2. The trusted network connection method of the trusted DCS controller according to claim 1, characterized in that: In S1, the trusted DCS controller collects the public keys of all devices that are allowed to connect, and stores them as certificates in the public key storage directory of the DCS controller; obtains the fingerprint information of the devices that are allowed to connect, and stores it in the fingerprint library of the DCS controller.

3. The trusted network connection method of the trusted DCS controller according to claim 1, characterized in that: In the S1, the reference value of the platform configuration register of the device allowed to be connected is collected and stored, specifically including: the trusted DCS controller sends a request to the device allowed to be connected, requiring the device allowed to be connected to send back the current value of the platform configuration register after signing, the device allowed to be connected reads the current value of the platform configuration register, signs the current value of the platform configuration register with a private key, and then sends the signed current value of the platform configuration register to the trusted DCS controller. After the trusted DCS controller verifies the signature, the current value of the platform configuration register is used as the reference value of the platform configuration register of the device requested to be connected, and the reference value of the platform configuration register is stored in the reference value directory of the DCS controller.

4. The trusted network connection method of the trusted DCS controller according to claim 3, characterized in that: In S2, an IP address, a public key, a reference value of a platform configuration register, and fingerprint information are used to jointly identify a unique device that is allowed to connect.

5. The trusted network connection method of the trusted DCS controller according to claim 1, characterized in that: In S3, when a connection requesting device requests to connect to a trusted DCS controller, the trusted DCS controller resolves the IP address of the connection requesting device and compares it with the IP addresses in the IP address whitelist; If the IP address of the device requesting connection is in the IP address whitelist, the next step of confirmation is performed. If not, the connection request is rejected.

6. The trusted network connection method of the trusted DCS controller according to claim 1, characterized in that: In the above S4, the trusted DCS controller sends a request to the connection requesting device, requiring the connection requesting device to send the current value of the platform configuration register to the trusted DCS controller; The device requesting the connection sends the current value of the platform configuration register signed by the private key; The trusted DCS controller uses the matrix table to find the IP address, public key and reference value of the platform configuration register of the device requesting connection, and uses the found public key to verify and compare the current value of the platform configuration register sent by the device requesting connection; if the verification and comparison are successful, the next step of verification is carried out; if unsuccessful, the connection request is rejected.

7. The trusted network connection method of the trusted DCS controller according to claim 1, characterized in that: In the S5, the trusted DCS controller sends a request to the device requesting connection, requiring the device requesting connection to send the device's disk ID, the MAC address of the network card and the endorsement key of the trusted computing module. The trusted DCS controller calculates the fingerprint information of the device requesting connection through an extended algorithm. The trusted DCS controller uses a matrix table to find the IP address and fingerprint information of the device requesting connection and compares them. If the comparison is successful, the connection is allowed, otherwise the connection request is rejected.

8. A trusted network connection system for a trusted DCS controller, used to implement the trusted network connection method for a trusted DCS controller according to any one of claims 1 to 7, characterized in that: It includes a data configuration module, a building module, a judgment module, a first verification module and a second verification module, wherein: The data configuration module is used to collect and form a whitelist of IP addresses of devices that are allowed to connect on the trusted DCS controller, collect and store the public keys of devices that are allowed to connect and the reference values ​​of platform configuration registers; obtain the fingerprint information of the devices that are allowed to connect based on the disk ID, MAC address of the network card and the endorsement key of the trusted computing module of the devices that are allowed to connect, and record the fingerprint information on the trusted DCS controller; The establishment module is used to establish a matrix table of IP address, public key, base value of platform configuration register and fingerprint information, and use IP address as key value to uniquely identify a device that is allowed to connect; The judging module is used for, when the device requesting connection is waiting for connection, the trusted DCS controller judges based on the connection request whether the IP address of the device requesting connection is in the IP address whitelist, then enters S4; if not, then rejects the connection request; The first verification module is used for the trusted DCS controller to perform trusted state verification, and to verify and compare the public key of the device requesting connection and the current value of the platform configuration register based on the public key of the device allowing connection and the reference value of the platform configuration register. If the verification and comparison are consistent, then enter S5; otherwise, reject the connection request; The second verification module is used to request the connection device to send fingerprint information to the trusted DCS controller, and the trusted DCS controller verifies the fingerprint information of the connection request device. If they are consistent, the connection is allowed; if they are inconsistent, the connection request is rejected.

9. A computer device comprising a memory, a processor and a computer program stored and executed on the memory, characterized in that: When the processor executes the computer program, the steps of the trusted network connection method of a trusted DCS controller according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the trusted network connection method of a trusted DCS controller according to any one of claims 1 to 7 are implemented.