Method, system, device and medium for trusted online input and exit of trusted DCS upper computer

By using hardware encryption chips to perform digital signatures and multi-level encryption policy files in DCS systems, the problem of inability to modify parameters due to credibility during device maintenance is solved, and the simplification and security guarantee of device maintenance is achieved.

CN120010412APending Publication Date: 2025-05-16XIAN THERMAL POWER RES INST CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510141621.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

After the prior art uses trusted computing technology to improve the security of DCS system, the equipment parameters cannot be modified due to the existence of trustworthiness during equipment maintenance, resulting in maintenance difficulties.

Method used

The client uses the private key stored in the hardware encryption chip to digitally sign the instructions, generates a disconnection instruction, and after receiving the device, the signature and hardware identification, enter maintenance mode. At the same time, the client issues multi-level encryption policy files, the device updates the trusted policy and conducts effectiveness tests, and restores the trusted state after maintenance is completed.

Benefits of technology

It realizes parameter modification and trustworthy policy updates in the maintenance mode of the equipment, simplifies the equipment maintenance process, and ensures the safety and trustworthiness of the equipment during the maintenance process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010412A_ABST
    Figure CN120010412A_ABST
Patent Text Reader

Abstract

The invention discloses a method, a system, equipment and a medium for trusted online input and exit of a trusted DCS (Distributed Control System) upper computer. The method comprises the following steps: sending a disconnection instruction to the equipment through a client, receiving the disconnection instruction by the equipment, maintaining in a maintenance mode according to the disconnection instruction, and maintaining the equipment in the maintenance mode; the strategy file is issued to the management platform through the client, the management platform issues the strategy file to the equipment, the equipment updates the credible strategy on the equipment according to the strategy file, and the method, the system, the equipment and the medium facilitate maintenance of the equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of automatic control and relates to a method, system, equipment and medium for trusted online input and output of a trusted DCS host computer. Background Art

[0002] Distributed Control System (DCS) is a multi-level computer system composed of process control level and process monitoring level with communication network as the link. DCS system is mainly composed of field control station (I / O station), data communication system, human-machine interface unit (operator station, engineer station, history station), cabinet, power supply, etc. At present, the security of thermal power control system faces many threats, such as viruses and malware, Trojans and worms, DDoS attacks, phishing attacks, social engineering attacks, malicious code injection, wireless network attacks and identity theft. In order to deal with these threats, trusted computing technology is used to improve network and host security. Ensure the security and stability of the network and host. After adding trusted computing technology, if the machine maintenance is encountered, the equipment does not need to communicate with the trusted management platform and the history station, and does not need to report the trusted status of the equipment in real time. After the equipment maintenance is completed, the trusted operation behavior and the change of the trusted status generated during the maintenance can be reported to the trusted management platform and the history station. However, in particular, the trusted operation is invested, which leads to the fact that when the parameters of the equipment need to be modified during equipment maintenance, the equipment cannot be maintained due to the existence of trust. Summary of the invention

[0003] The purpose of the present invention is to overcome the disadvantages of the prior art and provide a method, system, device and medium for trusted online entry and exit of a trusted DCS host computer, which facilitates the maintenance of the device.

[0004] To achieve the above object, the present invention discloses a method for trusted online entry and exit of a trusted DCS host computer, comprising:

[0005] The client digitally signs the instruction using the private key stored in the hardware encryption chip to obtain a disconnection instruction, which includes the unique hardware identification information of the device. The client sends the disconnection instruction to the device, and the device receives the disconnection instruction, verifies the validity of the digital signature, and compares the hardware identification information. After the verification is passed, the device enters the maintenance mode according to the disconnection instruction;

[0006] In maintenance mode, the device's boot trust, application trust, and file trust function modules are disabled;

[0007] The client sends the policy file to the management platform, the client performs multi-level encryption on the policy file, and the management platform establishes a secure transmission channel when sending the policy file to the device;

[0008] The device updates the trusted policy on the device according to the policy file, and performs a comprehensive validity test after the update is completed. If the test passes, the new policy is enabled. If the test fails, the original policy is rolled back and a policy update failure report is sent to the management platform;

[0009] After the device maintenance is completed, the client sends a reconnection command to the device. After the device verification is passed, the boot-up trust, application trust and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. The management platform is used to receive the change message, perform decryption and decompression operations, and update its own management database according to the change message.

[0010] Furthermore, the method further comprises:

[0011] In maintenance mode, the device starts an internal security monitoring subsystem built based on lightweight trusted execution environment technology, wherein the security monitoring subsystem is used to monitor the device's memory access, process activity and system call status in real time. When executing a change in the trusted policy on the device, all change operations are performed under the supervision of the security monitoring subsystem and recorded in a local, non-tamperable log storage area. At the same time, the trusted alarms and audit information generated by modifying the protected files are saved in a queue.

[0012] Furthermore, the policy file is encrypted at multiple levels, including:

[0013] The policy file is encrypted using a symmetric encryption algorithm and a key derived from a random key seed generated based on multiple factors, and asymmetric encryption is performed using the public key of the management platform.

[0014] Furthermore, before the device updates the trusted policy on the device according to the policy file, the method further includes:

[0015] The device uses a new type of hash function combined with a digital certificate to verify the source legitimacy and integrity of the policy file. If it passes, it adopts a gradual replacement method, first backing up the original policy to an independent redundant storage area, then updating the relevant module policy settings according to instructions and performing real-time compatibility testing. If there is an exception, it will roll back.

[0016] Furthermore, the content of the operation instruction recorded in the log by the device in the maintenance mode includes the operation time, operation type, and detailed information of the policy parameters involved in the operation;

[0017] Before sending the change message, the change message is compressed and encrypted.

[0018] Furthermore, the failure report sent by the device to the management platform after the policy update fails also includes at least one of the device's current hardware status information, network connection information, failure cause, error code, detailed test log, device current configuration information and operating status information.

[0019] The present invention discloses a reliable online input and output system of a reliable DCS host computer, comprising:

[0020] The signature module is used for the client to digitally sign the instruction using the private key stored in the hardware encryption chip to obtain the disconnection instruction, which includes the unique hardware identification information of the device. The client sends the disconnection instruction to the device, and the device receives the disconnection instruction, verifies the validity of the digital signature, and compares the hardware identification information. After the verification is passed, the maintenance mode is entered according to the disconnection instruction; in the maintenance mode, the boot-up trust, application trust and file trust function modules of the device are in a closed state;

[0021] The first sending module is used to send the policy file to the management platform through the client, the client performs multi-level encryption processing on the policy file, and the management platform establishes a secure transmission channel when sending the policy file to the device;

[0022] An update module is used for updating the trusted policy on the device according to the policy file, and performing a comprehensive validity test after the update is completed. If the test passes, the new policy is enabled; if the test fails, the original policy is rolled back and a policy update failure report is sent to the management platform;

[0023] The second sending module is used for the client to send a reconnection command to the device after the device maintenance is completed. After the device verification is passed, the boot-up trust, application trust and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. The management platform is used to perform decryption and decompression operations after receiving the change message and update its own management database according to the change message.

[0024] The invention discloses a computer device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for trusted online entry and exit of a trusted DCS host computer are implemented.

[0025] The present invention discloses a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for trusted online entry and exit of a trusted DCS host computer are implemented.

[0026] The present invention has the following beneficial effects:

[0027] The method, system, device and medium for trusted online entry and exit of a trusted DCS host computer described in the present invention can, during specific operation, place the device in maintenance mode and then perform maintenance on the device, or directly send a policy file to the device through a management platform, and the device updates the trusted policy on the device according to the policy file to achieve maintenance of the device, which is simple and convenient to operate. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The accompanying drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the accompanying drawings:

[0029] Figure 1 One of the flow charts of a method for trusted online entry and exit of a trusted DCS host computer provided by the present invention;

[0030] Figure 2 A second flow chart of a method for trusted online entry and exit of a trusted DCS host computer provided by the present invention;

[0031] Figure 3 A system structure diagram of a trusted DCS host computer trusted online input and output provided by the present invention;

[0032] Figure 4 A schematic diagram of the structure of a computer device provided by the present invention. DETAILED DESCRIPTION

[0033] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0034] In the description of the present invention, it should be understood that the terms “include” and “comprises” indicate the presence of described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.

[0035] It should also be understood that the terms used in the present specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an" and "the" are intended to include plural forms unless the context clearly indicates otherwise.

[0036] It should be further understood that the term "and / or" used in the present specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes these combinations. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in the present invention generally indicates that the associated objects are in an "or" relationship.

[0037] It should be understood that, although the terms first, second, third, etc. may be used to describe preset ranges, etc. in the embodiments of the present invention, these preset ranges should not be limited to these terms. These terms are only used to distinguish preset ranges from each other. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.

[0038] The word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.

[0039] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. The components of the embodiments of the present invention described and shown in the drawings here can usually be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0040] Various structural schematic diagrams of the embodiments disclosed in the present invention are shown in the accompanying drawings. These figures are not drawn to scale, and some details are magnified and some details may be omitted for the purpose of clear expression. The shapes of various regions and layers shown in the figures and the relative sizes and positional relationships therebetween are only exemplary, and may deviate in practice due to manufacturing tolerances or technical limitations, and those skilled in the art may additionally design regions / layers with different shapes, sizes, and relative positions according to actual needs.

[0041] See also Figure 1 , Figure 1 A flow chart of a method for trusted online entry and exit of a trusted DCS host computer provided by an embodiment of the present invention includes the following steps:

[0042] The client digitally signs the instruction using the private key stored in the hardware encryption chip to obtain a disconnection instruction, which includes the unique hardware identification information of the device. The client sends the disconnection instruction to the device, and the device receives the disconnection instruction, verifies the validity of the digital signature, and compares the hardware identification information. After the verification is passed, the device enters the maintenance mode according to the disconnection instruction;

[0043] In maintenance mode, the device's boot trust, application trust, and file trust function modules are disabled;

[0044] The client sends the policy file to the management platform, the client performs multi-level encryption on the policy file, and the management platform establishes a secure transmission channel when sending the policy file to the device;

[0045] The device updates the trusted policy on the device according to the policy file, and performs a comprehensive validity test after the update is completed. If the test passes, the new policy is enabled. If the test fails, the original policy is rolled back and a policy update failure report is sent to the management platform;

[0046] After the device maintenance is completed, the client sends a reconnection command to the device. After the device verification is passed, the boot-up trust, application trust and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. The management platform is used to receive the change message, perform decryption and decompression operations, and update its own management database according to the change message.

[0047] Specifically, a secure transmission channel can be established when the client communicates with the management platform: the secure transmission channel between the management platform and the device renegotiates the encryption key each time a policy file is transmitted; an enhanced version of the SSL or TLS protocol is adopted and a key generation and exchange mechanism based on a hardware security module is introduced during the key exchange process.

[0048] Furthermore, the method further comprises:

[0049] In maintenance mode, the device starts an internal security monitoring subsystem built based on lightweight trusted execution environment technology, wherein the security monitoring subsystem is used to monitor the device's memory access, process activity and system call status in real time. When executing a change in the trusted policy on the device, all change operations are performed under the supervision of the security monitoring subsystem and recorded in a local, non-tamperable log storage area. At the same time, the trusted alarms and audit information generated by modifying the protected files are saved in a queue.

[0050] Furthermore, the policy file is encrypted at multiple levels, including:

[0051] The policy file is encrypted using a symmetric encryption algorithm and a key derived from a random key seed generated based on multiple factors, and asymmetric encryption is performed using the public key of the management platform.

[0052] Furthermore, before the device updates the trusted policy on the device according to the policy file, the method further includes:

[0053] The device uses a new type of hash function combined with a digital certificate to verify the source legitimacy and integrity of the policy file. If it passes, it adopts a gradual replacement method, first backing up the original policy to an independent redundant storage area, then updating the relevant module policy settings according to instructions and performing real-time compatibility testing. If there is an exception, it will roll back.

[0054] Furthermore, the content of the operation instruction recorded in the log by the device in the maintenance mode includes the operation time, operation type, and detailed information of the policy parameters involved in the operation;

[0055] Before sending the change message, the change message is compressed and encrypted.

[0056] Specifically, an efficient compression algorithm can be used to reduce the amount of data transmission, and then a symmetric encryption algorithm can be used for encryption.

[0057] Furthermore, the failure report sent by the device to the management platform after the policy update fails also includes at least one of the device's current hardware status information, network connection information, failure cause, error code, detailed test log, device current configuration information and operating status information.

[0058] The method, system, device and medium for trusted online entry and exit of a trusted DCS host computer described in the present invention can, during specific operation, place the device in maintenance mode and then perform maintenance on the device, or directly send a policy file to the device through a management platform, and the device updates the trusted policy on the device according to the policy file to achieve maintenance of the device, which is simple and convenient to operate.

[0059] The following is a further explanation of the method for trusted online entry and exit of a trusted DCS host computer provided by the embodiment of the present invention with some specific embodiments:

[0060] Embodiment 1

[0061] refer to Figure 2 The method for trusted online entry and exit of a trusted DCS host computer of the present invention comprises the following steps:

[0062] 1) Safe startup and maintenance of equipment maintenance mode;

[0063] When the DCS system needs to be upgraded and maintained, the trusted whitelist and static trusted verification policy in the trusted function will prevent the customer from modifying the applications and files on the host computer, and the upgrade cannot be completed. At this time, the client can be used to change the investment and withdrawal status of the device's trusted function. When the trusted function is invested, the host computer has an active defense function, the device security level is high, and the device cannot be changed. When the trusted function is exited, all trusted function modules on the device are no longer enabled, and the management platform will no longer be able to modify the trusted policy on the host computer. At this time, the applications and files on the device can be modified and upgraded on the host computer, and the modification and audit records of the trusted policy on the device through the command line during the disconnection period are stored in the queue. After the device reconnects to the management platform, it is taken out of the queue and reported to the trusted management platform. During the upgrade and transformation period, the application on the device is upgraded. For newly installed applications, new trusted policies will be set for the new applications, including adding to the trusted whitelist, adding dynamic trusted verification policies, preventing malicious termination of processes, and static trusted verification policies. If an unnecessary application is deleted, the trusted policy of this application needs to be deleted. These actions can be achieved by issuing policy files on the client. It is possible to update the trusted policy online, including the following steps:

[0064] 11) Instruction sending and identity verification;

[0065] The client sends a disconnection instruction to the device. Before sending the instruction, the client needs to perform a multi-stage identity pre-verification. First, the client uses the private key stored in the hardware encryption chip to digitally sign the disconnection instruction, and extracts the unique hardware identification information of the device and embeds it in the instruction. When the device receives the instruction, it first verifies the validity of the digital signature and uses the algorithm that matches the client's public key for decryption verification. If the signature is invalid, the instruction is directly rejected and the abnormal information is recorded. Next, the device compares the extracted hardware identification information with its own pre-stored legal identification list to ensure the legitimacy of the source of the instruction. Only after the digital signature and hardware identification verification are passed, the device enters maintenance mode according to the disconnection instruction.

[0066] 12) Maintenance mode features and operations;

[0067] In maintenance mode, the device's boot-up trust, application trust, and file trust function modules are in a closed state, but the device is not completely unprotected. The device starts an independent internal security monitoring subsystem, which is built on lightweight trusted execution environment technology and monitors the device's memory access, process activity, and system calls in real time. When executing a change in the trusted policy on the device, all change operations are performed under the strict supervision of the security monitoring subsystem. Each change operation is recorded in a local, non-tamperable log storage area. The log content includes detailed information such as operation time, operation type, and policy parameters involved in the operation. At the same time, the trusted alarms and audit information generated by modifying the protected files are saved in a queue. The queue uses a first-in-first-out cache mechanism. When the queue is full, the earliest information is automatically backed up to an external storage device to ensure that the information is not lost.

[0068] 2) Secure issuance and update of policy files;

[0069] 21) Policy document issuance process;

[0070] The policy file is sent to the management platform through the client. Before sending it, the client first performs multi-level encryption on the policy file. First, the content of the policy file is encrypted using a symmetric encryption algorithm (such as AES-256). The encryption key is derived from a random key seed generated by the client based on multiple factors such as the current timestamp, the device's unique identifier, and the user's login credentials. Then, the encrypted policy file is asymmetrically encrypted again and encrypted using the public key of the management platform to ensure that only the management platform can decrypt it. When the management platform receives the policy file, it first uses the private key to decrypt the outer asymmetric encryption, and then uses the symmetric decryption algorithm and key agreed with the client to decrypt the inner encrypted content to verify the integrity and authenticity of the policy file. When the management platform sends the policy file to the device, it establishes a dedicated secure transmission channel and adopts an enhanced version of the SSL / TLS protocol. This version introduces a key generation and exchange mechanism based on a hardware security module during the key exchange process to further improve transmission security.

[0071] 22) Strategy update and recovery mechanism;

[0072] The device updates the trusted policy on the device according to the policy file. Before the update, the device uses a new hash function (such as Blake2b) in the hash algorithm family to perform integrity check on the policy file, and verifies the legitimacy of the source of the policy file in combination with a digital certificate. If both the check and verification pass, the device uses a step-by-step replacement method to update the policy. First, back up the original trusted policy to an independent redundant storage area, which has tamper-proof and data recovery functions. Then, according to the instructions in the policy file, the policy settings of the relevant modules are gradually updated. When updating each module, a real-time compatibility test is performed. If an abnormality occurs in the test, the update is immediately stopped and rolled back to the previous stable state. After the update is completed, a comprehensive effectiveness test is performed on the new policy, including simulating various normal and abnormal operation scenarios for testing. If the test passes, the new policy is officially enabled. If the test fails, it rolls back to the original policy, and sends a policy update failure report to the management platform. The report contains the failure reason, error code, detailed test log, and the current configuration information and operation status information of the device.

[0073] 3) Restoration and synchronization of maintenance mode;

[0074] After the maintenance is completed, the client sends a reconnection command to the device. The reconnection command must go through an identity authentication process similar to the disconnection command, including digital signature verification and hardware identification verification. After the device passes the verification, the boot-up trust, application trust, and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. When sending the change message, the message is first compressed and encrypted, and an efficient compression algorithm (such as LZ4) is used to reduce the amount of data transmission, and then a symmetric encryption algorithm (such as ChaCha20) is used for encryption to ensure the security of message transmission. After receiving the message, the management platform performs decryption and decompression operations, and then updates its own management database according to the change message to achieve status synchronization and data consistency between the device and the management platform.

[0075] It should be noted that during the operation of the device, the policy files can be issued to update the policy on the device to deal with malicious attacks. Improving the flexible investment and withdrawal of trusted computing technology can ensure the use of trusted technology to ensure the security of the host without affecting the normal maintenance of the machine.

[0076] Embodiment 2

[0077] The present invention discloses a reliable DCS host computer reliable online input and output system, specifically as follows Figure 3 As shown, including:

[0078] The signature module is used for the client to digitally sign the instruction using the private key stored in the hardware encryption chip to obtain the disconnection instruction, which includes the unique hardware identification information of the device. The client sends the disconnection instruction to the device, and the device receives the disconnection instruction, verifies the validity of the digital signature, and compares the hardware identification information. After the verification is passed, the maintenance mode is entered according to the disconnection instruction; in the maintenance mode, the boot-up trust, application trust and file trust function modules of the device are in a closed state;

[0079] The first sending module is used to send the policy file to the management platform through the client, the client performs multi-level encryption processing on the policy file, and the management platform establishes a secure transmission channel when sending the policy file to the device;

[0080] An update module is used for updating the trusted policy on the device according to the policy file, and performing a comprehensive validity test after the update is completed. If the test passes, the new policy is enabled; if the test fails, the original policy is rolled back and a policy update failure report is sent to the management platform;

[0081] The second sending module is used for the client to send a reconnection command to the device after the device maintenance is completed. After the device verification is passed, the boot-up trust, application trust and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. The management platform is used to perform decryption and decompression operations after receiving the change message and update its own management database according to the change message.

[0082] Furthermore, in maintenance mode, the device starts an internal security monitoring subsystem built based on lightweight trusted execution environment technology, wherein the security monitoring subsystem is used to monitor the device's memory access, process activity and system call status in real time. When executing a trusted policy change on the device, all change operations are performed under the supervision of the security monitoring subsystem and recorded in a local, non-tamperable log storage area. At the same time, the trusted alarms and audit information generated by modifying the protected files are saved in a queue.

[0083] Furthermore, the policy file is encrypted at multiple levels, including:

[0084] The policy file is encrypted using a symmetric encryption algorithm and a key derived from a random key seed generated based on multiple factors, and asymmetric encryption is performed using the public key of the management platform.

[0085] Furthermore, before the device updates the trusted policy on the device according to the policy file:

[0086] The device uses a new type of hash function combined with a digital certificate to verify the source legitimacy and integrity of the policy file. If it passes, it adopts a gradual replacement method, first backing up the original policy to an independent redundant storage area, then updating the relevant module policy settings according to instructions and performing real-time compatibility testing. If there is an exception, it will roll back.

[0087] Furthermore, the content of the operation instruction recorded in the log by the device in the maintenance mode includes the operation time, operation type, and detailed information of the policy parameters involved in the operation;

[0088] Before sending the change message, the change message is compressed and encrypted.

[0089] Furthermore, the failure report sent by the device to the management platform after the policy update fails also includes at least one of the device's current hardware status information, network connection information, failure cause, error code, detailed test log, device current configuration information and operating status information.

[0090] The division of modules in the embodiments of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional module in each embodiment of the present application may be integrated into a processor, or may exist physically separately, or two or more modules may be integrated into one module. The above-mentioned integrated modules may be implemented in the form of hardware or in the form of software functional modules.

[0091] Embodiment 3

[0092] A computer device, specifically implemented as Figure 4, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for implementing the trusted online input and exit of the trusted DCS host computer are implemented, for example, including sending a disconnection instruction to the device through the client, the device receiving the disconnection instruction, being in maintenance mode according to the disconnection instruction, and performing maintenance in the maintenance mode; sending a policy file to the management platform through the client, the management platform sending the policy file to the device, and the device updating the trusted policy on the device according to the policy file. Among them, the memory may include a memory, such as a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk memory, etc.; the processor, the network interface, and the memory are interconnected through an internal bus, and the internal bus may be an industrial standard architecture bus, a peripheral component interconnection standard bus, an extended industrial standard structure bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory is used to store programs. Specifically, the program may include a program code, and the program code includes computer operation instructions. The memory may include a memory and a non-volatile memory, and provide instructions and data to the processor.

[0093] Embodiment 4

[0094] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for implementing the trusted online entry and exit of the trusted DCS host computer are implemented, for example, including sending a disconnection instruction to a device through a client, the device receiving the disconnection instruction, being in maintenance mode according to the disconnection instruction, and performing maintenance in the maintenance mode; sending a policy file to a management platform through a client, the management platform sending the policy file to the device, and the device updating the trusted policy on the device according to the policy file. Specifically, the computer-readable storage medium includes, but is not limited to, for example, volatile memory and / or non-volatile memory. The volatile memory may include random access memory (RAM) and / or cache memory (cache), etc. The non-volatile memory may include read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc.

[0095] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0096] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0097] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0098] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0099] Those skilled in the art will readily appreciate other embodiments of the present invention after considering the specification and disclosure of the invention. This application is intended to cover any variations, uses or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art that are not disclosed by the present invention. The specification and examples are to be considered exemplary only, and the true scope and spirit of the present invention are indicated by the following claims.

[0100] It should be understood that the present invention is not limited to the exact construction that has been described above and shown in the drawings and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

[0101] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any way. Any simple modification, change and equivalent structural change made to the above embodiment based on the technical essence of the present invention still falls within the protection scope of the technical solution of the present invention.

Claims

1. A method for trusted online entry and exit of a trusted DCS host computer, characterized in that: include: The client digitally signs the instruction using the private key stored in the hardware encryption chip to obtain a disconnection instruction, which includes the unique hardware identification information of the device. The client sends the disconnection instruction to the device, and the device receives the disconnection instruction, verifies the validity of the digital signature, and compares the hardware identification information. After the verification is passed, the device enters the maintenance mode according to the disconnection instruction; In maintenance mode, the device's boot trust, application trust, and file trust function modules are disabled; The client sends the policy file to the management platform, the client performs multi-level encryption on the policy file, and the management platform establishes a secure transmission channel when sending the policy file to the device; The device updates the trusted policy on the device according to the policy file, and performs a comprehensive validity test after the update is completed. If the test passes, the new policy is enabled. If the test fails, the original policy is rolled back and a policy update failure report is sent to the management platform; After the device maintenance is completed, the client sends a reconnection command to the device. After the device verification is passed, the boot-up trust, application trust and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. The management platform is used to receive the change message, perform decryption and decompression operations, and update its own management database according to the change message.

2. The method for trusted online entry and exit of a trusted DCS host computer according to claim 1 is characterized in that: The method further comprises: In maintenance mode, the device starts an internal security monitoring subsystem built based on lightweight trusted execution environment technology, wherein the security monitoring subsystem is used to monitor the device's memory access, process activity and system call status in real time. When executing a change in the trusted policy on the device, all change operations are performed under the supervision of the security monitoring subsystem and recorded in a local, non-tamperable log storage area. At the same time, the trusted alarms and audit information generated by modifying the protected files are saved in a queue.

3. The method for trusted online entry and exit of a trusted DCS host computer according to claim 1 is characterized in that: The policy file is encrypted at multiple levels, including: The policy file is encrypted using a symmetric encryption algorithm and a key derived from a random key seed generated based on multiple factors, and asymmetric encryption is performed using the public key of the management platform.

4. The method for trusted online entry and exit of a trusted DCS host computer according to claim 1 is characterized in that: Before the device updates the trusted policy on the device according to the policy file, the method further includes: The device uses a new type of hash function combined with a digital certificate to verify the source legitimacy and integrity of the policy file. If it passes, it adopts a gradual replacement method, first backing up the original policy to an independent redundant storage area, then updating the relevant module policy settings according to instructions and performing real-time compatibility testing. If there is an exception, it will roll back.

5. The method for trusted online entry and exit of a trusted DCS host computer according to claim 1 is characterized in that: The content of the operation instruction recorded in the log of the device in the maintenance mode includes the operation time, operation type, and detailed information of the policy parameters involved in the operation; Before sending the change message, the change message is compressed and encrypted.

6. The method for trusted online entry and exit of a trusted DCS host computer according to claim 1 is characterized in that: The failure report sent by the device to the management platform after the policy update fails also includes at least one of the device's current hardware status information, network connection information, failure reason, error code, detailed test log, device current configuration information and operation status information.

7. A trusted DCS host computer trusted online input and output system, characterized in that: include: The signature module is used for the client to digitally sign the instruction using the private key stored in the hardware encryption chip to obtain the disconnection instruction, which includes the unique hardware identification information of the device. The client sends the disconnection instruction to the device, and the device receives the disconnection instruction, verifies the validity of the digital signature, and compares the hardware identification information. After the verification is passed, the maintenance mode is entered according to the disconnection instruction; in the maintenance mode, the boot-up trust, application trust and file trust function modules of the device are in a closed state; The first sending module is used to send the policy file to the management platform through the client, the client performs multi-level encryption processing on the policy file, and the management platform establishes a secure transmission channel when sending the policy file to the device; An update module is used for updating the trusted policy on the device according to the policy file, and performing a comprehensive validity test after the update is completed. If the test passes, the new policy is enabled; if the test fails, the original policy is rolled back and a policy update failure report is sent to the management platform; The second sending module is used for the client to send a reconnection command to the device after the device maintenance is completed. After the device verification is passed, the boot-up trust, application trust and file trust function modules are enabled, and the change message of the trust policy and the change message of the file trust status during the maintenance period are sent. The management platform is used to perform decryption and decompression operations after receiving the change message and update its own management database according to the change message.

8. The trusted online entry and exit system of the trusted DCS host computer according to claim 7 is characterized in that: In maintenance mode, the device starts an internal security monitoring subsystem built based on lightweight trusted execution environment technology, wherein the security monitoring subsystem is used to monitor the device's memory access, process activity and system call status in real time. When executing a change in the trusted policy on the device, all change operations are performed under the supervision of the security monitoring subsystem and recorded in a local, non-tamperable log storage area. At the same time, the trusted alarms and audit information generated by modifying the protected files are saved in a queue.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method for trusted online entry and exit of a trusted DCS host computer as described in any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, the steps of the method for trusted online entry and exit of a trusted DCS host computer as claimed in any one of claims 1 to 6 are implemented.