Method and related device for recovering protection file of trusted DCS (Distributed Control System)
By regularly judging protection file tampering in a trusted DCS system and performing recovery operations, the problem of timely recovery of protection files in the prior art is solved, and the stability of production operation and security of protection files are achieved.
Patent Information
- Application Number
- CN202510063140.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art cannot promptly recover protection files caused by tampering, loss or damage in a trusted DCS system, resulting in production interruptions and stability affected.
By regularly determining whether the protection files in the trusted DCS system are tampered with, recording and closing the process of using tampered protection files, completely deleting the tampered protection files, replacing the backup protection files to their original location, and finally restoring the closed process.
It realizes timely recovery after tampering with protection files, reduces the impact on trusted DCS systems, ensures the stability of production operation, and ensures that the recovered protection files are not tampered with by encryption and SM3 value comparison.
Smart Images

Figure CN120011138A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of data processing of a trusted DCS system, and in particular relates to a method for restoring a protected file of a trusted DCS system and a related device. Background Art
[0002] Trusted DCS systems play a key role in industrial production, responsible for monitoring and controlling the production process, ensuring the normal operation of equipment and production efficiency. The protection files in the trusted DCS system are crucial to the normal operation of the trusted DCS system and production decisions. Once the protection files are lost or damaged (that is, it is believed that the protection files have been tampered with), it will cause production interruption, data loss or leakage, bring serious losses and risks, and affect the stability of production operations. However, at present, the existing technology is unable to restore the lost or damaged protection files in a trusted DCS system in a timely manner after the protection files are lost or damaged, resulting in the stability of production operations being affected. Summary of the invention
[0003] In order to solve the problems existing in the prior art, the purpose of the present invention is to provide a method and related device for recovering protected files of a trusted DCS system. The present invention can promptly recover lost or damaged protected files after the protected files are tampered with in the trusted DCS system to ensure the stability of production operation.
[0004] To achieve the above purpose, the technical solution adopted by the present invention is as follows: A method for restoring protected files of a trusted DCS system includes the following steps: Regularly determine whether the protected files in the trusted backup configuration files in the trusted DCS system have been tampered with; When it is determined that the protected file has been tampered with, the information of the process using the tampered protected file is recorded, and the process using the tampered protected file is closed; When the process using the tampered protected file is closed, the tampered protected file will be completely deleted; When the tampered protection file is completely deleted, the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file; When the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file, the closed process using the tampered protection file is restored according to the information of the process using the tampered protection file.
[0005] Preferably, the process of periodically determining whether a protected file in a trusted backup configuration file in a trusted DCS system has been tampered with includes: Regularly calculate the SM3 value of the protection file in the trusted backup configuration file to obtain the SM3 calculation value of the protection file; The calculated SM3 value of the protection file is compared with the SM3 value of the protection file saved in the established database. If the calculated SM3 value of the protection file is inconsistent with the SM3 value of the protection file in the database, it is considered that the protection file has been tampered with.
[0006] Preferably, when it is determined that the protected file has been tampered with, the information of the process using the tampered protected file is recorded, and the process of closing the process using the tampered protected file includes: Check the tampered protection file to determine whether any process in the trusted DCS system is using the tampered protection file. If any process is using the tampered protection file, record the information of the process using the tampered protection file. After recording the information of the process using the tampered protection file, the process closing command of the platform system where the trusted DCS system is located is called to close the process using the tampered protection file.
[0007] Preferably, the tampered protected files are completely deleted, including: The delete command of the platform system where the trusted DCS system is located is called to completely delete the tampered protection file.
[0008] Preferably, after the tampered protection file is completely deleted, the backup protection file corresponding to the tampered protection file is replaced at the location of the tampered protection file, including: Read the encrypted backup protection file corresponding to the tampered protection file; Decrypting the encrypted backup protection file to obtain a decrypted backup protection file; The SM3 value of the decrypted backup protection file is compared with the SM3 value of the backup protection file in the database. When the SM3 value of the decrypted backup protection file is equal to the SM3 value of the backup protection file in the data, the decrypted backup protection file is replaced to the location of the tampered protection file.
[0009] Preferably, the method for restoring protected files of the above-mentioned trusted DCS system of the present invention further includes a backup process of the protected files: Write the path of the protected file to be protected into the trusted backup configuration file; When the trusted DCS system is started, check whether there is a trusted backup configuration file in the configuration file path of the trusted DCS system; When a trusted backup configuration file exists under the configuration file path, the trusted backup configuration file is read to obtain information in the trusted backup configuration file; and the SM3 value of the protected file is calculated and stored in the database; According to the information in the trusted backup configuration file, the configuration information of each protected file is read and a globally unique object identifier is generated. The object identifier and the configuration information of the protected file are stored in the database; the protected file is encrypted using a trusted chip to obtain a backup protected file; Save the backup protection file, and save the file name and path of the backup protection file in the database.
[0010] The present invention also provides a system for restoring protected files of a trusted DCS system, which is used to implement the method for restoring protected files of the trusted DCS system of the present invention, comprising: Judgment module: used to periodically judge whether the protected files in the trusted backup configuration files in the trusted DCS system have been tampered with; Execution module: when it is determined that the protected file has been tampered with, it records the information of the process using the tampered protected file and closes the process using the tampered protected file; Deletion module: used to completely delete the tampered protected file after the process using the tampered protected file is closed; Replacement module: used to replace the backup protection file corresponding to the tampered protection file with the location of the tampered protection file after the tampered protection file is completely deleted; Recovery module: used to restore the closed process using the tampered protection file according to the information of the process using the tampered protection file after the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file.
[0011] The present invention also provides an electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method for recovering protected files of the trusted DCS system as described above in the present invention.
[0012] The present invention also provides a storage medium on which a computer program is stored, wherein the computer program, when executed by a processor, implements the method for recovering protected files of a trusted DCS system as described above.
[0013] The present invention also provides a computer program product, which includes computer instructions, and is characterized in that the computer instructions instruct a computer to execute the method for recovering protected files of a trusted DCS system as described above.
[0014] The present invention has the following beneficial effects: The protection file recovery method of the trusted DCS system of the present invention can quickly recover abnormal protection files, and can quickly recover complete protection files when the protection files are damaged or maliciously tampered with, thereby reducing the impact on the trusted DCS system; at the same time, the present invention can handle other processes that are using abnormal protection files, thereby preventing the protection files from being occupied and causing recovery failure.
[0015] Furthermore, when the present invention replaces the backup protection file corresponding to the tampered protection file to the location of the tampered protection file, the SM3 value of the decrypted backup protection file is compared with the SM3 value of the backup protection file in the database, ensuring that the restored protection file is not tampered with, thereby ensuring the security of the trusted DCS system.
[0016] Furthermore, the backup process of protected files provided by the present invention uses a trusted chip to encrypt the protected files when backing up the protected files, thereby ensuring the integrity and confidentiality of the protected files, preventing malicious modification of the backup protected files, effectively responding to various unexpected situations, and ensuring the security and reliability of system data. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 The figure is a flow chart of a method for recovering protected files of a trusted DCS system of the present invention. DETAILED DESCRIPTION
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0019] Example 1 The method for restoring protected files of the trusted DCS system of this embodiment includes the following steps: S1, the file protection process in the trusted DCS system calculates the SM3 value of the protection file in the trusted backup configuration file according to the measurement time interval of each trusted backup configuration file, and obtains the SM3 calculated value of the protection file; compares the SM3 calculated value of the protection file with the SM3 value of the protection file stored in the database. If the SM3 calculated value of the protection file is consistent with the SM3 value of the protection file in the database, it is considered that the protection file has not been tampered with; when the SM3 calculated value of the protection file is inconsistent with the SM3 value of the protection file in the database, it is considered that the protection file has been tampered with, and the tampered protection file is considered to be an abnormal protection file; S2, when the protected file is tampered with, the mechanism for restoring the protected file is immediately started; in this step, when the protected file is tampered with, the file protection process can also generate an alarm and report it to the alarm window of the trusted DCS system, and remind through a pop-up window.
[0020] S3, after starting the mechanism for restoring protected files, the file protection process uses the viewing command to view the abnormal protected files, and determines whether there are processes in the trusted DCS system that are using the abnormal protected files. If there are processes that are using the abnormal protected files, the information of the processes that are using the abnormal protected files is recorded, and the file protection process calls the process closing command of the platform system where the trusted DCS system is located to close the process that is using the abnormal protected files. In this step, the platform system where the trusted DCS system is located can use the Linux system, Windows or Mac system; when the platform system where the trusted DCS system is located uses the Linux system, in the above scheme, the file protection process uses the lsof command to view the abnormal protected files, and when closing the process that is using the abnormal protected files, the kill command of the Linux system is used to close the process that is using the abnormal protected files. In addition, in the above scheme, the information of the process of the abnormal protected files includes the name of the process, the PID number and the startup parameters.
[0021] S4, when the process that is using the abnormal protection file is closed, the file protection process calls the delete command of the platform system where the trusted DCS system is located to completely delete the abnormal protection file; in this step, when the platform system where the trusted DCS system is located adopts the Linux system, the file protection process calls the delete command rm of the Linux system to completely delete the abnormal protection file; S5. When the tampered protection file is completely deleted, the file protection process reads the encrypted backup protection file corresponding to the OID and the abnormal protection file from the database, and the file protection process calls the trusted chip to decrypt the backup protection file to obtain the decrypted backup protection file; then the SM3 value of the decrypted backup protection file is compared with the SM3 value of the backup protection file in the database. When the SM3 value of the decrypted backup protection file is equal to the SM3 value of the backup protection file in the data, the decrypted backup protection file is replaced to the location of the abnormal protection file.
[0022] S5, when the decrypted backup protection file is replaced to the location of the abnormal protection file, the file protection process restores the process that uses the abnormal protection file that was closed in S3.
[0023] In the above solution of the present invention, the backup process of the protection file includes the following steps: Step 1, write the path of the protected file to be protected into a trusted backup configuration file (such as trust_backup.josn); wherein the trusted backup configuration file is configured with protection parameters, and the protection parameters include: the protected file path, whether to alarm, the measurement time interval, and whether to block; Step 2: After the trusted DCS system is started, the file protection process first detects whether there is a trusted backup configuration file under the configuration file path of the trusted DCS system (such as / etc / trust_config / ). If there is a trusted backup configuration file, the file protection process reads the trusted backup configuration file to obtain the information in the trusted backup configuration file. The file protection process reads the configuration information of each protected file based on the information in the trusted backup configuration file, generates a globally unique OID (i.e., object identifier), and stores the OID and the configuration information of the protected file in the database.
[0024] When the file protection process is reading the trusted backup configuration file, a multi-threaded SM3 value of the protection file is started, the SM3 value of the protection file is calculated, and the SM3 value of the protection file is stored in the database.
[0025] Step 3: The file protection process starts the encrypted backup multi-thread, encrypts the protected file using the trusted chip, saves the encrypted protected file, and saves the file name and path of the encrypted protected file in the database.
[0026] It can be seen from the above scheme that the present invention utilizes the characteristics of the trusted DCS system to achieve secure storage and reliable recovery of protected files. This method can not only effectively prevent the risk of loss or damage of protected files, but also ensure the integrity and confidentiality of protected files. By using encryption technology to protect the security of backup protected files, various unexpected situations can be effectively dealt with to ensure the security and reliability of data. In addition, the present invention also provides a function of quickly restoring protected files, which can quickly restore the integrity of protected files when protected files are lost, damaged or maliciously tampered with, reducing the impact of trusted DCS system failures on work.
[0027] In addition, an embodiment of the present invention further provides a system for implementing the method for restoring protected files of the above-mentioned trusted DCS system of the present invention, the system comprising: Judgment module: used to periodically judge whether the protected files in the trusted backup configuration files in the trusted DCS system have been tampered with; Execution module: when it is determined that the protected file has been tampered with, it records the information of the process using the tampered protected file and closes the process using the tampered protected file; Deletion module: used to completely delete the tampered protected file after the process using the tampered protected file is closed; Replacement module: used to replace the backup protection file corresponding to the tampered protection file with the location of the tampered protection file after the tampered protection file is completely deleted; Recovery module: used to restore the closed process using the tampered protection file according to the information of the process using the tampered protection file after the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file.
[0028] The process of the judgment module periodically judging whether the protected file in the trusted backup configuration file in the trusted DCS system has been tampered with includes: According to the measurement time interval of each trusted backup configuration file, the SM3 value of the protection file in the trusted backup configuration file is calculated regularly to obtain the SM3 calculated value of the protection file; the SM3 calculated value of the protection file is compared with the SM3 value of the protection file saved in the database. If the SM3 calculated value of the protection file is consistent with the SM3 value of the protection file in the database, it is considered that the protection file has not been tampered with; when the SM3 calculated value of the protection file is inconsistent with the SM3 value of the protection file in the database, it is considered that the protection file has been tampered with.
[0029] The process of the replacement module replacing the backup protection file corresponding to the tampered protection file to the location of the tampered protection file includes: Read the encrypted backup protection file corresponding to the OID and the abnormal protection file from the database, and call the trusted chip to decrypt the backup protection file to obtain the decrypted backup protection file; then compare the SM3 value of the decrypted backup protection file with the SM3 value of the backup protection file in the database. When the SM3 value of the decrypted backup protection file is equal to the SM3 value of the backup protection file in the data, replace the decrypted backup protection file with the location of the abnormal protection file.
[0030] The embodiment of the present invention also provides a system for implementing the backup process of the above-mentioned protected files, the system comprising: Writing unit: used to write the path of the protected file to be protected into the trusted backup configuration file; Detection unit: used to detect whether there is a trusted backup configuration file in the configuration file path of the trusted DCS system after the trusted DCS system is started; Calculation unit: used for reading the trusted backup configuration file when there is a trusted backup configuration file under the configuration file path, obtaining the information in the trusted backup configuration file; calculating the SM3 value of the protection file, and storing the SM3 value of the protection file in the database; Generation and encryption unit: used to read the configuration information of each protected file according to the information in the trusted backup configuration file, generate a globally unique object identifier, and store the object identifier and the configuration information of the protected file in the database; encrypt the protected file using the trusted chip to obtain the backup protected file; Storage unit: used to save the backup protection file, and save the file name and path of the backup protection file in the database.
[0031] An embodiment of the present invention further provides a computer program product, the computer program product comprising computer instructions, the computer instructions instructing a computer to execute the method for restoring protected files of the trusted DCS system.
[0032] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0033] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0034] The present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, readable storage media, optical storage, etc.) containing computer-usable program codes.
[0035] Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0036] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A method for restoring protected files of a trusted DCS system, characterized in that: The process includes the following: Regularly determine whether the protected files in the trusted backup configuration files in the trusted DCS system have been tampered with; When it is determined that the protected file has been tampered with, the information of the process using the tampered protected file is recorded, and the process using the tampered protected file is closed; When the process using the tampered protected file is closed, the tampered protected file will be completely deleted; When the tampered protection file is completely deleted, the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file; When the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file, the closed process using the tampered protection file is restored according to the information of the process using the tampered protection file.
2. The method for restoring protected files of a trusted DCS system according to claim 1, characterized in that: The process of periodically judging whether the protected file in the trusted backup configuration file in the trusted DCS system has been tampered with includes: Regularly calculate the SM3 value of the protection file in the trusted backup configuration file to obtain the SM3 calculation value of the protection file; The calculated SM3 value of the protection file is compared with the SM3 value of the protection file saved in the established database. If the calculated SM3 value of the protection file is inconsistent with the SM3 value of the protection file in the database, it is considered that the protection file has been tampered with.
3. The method for restoring protected files of a trusted DCS system according to claim 1, characterized in that: When it is determined that the protected file has been tampered with, information about the process using the tampered protected file is recorded, and the process of closing the process using the tampered protected file includes: Check the tampered protection file to determine whether any process in the trusted DCS system is using the tampered protection file. If any process is using the tampered protection file, record the information of the process using the tampered protection file. After recording the information of the process using the tampered protection file, the process closing command of the platform system where the trusted DCS system is located is called to close the process using the tampered protection file.
4. The method for restoring protected files of a trusted DCS system according to claim 1, characterized in that: Completely delete the tampered protected files, including: The delete command of the platform system where the trusted DCS system is located is called to completely delete the tampered protection file.
5. The method for restoring protected files of a trusted DCS system according to claim 1, characterized in that: When the tampered protection file is completely deleted, the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file, including: Read the encrypted backup protection file corresponding to the tampered protection file; Decrypting the encrypted backup protection file to obtain a decrypted backup protection file; The SM3 value of the decrypted backup protection file is compared with the SM3 value of the backup protection file in the database. When the SM3 value of the decrypted backup protection file is equal to the SM3 value of the backup protection file in the data, the decrypted backup protection file is replaced to the location of the tampered protection file.
6. The method for restoring protected files of a trusted DCS system according to claim 1, characterized in that: Also includes backup procedures to protect your files: Write the path of the protected file to be protected into the trusted backup configuration file; When the trusted DCS system is started, check whether there is a trusted backup configuration file in the configuration file path of the trusted DCS system; When a trusted backup configuration file exists in the configuration file path, the trusted backup configuration file is read to obtain information in the trusted backup configuration file; And calculate the SM3 value of the protected file, and store the SM3 value of the protected file in the database; According to the information in the trusted backup configuration file, the configuration information of each protected file is read, and a globally unique object identifier is generated, and the object identifier and the configuration information of the protected file are stored in the database; Use a trusted chip to encrypt the protected file and obtain a backup protected file; Save the backup protection file, and save the file name and path of the backup protection file in the database.
7. A system for restoring protected files of a trusted DCS system, characterized in that: include: Judgment module: used to periodically judge whether the protected files in the trusted backup configuration files in the trusted DCS system have been tampered with; Execution module: when it is determined that the protected file has been tampered with, it records the information of the process using the tampered protected file and closes the process using the tampered protected file; Deletion module: used to completely delete the tampered protected file after the process using the tampered protected file is closed; Replacement module: used to replace the backup protection file corresponding to the tampered protection file with the location of the tampered protection file after the tampered protection file is completely deleted; Recovery module: used to restore the closed process using the tampered protection file according to the information of the process using the tampered protection file after the backup protection file corresponding to the tampered protection file is replaced to the location of the tampered protection file.
8. An electronic device, characterized in that: include: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method for recovering protected files of a trusted DCS system according to any one of claims 1 to 6.
9. A storage medium, characterized in that: A computer program is stored thereon, wherein when the computer program is executed by a processor, the method for recovering protected files of a trusted DCS system according to any one of claims 1 to 6 is implemented.
10. A computer program product, comprising computer instructions, characterized in that: The computer instructions instruct the computer to execute the method for recovering protected files of a trusted DCS system according to any one of claims 1 to 6.
Citation Information
Cited By
Method and system for recovering protected file of trusted DCS system, and electronic device, storage medium and computer program product
WO2026152610A1