Electric power information security system and method
By introducing hardware security modules and network security modules into the power information system, all-round protection of the physical security and network security of power equipment is achieved, complex network threats and security risks faced by the power information system are solved, and the security and reliability of the system are significantly improved.
Patent Information
- Application Number
- CN202510177701.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-16
AI Technical Summary
Existing power information systems are facing increasingly complex cyber threats, and security risks are increasing. Traditional system architectures cannot fully meet the current power system's security and expansion capabilities requirements.
A power information security system is adopted, including hardware security modules and network security modules. The hardware security module protects physical security by controlling the security chips on the power equipment. The network security module includes an identity authentication module, a data access control module, a data encryption module and a security monitoring module. Through real-time authentication, fine access control, end-to-end encryption and real-time monitoring, the security of the power information system is ensured.
It effectively protects the physical security of power equipment, prevents unauthorized access and data leakage, ensures the security of data during transmission and storage, promptly detects and deals with potential security threats, and significantly improves the overall security and reliability of power information systems.
Smart Images

Figure CN120017380A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power production safety, and in particular relates to a power information safety system and method. Background Art
[0002] In recent years, the construction of UHV AC and DC power grids has been rapidly promoted. The increasing operational complexity of large power grids and the expansion of new functions have put forward higher requirements for safety, system reliability and flexibility. The master-substation deployment and redundant configuration based on expected accidents under the traditional system architecture cannot fully meet the safety and expansion capacity requirements of the current power system. In order to achieve the daily goal of efficient energy utilization and meet the extensive needs of electricity consumers and adapt to the wide access of more distributed energy, a large number of monitoring terminals have become necessary for access and interconnection, but this also provides more network attack channels and attack methods for hostile forces. The power information system carries key business data such as power production, transmission, and distribution. Once it is damaged or attacked, it will have a serious impact on society and the economy.
[0003] Smart grid is a major project that is being vigorously promoted. An important feature of smart grid is that it can collect electricity consumption information of electricity users through the power information collection system and settle charges for electricity users through the power information collection system. The power information collection system must complete the collection of power consumption information through the network. With the widespread application of technologies such as the Internet of Things and cloud computing, the power information system faces increasingly complex network threats, such as data leakage, malicious attacks, ransomware, etc., and the security risks are increasing. Summary of the invention
[0004] Based on this, in order to solve the problem that the existing power information system is facing increasingly complex network threats and increasing security risks, the present invention provides a power information security system and method.
[0005] In order to achieve the above object, the present invention adopts the following technical solution: An electric power information security system, comprising a hardware security module and a network security module; The hardware security module protects the physical security of the power equipment by controlling the security chip on the power equipment; The network security module includes: The identity verification module includes an identity verification module, wherein the identity verification module is used to verify the identity information of the visitor; The data access control module establishes a real-time access control mechanism to verify and authorize visitor access requests in real time, thereby controlling visitor access rights; Data encryption module, used to perform end-to-end encryption on data to ensure the security of data during transmission and storage; The security monitoring module includes a real-time monitoring module, and the real-time monitoring module is used to monitor and detect the system.
[0006] A further improvement of the present invention is that the identity authentication module includes a two-factor identity authentication unit, which uses a two-factor identity authentication method to perform verification. The two-factor identity authentication method combines two of the four elements: password element, fingerprint element, SMS verification code element and hardware token.
[0007] A further improvement of the present invention is that the identity authentication module also includes a dual-level identity authentication unit, which adopts a multi-level identity authentication method for identity authentication, and the multi-level identity authentication method includes a first-level identity authentication and a second-level identity authentication, the first-level identity authentication includes password verification, gesture verification or SMS verification code, and the second-level identity authentication includes fingerprint verification, face recognition verification, pupil recognition verification or palm print recognition verification.
[0008] A further improvement of the present invention is that the data access control module includes a first access control module and a second access control module, wherein the first access control module establishes a mapping relationship between access roles and access rights and assigns visitors to different roles, thereby equipping visitors with access rights possessed by each access role; The second access control module dynamically determines the visitor's access rights to the power information by defining an access control policy and combining visitor information, wherein the visitor information includes visitor attributes, environmental factors and permission rules.
[0009] A further improvement of the present invention is that the data access control module includes an access control management module, and the access control management module includes an access list unit, an access management unit and an audit log unit; The access list unit is used to set an access control list for a visitor, and the access control list defines the access rights that a visitor or an access role has; The access management unit is used to manage the visitor's access behavior and operation behavior, and the management action includes limiting the access time and access duration of the access behavior, and limiting the information modification and information download of the operation behavior; The audit log unit is used to record the visitor's access behavior and operation behavior.
[0010] A further improvement of the present invention is that the access control module also includes a strong password policy module, an abnormal login detection module, a login audit module and a real-time access control module; The strong password policy module is used to limit visitors to set login passwords according to password setting requirements, and the password setting requirements include password length requirements, complexity requirements and password change time interval requirements; The abnormal login detection module is used to establish an abnormal login detection mechanism and monitor user login behavior, which includes login time, IP address, and login device information; The login audit module is used to record the user's login behavior; The real-time access control module is used to establish a real-time access control mechanism to perform real-time verification and authorization on the user's access request.
[0011] A further improvement of the present invention is that the data access control module also includes a strong authentication mechanism module, and the strong authentication mechanism module is used to limit the visitor to input verification information to the identity authentication module for authentication, thereby confirming the visitor's identity information.
[0012] A further improvement of the present invention is that the data encryption module includes a data transmission encryption module, a data storage encryption module and an encryption processing module: The data transmission encryption module uses an encryption protocol to encrypt and protect the power data in the power information during transmission, and the encryption protocol includes an SSL / TLS protocol; The data storage encryption module includes a data classification unit and a data encryption unit, wherein the data classification unit is used to identify and classify power information into sensitive data and non-sensitive data, and the data encryption unit is used to encrypt and store sensitive data and use an encryption algorithm to encrypt and protect the data; The encryption processing module includes: A key generation unit, used to generate a key pair, the key pair includes a public key and a private key; An encryption data unit, which encrypts the power data in the power information to be transmitted by using the public key; A transmission encryption unit transmits the encrypted power data; A decryption data unit, decrypting the received power data using the private key; The data backup encryption module is used to encrypt and protect some power information.
[0013] A further improvement of the present invention is that the network security module also includes an emergency response module; The emergency response module includes: Vulnerability remediation module, used to identify vulnerabilities, evaluate vulnerabilities, develop a vulnerability remediation plan, remediate vulnerabilities, and perform secondary verification of vulnerabilities; An incident response module for detecting incidents, assessing and classifying incident priorities, developing incident response plans, responding to incidents, and analyzing and reporting on incidents; The recovery planning module is used to define recovery objectives and strategies, develop recovery plans, perform recovery operations, verify recovery operations, and generate recovery reports.
[0014] A power information security method, based on the power information security system, comprises: The hardware security module protects the physical security of power equipment by controlling the security chip on the power equipment; The identity authentication module of the network security module verifies the identity information of the visitor through the identity authentication module; The data access control module establishes a real-time access control mechanism to verify and authorize visitor access requests in real time, thereby controlling visitor access rights; The data encryption module performs end-to-end encryption on data to ensure the security of data during transmission and storage; The security monitoring module monitors and detects the system through the real-time monitoring module.
[0015] Compared with the prior art, the present invention has at least the following beneficial technical effects: The present invention provides a power information security system and method, in which a hardware security module directly protects the physical security of power equipment by controlling a security chip on the power equipment. This control method is more direct and effective than software-level protection, and can prevent malicious attacks and illegal access at the physical level. The security chip usually has independent processing power and storage space, and does not rely on the processor and memory of the main system, so it can enhance the overall reliability and stability of the system. Even if the main system is attacked or fails, the security chip can still continue to protect key data and functions. The identity authentication module verifies the identity information of the visitor through the identity authentication module to ensure that only legitimate users can access the system. This helps prevent unauthorized access and potential malicious behavior. The data access control module verifies and authorizes the visitor's access request in real time by establishing a real-time access control mechanism. This sophisticated access control can ensure that users can only access data and functions within their authority, thereby protecting sensitive information from being leaked. The data encryption module performs end-to-end encryption on the data to ensure the security of the data during transmission and storage. This encryption method can prevent data from being stolen or tampered with during transmission, and protect the data stored in the system from being illegally accessed. The security monitoring module monitors and detects the system through the real-time monitoring module, which can promptly detect and respond to potential security threats. This real-time monitoring function helps prevent security incidents and take quick measures to respond when an incident occurs. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The present invention can be further understood from the following description in conjunction with the accompanying drawings. The components in the figures are not necessarily drawn to scale, but the emphasis is placed on illustrating the principles of the embodiments. In different views, the same reference numerals designate corresponding parts.
[0017] Figure 1 It is a structural framework diagram of the power information security system described in one embodiment of the present invention.
[0018] Description of reference numerals: 1-Hardware security module, 2-Network security module, 3-Authentication module, 4-Data access control module, 5-Data encryption module, 6-Security monitoring module, 7-Emergency response module; 31-Authentication module; 311-two-factor authentication unit, 312-two-level authentication unit; 41-first access control module, 42-second access control module, 43-access control management module; 44- strong password policy module, 45- abnormal login detection module, 46- login audit module, 47- real-time access control module, 48- strong authentication mechanism module; 431-access list unit, 432-access management unit, 433-audit log unit; 51-data transmission encryption module, 52-data storage encryption module, 53-encryption processing module; 521-data classification unit, 522-data encryption unit; 531-key generation unit, 532-encryption data unit, 533-transmission encryption unit, 534-decryption data unit; 61- Real-time monitoring module; 71-Vulnerability repair module, 72-Incident response module, 73-Recovery plan module. DETAILED DESCRIPTION
[0019] In the following, only some exemplary embodiments are briefly described. As those skilled in the art will appreciate, the described embodiments may be modified in various ways without departing from the spirit or scope of the present invention. Therefore, the drawings and descriptions are considered to be exemplary and non-restrictive in nature.
[0020] It should be understood that when used in this specification and the appended claims, the terms "include" and "comprises" indicate the presence of described features, integers, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or combinations thereof.
[0021] It should also be understood that the terms used in the present specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include plural forms.
[0022] It should be further understood that the term "and / or" used in the present description and the appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0023] Various structural schematic diagrams of the embodiments disclosed in the present invention are shown in the accompanying drawings. These figures are not drawn to scale, and some details are magnified and some details may be omitted for the purpose of clear expression. The shapes of various regions and layers shown in the figures and the relative sizes and positional relationships therebetween are only exemplary, and may deviate in practice due to manufacturing tolerances or technical limitations, and those skilled in the art may additionally design regions / layers with different shapes, sizes, and relative positions according to actual needs.
[0024] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0025] Example 1 like Figure 1 As shown, the present invention provides an electric power information security system, comprising a hardware security module 1 and a network security module 2; the hardware security module 1 protects the physical security of the electric power equipment by controlling the security chip on the electric power equipment. The network security module 2 includes: The identity verification module 3 includes an identity verification module 31, wherein the identity verification module 31 is used to verify the identity information of the visitor; Data access control module 4, through the establishment of a real-time access control mechanism, verifies and authorizes the visitor's access request in real time, thereby controlling the visitor's access rights; Data encryption module 5, used to perform end-to-end encryption on data to ensure the security of data during transmission and storage; The security monitoring module 6 includes a real-time monitoring module 61, which is used to monitor and detect the system.
[0026] The above-mentioned power information security system protects the physical security of power equipment through the hardware security module 1, authenticates the visitors of the power network security through the network security module 2 using the identity authentication module 3, limits the access rights of visitors using the data access control module 4, encrypts the data end-to-end using the data encryption module 5, and monitors and detects the system using the security monitoring module 6, thus comprehensively packaging the information security of power equipment.
[0027] In one embodiment, the identity authentication module 31 includes a two-factor identity authentication unit 311, and the two-factor identity authentication unit 311 uses a two-factor identity authentication method for authentication, and the two-factor identity authentication method combines two of the four elements of a password element, a fingerprint element, a text message verification code element, and a hardware token. In this way, by requiring visitors to provide two different types of identity authentication elements, such as a password and a text message verification code, the security of identity authentication is increased to prevent unauthorized visitors from accessing power information and causing information leakage.
[0028] In one embodiment, the identity authentication module 31 further includes a dual-level identity authentication unit 312, which uses a multi-level identity authentication method for identity authentication, and the multi-level identity authentication method includes a first-level identity authentication and a second-level identity authentication, wherein the first-level identity authentication includes password authentication, gesture authentication or SMS verification code, and the second-level identity authentication includes fingerprint authentication, face recognition authentication, pupil recognition authentication or palm print recognition authentication. In this way, the second-level identity authentication has biometric information, and the combination of the first-level identity authentication and the second-level identity authentication can effectively increase the authenticity of the identity authentication and reduce the risk of being cracked or used fraudulently.
[0029] In one embodiment, the data access control module 4 includes a first access control module 41 and a second access control module 42. The first access control module 41 establishes a mapping relationship between access roles and access rights and assigns visitors to different roles, so that visitors are equipped with access rights owned by each access role; the second access control module 42 defines access control policies and dynamically determines the visitor's access rights to power information in combination with visitor information, and the visitor information includes visitor attributes, environmental factors, and permission rules. In this way, by limiting the visitor's access rights, strict access control is performed on the power information, and only authorized visitors can access the power information with corresponding permissions, avoiding data leakage and illegal access.
[0030] In one embodiment, the data access control module 4 includes an access control management module 43, which includes an access list unit 431, an access management unit 432 and an audit log unit 433; the access list unit 431 is used to set an access control list for visitors, and the access control list limits the access rights of visitors or access roles; the access management unit 432 is used to manage the access behavior and operation behavior of visitors, and the management action includes limiting the access time and access duration of the access behavior, and limiting the information modification and information download of the operation behavior; the audit log unit 433 is used to record the access behavior and operation behavior of visitors. In this way, an access control list is set for specific power information or visitors, and it is clearly specified which visitors or access roles have the right to access the power information, so as to achieve precise control of the power information; in addition, the access time and access duration of the access behavior are limited by the access management unit 432, and the information modification and information download of the operation behavior are limited, and the audit log unit 433 is used to record the access behavior and operation behavior of visitors to ensure the overall security of the power information.
[0031] In one embodiment, the access control module 4 also includes a strong password policy module 44, an abnormal login detection module 45, a login audit module 46 and a real-time access control module 47; the strong password policy module 44 is used to limit visitors to set login passwords according to password setting requirements, and the password setting requirements include password length requirements, complexity requirements and password change time interval requirements; the abnormal login detection module 45 is used to establish an abnormal login detection mechanism and monitor user login behavior, and the login behavior includes login time, IP address, and login device information; the login audit module 46 is used to record the user's login behavior; the real-time access control module 47 is used to establish a real-time access control mechanism to perform real-time verification and authorization on the user's access request. In this way, the strong password policy module 44 limits visitors to set strong passwords, reducing the risk of login passwords being cracked and used; the abnormal login detection module 45 establishes an abnormal login detection mechanism and monitors user login behavior, 46 is used to record user login behavior, and the real-time access control module 47 establishes a real-time access control mechanism, thereby maximizing the stability of visitors' login system access to power information and preventing illegal elements from illegally accessing data.
[0032] In one embodiment, the data access control module 4 also includes a strong authentication mechanism module 48, which is used to limit visitors to input verification information into the identity authentication module for authentication, so as to prevent criminals from circumventing identity authentication and accessing power information, thereby confirming the identity information of the visitor.
[0033] In one embodiment, the data encryption module 5 includes a data transmission encryption module 51, a data storage encryption module 52 and an encryption processing module 53: the data transmission encryption module 51 uses an encryption protocol to encrypt and protect the power data in the power information during transmission, and the encryption protocol includes an SSL / TLS protocol; the data storage encryption module 52 includes a data classification unit 521 and a data encryption unit 522, the data classification unit 521 is used to identify the power information and classify it into sensitive data and non-sensitive data, the data encryption unit 522 is used to encrypt and store sensitive data and use an encryption algorithm to encrypt and protect the data; the encryption processing module 53 includes: A key generation unit 531 is used to generate a key pair, the key pair includes a public key and a private key; An encryption data unit 532, encrypting the power data in the power information to be transmitted by using the public key; A transmission encryption unit 533 transmits the encrypted power data; The data decryption unit 534 decrypts the received power data using the private key.
[0034] In this way, the power data in the entire communication process is encrypted and protected, and only the sender and the receiver can access the power data, thereby playing the role of encrypting and protecting the power data in the power information during the transmission process.
[0035] In one embodiment, the encryption processing module 53 further includes a key exchange unit, which securely exchanges keys between the communicating parties through a key exchange protocol. The key exchange protocol includes Diffie-Hellman key exchange and Elliptic Curve Diffie-Hellman (ECDH) key exchange. The key exchange protocol allows the communicating parties to negotiate a shared symmetric key without third-party intervention, thereby completing end-to-end power data transmission.
[0036] In one embodiment, the data encryption module 5 also includes a data backup encryption module 54, which is used to encrypt and protect part of the power information. Specifically, the data backup encryption module 54 includes the following steps during operation: 1. Determine the encryption requirements: determine which power data needs to be backed up and encrypted. The scope of encryption can be determined according to the sensitivity of the data and regulatory requirements; 2. Select an encryption algorithm: select a suitable encryption algorithm to encrypt the backup data. Common encryption algorithms include symmetric encryption algorithms (such as AES) and asymmetric encryption algorithms (such as RSA); 3. Generate keys: generate keys for encrypting and decrypting backup data according to the selected encryption algorithm. Symmetric encryption algorithms use the same key, while asymmetric encryption algorithms use a pair of keys (public key and private key); 4. Encrypt backup data: encrypt the backup data using the generated key. Specialized encryption software or libraries can be used to implement the encryption process to ensure reasonable encryption parameters and secure key management. 5. Key management: properly manage and protect the generated keys. The key should be stored in a secure location and only authorized operators can access it; 6. Transmit and store encrypted data: Transmit the encrypted backup data to a secure storage medium or remote server to ensure the security of the encrypted data during transmission. Secure transmission protocols such as TLS can be used to protect the data. 7. Decrypt backup data: When the backup data needs to be restored, the encrypted data is decrypted using the corresponding key to ensure that only authorized operators can access the decrypted data; 8. Monitoring and auditing: Regularly monitor the operating status of the backup encryption system to ensure the effectiveness and security of the encryption process. Conduct audits to check for abnormal activities or security vulnerabilities; 9. Update keys: Update keys regularly to improve data security. Key updates can be performed based on security policies or actual needs. 10. Disaster recovery testing: Perform disaster recovery testing regularly to verify the integrity and recoverability of backup data. Ensure the correctness of the encryption and decryption process, and check whether the backup data can be successfully restored.
[0037] In one embodiment, the network security module 2 further includes an emergency response module 7; the emergency response module 7 includes: a vulnerability repair module 71, for identifying vulnerabilities, evaluating vulnerabilities, developing a vulnerability repair plan, repairing vulnerabilities, and performing secondary verification of vulnerabilities; An incident response module 72 for detecting incidents, assessing and classifying incident priorities, developing incident response plans, responding to incidents, and analyzing and reporting incidents; The recovery plan module 73 is used to define recovery objectives and strategies, formulate recovery plans, perform recovery operations, verify recovery operations, and generate recovery reports.
[0038] In this way, the vulnerability repair module 71, the event response module 72 and the recovery plan module 73 are used to repair the vulnerability, respond to the power information intrusion incident, and restore the damaged or lost power information in turn, thereby preventing the power equipment from being maliciously invaded during use and affecting the power safety; at the same time, by following the pre-established procedures and best practices, and conducting regular drills and evaluations, the effectiveness and timeliness of the emergency response are ensured.
[0039] Example 2 The present invention provides a power information security method, comprising: The hardware security module protects the physical security of power equipment by controlling the security chip on the power equipment; The identity authentication module of the network security module verifies the identity information of the visitor through the identity authentication module; The data access control module establishes a real-time access control mechanism to verify and authorize visitor access requests in real time, thereby controlling visitor access rights; The data encryption module performs end-to-end encryption on data to ensure the security of data during transmission and storage; The security monitoring module monitors and detects the system through the real-time monitoring module.
[0040] In summary, the present invention controls the security chip on the power equipment through the hardware security module, and this method provides physical security protection. Hardware-level security measures are often more difficult to crack than software-level measures, so they can more effectively protect the physical security of power equipment. The identity authentication module in the network security module can verify the identity information of the visitor, which helps to prevent unauthorized access. This identity authentication mechanism is the first line of defense to ensure the security of the system and can greatly reduce potential security risks. The data access control module verifies and authorizes the visitor's access request in real time by establishing a real-time access control mechanism. This sophisticated access control can ensure that only authorized users can access sensitive data or perform key operations, thereby further enhancing the security of the system. The data encryption module encrypts the data end-to-end, which ensures the security of the data during transmission and storage. Even if the data is intercepted during transmission, since it has been encrypted, the attacker cannot easily obtain the sensitive information therein. The security monitoring module monitors and detects the system through a real-time monitoring module, which helps to promptly discover and respond to potential security threats. Comprehensive security monitoring can ensure that the system is under control at all times, thereby minimizing security risks.
[0041] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic features of the present invention. Therefore, no matter from which point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the attached claims rather than the above description, and it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present invention. Any figure mark in the claims should not be regarded as limiting the claims involved.
[0042] In addition, it should be understood that although this specification is described in accordance with the implementation modes, not every implementation mode contains only one independent technical solution. This description of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation modes that can be understood by those skilled in the art. The above content is only to illustrate the technical idea of the present invention, and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution according to the technical idea proposed by the present invention shall fall within the protection scope of the claims of the present invention.
Claims
1. A power information security system, characterized in that: Including hardware security module and network security module; The hardware security module protects the physical security of the power equipment by controlling the security chip on the power equipment; The network security module includes: The identity verification module includes an identity verification module, wherein the identity verification module is used to verify the identity information of the visitor; The data access control module establishes a real-time access control mechanism to verify and authorize visitor access requests in real time, thereby controlling visitor access rights; Data encryption module, used to perform end-to-end encryption on data to ensure the security of data during transmission and storage; The security monitoring module includes a real-time monitoring module, and the real-time monitoring module is used to monitor and detect the system.
2. The power information security system according to claim 1, characterized in that: The identity authentication module includes a two-factor identity authentication unit, which uses a two-factor identity authentication method for verification. The two-factor identity authentication method combines two of the four factors: a password factor, a fingerprint factor, a text message verification code factor, and a hardware token.
3. The power information security system according to claim 1, characterized in that: The identity authentication module also includes a two-level identity authentication unit, which uses a multi-level identity authentication method for identity authentication. The multi-level identity authentication method includes a first-level identity authentication and a second-level identity authentication. The first-level identity authentication includes password verification, gesture verification or SMS verification code, and the second-level identity authentication includes fingerprint verification, face recognition verification, pupil recognition verification or palm print recognition verification.
4. The power information security system according to claim 1, characterized in that: The data access control module includes a first access control module and a second access control module. The first access control module establishes a mapping relationship between access roles and access rights and assigns visitors to different roles, so that the visitors are equipped with access rights owned by each access role. The second access control module dynamically determines the visitor's access rights to the power information by defining an access control policy and combining visitor information, wherein the visitor information includes visitor attributes, environmental factors, and permission rules.
5. The power information security system according to claim 4, characterized in that: The data access control module includes an access control management module, and the access control management module includes an access list unit, an access management unit and an audit log unit; The access list unit is used to set an access control list for a visitor, and the access control list defines the access rights that a visitor or an access role has; The access management unit is used to manage the visitor's access behavior and operation behavior, and the management action includes limiting the access time and access duration of the access behavior, and limiting the information modification and information download of the operation behavior; The audit log unit is used to record the visitor's access behavior and operation behavior.
6. The power information security system according to claim 4, characterized in that: The access control module also includes a strong password policy module, an abnormal login detection module, a login audit module and a real-time access control module; The strong password policy module is used to limit visitors to set login passwords according to password setting requirements, and the password setting requirements include password length requirements, complexity requirements and password change time interval requirements; The abnormal login detection module is used to establish an abnormal login detection mechanism and monitor user login behavior, which includes login time, IP address, and login device information; The login audit module is used to record the user's login behavior; The real-time access control module is used to establish a real-time access control mechanism to perform real-time verification and authorization on the user's access request.
7. The power information security system according to claim 4, characterized in that: The data access control module also includes a strong authentication mechanism module, which is used to limit visitors to input verification information to the identity authentication module for authentication, thereby confirming the identity information of the visitor.
8. The power information security system according to claim 1, characterized in that: The data encryption module includes a data transmission encryption module, a data storage encryption module and an encryption processing module: The data transmission encryption module uses an encryption protocol to encrypt and protect the power data in the power information during transmission, and the encryption protocol includes an SSL / TLS protocol; The data storage encryption module includes a data classification unit and a data encryption unit, wherein the data classification unit is used to identify and classify power information into sensitive data and non-sensitive data, and the data encryption unit is used to encrypt and store sensitive data and use an encryption algorithm to encrypt and protect the data; The encryption processing module includes: A key generation unit, used to generate a key pair, the key pair includes a public key and a private key; An encryption data unit, which encrypts the power data in the power information to be transmitted by using the public key; A transmission encryption unit transmits the encrypted power data; A decryption data unit, decrypting the received power data using the private key; The data backup encryption module is used to encrypt and protect some power information.
9. The power information security system according to claim 1, characterized in that: The network security module also includes an emergency response module; The emergency response module includes: Vulnerability remediation module, used to identify vulnerabilities, evaluate vulnerabilities, develop a vulnerability remediation plan, remediate vulnerabilities, and perform secondary verification of vulnerabilities; An incident response module for detecting incidents, assessing and classifying incident priorities, developing incident response plans, responding to incidents, and analyzing and reporting on incidents; The recovery planning module is used to define recovery objectives and strategies, develop recovery plans, perform recovery operations, verify recovery operations, and generate recovery reports.
10. A power information security method, characterized in that: The method is based on a power information security system according to any one of claims 1 to 9, comprising: The hardware security module protects the physical security of power equipment by controlling the security chip on the power equipment; The identity authentication module of the network security module verifies the identity information of the visitor through the identity authentication module; The data access control module establishes a real-time access control mechanism to verify and authorize visitor access requests in real time, thereby controlling visitor access rights; The data encryption module performs end-to-end encryption on data to ensure the security of data during transmission and storage; The security monitoring module monitors and detects the system through the real-time monitoring module.
Citation Information
Patent Citations
Reset and self-destruction management system for security chip
CN104268487A
Zero-trust-based power Internet of Things security protection method
CN112507317A
ERP (Enterprise Resource Planning) system access control method and platform
CN117370953A
Internet of Things equipment security detection system and method
CN117375996A
Power equipment security key fob and system
CN210578594U
Cited By
Data transmission system and method, electronic device, medium and program product
CN120263540A