Real-time operation permission allocation method, device and equipment for trusted DCS (Distributed Control System) controller and storage medium

By dynamically adjusting the permissions of computing tasks in real-time in the DCS controller, combining triggered and monitored security policies, the problems of vulnerability and permission fixed by DCS controllers are solved, achieving higher security and flexibility.

CN120046155APending Publication Date: 2025-05-27XIAN THERMAL POWER RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510069840.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

DCS controllers are susceptible to attacks when performing various operations. Due to fixed permissions, once the operation is attacked, it will affect the progress of the operation and even threaten the security of the entire DCS system.

Method used

A trusted DCS controller real-time operation permission allocation method is adopted, including defining operation permissions for operation tasks in the initial operation stage, conducting security assessments for each operation task, formulating triggered and monitored security policies, and dynamically adjusting permissions to prevent unauthorized access and malicious attacks.

Benefits of technology

By introducing a refined permission management mechanism, we ensure that each computing task can only be executed within the scope of authorization, effectively prevent unauthorized access and malicious attacks, improve the endogenous security protection capabilities of the control system, and improve the security and flexibility of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046155A_ABST
    Figure CN120046155A_ABST
Patent Text Reader

Abstract

The invention discloses a trusted DCS controller real-time operation permission allocation method, device and equipment and a storage medium, and belongs to the technical field of trusted DCS. According to the method, in the initial operation stage of a DCS controller, the authority level of an operation task is defined, and a reference value measured by the DCS controller for the operation task is stored in a TPM chip; in the execution process of the operation task, whether the reference value and the metric value of the operation task are consistent or not is compared, if yes, it is determined that the operation task is credible, if yes, continuous monitoring is conducted, otherwise, it is determined that the operation task is not credible, the permission level of the operation task is modified, and the information that the operation task is not credible is uploaded to the credible management platform. According to the method, a refined authority management mechanism is introduced, the authority can be dynamically distributed and adjusted according to the requirements and security strategies of the real-time operation tasks, it is ensured that each operation task can only be executed within the authorization range, and therefore the security and flexibility of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of trusted DCS, and particularly relates to a method, device, equipment, and storage medium for real-time operation permission allocation of a trusted DCS controller. Background Art

[0002] In the power industry, the distributed control system (DCS), as the core computer control system, plays a crucial role in monitoring and controlling all aspects of the power production process. The reliability, security, and real-time performance of the DCS controller are directly related to the stable operation of the power system and the power supply quality, and are of great significance for ensuring energy security and social and economic stability.

[0003] However, with the rapid development of information technology, cyber security threats have become increasingly complex and changeable. In recent years, ransomware attacks have not only targeted the information systems of individuals and enterprises, but also shifted their targets to critical infrastructure related to national economy and people's livelihood, such as the power system.

[0004] Traditional network security protection measures, such as firewalls, intrusion detection systems, and virus prevention software, although can resist some network attacks to a certain extent, are powerless in the face of advanced persistent threats (APT), zero-day vulnerability exploitation, and complex and changeable ransomware attacks. These passive defense mechanisms of the "old three" can often only block and kill after an attack occurs, and it is difficult to effectively warn and actively defend before an attack occurs.

[0005] Due to the wide range of controlled devices, multiple levels, and real-time operation of the DCS controller, it is vulnerable to attacks at any time when performing various operations; however, the permissions of various operations are fixed at the initial stage of operation, so once an operation is attacked, it will affect the progress of the operation and even may threaten the security of the entire DCS system. Summary of the Invention

[0006] The purpose of the present invention is to overcome the above-mentioned shortcomings of the prior art and provide a method, device, equipment, and storage medium for real-time operation permission allocation of a trusted DCS controller to solve the problem that the DCS controller in the prior art is vulnerable to attacks at any time when performing various operations.

[0007] To achieve the above purpose, the present invention adopts the following technical solutions: A method for real-time operation permission allocation of a trusted DCS controller includes the following steps: S1. In the initial operation stage of the DCS controller, define the operation permissions of the operation tasks; S2. Conduct a security assessment on each operation task and formulate corresponding security policies, where the security policies include trigger-based security policies and monitoring-based security policies; S3. For the computing tasks subject to the trigger-based security policy, when the computing task is invaded, an alarm is issued and S4 is executed; for the computing tasks subject to the monitoring-based security policy, the computing tasks are periodically verified for trustworthiness, and if they are untrusted, S4 is executed. S4. Modify the operation permission level of the computing task and upload the untrusted information of the computing task to the trusted management platform.

[0008] A further improvement of the present invention lies in: Preferably, in S1, the operation permissions include read-write, write, and execute.

[0009] Preferably, in S1, the DCS controller stores the reference values of each operation of the computing task in the TPM chip.

[0010] Preferably, in S2, the process of performing a security assessment on each computing task is as follows: analyze the data accessed by the computing task and the object targeted by the executed operation, determine the resulting security risks, and formulate a security policy.

[0011] Preferably, the trigger-based security policy includes static, subject-object security policy, whitelist security policy, and blacklist security policy.

[0012] Preferably, in S4, during the periodic verification of the trustworthiness of the computing task, if the computing task exceeds its permissions or is untrusted, revoke the permissions of the computing task or downgrade the permission level of the computing task.

[0013] Preferably, in S5, the modification of the operation permission level of the computing task is to stop the untrusted operations of the computing task and continue to execute the trusted operations of the computing task.

[0014] A trusted DCS controller operation permission allocation device includes: A definition module, used to define the operation permissions of the computing task during the initial operation stage of the DCS controller; An evaluation module, used to perform a security assessment on each computing task and formulate a corresponding security policy, where the security policy includes a trigger-based security policy and a monitoring-based security policy; A judgment module, used to execute the trigger-based security policy for the computing task. When the computing task is invaded, an alarm is issued and the processing module is executed; for the computing task that executes the monitoring-based security policy, the computing task is periodically verified for trustworthiness, and if it is untrusted, the processing module is executed; A processing module, used to modify the permission level of the computing task and upload the untrusted information of the computing task to the trusted management platform.

[0015] Compared with the prior art, the present invention has the following beneficial effects: The invention discloses a method for allocating real-time computing authority of a trusted DCS controller. The authority method defines the operation authority of the computing tasks according to the functions of the computing tasks in the initial operation stage for multiple computing tasks in the DCS controller, and performs security assessment on each computing task separately to formulate corresponding security strategies. For computing tasks that execute a triggered security strategy, corresponding processing is performed only when the computing tasks are invaded, while for computing tasks that execute a monitoring room security strategy, it is necessary to periodically perform trusted verification on the computing tasks, and once it is found that the computing tasks are untrustworthy or operations that exceed the operation authority are performed, processing is performed. By introducing a refined authority management mechanism, the method can dynamically allocate and adjust authority according to the needs and security strategies of real-time computing tasks, ensure that each computing task can only be executed within the authorized scope, and only authorized and verified entities can execute corresponding operations, thereby effectively preventing unauthorized access and malicious attacks, improving the inherent security protection capability of the control system, and improving the security and flexibility of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A flow chart of a method for allocating real-time computing permissions to a trusted DCS controller according to the present invention; Figure 2 The flowchart is an embodiment of the method for allocating real-time computing permissions of a trusted DCS controller of the present invention. DETAILED DESCRIPTION

[0017] In the following, the terms "first", "second", "third", and "fourth" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, a feature defined as "first", "second", "third", and "fourth" may explicitly or implicitly include one or more of the features.

[0018] The co-shooting method provided in the embodiment of the present application can be applied to terminal devices such as mobile phones, tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), etc. The embodiment of the present application does not impose any restrictions on the specific type of the terminal device.

[0019] It should be noted that the terms "first", "second", etc. in the specification and drawings of the present invention are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0020] As proposed in the background art of the present invention, the traditional DCS controller privilege allocation often adopts a static and fixed method, which is difficult to adapt to the complex and changeable industrial production environment. During the execution of various operations by the DCS controller, it is vulnerable to various attacks. Once attacked, it will affect the progress of the operation and may even threaten the security of the entire DCS controller.

[0021] To solve the above problems, the first aspect of the present invention discloses a method for real-time operation privilege allocation of a trusted DCS controller, which includes the following steps: S1, in the initial operation stage of the DCS controller, define the operation privileges of the operation tasks; S2, conduct a security assessment on each operation task and formulate corresponding security policies, where the security policies include trigger-based security policies and monitoring-based security policies; S3, for the operation tasks with trigger-based security policies, when the operation tasks are invaded, alarm and execute S4; for the operation tasks with monitoring-based security policies, periodically conduct trusted verification on the operation tasks, and if they are untrusted, execute S4; S4, modify the operation privilege level of the operation task and upload the untrusted information of the operation task to the trusted management platform.

[0022] This permission method targets multiple computing tasks in a DCS controller. In the initial operation stage, according to the functions of each computing task, it defines the operation permissions of the computing tasks, conducts a separate security assessment for each computing task, and formulates corresponding security policies. For computing tasks that execute triggered security policies, corresponding processing is only carried out when the computing task is invaded. For computing tasks that execute security policies in the monitoring room, it is necessary to periodically perform trusted verification on the computing tasks. Once it is found that the computing task is untrusted or performs operations beyond the operation permissions, processing is carried out. By introducing a refined permission management mechanism, this method can dynamically allocate and adjust permissions according to the requirements of real-time computing tasks and security policies, ensuring that each computing task can only be executed within the authorized scope, and only authorized and verified entities can execute corresponding operations, thereby effectively preventing unauthorized access and malicious attacks, enhancing the endogenous security protection ability of the control system, and improving the security and flexibility of the system at the same time.

[0023] Furthermore, one embodiment of the present invention discloses a method for dynamically allocating real-time computing permissions for a trusted DCS controller. The dynamic trusted verification function of this method will periodically perform trusted measurement on specified processes in the controller and modify the execution permissions of the processes according to their running states periodically. The specific steps of this method are as follows: S1, define the permission levels and policies of computing tasks.

[0024] First, in the initial operation stage of the DCS controller, define the operation permissions and operation scopes of each computing task. The specific operation types include: reading, writing, and executing, etc.

[0025] It should be noted that permission allocation policies are formulated for each computing task, including which operations the corresponding computing task can perform, as well as the effective time, effective location, and effective method of these operations.

[0026] Specifically, in this step, in the initial operation stage of the DCS controller, the DCS controller also places the reference measurement value in the TPM chip. Specifically, the DCS controller stores the first measurement value as the reference value in the TPM chip and sends the reference value to the trusted management platform. In the subsequent process, the DCS controller will periodically send measurement values to the trusted management platform to judge the state of the DCS controller.

[0027] The trusted management platform provides comprehensive management capabilities such as centralized setting, policy deletion, status monitoring, trusted status display, and function auditing for each function in the DCS controller system. Through this platform, users can easily implement security policies and enhance the overall security and reliability of the system.

[0028] S2, real-time task requirement analysis and security assessment.

[0029] For each real-time operation task, during the initial operation stage of the DCS controller, the operation engineer analyzes and evaluates specific requirements such as the data accessed and the operations performed when each operation task is executed.

[0030] Specifically, conduct a security assessment of the operation task to determine the possible security risks it may bring, and accordingly formulate corresponding security policies. The security policies include trigger-based security policies and monitoring-based security policies. The trigger-based security policy means that the operation task proceeds normally under normal conditions, and the system does not monitor the operation task. When the operation task is invaded or tampered with, modify the permissions of the operation task, alarm on the trusted management platform, and handle it through a pre-set program or the operation engineer. Specifically, trigger-based security policies such as static policies, subjects and objects, whitelists, and blacklists.

[0031] The monitoring-based security policy is a dynamic security policy that continuously monitors the operation task and periodically conducts a trusted measurement of the operation task according to the set time. For example, the dynamic trusted policy calculates the hash value as the reference value when the process is first executed, and then calculates the hash value measurement value periodically. If the measurement value is consistent with the reference value, it is trusted; if the measurement value is inconsistent with the reference value, it is untrusted.

[0032] It should be noted that the operation tasks that execute the monitoring-based security policy also execute the trigger-based security policy, so that for such tasks, not only can a trusted result be obtained through periodic measurement, but also an alarm can be issued and corresponding operations can be performed once such operation tasks are invaded or tampered with.

[0033] S3, permission monitoring and adjustment.

[0034] During the operation execution process, for the operation tasks that execute the monitoring-based security policy, the system should monitor the usage of permissions in real time to ensure that the permissions are not misused.

[0035] During the monitoring process, once the operation tasks of the trigger-based security policy are actively modified, adjust the permissions dynamically according to the execution situation of the task and the security state of the system. If the operation task is trusted during the task execution, continue to execute the task.

[0036] It should be noted that for the security state of the system, once an operation task is no longer secure, the system is no longer secure. Only when all operation tasks are not tampered with and are trusted, the entire system is trusted.

[0037] In some embodiments of the present invention, according to the requirements of the operation task and the security policy, the system dynamically assigns corresponding permissions to the task. Specifically, if it is found that a certain operation in the computing task is untrusted, but other operations of the computing task are trusted, then execute other operation tasks of the computing task. That is, implementing dynamic permission allocation means that the permission allocation is not fixed, but can be changed according to the runtime situation or specific conditions. For example, the operations that a certain computing task can execute include reading, writing, and executing. During periodic trusted operation measurement, if it is found that the writing operation is no longer trusted, then modify the permissions of the computing task so that it can only perform reading and executing operations, but cannot perform writing operations. At the same time, report the untrusted information and upload it to the trusted management platform.

[0038] Taking the core program DPU in the controller as an example, the permissions of the DPU during normal operation are readable, writable, and executable. The dynamic trusted verification function will periodically measure the code segment and read-only data segment of the dynamic link library used by the DPU program. When the measured code value and the measured value of the read-only data segment are inconsistent with the reference value, it is untrusted. When the verification is untrusted, the process is controlled according to the security policy of the execution task. When the DPU is verified to be untrusted, the permissions of the DPU will be modified to be readable and executable to ensure the normal execution of the controller. However, the writable operation will modify the data abnormally, and the abnormal information will be uploaded to the trusted management platform; the DPU program will be processed by the system administrator.

[0039] S4, if an abnormality is found during the task execution process in this process, revoke or reduce the permissions in a timely manner when the abnormal behavior is found.

[0040] In some embodiments of the present invention, the trusted management platform realizes centralized management and visual operation of permissions, which is convenient for the administrator to configure, query, and monitor the permissions of the controller. The trusted management platform will display the permissions of the processes configured with dynamic trusted verification in each controller, as well as the trusted status of each program. The system will periodically measure the program to confirm whether the program is trusted.

[0041] By introducing a refined permission management mechanism, the method of the present invention can dynamically allocate and adjust permissions according to the requirements of real-time computing tasks and security policies, ensure that each computing task can only be executed within the authorized scope, and only authorized and verified entities can execute corresponding operations, thereby effectively preventing unauthorized access and malicious attacks, improving the endogenous security protection ability of the control system, and at the same time improving the security and flexibility of the system.

[0042] The second aspect of the present invention discloses a trusted DCS controller operation permission allocation device, including: A definition module, used to define the operation permissions of the computing task during the initial operation stage of the DCS controller; An evaluation module for performing a security evaluation on each operation task and formulating corresponding security policies, where the security policies include a trigger-based security policy and a monitoring-based security policy; A judgment module for executing the operation tasks of the trigger-based security policy. When the operation task is invaded, it alarms and executes S4; for the operation tasks of the monitoring-based security policy, it periodically performs a trust verification on the operation tasks, and if it is untrusted, it executes S4; A processing module for modifying the permission level of the operation task and uploading the untrusted information of the operation task to the trusted management platform.

[0043] The third aspect of the present invention discloses a computer device. The computer terminal device includes a processor and a memory. The memory is used to store a computer program. The computer program includes program instructions. The processor is used to execute the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions to implement the corresponding method flow or corresponding function; the processor described in this embodiment can be used to implement a method for real-time operation permission allocation of a trusted DCS controller, including the following steps: S1, in the initial operation stage of the DCS controller, define the operation permissions of the operation tasks; S2, perform a security evaluation on each operation task and formulate corresponding security policies, where the security policies include a trigger-based security policy and a monitoring-based security policy; S3, for the operation tasks of the trigger-based security policy, when the operation task is invaded, alarm and execute S4; for the operation tasks of the monitoring-based security policy, periodically perform a trust verification on the operation tasks, and if it is untrusted, execute S4; S4, modify the permission level of the operation task and upload the untrusted information of the operation task to the trusted management platform.

[0044] The fourth aspect of the present invention discloses a storage medium, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in a terminal device and is used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and, of course, the extended storage medium supported by the terminal device. The computer-readable storage medium provides a storage space, and the operating system of the terminal is stored in this storage space. Moreover, one or more instructions suitable for being loaded and executed by the processor are stored in this storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. One or more instructions stored in the computer-readable storage medium can be loaded and executed by the processor to implement the method for real-time operation permission allocation of a trusted DCS controller in the above embodiments, including the following steps: S1. In the initial operation stage of the DCS controller, define the operation permissions of the operation tasks; S2. Conduct a security assessment on each operation task and formulate corresponding security policies, where the security policies include trigger-based security policies and monitoring-based security policies; S3. For the operation tasks that execute the trigger-based security policies, when the operation tasks are invaded, alarm and execute S4; for the operation tasks that execute the monitoring-based security policies, periodically conduct a trust verification on the operation tasks. If they are untrusted, execute S4; S4. Modify the permission level of the operation tasks and upload the untrusted information of the operation tasks to the trusted management platform.

[0045] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for allocating real-time computing permissions of a trusted DCS controller, characterized in that: The following steps are involved: S1, the initial operation stage of the DCS controller, defines the operation authority of the computing task; S2, perform security assessment on each computing task and formulate corresponding security strategies, which include trigger-based security strategies and monitoring-based security strategies; S3, for the computing task of the trigger security strategy, when the computing task is invaded, an alarm is issued and S4 is executed; for the computing task of the monitoring security strategy, the computing task is periodically verified to be trustworthy, and if it is not trustworthy, S4 is executed; S4, modify the operation authority level of the computing task, and upload the untrusted information of the computing task to the trusted management platform.

2. A method for allocating real-time computing permissions of a trusted DCS controller according to claim 1, characterized in that: In S1, the operation permissions include read-write, write and execute.

3. A method for allocating real-time computing permissions of a trusted DCS controller according to claim 1, characterized in that: In S1, the DCS controller stores the reference values ​​of each operation of the computing task in the TPM chip.

4. A method for allocating real-time computing permissions of a trusted DCS controller according to claim 1, characterized in that: In S2, the process of security assessment for each computing task is: analyzing the data accessed by the computing task and the objects targeted by the execution operation, determining the security risks brought about, and formulating security strategies.

5. A method for allocating real-time computing permissions of a trusted DCS controller according to claim 1, characterized in that: The trigger-type security policies include static, subject-object security policies, whitelist security policies and blacklist security policies.

6. A method for allocating real-time computing permissions of a trusted DCS controller according to claim 1, characterized in that: In S4, during the periodic trusted verification of the computing task, if the computing task exceeds the authority or is untrustworthy, the authority of the computing task is revoked or the authority level of the computing task is downgraded.

7. A method for allocating real-time computing permissions of a trusted DCS controller according to claim 5, characterized in that: S5, the operation authority level of the modified computing task is to stop the untrusted operations of the computing task and continue to execute the trusted operations of the computing task.

8. A trusted DCS controller computing authority allocation device, characterized in that: include: Definition module, used to define the operation authority of the computing task during the initial operation phase of the DCS controller; An evaluation module is used to perform security evaluation on each computing task and formulate corresponding security strategies, which include trigger-based security strategies and monitoring-based security strategies; The judgment module is used to execute the computing task of the trigger security strategy. When the computing task is invaded, an alarm is issued and the processing module is executed; the computing task of the monitoring security strategy is executed, and the computing task is periodically verified to be trustworthy. If it is not trustworthy, the processing module is executed; The processing module is used to modify the permission level of the computing task and upload the untrusted information of the computing task to the trusted management platform.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method for allocating real-time computing permissions of a trusted DCS controller as claimed in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method for allocating real-time computing permissions of a trusted DCS controller as claimed in any one of claims 1 to 7 is implemented.