Power system data communication gateway machine screen security design method and system
By introducing separate authority management, multiple identity authentication and strict data encryption protection into the power system data communication gateway, the problems of insufficient identity authentication, lax data verification and lack of security audit functions in the existing technology are solved, and the system is high security and reliability are achieved.
Patent Information
- Application Number
- CN202510013401.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-05-27
AI Technical Summary
The existing data communication methods of power system have problems such as insufficient identity authentication, poor data verification and lack of security audit functions, which makes it difficult for the system to defend against cyber attacks.
Adopt permission management based on separation of powers, multiple identity authentication mechanisms and strict data encryption protection, combined with security audit modules and data monitoring functions to ensure the security and reliability of the system.
By introducing these security measures, the overall security and reliability of the system are improved, information leakage and potential damage are prevented, and the stability of the system is ensured in the face of cyber attacks.
Smart Images

Figure CN120050064A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system data communication, and particularly to a power system data communication network shutdown screen security design method and system. Background Art
[0002] In modern power systems, with the rapid development of smart grids and distributed energy management, the application of data communication technology has become increasingly widespread. As an important part of the power system, data communication network shutdown devices provide infrastructure support for data exchange and processing. These network shutdown devices are responsible for encoding, decoding, and real-time transmission of information from various devices, ensuring the efficient operation of the entire power system. In recent years, with the maturity of Internet of Things technology, the power system has put forward more stringent requirements for the real-time, security, and reliability of data, thus promoting the innovation of data communication network shutdown technology. The use of network architectures such as wide area network (WAN) and local area network (LAN) has also made this technology play an important role in information improvement.
[0003] Although there have been significant improvements in power system data communication technology, there are still many deficiencies in the existing technology. The current data communication network shutdown devices have weak protection capabilities in terms of security design, especially in aspects such as identity authentication, data encryption, and permission management. Most systems still rely on traditional username and password methods and lack a strong identity verification mechanism. This weak authentication is insufficient to prevent various security threats in the modern network environment and is easily vulnerable to man-in-the-middle attacks and brute force cracking. In addition, the data validity verification mechanism is insufficient, unable to effectively avoid the input of type errors or non-compliant data, thus causing problems such as system failures and data chaos. At the same time, many systems do not provide a comprehensive security audit function and lack effective monitoring and analysis of operation records, making it difficult to trace and identify responsibilities in the event of a security incident. In view of the above deficiencies, the present invention proposes a power system data communication network shutdown screen security design method and system. By introducing a permission management based on the separation of powers, a comprehensive identity authentication mechanism, and enhanced data encryption protection, not only the security and reliability of the overall system are improved, but also the stability of the system in the face of various network attacks is ensured, thus effectively preventing information leakage and potential damage. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by the present invention is: the existing power system data communication methods have problems of insufficient identity authentication, lax data verification, and lack of security audit functions, and how to effectively solve these problems in terms of improving the security and reliability of the system.
[0006] To solve the above technical problems, the present invention provides the following technical solutions: A method for the security design of the power system data communication network shutdown screen, including presetting members belonging to the first authority according to the first authority division principle, and allocating authorities to the members belonging to the first authority based on the first authority division principle; controlling the members belonging to the first authority to access the system securely through the first security protection method; deploying the first audit policy and the first data protection policy to monitor and diagnose data security.
[0007] As a preferred solution of the method for the security design of the power system data communication network shutdown screen according to the present invention, wherein: the presetting of the members belonging to the first authority includes presetting members belonging to the first right responsible for different services according to different services of the system through the first authority division principle.
[0008] As a preferred solution of the method for the security design of the power system data communication network shutdown screen according to the present invention, wherein: the authority allocation includes allocating independent system authorities to the members belonging to the first authority based on the different levels of services they are responsible for according to the first authority division principle.
[0009] As a preferred solution of the method for the security design of the power system data communication network shutdown screen according to the present invention, wherein: the secure access to the system includes controlling the members belonging to the first authority to perform identity authentication through the first security protection method and performing access control on the system.
[0010] As a preferred solution of the method for the security design of the power system data communication network shutdown screen according to the present invention, wherein: the deployment of the first audit policy and the first data protection policy to monitor and diagnose data security includes recording events, content analysis, viewing audit results, and protecting audit data through the deployed first audit policy.
[0011] As a preferred solution of the method for the security design of the power system data communication network shutdown screen according to the present invention, wherein: the deployment of the first audit policy and the first data protection policy to monitor and diagnose data security further includes implementing classified protection for data of different sensitive levels through the deployed first data protection policy.
[0012] As a preferred solution of the method for the security design of the power system data communication network shutdown screen according to the present invention, wherein: the deployment of the first audit policy and the first data protection policy to monitor and diagnose data security includes protecting and monitoring the key processes of the system through the real-time self-diagnosis and automatic reply functions of the deployed first data protection policy.
[0013] Another object of the present invention is to provide a power system data communication network shutdown screen security design system, which can solve the potential risks and hidden dangers in the current power system communication technology in terms of security and data integrity by introducing a separation of powers-based permission management mechanism, strict identity authentication, and data encryption scheme.
[0014] As a preferred solution of the power system data communication network shutdown screen security design system described in the present invention, it includes a permission allocation module, a security protection module, and a data monitoring module; the permission allocation module is used to preset the members belonging to the first permission according to the first permission splitting principle, and allocate permissions to the members belonging to the first permission based on the first permission splitting principle; the security protection module is used to control the members belonging to the first permission to access the system safely through the first security protection method; the data monitoring module is used to deploy the first audit policy and the first data protection policy to monitor and diagnose data security.
[0015] A computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement the steps of the power system data communication network shutdown screen security design method.
[0016] A computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, it implements the steps of the power system data communication network shutdown screen security design method.
[0017] The beneficial effects of the present invention: The power system data communication network shutdown screen security design method provided by the present invention improves the overall security of the system by introducing permission management based on the principle of separation of powers, isolating the access permissions of different roles, reducing the risk of unauthorized operations, and preventing internal personnel from abusing permissions or external attackers from intruding; by adopting a multi-factor identity authentication mechanism, it ensures that only strictly verified users can access the system, effectively resisting common network threats such as brute-force cracking and phishing attacks; by implementing a strict data verification mechanism, it ensures that the input data conforms to the predetermined rules, avoiding system failures caused by incorrect data, and at the same time, the real-time monitoring of data flow by this mechanism can promptly identify and correct abnormal situations; by equipping a security audit module, it comprehensively records user operations and system status, providing detailed data for event tracing and responsibility division, not only improving the transparency of the system, but also enhancing the monitoring ability of potential security incidents; by adopting the strong data encryption technology of the national cryptographic algorithm, it ensures that sensitive information during data transmission and storage is not illegally accessed. Description of the Drawings
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0019] Figure 1 It is the overall flowchart of a method for the security design of the power system data communication network shutdown screen provided by the first embodiment of the present invention.
[0020] Figure 2 It is the architecture diagram of the data communication network shutdown access service system for the security design of the power system data communication network shutdown screen provided by the first embodiment of the present invention.
[0021] Figure 3 It is the schematic diagram of the separation of powers architecture for the security design of the power system data communication network shutdown screen provided by the first embodiment of the present invention.
[0022] Figure 4 It is the schematic diagram of an example of unauthorized access to the screen security for the security design of the power system data communication network shutdown screen provided by the first embodiment of the present invention.
[0023] Figure 5 It is the access diagram of the screen security audit log for the security design of the power system data communication network shutdown screen provided by the first embodiment of the present invention.
[0024] Figure 6 It is the schematic diagram of the screen security file backup for the security design of the power system data communication network shutdown screen provided by the first embodiment of the present invention.
[0025] Figure 7 It is the overall flowchart of a system for the security design of the power system data communication network shutdown screen provided by the third embodiment of the present invention. Specific Embodiments
[0026] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0027] Embodiment 1, referring to Figures 1-6 , which is an embodiment of the present invention, provides a method for the security design of the power system data communication network shutdown screen, including:
[0028] S1: Preset the members belonging to the first permission according to the first permission splitting principle, and allocate permissions to the members belonging to the first permission based on the first permission splitting principle.
[0029] Furthermore, it is preset that the members belonging to the first permission include the members belonging to the first permission responsible for different services preset according to different services of the system by the first permission splitting principle.
[0030] It should be noted that permission allocation includes allocating independent system permissions to the members belonging to the first permission based on the different levels of services they are responsible for by the first permission splitting principle.
[0031] It should also be noted that the first permission splitting principle can be the principle of separation of powers, or the principle of least privilege, or other security principles or methods that can effectively separate permissions.
[0032] It should also be noted that in the embodiment of the present application, the first permission splitting principle used is the principle of separation of powers. Based on the principle of separation of powers, the system presets the members belonging to the first permission, who are respectively responsible for business management at different levels, ensuring that the permission allocation is clear and independent of each other. The members belonging to the first permission include, but are not limited to, administrators, auditors, operators, etc. In the embodiment of the present application, the members belonging to the first permission are set as administrators, auditors, and operators.
[0033] Among them, the administrator has the permissions of adding and deleting users, unlocking users, setting passwords, and allocating permissions; the auditor has the functions of filtering and querying audit logs, formulating an audit history file rotation mechanism, and configuring a storage space margin control policy; the operator has the functions of viewing operation information, configuring screen parameters, configuring network parameters, and operating business functions. If a role with permission accesses beyond its authority, the access behavior will be rejected and a pop-up window will be prompted.
[0034] It should also be noted that in an alternative embodiment, the first permission allocation principle used is the principle of least privilege. Based on the principle of least privilege, the system presets the members belonging to the first permission, lists the minimum permissions required for each role, designs roles according to the importance of responsibilities and the complexity of operations, ensuring that each role has specific permissions and responsibilities, such as developers, testers, operation and maintenance personnel, business users, etc. As the organization develops and business changes, roles and permissions are flexible and can quickly adjust and adapt to new business requirements. In some cases, composite roles can be preset to simplify management.
[0035] S2: Control the secure access of the members belonging to the first permission to the system through the first security protection method.
[0036] Furthermore, secure access to the system includes controlling members belonging to the first permission to perform identity authentication through the first security protection method and performing access control on the system.
[0037] It should be noted that the first security protection method can be a multi-factor authentication mechanism, a biometric technology, or other human-machine security protection methods.
[0038] It should also be noted that in the embodiment of the present application, the first security protection method uses a multi-factor authentication mechanism, which includes password complexity verification, unique identity identification, timeout login mechanism, and multiple identity authentication methods for login failure and password brute-force protection to strengthen human-machine interaction and improve system security.
[0039] Password complexity verification includes the system implementing a strict password policy, requiring the password set by members belonging to the first permission to meet certain complexity standards, which include but are not limited to combinations of uppercase and lowercase letters, numbers, and special characters, to prevent security risks brought by weak passwords; unique identity identification includes each member belonging to the first permission having a unique identity identification in the system to ensure the uniqueness and non-replicability of the user identity, which helps to accurately identify and manage users and provides a reliable basis for auditing and accountability tracking; the timeout login mechanism includes setting a session timeout mechanism by the system to prevent unauthorized access. If a member belonging to the first permission does not perform any operation within a certain period of time, the system will automatically log out the current session and require the member belonging to the first permission to log in again; login failure and password brute-force protection includes the system strictly monitoring members belonging to the first permission who have failed to log in multiple times. Once an abnormal login is detected, which includes but is not limited to brute-force attack, etc., the system will immediately lock the account or trigger an alarm to notify the administrator and record all failed login attempts for subsequent analysis and investigation.
[0040] It should also be noted that in an optional embodiment, the first security protection method uses biometric technology to enhance the security of human-computer interaction by combining fingerprint recognition and face recognition. The specific steps are as follows: Design the registration process for members belonging to the first permission, install a fingerprint scanner and a face recognition camera. When a member belonging to the first permission uses it for the first time, require the member to enter fingerprints and facial features, and guide the member to correctly collect fingerprints and facial features. Extract key feature points from the fingerprint and facial images, generate a fingerprint template and a facial feature template, encrypt the generated fingerprint template and facial template, and securely store the templates in the database. The templates stored in the database can be added or deleted by the administrator. When a member attempts to log in, prompt the user to perform fingerprint and face recognition in sequence. Authenticate the identity by comparing the user's current fingerprint and facial features with the templates stored in the database. Require both to match for authentication to pass. According to the identity authentication result, control the user's access rights accordingly to ensure that users who have passed double verification can access sensitive resources or perform privileged operations.
[0041] S3: Deploy the first audit policy and the first data protection policy to monitor and diagnose data security.
[0042] Furthermore, deploying the first audit policy and the first data protection policy to monitor and diagnose data security includes recording events, content analysis, viewing audit results, and auditing data protection through the deployed first audit policy.
[0043] The first audit policy includes a built-in security audit module. The security audit module covers functions such as event recording and content analysis, viewing audit results, and auditing data protection, ensuring that all operations are traceable. The main content and recorded information include, but are not limited to, serial number, time, user, subject, object, component, result, type, and level, etc.
[0044] It should be noted that deploying the first audit policy and the first data protection policy to monitor and diagnose data security also includes implementing classified protection for data with different sensitivity levels through the deployed first data protection policy.
[0045] It should also be noted that deploying the first audit policy and the first data protection policy to monitor and diagnose data security includes guarding and monitoring the status of system key processes through the real-time self-diagnosis and automatic recovery functions of the deployed first data protection policy.
[0046] The first data protection policy includes adopting national cryptographic algorithms to implement classified protection for data of different sensitivity levels, and storing and processing the passwords of authorized members in ciphertext through national cryptographic algorithms during storage and transmission. A backup and recovery mechanism is deployed for important business data. Through real-time self-diagnosis and automatic recovery functions, business logic vulnerabilities are prevented, and a watchdog is deployed to guard key processes, monitor the status of key processes in real time, strictly restrict the use of high-risk ports, eliminate potential security threats from the source, enhance the protection ability of the network boundary, prohibit vulnerable high-risk ports and services, and prohibit the opening of ports unrelated to the business.
[0047] It should also be noted that the deployment of the backup and recovery mechanism for important business data includes data rationality verification and data type and length verification.
[0048] Data rationality verification includes the system's verification of input data according to logical and business rules. For example, for date bytes, the system will check whether they conform to the actual date format. When filtering illegal input time fields in the audit log time, for numerical fields, the system will verify whether the numerical fields are within the expected range. For example, when modifying the IP address exceeding 255, through the verification rules, the system will promptly reject data that does not conform to the specifications to avoid incorrect information from entering the system.
[0049] Data type and length verification includes the system's automatic checking of the data type and length when receiving input from authorized members to prevent incorrect input of types or lengths, such as the length of the username, the Chinese description of the four remote measurement points, etc., to verify that the data type and length are correct.
[0050] It should also be noted that the key processes guarded by the watchdog include, but are not limited to, data services and audit services.
[0051] It should also be noted that high-risk ports and services include, but are not limited to, Telnet and FTP.
[0052] Embodiment 2 is an embodiment of the present invention, which provides a method for the security design of the power system data communication network shutdown screen. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0053] In order to verify the effectiveness and superiority of the method for the security design of the power system data communication network shutdown screen, a simulation experiment environment is set up. First, a certain power company is selected as the test object for the environment. The environment design includes 4 power data communication network shutdowns, connecting 20 various power equipment. The network shutdowns are configured with the security design of the present invention, including authority management based on separation of powers, a strong identity authentication mechanism, and data encryption protection.
[0054] In the initial stage of the experiment, a power data communication network shutdown of the prior art was installed as a control group. To ensure the objectivity of the test, the operators involved in the network shutdown were from different departments and had received training to avoid data errors caused by improper operations. The experiment was divided into two stages. The first stage was the baseline test, aiming to record the data transmission and security of the prior art under normal circumstances. The second stage was to add various simulated attack scenarios to compare the defense effect of the gateway security design of the present invention.
[0055] During the data collection process, a series of key performance indicators were set before and after the experiment, such as data transmission success rate, data encryption speed, identity authentication success rate, number of system failures, number of information leakage incidents, and user operation feedback scores. The data was recorded for 30 days to ensure sufficient data samples and verify the reliability of the experimental results.
[0056] During the experiment, professional security monitoring tools were used to comprehensively monitor network traffic and access records, and data analysis software was used to organize and analyze the collected data. By comparing the two groups of recorded data, as shown in Table 1 below, the advantages and disadvantages of the two technical solutions were evaluated.
[0057] Table 1 Comparison of Data of Two Test Objects
[0058]
[0059] As can be seen from the data in Table 1, by comparing the data performance of the prior art and the technology of the present invention, the innovation and technical advantages of the present invention can be clearly reflected. First, in terms of the data transmission success rate, the prior art was 85%, while the present invention reached 98%, indicating that the present invention has an advantage in data stability and can effectively reduce economic losses and security risks caused by data transmission failures.
[0060] Secondly, in terms of data encryption speed, the gateway of the present invention had a speed of 10 Mbps, which was higher than 3.5 Mbps of the prior art. This not only improved the efficiency of data protection, but also provided a guarantee for real-time monitoring and control, and was more capable of meeting the transmission requirements of large-scale data. In terms of the identity authentication success rate, by combining multi-level identity verification mechanisms, the present invention achieved a success rate of 95%, while the prior art was only 78%. This not only effectively resisted potential security threats, significantly improved the overall security of the system, but also better prevented illegal access and data tampering. The parameters of the number of system failures and the number of information leakage incidents also showed the advantages of the present invention. The number of failures was reduced to 1, and the number of information leakage incidents was 0. This indicates that the present invention effectively strengthened the system stability and anti-attack ability against common security vulnerabilities and system vulnerabilities in the prior art.
[0061] Finally, in terms of user feedback ratings, after implementing our invention, the overall user response has been good and the ratings are high. This not only indicates that users recognize the stability and security of the system, but also reflects the friendliness and ease of use of the system in actual operation.
[0062] Example 3, referring to Figure 7 , which is an embodiment of the present invention, provides a power system data communication network shutdown screen security design system, including a permission allocation module, a security protection module, and a data monitoring module.
[0063] Among them, the permission allocation module is used to preset the members belonging to the first permission according to the first permission splitting principle, and allocate permissions to the members belonging to the first permission based on the first permission splitting principle; the security protection module is used to control the secure access of the members belonging to the first permission to the system through the first security protection method; the data monitoring module is used to deploy the first audit policy and the first data protection policy to monitor and diagnose data security.
[0064] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. And the aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical disks, etc., which can store program codes.
[0065] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0066] More specific examples (a non-exhaustive list) of computer-readable media include the following: electrical connections (electronic devices) having one or more wirings, portable computer diskettes (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber devices, and portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which a program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or otherwise processing it as appropriate, and then storing it in a computer memory.
[0067] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
[0068] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A screen security design method for a power system data communication gateway, characterized in that: include: Presetting the members to whom the first authority belongs according to the first authority division principle, and allocating authority to the members to whom the first authority belongs based on the first authority division principle; Controlling the security access of the member with the first authority to the system through the first security protection method; Deploy the first audit strategy and the first data protection strategy to monitor and diagnose data security.
2. The power system data communication gateway machine screen security design method according to claim 1, characterized in that: The preset first authority members include first authority members who are responsible for different businesses preset according to different businesses of the system through the first authority division principle.
3. The power system data communication gateway machine screen security design method according to claim 2, characterized in that: The authority allocation includes allocating independent system authorities to the members with the first authority based on the first authority division principle according to different levels of business that the members with the first authority are responsible for.
4. The power system data communication gateway machine screen security design method according to claim 3, characterized in that: The secure access to the system includes controlling the identity authentication of members with the first permission through a first security protection method, and performing access control on the system.
5. The power system data communication gateway machine screen security design method according to claim 4, characterized in that: The deployment of the first audit policy and the first data protection policy to monitor and diagnose data security includes recording events, content analysis, audit result review, and audit data protection through the deployed first audit policy.
6. The power system data communication gateway machine screen security design method according to claim 5, characterized in that: The deploying of the first audit strategy and the first data protection strategy to monitor and diagnose data security also includes implementing classified protection for data of different sensitivity levels through the deployed first data protection strategy.
7. The power system data communication gateway machine screen security design method according to claim 6, characterized in that: The deployment of the first audit strategy and the first data protection strategy to monitor and diagnose data security includes guarding and monitoring the status of key system processes through real-time self-diagnosis and automatic reply functions through the deployed first data protection strategy.
8. A system using the power system data communication gateway machine screen security design method as claimed in any one of claims 1 to 7, characterized in that: Including authority allocation module, security protection module, and data monitoring module; The authority allocation module is used to preset the members belonging to the first authority according to the first authority division principle, and allocate authority to the members belonging to the first authority based on the first authority division principle; The security protection module is used to control the first permission member to perform secure access to the system through a first security protection method; The data monitoring module is used to deploy a first audit strategy and a first data protection strategy to monitor and diagnose data security.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the power system data communication gateway machine screen security design method described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the power system data communication gateway machine screen security design method described in any one of claims 1 to 7 are implemented.