Pressing plate data acquisition module based on trusted WLAN network security authentication

By adopting a platen data acquisition module based on a trusted WLAN network in the substation, using the key certificate generation unit and the intranet key certificate server to manage the keys and certificates, the application problem of traditional wired LAN in the substation is solved, and the security and reliability of the network are improved.

CN120151841APending Publication Date: 2025-06-13XIAN LIANGLI INSTR & METER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510010640.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Traditional wired LANs are subject to high cost, fixed location and poor mobility in substations. There is a risk of leaking passwords and certificates for WLAN access, which is difficult to ensure the security and leak prevention of networks.

Method used

The platen data acquisition module based on a trusted WLAN network is adopted to generate and manage temporary and formal keys and certificates through the key certificate generation unit and the intranet key certificate server to ensure the secure access and data transmission of equipment in the substation network.

Benefits of technology

Improve the security of the substation network, and reduce the risk of leakage through automated management of keys and certificates, ensuring network reliability and data confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151841A_ABST
    Figure CN120151841A_ABST
Patent Text Reader

Abstract

The invention relates to a pressure plate data acquisition module based on trusted WLAN (Wireless Local Area Network) network security authentication, which comprises a secret key and certificate generation unit, a secret key and certificate management unit and a pressure plate data acquisition unit, the intranet secret key certificate server is responsible for issuing, verifying and managing equipment, certificates and secret keys used in the intranet; the trusted pressure plate data acquisition module provides an equipment MAC address for the secret key certificate generation unit, when equipment enters a debugging stage after being installed in a transformer substation, a transformer substation trusted WLAN network starts a temporary network, an intranet secret key certificate server is started, and the intranet secret key certificate server applies for replacing a formal secret key or certificate; after the application, a formal secret key and a formal certificate are automatically distributed to the equipment after comparison and auditing to an intranet secret key certificate server are completed. According to the invention, the network security is improved to a great extent, the transformer substation pressing plate acquires the secret key certificate of the network to realize automatic management, and the security requirement of state grid intelligent development is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of substation monitoring, and specifically to a pressure plate data acquisition module based on trusted WLAN network security authentication. Background Art

[0002] Traditional wired local area networks are widely used in substations. However, the laying cost of wired media is relatively high, and their positions are fixed with poor mobility. The safe production and operation service of the power grid continue to evolve towards IP and broadband, posing new challenges to the bandwidth, delay, reliability, and service differentiation management of the power communication network.

[0003] Trusted WLAN is a new generation of communication access technology based on China's self-developed WAPI standard. With the deep application of the "SPN + trusted WLAN" technology by the State Grid power supply company, the application of trusted WLAN in the substation field will be more extensive. This technology can not only solve practical problems such as fire prevention and flood control, but also support the digital transformation and development of the power grid, and empower the construction of a new power system.

[0004] Currently, there are two ways to access the WLAN network: password and certificate. However, both of these methods have the risk of information leakage. The present invention has made in-depth optimizations for the substation pressure plate acquisition application scenario based on the current basic architecture of the WLAN network application. A new design has been added mainly in the aspect of the network access security authentication of the pressure plate data acquisition device, ensuring the security and anti-information leakage of the entire device accessing the WLAN network. Summary of the Invention

[0005] The present invention provides a pressure plate data acquisition module based on trusted WLAN network security authentication to solve the technical problems mentioned in the above background art.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A pressure plate data acquisition module based on trusted WLAN network security authentication, the module includes:

[0008] A secret key certificate generation unit, which is responsible for generating and managing the secret keys and certificates used for encrypted communication and identity authentication;

[0009] An intranet secret key certificate server, which is responsible for issuing, verifying, and managing the devices, digital certificates, and secret keys used in the intranet, and the certificate is a digital certificate;

[0010] The trusted pressure plate data acquisition module is a device developed specifically for the trusted WLAN network in substations. By providing the device MAC address to the secret key certificate generation unit, a temporary secret key or temporary certificate is generated and then downloaded to the device first. At this time, the secret key or certificate stored on the device is temporary. When the device is installed in the substation and enters the commissioning stage, the trusted WLAN network in the substation enables the temporary network and starts the internal network secret key certificate server. The device side accesses the network through the temporary secret key and temporary certificate, and applies to the internal network secret key certificate server to replace the formal secret key or certificate. After the comparison and verification by the internal network secret key certificate server, the formal secret key and formal certificate are automatically distributed to the device. After all the installed pressure plate acquisition devices complete the application and exchange of the formal secret key and certificate, the internal network secret key certificate server can disable the temporary secret key and temporary certificate, and start the formal network and secret key certificate. At this time, the secret key or certificate used by all devices accessing the trusted WLAN in the substation is automatically updated by the internal network secret key certificate server, and the temporary secret keys or certificates known to relevant personnel such as on-site construction personnel and equipment manufacturers have become invalid, greatly improving the security of the substation network.

[0011] As a further technical solution of the present invention, the internal network secret key certificate server can verify the validity of the digital certificates used in the internal system. By checking information such as the issuing authority, signature, and validity period of the digital certificate, it is ensured that the digital certificate has not been tampered with and is still within the validity period. During the data transmission process, the device will send its own digital certificate to the server, and the internal network secret key certificate server verifies the authenticity of the digital certificate, thereby establishing a secure communication connection.

[0012] As a further technical solution of the present invention, the internal network secret key certificate server provides the function of digital certificate management, including the issuance, update, revocation, and backup of digital certificates, etc. The administrator can easily manage all digital certificates in the internal network through the internal network secret key certificate server software.

[0013] Compared with the prior art, the beneficial effects of the present invention are: The present invention provides a pressure plate data acquisition module based on trusted WLAN network security authentication. Compared with the prior art, it improves the management of secret keys and certificates in the implementation process of the trusted WLAN-related industry, greatly improves network security, and through encryption and decryption algorithms, network update secret key and certificate algorithms, and a trusted pressure plate data acquisition module that supports automatic update of secret keys and certificates, the secret key certificates of the substation pressure plate acquisition network are automatically managed, further meeting the security requirements for the intelligent development of the State Grid. Description of the Drawings

[0014] Figure 1 It is an architecture diagram of a pressure plate data acquisition module based on trusted WLAN network security authentication.

[0015] Figure 2 It is a flowchart of the replacement application process in a platen data acquisition module based on trusted WLAN network security authentication. Specific embodiments

[0016] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0017] The technical solution of the present invention is composed of a secret key certificate generation unit, an intranet secret key certificate server, and a trusted platen data acquisition module. The architecture diagram of the entire system operation is as Figure 1 shown. Among them, the wireless controller AC (Access Controller): In a centralized network architecture, the AC controls and manages all APs in the wireless local area network. The access point AP (Access Point): provides wireless access services based on the WAPI standard for terminal devices and acts as a bridge between the wired network and the wireless network. The remote unit RU (Remote unit): In a centralized network architecture, the remote unit is the remote radio frequency module of the central AP and is responsible for the transceiver of air interface WAPI messages.

[0018] After the installation of the trusted platen data acquisition module device is completed, before it is officially put into use, it will initiate an online automatic update of the secret key or certificate to the intranet secret key certificate server. After all the platen data acquisition module devices in the entire substation have completed the update of the secret key and certificate, the official business network in the station is enabled, and the device enters the normal business state. The entire replacement application process is as Figure 2 shown.

[0019] Please refer to Figures 1 to 2 , the embodiment of the present invention provides a platen data acquisition module based on trusted WLAN network security authentication, and the module includes:

[0020] The trusted pressure plate data acquisition module is a device specially developed for the trusted WLAN network in substations. By providing the device MAC address to the key certificate generation unit, a temporary key or temporary certificate is generated and first downloaded to the device. At this time, the key or certificate stored on the device is temporary. When the device is installed in the substation and enters the commissioning stage, the trusted WLAN network in the substation enables a temporary network and starts the internal network key certificate server. The device end accesses the network through the temporary key and temporary certificate, and applies to the internal network key certificate server to replace the formal key or certificate. After the comparison and verification by the internal network key certificate server, the formal key and formal certificate are automatically distributed to the device. After all installed pressure plate acquisition devices complete the application and exchange of the formal key and certificate, the internal network key certificate server can disable the temporary key and temporary certificate, and start the formal network and key certificate. At this time, the keys or certificates used by all devices accessing the trusted WLAN in the substation are automatically updated by the internal network key certificate server, and the temporary keys or certificates known to relevant personnel such as on-site construction personnel and device manufacturers have become invalid, greatly improving the security of the substation network.

[0021] In this embodiment, after the device is installed, a series of operations such as network access, authentication, and certificate replacement can all be automated, and the entire process is more secure, and the device management in the substation is more intelligent. When the module leaves the factory, a certificate file is generated in advance according to the device MAC address through the key certificate generation unit and the internal network key certificate server, and the certificate file is stored in the module. When the module is powered on and connected to the internal AP in the substation, the internal network key certificate server completes authentication encryption and decryption through the module MAC address and its internal certificate. The security of the connected device is ensured by the unique MAC address and the internal temporary certificate, and at the same time, the autonomous certificate replacement starts to complete the replacement of the internal temporary certificate in the module.

[0022] The key certificate generation unit is responsible for generating and managing keys and certificates used for encrypted communication and authentication; according to the device MAC address and applicant information key in advance, it will automatically generate keys or certificates; the key certificate generation unit uses national commercial cryptography algorithms such as SM4 and SM3, and performs encrypted communication based on dynamic updates during the user communication process, realizing high-strength encryption protection for State Grid data.

[0023] An intranet key certificate server is responsible for issuing, verifying, and managing devices, digital certificates, and keys used in the intranet. The certificates are digital certificates. By providing secure and reliable key and certificate services through the device MAC address, the intranet key certificate server ensures the confidentiality, integrity, and credibility of internal network communications. The intranet key certificate server can issue digital certificates or keys to devices according to requests for pre-entered device information. These certificates contain necessary authentication information, and the certificate issuance process follows the standard procedures of the Public Key Infrastructure (PKI) to ensure the authenticity and reliability of the certificates. The intranet key certificate server can verify the validity of the certificates used in the internal system. By checking information such as the certificate issuing authority, signature, and expiration date, it ensures that the digital certificates have not been tampered with and are still within the expiration date. During data transmission, the device sends its digital certificate to the server, and the intranet certificate server verifies the authenticity of the certificate to establish a secure communication connection. The intranet key certificate server provides functions for digital certificate management, including the release, update, revocation, and backup of digital certificates. Administrators can easily manage all certificates in the internal network through the server software;

[0024] In this embodiment, the intranet key certificate server uses MAC address plus certificate authentication to jointly manage devices. After linking to the intranet key certificate server based on the temporary certificate issued by the original pressure plate data acquisition module at the factory, through the pre-entry of the module MAC address, the temporary certificate authentication is automatically triggered, the module certificate is automatically replaced online, and the management module completes related processes such as automatic certificate replacement.

[0025] It should be noted that in this article, the term "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without more limitations, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device including that element.

[0026] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural or equivalent process transformations made by using the description and drawings of the present invention, or directly or indirectly applied in other related technical fields, are equally included in the patent protection scope of the present invention.

Claims

1. A platen data acquisition module based on trusted WLAN network security authentication, characterized in that: The modules include: The key and certificate generation unit is responsible for generating and managing keys and certificates used for encrypted communication and identity authentication; The intranet key certificate server is responsible for issuing, verifying and managing the devices, certificates and keys used in the intranet. The certificates are digital certificates. The trusted pressure plate data acquisition module provides the device MAC address to the key certificate generation unit, generates a temporary key or temporary certificate, and then downloads it to the device. When the device is installed in the substation and enters the debugging stage, the substation trusted WLAN network enables the temporary network, and turns on the intranet key certificate server. The device accesses the network through the temporary key and temporary certificate, and applies to the intranet key certificate server for a replacement of the formal key or certificate. After the application is compared and reviewed by the intranet key certificate server, the formal key and formal certificate are automatically distributed to the device. After all installed pressure plate acquisition devices complete the application and exchange of the formal key and certificate, the intranet key certificate server disables the temporary key and temporary certificate, and turns on the formal network and key certificate. At this time, the keys or certificates used by all devices connected to the substation trusted WLAN are automatically updated by the intranet key certificate server.

2. According to the press plate data acquisition module based on trusted WLAN network security authentication according to claim 1, it is characterized in that: The intranet secret key certificate server verifies the validity of the digital certificate used in the internal system. By checking the issuing authority, signature and validity period of the digital certificate, it ensures that the digital certificate has not been tampered with and is still within the validity period. During data transmission, the device will send its own digital certificate to the server and verify the authenticity of the digital certificate through the intranet secret key certificate server, thereby establishing a secure communication connection.

3. A platen data acquisition module based on trusted WLAN network security authentication according to claim 2, characterized in that: The intranet secret key certificate server provides digital certificate management functions, including the issuance, renewal, revocation and backup of digital certificates. Administrators can easily manage all digital certificates in the internal network through the intranet secret key certificate server software.