Encryption method and device for registration communication between terminal devices of industrial control system
By introducing SM2, SM3, SM4 encryption algorithms and cryptographic machines into the industrial control system, combined with three-level registration verification, it solves the problem that industrial control system communication is prone to illegal intrusion, realizes secure encrypted communication between terminal devices, and improves system protection capabilities and management efficiency.
Patent Information
- Application Number
- CN202510395699.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-08
AI Technical Summary
The communication process of the industrial control system is easily illegally intruded or tampered with, resulting in security accidents and economic losses.
Encryption algorithms such as SM2, SM3, SM4 and special cryptographic machines are adopted, combined with a three-level registration verification mechanism, encrypted communication between terminal devices is carried out through the historical station, the operator station and the controller to ensure the security of key configurations and synchronized data.
Effectively prevent unauthorized access and tampering, improve system protection capabilities, simplify management processes, and reduce the risk of configuration errors.
Smart Images

Figure CN120281523A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication encryption technology, and in particular, to a registration communication encryption method and device for terminal devices in an industrial control system. Background Art
[0002] With the continuous development of industrial automation technology, industrial control systems play an increasingly important role in fields such as industrial control and power production. However, once the communication process of an industrial control system is illegally invaded or tampered with, it may lead to serious safety accidents and economic losses. Summary of the Invention
[0003] The present invention provides a registration communication encryption method and device for terminal devices in an industrial control system to solve existing problems.
[0004] The object of the present invention can be achieved by the following technical solutions: In a first aspect, the present invention provides a registration communication encryption method for terminal devices in an industrial control system, including: Obtaining various information of terminal devices in the industrial control system; obtaining configuration files of all devices in the industrial control system; wherein, the devices in the industrial control system include: historical stations, operator stations, and controllers; among them, the operator stations and controllers are terminal devices; According to various information and configuration files of the historical station in the industrial control system, starting each server application program in the historical station; After the historical station is started, starting the net_daemon client application program, pdb_server client application program, and file_server client application program according to various information and configuration files of the terminal devices, and then transmitting the files to be synchronized.
[0005] Further, the obtaining various information of terminal devices in the industrial control system; obtaining configuration files of all devices in the industrial control system includes: Obtaining various information in each terminal device through the offline_cfg configuration software in the historical station, including: nodeName, dual-network IP, and UUID, and verifying and encrypting and storing the various information of the terminal devices in the sysinfor.dat file; Among them, the specific process of verification, encryption, and storage is: Calling the API of the cryptographic machine to first perform integrity verification on the nodeName, dual-network IP, and UUID of all terminal devices through the SM3 algorithm, and then perform encryption through the SM2 algorithm; finally, storing the verified and encrypted content in the sysinfor.dat file; The configuration files include: the network initialization registration information configuration file net_sys.conf and the file synchronization transfer configuration file file_server_cfg.conf; among them, net_sys.conf contains multisiteName and netCout; file_server_cfg.conf contains fileServerIp and fileSysncFlag.
[0006] Further, starting each server application in the historical station according to various information and configuration files in the industrial control system includes: The specific process of starting each server application in the historical station is as follows: The net_daemon application first loads and reads the net_sys.conf file, and then decrypts the net_sys.conf file using the SM4 algorithm and performs integrity verification using the SM3 algorithm through a cryptographic machine; after the verification passes, it reads multisiteName and netCout in the file as parameters for starting the net_daemon server application; among them, the cryptographic machine is a third-party device; After the net_daemon server application is started, it starts to start the pdb_server server application. When the pdb_server server application starts, it first loads and reads the sysinfor.dat file, and then decrypts the encrypted sysinfor.dat file using the SM2 algorithm and performs integrity verification using the SM3 algorithm through the API of the cryptographic machine. After the verification passes, it reads the nodeName, dual-network IP, and UUID of all terminal devices and maintains them in a vector for subsequent comparison during device registration; Among them, no parameters are required during the startup process of the pdb_server server application, and it can be started directly by loading the sysinfor.dat file; After the pdb_server server application is started, it starts to start the file_server server application. When the file_server server application starts, it first loads and reads the file_server_cfg.conf file, and then decrypts the file_server_cfg.conf file using the SM4 algorithm and performs integrity verification using the SM3 algorithm through the cryptographic machine API. After the verification passes, it reads fileServerIp and fileSysncFlag in the file as parameters for starting the file_server server application.
[0007] Further, after the historical station is started, the net_daemon client application, pdb_server client application, and file_server client application are started according to various information of the terminal device and the configuration file, and then the files to be synchronized are transmitted, including: After the historical station is started, consistency verification is performed based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, the net_daemon client application is started according to various information of the terminal device and the configuration file; After the net_daemon client applications of all terminal devices in the industrial control system are started, consistency verification is performed based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, the pdb_server client application is started; After the pdb_server client applications of all terminal devices in the industrial control system are started, consistency verification is performed based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, the file_server client application is started according to the configuration file of the terminal device, and the files to be synchronized are transmitted.
[0008] Further, after the historical station is started, consistency verification is performed based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, the net_daemon client application is started according to various information of the terminal device and the configuration file, including: The specific process of performing consistency verification based on the information in the terminal device and the corresponding information in the historical station is as follows: Obtain the nodeName, multisiteName, and netCout of each terminal device through the net_daemon client application; then use the SM4 algorithm to encrypt and the SM3 algorithm to perform integrity verification on the nodeName, multisiteName, and netCout through the cryptographic machine API; send the encrypted and verified data to the net_daemon server for verification; after the net_daemon server in the historical station receives the information, first use the SM4 algorithm to decrypt and the SM3 algorithm to perform integrity verification. After the verification passes, if the multisiteName of the terminal device is inconsistent with the multisiteName of the historical station, a stop start signal is returned to prevent the net_daemon client from starting; if they are consistent, a continue start signal is sent to guide the net_daemon applications in other terminal devices to complete the start; Among them, after the consistency verification passes, the start process of the net_daemon client application is as follows: First, load and read the net_sys.conf file, then use the SM4 algorithm to decrypt the file through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, read the multisiteName and netCout in the file as parameters of the net_daemon client application to start it.
[0009] Further, after the net_daemon client applications of all terminal devices in the industrial control system are started, perform consistency verification based on the information in the terminal devices and the corresponding information in the historical station. When the consistency verification passes, start the pdb_server client application, including: The specific process of performing consistency verification based on the information in the terminal devices and the corresponding information in the historical station is as follows: Obtain the nodeName, dual-network IP, and UUID of each terminal device, use the SM2 algorithm to encrypt various information data through the cryptographic API and use the SM3 algorithm for integrity verification, and broadcast the encrypted data and verification code to the historical station; after the historical station receives the information, use the SM2 algorithm to decrypt the information through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, check whether there is a corresponding node in the vector according to the nodeName. If not, return a stop start signal; if so, then compare whether the dual-network IP and UUID are consistent. If they are inconsistent, return a stop start signal. If they are consistent, send a continue start signal to guide the pdb_server client programs in other terminal devices to complete the start; Among them, when the consistency verification passes, directly start the pdb_server client application.
[0010] Further, after the pdb_server client applications of all terminal devices in the industrial control system are started, perform consistency verification based on the information in the terminal devices and the corresponding information in the historical station. When the consistency verification passes, start the file_server client application according to the configuration file of the terminal device and transfer the files to be synchronized, including: The specific process of performing consistency verification based on the information in the terminal devices and the corresponding information in the historical station is as follows: Obtain the fileSysncFlag of each terminal device, use the SM4 algorithm to encrypt the fileSysncFlag and the file path information to be synchronized through the cryptographic API, and use the SM3 algorithm to perform integrity verification, and send the encrypted and verified data to the file_server server for verification; after the file_server server in the historical station receives the information, first use the SM4 algorithm for decryption and the SM3 algorithm for integrity verification. After the verification passes, if the fileSysncFlag of the terminal device is inconsistent with the fileSysncFlag in the historical station, a stop startup signal is returned to prevent the file_server client application from starting; if they are consistent, a continue startup signal is sent to guide the file_server client application in other terminal devices to complete the startup; Among them, after the consistency verification passes, the startup process of the file_server client application is as follows: Load and read the file_server_cfg.conf file, and use the SM4 algorithm to decrypt the file through the cryptographic API and use the SM3 algorithm to perform integrity verification; after the verification passes, read parameters such as fileServerIp and fileSysncFlag in the file as the parameters of the file_server client application to start; Among them, the file path information to be synchronized is carried during the encryption and decryption of the fileSysncFlag, and they are encrypted and decrypted together. After the above-mentioned consistency verification passes, the file_server client application will be started. After the file_server client application is started, the file to be synchronized will be directly transmitted.
[0011] The second aspect of the present invention is to provide a registration communication encryption device between terminal devices for an industrial control system, including a historical station, an operator station, a controller, and a cryptographic machine. The historical station, operator station, controller, and cryptographic machine send instructions to the processor and perform data exchange. When the processor executes the computer program, the registration communication encryption method between terminal devices for an industrial control system is implemented.
[0012] The third aspect of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the registration communication encryption method between terminal devices for an industrial control system is implemented.
[0013] The fourth aspect of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the method for registration communication encryption between terminal devices for an industrial control system.
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: By integrating advanced encryption algorithms such as SM2, SM3, and SM4 with a dedicated cryptographic machine, the security of key configurations and synchronized data is ensured, effectively preventing unauthorized access and tampering, and significantly enhancing the overall protection ability of the system. The system adopts a three-level registration verification mechanism. First, the multisiteName of net_daemon is verified, then the device name, IP, and UUID mapping of pdb_server are performed, and finally the fileSysncFlag of file_server is verified; encryption verification is combined in the registration verification mechanism to ensure the secure access of devices, simplify the management process, and reduce the risk of configuration errors. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 It is a schematic flowchart of the steps of a method for registration communication encryption between terminal devices for an industrial control system provided by the present invention; Figure 2 It is a schematic flowchart of the registration communication encryption process between terminal devices for an industrial control system. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0018] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0019] In view of the problems existing in the background technology, the first aspect of the present invention is to provide a registration communication encryption method and device for terminal devices in an industrial control system, which has important practical significance.
[0020] As Figure 1 shown, the first aspect of the present invention is to provide a registration communication encryption method for terminal devices in an industrial control system, including the following steps: Step S001: Obtain various information of terminal devices in the industrial control system, and store the various information of the terminal devices in the sysinfor.dat file.
[0021] It should be noted that in order to make the industrial control system more secure and stable, it is necessary to ensure the security and controllability of each device in the industrial control system. And some secure and reliable management systems are established through the unique identifier, IP address and corresponding node of each terminal device to ensure the security and controllability of each device.
[0022] Furthermore, it should be noted that the industrial control system includes a historical station, an operator station, and a controller; the historical station usually refers to a station for storing and managing information such as historical data, events, and alarm records generated in the system; among them, the operator station and the controller are terminal devices.
[0023] Specifically, various information of each terminal device is obtained through the offline_cfg (offline configuration) configuration software in the historical station, including: nodeName (node name), dual-network IP (Internet Protocol), and UUID (Universally Unique Identifier), and the various information of the terminal device is verified and encrypted and stored in the sysinfor.dat file (system information file).
[0024] Among them, there is a one-to-one correspondence between the nodeName, dual-network IP, and UUID of each device. Among them, the offline_cfg configuration software is used to configure and manage functions such as offline data collection, storage, and transmission.
[0025] The specific processes of verification encryption and storage are as follows: Call the API (interface) of the cryptographic machine to first perform integrity verification on the nodeName, dual-network IP, and UUID of all terminal devices through the SM3 algorithm, and then perform encryption through the SM2 algorithm; finally, store the verified and encrypted content in the sysinfor.dat file. Among them, the cryptographic machine is a third-party device.
[0026] Among them, both the SM2 algorithm and the SM3 algorithm are well-known technologies, and no specific elaboration will be made here.
[0027] Step S002: Obtain the configuration files of all devices in the industrial control system, and perform verification and encryption on the configuration files.
[0028] Obtain the configuration files of all devices in the industrial control system. Among them, the configuration files include: the network initialization registration information configuration file net_sys.conf and the file synchronization transmission configuration file file_server_cfg.conf. Among them, net_sys.conf contains network registration information such as multisiteName (site name) and netCout (number of network connections); file_server_cfg.conf contains file synchronization information such as fileServerIp (address of the file server) and fileSysncFlag (synchronization flag). Use encryptFile (file encryption software) to call the API of the cryptographic machine to perform integrity verification on all configuration files using the SM3 algorithm and encryption using the SM4 algorithm.
[0029] Step S003: Start each server application in the historical station.
[0030] The specific process of starting each server application in the historical station is as follows: (1) Start the net_daemon (network daemon process) server application; The net_daemon application first loads and reads the net_sys.conf file, and then decrypts the net_sys.conf file using the SM4 algorithm through the cryptographic machine and performs integrity verification using the SM3 algorithm. After the verification passes, read the multisiteName and netCout in the file as parameters of the net_daemon server application to start.
[0031] (2)Start the pdb_server (PDB server) server application. After startup, place various information of the terminal device in a vector (container) for easy comparison during subsequent device registration; After the net_daemon server application starts, start the pdb_server server application. When the pdb_server server application starts, first load and read the sysinfor.dat file, then use the SM2 algorithm to decrypt the encrypted sysinfor.dat file through the API of the cryptographic machine and use the SM3 algorithm for integrity verification. After the verification passes, read and maintain the nodeName, dual-network IP, and UUID of all terminal devices in a vector (container) for easy comparison during subsequent device registration.
[0032] Among them, no parameters are required during the startup process of the pdb_server server application, and it can be started directly by loading the sysinfor.dat file.
[0033] (3)Start the file_server (file server) server application.
[0034] After the pdb_server server application starts, start the file_server server application. When the file_server server application starts, first load and read the file_server_cfg.conf file, then use the SM4 algorithm to decrypt the file_server_cfg.conf file through the cryptographic machine API and use the SM3 algorithm for integrity verification. After the verification passes, read the fileServerIp and fileSysncFlag in the file as parameters of the file_server server application to start.
[0035] Step S004: Start each client application in the terminal device.
[0036] (1)After the historical station starts, perform consistency verification based on the information in the terminal device and the corresponding information in the historical station. When the consistency verification passes, start the net_daemon client application according to the various information and configuration files of the terminal device; The specific process of performing consistency verification based on the information in the terminal device and the corresponding information in the historical station is as follows: Obtain the nodeName, multisiteName, and netCout of each terminal device through the net_daemon client application; then use the SM4 algorithm to encrypt the nodeName, multisiteName, and netCout through the cryptographic API and use the SM3 algorithm for integrity verification; send the encrypted and verified data to the net_daemon server for verification; after the net_daemon server in the historical station receives the information, first use the SM4 algorithm for decryption and the SM3 algorithm for integrity verification. After the verification passes, if the multisiteName of the terminal device is inconsistent with the multisiteName of the historical station, return a stop startup signal to prevent the net_daemon client from starting; if they are consistent, send a continue startup signal to guide the net_daemon application in other terminal devices to complete the startup.
[0037] Among them, after the consistency verification passes, the startup process of the net_daemon client application is as follows: First, load and read the net_sys.conf file, then use the SM4 algorithm to decrypt the file through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, read the multisiteName and netCout in the file as parameters of the net_daemon client application to start.
[0038] (2) After the net_daemon client applications of all terminal devices in the industrial control system are started, perform consistency verification based on the information in the terminal devices and the corresponding information in the historical station. After the consistency verification passes, start the pdb_server client application; The specific process of performing consistency verification based on the information in the terminal devices and the corresponding information in the historical station is as follows: Obtain the nodeName, dual-network IP, and UUID of each terminal device, use the SM2 algorithm to encrypt various information data through the cryptographic API and use the SM3 algorithm for integrity verification, and send the encrypted data and verification code to the historical station through broadcasting; after the historical station receives the information, use the SM2 algorithm to decrypt the information through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, check whether there is a corresponding node in the vector according to the nodeName. If not, return a stop startup signal; if there is, then compare whether the dual-network IP and UUID are consistent. If they are inconsistent, return a stop startup signal. If they are consistent, send a continue startup signal to guide the pdb_server client program in other terminal devices to complete the startup.
[0039] Among them, after the consistency verification passes, the pdb_server client application program is directly started.
[0040] (3) After the pdb_server client application programs of all terminal devices in the industrial control system are started, consistency verification is performed based on the information in the terminal devices and the corresponding information in the historical station. After the consistency verification passes, the file_server client application program is started according to the configuration file of the terminal device.
[0041] The process of consistency verification based on the information in the terminal devices and the corresponding information in the historical station and the transmission of synchronized files are as follows: Obtain the fileSysncFlag of each terminal device and the information of the file path to be synchronized. Use the SM4 algorithm to encrypt the fileSysncFlag and the information of the file path to be synchronized through the cryptographic API and use the SM3 algorithm for integrity verification, and send the encrypted and verified data to the file_server server for verification; after receiving the information, the file_server server in the historical station first uses the SM4 algorithm for decryption and the SM3 algorithm for integrity verification. After the verification passes, if the fileSysncFlag of the terminal device is inconsistent with the fileSysncFlag in the historical station, a stop start signal is returned to prevent the file_server client application program from starting; if they are consistent, a continue start signal is sent to guide the file_server client application programs in other terminal devices to complete the start and transmit the files to be synchronized.
[0042] Among them, the startup process of the file_server client application program is as follows: First, load and read the file_server_cfg.conf file, and use the SM4 algorithm to decrypt the file through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, read parameters such as fileServerIp and fileSysncFlag in the file as the parameters of the file_server client application program to start. Among them, a schematic flow diagram of the registration communication encryption process between terminal devices for an industrial control system is as Figure 2 shown.
[0043] The second aspect of the present invention is to provide a registration communication encryption device between terminal devices for an industrial control system, including a historical station, an operator station, a controller, and a cryptographic machine. The historical station, operator station, controller, and cryptographic machine send instructions to the processor and perform data exchange. When the processor executes the computer program, a registration communication encryption method between terminal devices for an industrial control system is implemented.
[0044] The third aspect of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, a registration communication encryption method for terminal devices in an industrial control system is implemented.
[0045] The fourth aspect of the present invention is to provide a computer-readable storage medium storing a computer program, which when executed by a processor, implements a registration communication encryption method for terminal devices in an industrial control system.
[0046] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0047] The present invention is described with reference to the flowcharts and / or block diagrams of methods, systems, and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0048] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the specified functions in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0049] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the specified functions in Figure 1 one or more flows and / or blocksFigure 1 Steps of functions specified in one or more boxes.
[0050] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present invention, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the present invention.
Claims
1. A registration communication encryption method between terminal devices for an industrial control system, characterized in that, Including: Obtaining various information of terminal devices in the industrial control system; Obtaining the configuration files of all devices in the industrial control system; wherein, the devices in the industrial control system include: historical stations, operator stations, and controllers; among them, the operator stations and controllers are terminal devices; Starting each server application in the historical station according to various information and configuration files of the historical station in the industrial control system; After the historical station is started, start the net_daemon client application, pdb_server client application, and file_server client application according to various information and configuration files of the terminal devices, and then transfer the files to be synchronized.
2. The registration communication encryption method between terminal devices for an industrial control system according to claim 1, wherein The obtaining of various information of terminal devices in the industrial control system; the obtaining of the configuration files of all devices in the industrial control system includes: Obtaining various information of each terminal device through the offline_cfg configuration software in the historical station, including: nodeName, dual-network IP, and UUID, and verifying, encrypting, and storing the various information of the terminal devices in the sysinfor.dat file; Among them, the specific process of verification, encryption, and storage is: Calling the API of the cryptographic machine to first perform integrity verification on the nodeName, dual-network IP, and UUID of all terminal devices through the SM3 algorithm, and then encrypt them through the SM2 algorithm; finally, store the verified and encrypted content in the sysinfor.dat file; The configuration files include: the network initialization registration information configuration file net_sys.conf and the file synchronization transmission configuration file file_server_cfg.conf; wherein, net_sys.conf contains multisiteName and netCout; file_server_cfg.conf contains fileServerIp and fileSysncFlag.
3. The registration communication encryption method between terminal devices for an industrial control system according to claim 2, characterized in that The starting of each server application in the historical station according to various information and configuration files of the historical station in the industrial control system includes: The specific process of starting each server application in the historical station is as follows: The net_daemon application first loads and reads the net_sys.conf file, then decrypts the net_sys.conf file using the SM4 algorithm through the cryptographic machine and performs integrity verification using the SM3 algorithm; after the verification passes, read the multisiteName and netCout in the file as parameters of the net_daemon server application to start; wherein, the cryptographic machine is a third-party device; After the net_daemon server application starts, the pdb_server server application begins to start. When the pdb_server server application starts, it first loads and reads the sysinfor.dat file, and then uses the SM2 algorithm to decrypt the encrypted sysinfor.dat file through the API of the cryptographic machine and uses the SM3 algorithm for integrity verification. After the verification passes, it reads the nodeName, dual-network IP, and UUID of all terminal devices into and maintains them in a vector for comparison during subsequent device registration; Among them, no parameters are required during the startup process of the pdb_server server application, and it can be started directly by loading the sysinfor.dat file; After the pdb_server server application starts, the file_server server application begins to start. When the file_server server application starts, it first loads and reads the file_server_cfg.conf file, and then uses the SM4 algorithm to decrypt the file_server_cfg.conf file through the cryptographic machine API and uses the SM3 algorithm for integrity verification. After the verification passes, it reads the fileServerIp and fileSysncFlag in the file as parameters for starting the file_server server application.
4. The registration communication encryption method between terminal devices for an industrial control system according to claim 3, characterized in that, After the historical station starts, it starts the net_daemon client application, pdb_server client application, and file_server client application according to various information of the terminal device and the configuration file, and then transfers the files to be synchronized, including: After the historical station starts, it performs consistency verification based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, it starts the net_daemon client application according to various information of the terminal device and the configuration file; After the net_daemon client applications of all terminal devices in the industrial control system start, it performs consistency verification based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, the pdb_server client application is started; After the pdb_server client applications of all terminal devices in the industrial control system start, it performs consistency verification based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, it starts the file_server client application according to the configuration file of the terminal device and transfers the files to be synchronized.
5. A registration communication encryption method between terminal devices for an industrial control system according to claim 4, characterized in that, After the historical station starts, it performs consistency verification based on the information in the terminal device and the corresponding information in the historical station. After the consistency verification passes, it starts the net_daemon client application according to various information of the terminal device and the configuration file, including: The specific process of performing consistency verification based on the information in the terminal device and the corresponding information in the historical station is: Obtain the nodeName, multisiteName, and netCout of each terminal device through the net_daemon client application; then use the SM4 algorithm to encrypt the nodeName, multisiteName, and netCout through the cryptographic API and use the SM3 algorithm for integrity verification; send the encrypted and verified data to the net_daemon server for verification; after the net_daemon server in the historical station receives the information, first use the SM4 algorithm for decryption and the SM3 algorithm for integrity verification. After the verification passes, if the multisiteName of the terminal device is inconsistent with the multisiteName of the historical station, return a stop startup signal to prevent the net_daemon client from starting; if they are consistent, send a continue startup signal to guide the net_daemon application in other terminal devices to complete the startup; Among them, after the consistency verification passes, the startup process of the net_daemon client application is as follows: First, load and read the net_sys.conf file, then use the SM4 algorithm to decrypt the file through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, read the multisiteName and netCout in the file as parameters of the net_daemon client application to start.
6. A registration communication encryption method between terminal devices for an industrial control system according to claim 4, characterized in that, When the net_daemon client applications of all terminal devices in the industrial control system are started, perform consistency verification based on the information in the terminal devices and the corresponding information in the historical station. After the consistency verification passes, start the pdb_server client application, including: The specific process of performing consistency verification based on the information in the terminal devices and the corresponding information in the historical station is: Obtain the nodeName, dual-network IP, and UUID of each terminal device, use the SM2 algorithm to encrypt various information data through the cryptographic API and use the SM3 algorithm for integrity verification, and send the encrypted data and verification code to the historical station through broadcasting; after the historical station receives the information, use the SM2 algorithm to decrypt the information through the cryptographic API and use the SM3 algorithm for integrity verification. After the verification passes, check whether there is a corresponding node in the vector according to the nodeName. If not, return a stop startup signal; if there is, then compare whether the dual-network IP and UUID are consistent. If they are inconsistent, return a stop startup signal. If they are consistent, send a continue startup signal to guide the pdb_server client program in other terminal devices to complete the startup; Among them, after the consistency verification passes, directly start the pdb_server client application.
7. A registration communication encryption method between terminal devices for an industrial control system according to claim 4, characterized in that, After the pdb_server client applications of all terminal devices in the industrial control system are started, consistency verification is performed based on the information in the terminal devices and the corresponding information in the historical station. After the consistency verification passes, the file_server client application is started according to the configuration file of the terminal device, and the files to be synchronized are transmitted, including: The specific process of performing consistency verification based on the information in the terminal device and the corresponding information in the historical station is as follows: Obtain the fileSysncFlag of each terminal device, encrypt the fileSysncFlag and the file path information to be synchronized using the SM4 algorithm through the cryptographic API and perform integrity verification using the SM3 algorithm, and send the encrypted and verified data to the file_server server for verification; after receiving the information, the file_server server in the historical station first decrypts using the SM4 algorithm and performs integrity verification using the SM3 algorithm. After the verification passes, if the fileSysncFlag of the terminal device is inconsistent with the fileSysncFlag in the historical station, a stop startup signal is returned to prevent the file_server client application from starting; if they are consistent, a continue startup signal is sent to guide the file_server client applications in other terminal devices to complete the startup; Among them, after the consistency verification passes, the startup process of the file_server client application is as follows: Load and read the file_server_cfg.conf file, decrypt the file using the SM4 algorithm through the cryptographic API and perform integrity verification using the SM3 algorithm; after the verification passes, read parameters such as fileServerIp and fileSysncFlag in the file as the parameters of the file_server client application to start; Among them, the file path information to be synchronized is carried during the encryption and decryption of the fileSysncFlag, and encryption and decryption are performed together. After the above consistency verification passes, the file_server client application will be started. After the file_server client application is started, the files to be synchronized are directly transmitted.
8. A registration communication encryption device between terminal devices for an industrial control system, characterized in that, Including a historical station, an operator station, a controller, and a cryptographic machine, the historical station, operator station, controller, and cryptographic machine send instructions and perform data exchange with the processor, and the processor implements the method for encrypted registration communication between terminal devices for an industrial control system according to any one of claims 1-7 when executing the computer program.
9. An electronic device, characterized in that, Including a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor implements the method for encrypted registration communication between terminal devices for an industrial control system according to any one of claims 1-7 when executing the computer program.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method for registering and communicating encryption between terminal devices for an industrial control system according to any one of claims 1-7.