CMS encryption remote control communication method and device based on transformer substation monitoring system
By setting the encrypted transmission mode and SM2 algorithm signature verification in the substation monitoring system, the security problem of communication process during remote control operations is solved, the encrypted transmission of remote control messages is realized, equipment attacks are prevented, and the security and reliability of the substation are improved.
Patent Information
- Application Number
- CN202510433986.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-11
AI Technical Summary
The CMS communication of existing substation monitoring systems lacks encrypted transmission in remote control operations, resulting in replay messages or network attacks that may lead to misoperation of equipment and cause huge losses.
Set the encryption transmission mode on the CMS server and client, and sign and verify the remote control packets through the SM2 algorithm to realize the encrypted transmission and bidirectional authentication of the remote control packets.
It realizes encrypted transmission of remote control communication process, prevents packets from being intercepted and attacks the substation equipment, and improves the security and reliability of the substation.
Smart Images

Figure CN120301642A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of substation monitoring, and particularly relates to a CMS encrypted remote control communication method and device based on a substation monitoring system. Background Art
[0002] The statements in this part merely provide background technical information related to the present invention and do not necessarily constitute prior art.
[0003] The new generation of substation monitoring systems uses CMS communication, and the CMS communication process adopts ordinary communication and encrypted communication. Among them, in order to ensure the security of information transmission, the existing CMS communication implements two-way authentication, but only during the communication process. However, during the communication process, remote control operation is a key operation, and the existing technology ignores the encrypted transmission of remote control operations, which may lead to replay messages or network attacks being easily misoperated on the primary equipment in the station, thus causing huge losses in the substation. Summary of the Invention
[0004] In order to solve the technical problems existing in the above background art, the present invention provides a CMS encrypted remote control communication method and device based on a substation monitoring system, which can improve the security and reliability in the substation.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] The first aspect of the present invention provides a CMS encrypted remote control communication method based on a substation monitoring system.
[0007] A CMS encrypted remote control communication method based on a substation monitoring system, comprising:
[0008] Set the encrypted transmission mode on both the CMS server and the CMS client, and load the corresponding database for configuration;
[0009] Judge whether a connection is established with the CMS server port on the CMS client. If so, send a remote control command to the CMS server;
[0010] On the CMS server, listen to the TCP / IP port to judge whether a remote control command is received. If so, continue to judge the positive response. If it is a signature for the remote control message, put the signature content into the remote control structure, encode the remote control message and send the message, and then forward the remote control success response to the CMS client;
[0011] After receiving the remote control response on the CMS client, verify the signature of the remote control message, and then judge whether the signature verification passes. If so, the remote control is successful; otherwise, the remote control fails.
[0012] As an implementation, if the CMS client fails to establish a connection with the CMS server port, the network connection volume to the CMS server is tested, and the CMS server port is periodically detected. If the CMS server is detected, the CMS server is connected.
[0013] As an implementation, the remote control message structure includes a reference, a controlled value, a remote control service operation time, a request origin, the identity of the request initiator, a remote control serial number, a change time, a test status, an inspection condition, and an attachment reason.
[0014] As an implementation, if the CMS server is in a positive response, the remote control message is signed by the SM2 algorithm to generate a 64-bit hash value, and the 64-bit hash value is placed into the remote control structure.
[0015] As an implementation, the remote control commands include: remote control selection, remote control execution, and remote control cancellation.
[0016] As an implementation, after the remote control is successful, the CMS server performs corresponding response operations according to the actual request operations corresponding to the remote control commands.
[0017] The second aspect of the present invention provides a CMS encrypted remote control communication device based on a substation monitoring system.
[0018] A CMS encrypted remote control communication device based on a substation monitoring system includes: a CMS server and a CMS client; wherein, an encrypted transmission mode is preset and a corresponding database is configured in both the CMS server and the CMS client;
[0019] The CMS client is used to determine whether it has established a connection with the CMS server port. If so, it issues a remote control command to the CMS server;
[0020] The CMS server is used to listen to the TCP / IP port to determine whether it has received a remote control command. If so, it continues to determine the positive response. If it is, it signs the remote control message, places the signed content into the remote control structure, encodes the remote control message and sends the message, and then forwards the remote control success response to the CMS client;
[0021] The CMS client is used to verify the signature of the remote control message after receiving the remote control response, and then determine whether the signature verification passes. If so, the remote control is successful; otherwise, the remote control fails.
[0022] As an implementation, the CMS client is further used to test the network connection volume to the CMS server and periodically detect the CMS server port if it fails to establish a connection with the CMS server port. If the CMS server is detected, the CMS server is connected.
[0023] As an implementation manner, the remote control message structure includes a reference, a controlled value, a remote control service operation time, a request origin, the identity of the request initiator, a remote control serial number, a change time, a test status, an inspection condition, and an attachment reason.
[0024] As an implementation manner, the CMS server is further configured to, if it is in a responsive state, sign the remote control message by using the SM2 algorithm to generate a 64-bit hash value, and put the 64-bit hash value into the remote control structure.
[0025] The beneficial effects of the present invention are as follows:
[0026] The present invention provides a CMS encrypted remote control communication method and device based on a substation monitoring system, which realizes the remote control encrypted communication process during the CMS communication of the substation monitoring system, encrypts the application layer, and performs ciphertext transmission during the remote control communication process. Moreover, it realizes that after intercepting the message, the message cannot be replayed to attack the devices in the substation, greatly improving the security and reliability in the substation.
[0027] Advantages of additional aspects of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The specification drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and the descriptions thereof are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0029] Figure 1 It is a flowchart of the CMS encrypted remote control communication method based on the substation monitoring system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] The present invention will be further described below in conjunction with the drawings and embodiments.
[0031] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0032] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless otherwise clearly specified in the context, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "include" and / or "comprise" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0033] Figure 1 This is the flowchart of the CMS encrypted remote control communication method based on the substation monitoring system according to the embodiments of the present invention. As Figure 1 shown, the embodiments of the present invention provide a CMS encrypted remote control communication method based on the substation monitoring system, which includes:
[0034] Step 1: Set the encrypted transmission mode on both the CMS server and the CMS client, and load the corresponding database for configuration;
[0035] Step 2: Determine whether a connection is established with the CMS server port on the CMS client. If so, send a remote control command to the CMS server;
[0036] Step 3: Listen to the TCP / IP port on the CMS server to determine whether a remote control command is received. If so, continue to judge the positive response. If it is a remote control message, sign it, put the signature content into the remote control structure, encode the remote control message and send the message, and then forward the remote control success response to the CMS client;
[0037] Step 4: After receiving the remote control response on the CMS client, verify the signature of the remote control message, and then determine whether the signature verification passes. If so, the remote control is successful; otherwise, the remote control fails.
[0038] In this embodiment, the present invention realizes two-way encryption authentication of the transport layer and the application layer through the existing CMS communication, encrypts the overall process of the remote control communication, and realizes that after intercepting the message, the message cannot be replayed to attack the equipment in the substation, improving the security and reliability of the in-station equipment.
[0039] In step 1, the encrypted transmission mode can be specifically set according to the actual situation.
[0040] In step 2, if the CMS client fails to establish a connection with the CMS server port, then test the network connection volume with the CMS server (for example, ping the CMS server IP), and periodically detect the CMS server port. If the CMS server is detected, connect to the CMS server.
[0041] It should be noted here that in other embodiments, other existing command operations can also be used to test the network connection volume with the CMS server.
[0042] In step 2, if the TCP / IP port is not monitored, then exit the main process of the CMS server module.
[0043] In this embodiment, the remote control message structure includes a reference, a controlled value (ctlVal), an operation time of the remote control service (operTm), a request origin (origin_orCat), the identity of the request initiator (origin_orIdent), a remote control sequence number (ctlNum), a change time (t), a test status (test), a check condition (check), and an attachment reason (AddCause).
[0044] In step 3, if the CMS server is in a positive response state, sign the remote control message using the SM2 algorithm to generate a 64-bit hash value, and place the 64-bit hash value into the remote control structure.
[0045] Specifically, the 64-bit hash value is placed into the origin_orident field in the remote control structure.
[0046] In step 3, if the CMS server is in a negative response state, then give a negative remote control response.
[0047] Among them, the remote control commands include: remote control selection, remote control execution, and remote control cancellation.
[0048] In step 4, when the remote control is successful, perform corresponding response operations on the CMS server according to the actual request operations corresponding to the remote control commands.
[0049] In step 4, after the signature verification passes, the CMS server performs positive (negative) remote control response operations according to the actual remote control request operations. For a positive response, the switch is in the closed or open position, and the remote control ends. Otherwise, directly return a negative response, and the remote control ends.
[0050] In some other embodiments, a CMS encrypted remote control communication device based on a substation monitoring system is further provided, which includes: a CMS server and a CMS client; wherein, an encryption transmission mode is pre-set and a corresponding database is configured in both the CMS server and the CMS client;
[0051] The CMS client is used to determine whether it has established a connection with the CMS server port. If so, send a remote control command to the CMS server;
[0052] The CMS server is used to listen to the TCP / IP port to determine whether a remote control command is received. If so, continue to determine a positive response. If it is, sign the remote control message, place the signature content into the remote control structure, encode the remote control message and send the message, and then forward the remote control success response to the CMS client;
[0053] The CMS client is used to verify the signature of the remote control message after receiving the remote control response, and then determine whether the signature verification passes. If it does, the remote control is successful; otherwise, the remote control fails.
[0054] In the specific implementation process, the CMS client is further used to test the network connection volume with the CMS server and periodically detect the CMS server port if no connection is established with the CMS server port. If the CMS server is detected, it will connect to the CMS server.
[0055] Among them, the remote control message structure includes a reference, a controlled value, a remote control service operation time, a request origin, the identity of the request initiator, a remote control serial number, a change time, a test status, an inspection condition, and an attachment reason.
[0056] In the specific implementation process, the CMS server is further used to sign the remote control message through the SM2 algorithm if it is in a positive response, generate a 64-bit hash value, and put the 64-bit hash value into the remote control structure.
[0057] This embodiment realizes the remote control encryption communication process during the CMS communication of the substation monitoring system, encrypts the application layer, and performs ciphertext transmission during the remote control communication process. It realizes that after intercepting the message, the message cannot be replayed to attack the equipment in the substation, greatly improving the security and reliability in the substation.
[0058] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A CMS encrypted remote control communication method based on a substation monitoring system, characterized in that, It includes: Set the encrypted transmission mode on both the CMS server and the CMS client, and load the corresponding database for configuration; The CMS client determines whether a connection is established with the CMS server port. If so, it sends a remote control command to the CMS server; The CMS server listens to the TCP / IP port to determine whether a remote control command is received. If so, it continues to judge the positive response. If it is, it signs the remote control message, puts the signature content into the remote control structure, encodes the remote control message and sends the message, and then forwards the remote control success response to the CMS client; After receiving the remote control response, the CMS client verifies the signature of the remote control message, and then judges whether the signature verification passes. If so, the remote control is successful; otherwise, the remote control fails.
2. The CMS encrypted remote control communication method based on the substation monitoring system according to claim 1, wherein, If the CMS client fails to establish a connection with the CMS server port, it tests the network connection volume with the CMS server and periodically detects the CMS server port. If the CMS server is detected, it connects to the CMS server.
3. The CMS encrypted remote control communication method based on the substation monitoring system according to claim 1, wherein, The remote control message structure includes a reference, a controlled value, a remote control service operation time, a request origin, the identity of the request initiator, a remote control serial number, a change time, a test status, an inspection condition, and an attachment reason.
4. The CMS encrypted remote control communication method based on the substation monitoring system according to claim 1, wherein, If the CMS server has a positive response, it signs the remote control message through the SM2 algorithm to generate a 64-bit hash value, and puts the 64-bit hash value into the remote control structure.
5. The CMS encrypted remote control communication method based on the substation monitoring system according to claim 1, characterized in that The remote control command includes: remote control selection, remote control execution, and remote control cancellation.
6. The CMS encrypted remote control communication method based on the substation monitoring system according to claim 1, wherein After the remote control is successful, the CMS server performs corresponding response operations according to the actual request operations corresponding to the remote control command.
7. A CMS encrypted remote control communication device based on a substation monitoring system, characterized in that, It includes: A CMS server and a CMS client; among them, an encrypted transmission mode is preset in both the CMS server and the CMS client, and a corresponding database is configured; The CMS client is used to determine whether it has established a connection with the CMS server port. If so, it sends a remote control command to the CMS server; The CMS server is used to listen to the TCP / IP port to determine whether a remote control command is received. If so, it continues to judge the positive response. If it is, it signs the remote control message, puts the signature content into the remote control structure, encodes the remote control message and sends the message, and then forwards the remote control success response to the CMS client; The CMS client is used to verify the signature of the remote control message after receiving the remote control response, and then judge whether the signature verification passes. If so, the remote control is successful; otherwise, the remote control fails.
8. The CMS encrypted remote control communication device based on the substation monitoring system according to claim 7, characterized in that, The CMS client is also used to test the network connection volume with the CMS server and periodically detect the CMS server port if it fails to establish a connection with the CMS server port. If the CMS server is detected, it connects to the CMS server.
9. The CMS encrypted remote control communication device based on the substation monitoring system according to claim 7, wherein, The remote control message structure includes a reference, a controlled value, a remote control service operation time, a request origin, the identity of the request initiator, a remote control serial number, a change time, a test status, an inspection condition, and an attachment reason.
10. The CMS encrypted remote control communication device based on the substation monitoring system according to claim 7, wherein, The CMS server is also used to sign the remote control message through the SM2 algorithm to generate a 64-bit hash value and put the 64-bit hash value into the remote control structure if it has a positive response.