Terminal trusted connection method and system for secure transmission of power grid data
Through the security guarantee method of hierarchical architecture, the credibility problem of data transmission of power grid terminals is solved, and a safe and trustworthy network connection environment is built to ensure the security and integrity of power grid data transmission, and to enhance the credibility of power grid terminals.
Patent Information
- Application Number
- CN202510571507.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-15
AI Technical Summary
It is difficult for the prior art to build a safe and trustworthy data transmission environment in the power grid terminal, which affects the stable operation of the power grid and the security of energy supply.
The security guarantee method adopts a hierarchical architecture, including dedicated client identity authentication at the application layer, end-to-end encryption of data at the transmission layer, communication path encryption and routing at the network layer, terminal fingerprint trusted authentication at the device layer and regular security audits, and the authentication information is regularly updated with the OSI model and TCP/IP model.
A safer and more trusted network connection architecture is built to ensure the security, integrity and credibility of power grid data during transmission, and enhance the robustness of power grid terminals.
Smart Images

Figure CN120499288A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power grid information security, and in particular to a terminal trusted connection method and system for secure transmission of power grid data. Background Art
[0002] As an important component of the power grid system, the reliability of grid terminals is directly related to the stable operation of the power grid and the security of energy supply. Therefore, improving the reliability of grid terminals has become an important task to ensure the security of power supply.
[0003] Improving the trustworthiness of power grid terminals is not only a development need for power grid companies themselves, but also an important measure to ensure social energy security. Therefore, it is necessary to propose a terminal trusted connection architecture for secure transmission of power grid data. Summary of the Invention
[0004] Purpose of the invention: The purpose of the present invention is to provide a terminal trusted connection method and system for secure transmission of power grid data.
[0005] Technical solution: The terminal trusted connection method for secure transmission of power grid data described in the present invention includes the following steps:
[0006] (1) Dedicated client authentication at the application layer;
[0007] (2) End-to-end encryption and transmission of data at the transport layer;
[0008] (3) Communication path encryption and routing selection at the network layer;
[0009] (4) Terminal fingerprint trusted authentication and data transmission at the device layer;
[0010] (5) Conduct safety audits regularly;
[0011] (6) Regularly update relevant certification information.
[0012] Furthermore, the step (1) uses a dedicated client to initiate a connection request to the server in the power grid system at the user-oriented terminal application layer, including:
[0013] (1.1) Install the dedicated client on the user's terminal as required. The user needs to enter his / her account and password to log in to the dedicated client;
[0014] (1.2) The user imports the data to be transmitted to the server side of the power grid system, such as text, files, etc., into the dedicated client as application layer data.
[0015] Furthermore, the step (2) receives the data unit from the application layer, encrypts it, and uses a reliable transmission protocol to ensure the integrity and security of the data, including:
[0016] (2.1) Encrypting application layer data units using a hybrid encryption scheme;
[0017] (2.2) Use a reliable transmission protocol to establish a connection first and then transmit data.
[0018] Furthermore, the step (3) selects and uses appropriate encryption algorithms and verification algorithms to encrypt and encapsulate network layer datagrams, sets routing strategies within the power grid system, and establishes network layer transmission tunnels to ensure data security.
[0019] Furthermore, the step (4) authenticates the current terminal through the terminal fingerprint to verify whether it is trustworthy, and encapsulates the data frame in a trustworthy state.
[0020] Furthermore, the step (4) includes:
[0021] (4.1) After the professional client is installed, it collects and combines multiple hardware and software attributes to create a terminal fingerprint, and uploads it to the server for storage;
[0022] (4.2) When a user initiates a data transmission request through a terminal, the server will request the terminal fingerprint of the current terminal and compare it with the previously stored fingerprint. If they match, it means that the terminal is trustworthy; if they do not match, the server will refuse to continue the operation;
[0023] (4.3) When the terminal is in a trusted state, the terminal fingerprint is inserted between the datagram and the device layer header, encapsulated into a data frame and sent out.
[0024] Furthermore, the software attributes of step (4.1) include CPU serial number, hard disk serial number, operating system product ID and IP address.
[0025] Furthermore, the step (5) includes recording relevant logs of security events and path selection decisions, and analyzing them afterwards to discover and deal with potential security risks.
[0026] Furthermore, the step (6) takes into account the dynamic nature of network security and regularly updates the trusted authentication information of the terminal, including account passwords, encryption keys of the transport layer and network layer, and terminal fingerprints.
[0027] The terminal trusted connection system for secure transmission of power grid data according to the present invention comprises:
[0028] Application layer: The user-oriented application layer authenticates the user of the terminal through the account and password;
[0029] The transport layer performs end-to-end encryption on data units from the application layer and uses a reliable transmission protocol to ensure data integrity and security;
[0030] The network layer uses encryption and authentication algorithms to encrypt and encapsulate IP datagrams, set routing strategies within the power grid system, and establish secure data transmission tunnels;
[0031] At the device layer, the terminal is authenticated through its fingerprint to verify its legitimacy and enhance the robustness of the overall security architecture.
[0032] Beneficial effects: Compared with the existing technology, the present invention has the following significant advantages: the present invention comprehensively considers the complexity of the power grid, the sensitivity of the data and the potential security threats, and adopts different security methods and measures at different levels to cooperate with each other to jointly build a trusted communication environment; it combines the layered network trusted connection architecture with the OSI model or the TCP / IP model, and combines the needs of secure transmission of power grid data. The corresponding layers in the OSI model or the TCP / IP model are expanded and customized to ensure the security, integrity and credibility of power grid data during transmission, and integrates key technologies such as identity authentication and data encryption in the corresponding layers to build a more secure and reliable network connection architecture. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is the structure diagram of OSI model and TCP / IP model;
[0034] Figure 2 This is a system diagram of the terminal trusted connection architecture for secure transmission of power grid data;
[0035] Figure 3 This is an example of calculating a terminal fingerprint using terminal feature information. DETAILED DESCRIPTION
[0036] The technical solution of the present invention will be further described below with reference to the accompanying drawings.
[0037] The OSI model and the TCP / IP model are two architectural models used for network communications. Although they differ in design concepts, layer divisions, and practical applications, their goal is to provide a unified framework for understanding, designing, and implementing network communications. Figure 1As shown. The OSI model was proposed by the International Organization for Standardization (ISO) in 1984. The OSI model divides the network communication process into seven layers, from low to high: Physical layer: responsible for transmitting bit streams, defining the physical interface, electrical characteristics, signal coding, etc. of network equipment; Data link layer: responsible for providing reliable data transmission services between adjacent nodes, including link management, error control, flow control, etc.; Network layer: responsible for transmitting datagrams from the source to the destination, mainly handling issues such as packet routing and address resolution; Transport layer: provides end-to-end reliable or unreliable data transmission services to the upper layer, handling issues such as data segmentation and reassembly, flow control, and congestion control; Session layer: manages sessions between two application processes, including establishing, managing, and terminating sessions; Presentation layer: handles data presentation issues, including data encoding, data encryption, and data compression; Application layer: provides network services such as HTTP, FTP, and SMTP to user application processes.
[0038] The TCP / IP model is a four-layer architecture that forms the core protocol suite of the Internet, developed from the ARPANET network. While not as strictly defined as the OSI model, the TCP / IP model is more widely used in practice. The four layers of the TCP / IP model, from lowest to highest, are: Network Interface Layer: This corresponds to the physical and data link layers of the OSI model and is responsible for the physical transmission of data; Network Layer: This corresponds to the network layer of the OSI model and is responsible for routing and forwarding data packets. Its primary protocols include IP; Transport Layer: This corresponds to the transport layer of the OSI model and provides end-to-end reliable or unreliable data transmission services. Its primary protocols include TCP and UDP; Application Layer: This corresponds to the application, presentation, and session layers of the OSI model and is responsible for providing specific network application services, such as HTTP, FTP, and SMTP.
[0039] In network communications, to ensure the security and integrity of data transmission, commonly used data encryption algorithms include symmetric, asymmetric, and hybrid algorithms. Among symmetric encryption algorithms, AES (Advanced Encryption Standard) is currently the most commonly used symmetric encryption algorithm, supporting key lengths of 128, 192, and 256 bits and offering high strength and good performance. SM4 (Secure Multipurpose Mailbox Encryption Algorithm) is a symmetric encryption algorithm developed and released in China for data encryption and decryption. SM4 was designed to replace the DES algorithm to meet domestic security requirements and is compatible with the international standard AES algorithm. Asymmetric encryption algorithms mainly include RSA and ECC. RSA is one of the earliest public-key encryption algorithms, using a pair of keys (public and private). The RSA algorithm is based on the mathematical difficulty of factoring large prime numbers, and its security relies on the difficulty of finding the factorization of the product of two large prime numbers. The ECC algorithm is based on the complexity of the elliptic curve discrete logarithm problem. The security of ECC is based on the irreversibility of point multiplication on elliptic curves. At the same security level, ECC requires a much shorter key length than RSA. In practical applications, hybrid encryption schemes are often used to balance security and efficiency. This involves using an asymmetric encryption algorithm to securely exchange the key for a symmetric encryption algorithm, which is then used to encrypt the actual transmitted data. The TLS (Transport Layer Security) protocol is a typical example of hybrid encryption, combining symmetric and asymmetric encryption to provide an encrypted communication channel between two communicating applications.
[0040] A hash algorithm is a process that converts data of any length (such as text, files, etc.) into data of fixed length (usually a combination of numbers and letters) through a specific algorithm. This conversion is irreversible, that is, the original data cannot be restored from the fixed-length data. The main features of a hash algorithm include: (1) uniqueness. For different original data, the hash algorithm will generate different hash values. Although it is theoretically possible that different data will generate the same hash value, the probability of this happening is extremely low; (2) irreversibility. The original data cannot be deduced from the hash value; (3) fast calculation. For any given data, the hash algorithm can quickly calculate the hash value. SHA256 (Secure Hash Algorithm 256-bit) is a widely used hash algorithm and a member of the SHA-2 (Secure Hash Algorithm 2) family. The hash value it generates is 256 bits (32 bytes) long and is more secure than earlier hash algorithms such as SHA-1. It can resist more cryptanalysis attacks, including collision attacks and pre-mapping attacks.
[0041] Network tunneling technology is a method of establishing a virtual link between networks to transmit data. It mainly uses network tunneling protocols to achieve data encapsulation and transmission, allowing data packets to traverse insecure or incompatible networks. There are many protocols in network tunneling technology, and common tunneling protocols include IPsec, GRE, and SSH. IPsec provides encryption and authentication to ensure data integrity and confidentiality. It is suitable for site-to-site connections and can encrypt and encapsulate data at the IP layer. GRE (Generic Routing Encapsulation) encapsulates data packets of one routing protocol in data packets using another protocol. GRE is a method for establishing direct point-to-point connections across networks, with the goal of simplifying connections between different networks. SSH (Secure Shell Protocol) uses encrypted channels for secure data transmission and is often used for remote login and establishing secure tunnels. SSH operates at Layer 7 (the application layer) of the OSI model.
[0042] Terminal fingerprint refers to the device characteristics or unique device identification that can be used to uniquely identify the terminal device. By collecting various characteristic information of the terminal, a unique identifier is generated, similar to a human fingerprint, which is unique and difficult to copy, and can be used as the identity of the terminal. The components of the terminal fingerprint usually include: (1) hardware information, such as the device's hardware ID, MAC address, IMEI number, etc. This information is assigned during the device production process and is unique; (2) software information, including operating system type, installed plug-ins, browser type and version, etc.; (3) network information, such as MAC address, IP address, network type, etc. that reflect the device's network environment; (4) environmental information, such as the device's geographic location, time zone, language settings, etc. The terminal's hardware and software will be updated over time, so the terminal fingerprint also needs to be updated regularly. This can be achieved through user-initiated updates or regular automatic updates.
[0043] This embodiment provides a technical solution: a terminal trusted connection architecture and method for secure transmission of power grid data, which uses a layered architecture to use different security methods and measures at different levels to collaborate and jointly build a trusted connection for the terminal. Figure 2As shown, at the user-facing application layer, the terminal user's identity is authenticated through their account and password. At the transport layer, data units from the application layer are encrypted end-to-end, and a reliable transmission protocol is used to ensure data integrity and security. At the network layer, encryption and verification algorithms are used to encrypt and encapsulate IP datagrams, set routing strategies within the power grid system, and establish secure data transmission tunnels. At the device layer, trusted terminals are authenticated and verified through terminal fingerprints to verify their legitimacy, thereby enhancing the robustness of the overall security architecture. Taking into account the dynamic nature of the network environment, regular security audits are conducted on terminals through log analysis of security events and path selection decisions. The terminal's trusted authentication information, including account passwords, encryption keys for the transport and network layers, and terminal fingerprints, is regularly updated to prevent passwords, keys, and other related information from being cracked or leaked.
[0044] As an important component of the power grid system, the reliability of grid terminals is directly related to the stable operation of the power grid and the security of energy supply. Therefore, improving the reliability of grid terminals has become an important task to ensure the security of power supply.
[0045] In one embodiment, the specific technical solution is implemented as follows:
[0046] (1) When the terminal starts the dedicated client, the dedicated client collects the characteristic information of the current terminal device, including the CPU serial number, hard disk serial number, operating system type and version, and IP address, and uses the hash algorithm to calculate the characteristic information to generate a unique terminal fingerprint and send it together with the current dedicated client ID to the server in the power grid system. Figure 3 As shown, for the current terminal device feature information, where the CPU serial number is "ABC123456789", the hard disk serial number is "DEF9876543210", the operation type and version are "Linux 4.15.0-103-generic", and the IP address is "192.168.1.100", the terminal fingerprint (hash value) is calculated using the SHA256 algorithm.
[0047] (2) The server receives the terminal fingerprint from the dedicated client and compares the terminal fingerprint with the corresponding fingerprint in the terminal fingerprint library in the server. If the fingerprints match, the current terminal is confirmed to be trustworthy. Otherwise, it is untrustworthy and the trust status of the current terminal is returned to the dedicated client.
[0048] (3) The dedicated client receives the terminal trust status from the server. If the current terminal is in an untrusted state, a warning message "The current terminal is in an untrusted state, the client will be closed soon..." will be displayed on the login interface. At the same time, the account and password input fields will be set to a non-input state, and the dedicated client will be closed within 10 seconds. If the current terminal is in a trusted state, the user enters the correct account and password on the login interface to enter the dedicated client.
[0049] (4) The user imports the data to be transmitted to the power grid server, such as text and files, from the terminal into the dedicated client and sends it to the server as application layer data;
[0050] (5) The transport layer receives data units from the application layer and encrypts the application layer data units using a hybrid encryption scheme to ensure that the communication data is not eavesdropped during transmission. For example, using the TLS protocol, the client and server use an asymmetric encryption algorithm (such as RSA or ECC) to exchange keys, and then use the key generated from the asymmetric encryption. The client and server begin to use a symmetric encryption algorithm (such as AES) to encrypt subsequent communication data; at the same time, in order to ensure the secure transmission of power grid data, a reliable transmission protocol is selected to establish a connection first and then transmit data. For example, the TCP protocol is used to ensure reliable data transmission, and data loss is avoided through mechanisms such as flow control and congestion control.
[0051] (6) The network layer receives data units from the transport layer and first adds a network layer header to them to form a datagram. It then selects and uses appropriate encryption and authentication algorithms to encrypt and encapsulate the datagram, sets routing strategies within the power grid system, and establishes network layer transmission tunnels to ensure secure data transmission. For example, when using the IPsec protocol, the ESP (Encapsulating Security Payload) protocol is first used to encrypt the IP data packet to ensure data confidentiality, and then the AH (Authentication Header) protocol is used to perform integrity checks on the IP data packet to prevent data tampering during transmission. Enable the IPsec function on network devices (such as routers and firewalls) and apply relevant policies to the interfaces.
[0052] (7) The device layer receives the datagram (encrypted and encapsulated) from the network layer, and adds the terminal fingerprint of the current terminal between the datagram and the device layer header. The server can verify the trust status of the terminal device again through the terminal fingerprint.
[0053] (8) The dedicated client records all security events and path selection decision logs in the above steps and sends them to the server so that security audits can be carried out regularly. By analyzing the log records, potential security risks can be discovered and handled in a timely manner.
[0054] (9) Considering the dynamic nature of network security, the trusted authentication information of the terminal should be updated regularly, including account passwords, encryption keys at the transport layer and network layer, etc., to prevent passwords, keys and other related information from being cracked or leaked. In addition, the hardware and software of the terminal device will be updated over time, so the terminal fingerprint also needs to be updated regularly. Each time the dedicated client is started, if the feature information used to generate the terminal fingerprint (such as CPU serial number, hard disk serial number, operating system type and version, and IP address, etc.) is found to have changed, it should be automatically sent to the server and marked as abnormal, and manually confirmed and updated.
Claims
1. A terminal trusted connection method for secure transmission of power grid data, characterized in that: The steps include: (1) Dedicated client authentication at the application layer; (2) End-to-end encryption and transmission of data at the transport layer; (3) Communication path encryption and routing selection at the network layer; (4) Terminal fingerprint trusted authentication and data transmission at the device layer; (5) Conduct safety audits regularly; (6) Regularly update relevant certification information.
2. The terminal trusted connection method for secure transmission of power grid data according to claim 1 is characterized in that: The step (1) uses a dedicated client to initiate a connection request to a server in the power grid system at the user-oriented terminal application layer, including: (1.1) Install the dedicated client on the user's terminal as required. The user needs to enter his / her account and password to log in to the dedicated client; (1.2) The user imports the data to be transmitted to the server side of the power grid system, such as text, files, etc., into the dedicated client as application layer data.
3. The terminal trusted connection method for secure transmission of power grid data according to claim 1 is characterized in that: The step (2) receives the data unit from the application layer, encrypts it, and uses a reliable transmission protocol to ensure the integrity and security of the data, including: (2.1) Encrypting application layer data units using a hybrid encryption scheme; (2.2) Use a reliable transmission protocol to establish a connection first and then transmit data.
4. The terminal trusted connection method for secure transmission of power grid data according to claim 1 is characterized in that: The step (3) selects and uses appropriate encryption algorithms and verification algorithms to encrypt and encapsulate network layer datagrams, sets routing strategies within the power grid system, establishes network layer transmission tunnels, and ensures data security.
5. The terminal trusted connection method for secure transmission of power grid data according to claim 1 is characterized in that: The step (4) authenticates the current terminal through the terminal fingerprint to verify whether it is trustworthy, and encapsulates the data frame in a trustworthy state.
6. The terminal trusted connection method for secure transmission of power grid data according to claim 1, characterized in that: The step (4) comprises: (4.1) After the professional client is installed, it collects and combines multiple hardware and software attributes to create a terminal fingerprint, and uploads it to the server for storage; (4.2) When a user initiates a data transmission request through a terminal, the server will request the terminal fingerprint of the current terminal and compare it with the previously stored fingerprint. If they match, it means that the terminal is trustworthy; if they do not match, the server will refuse to continue the operation; (4.3) When the terminal is in a trusted state, the terminal fingerprint is inserted between the datagram and the device layer header, encapsulated into a data frame and sent out.
7. The terminal trusted connection method for secure transmission of power grid data according to claim 6, characterized in that: The software attributes of step (4.1) include CPU serial number, hard disk serial number, operating system product ID and IP address.
8. The terminal trusted connection method for secure transmission of power grid data according to claim 1, characterized in that: The step (5) includes recording relevant logs of security events and path selection decisions, and analyzing them afterwards to discover and deal with potential security risks.
9. The terminal trusted connection method for secure transmission of power grid data according to claim 1, characterized in that: The step (6) takes into account the dynamic nature of network security and regularly updates the trusted authentication information of the terminal, including account passwords, encryption keys of the transport layer and network layer, and terminal fingerprints.
10. A terminal trusted connection system for secure transmission of power grid data, characterized in that: include: Application layer: The user-oriented application layer authenticates the user of the terminal through the account and password; The transport layer performs end-to-end encryption on data units from the application layer and uses a reliable transmission protocol to ensure data integrity and security; The network layer uses encryption and authentication algorithms to encrypt and encapsulate IP datagrams, set routing strategies within the power grid system, and establish secure data transmission tunnels; At the device layer, the terminal is authenticated through its fingerprint to verify its legitimacy and enhance the robustness of the overall security architecture.