Cross-security domain data transmission method and device based on Telnet communication protocol, electronic equipment and storage medium
By processing Telnet protocol messages using the SM3 hash algorithm, SM4 encryption, and SM2 signature, the problems of data eavesdropping and tampering in cross-domain communications of the power monitoring system are solved, and the security and reliability of data transmission are improved.
Patent Information
- Application Number
- CN202510959645.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-09-16
AI Technical Summary
The existing power monitoring system lacks effective encryption and authentication mechanisms during cross-security domain communication, which makes data vulnerable to eavesdropping and tampering, threatening system stability and reliability.
The SM3 hash algorithm is used to generate hash values and sign them, combined with SM4 encryption and SM2 signature. Through the instruction anti-tampering device, cross-security domain front-end communication device and cross-security domain protocol message conversion device, the Telnet protocol message is tamper-proof and encrypted, and data integrity and signature legitimacy verification are performed on the target device.
It effectively prevents data from being eavesdropped and tampered with during transmission, improves the security and reliability of cross-domain communication in the power monitoring system, and ensures the integrity and confidentiality of data.
Smart Images

Figure CN120658492A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power grid information security technology, and in particular to a cross-security domain data transmission method, device, electronic device and storage medium based on the Telnet communication protocol. Background Art
[0002] With the rapid development of power systems toward intelligent and information-based systems, power monitoring systems play a vital role in ensuring the safe, stable, and efficient operation of power grids. With the increasing complexity of communication networks, data exchange and command transmission between multiple security domains (such as the control area and non-control area) in power monitoring systems have become critical to ensuring the overall performance and security of the system. However, traditional power monitoring systems face severe security challenges during cross-domain communication, such as data tampering, replay attacks, and communication hijacking. These issues seriously threaten the stability and reliability of the power system.
[0003] Currently, widely used communication protocols in power monitoring systems, such as Telnet, meet data transmission needs to a certain extent, but they lack security. Telnet, in particular, uses a username and password model that presents significant security risks. The lack of effective encryption and authentication mechanisms makes data transmission susceptible to eavesdropping and tampering. Summary of the Invention
[0004] The present invention provides a cross-security domain data transmission method, device, electronic device and storage medium based on the Telnet communication protocol, which can solve the problem that the existing technology lacks effective encryption and authentication mechanisms and data is easily eavesdropped and tampered during transmission.
[0005] In order to solve the above technical problems, an embodiment of the present invention provides a cross-security domain data transmission method based on the Telnet communication protocol, comprising:
[0006] Obtaining an original Telnet protocol message, calculating a hash value corresponding to the Telnet protocol message, and performing data tamper-proof processing on the Telnet protocol message according to the hash value;
[0007] Performing SM4 encryption on the Telnet protocol message according to a preset SM4 algorithm, and signing the Telnet protocol message after the SM4 encryption process to obtain an encrypted data message to be transmitted;
[0008] The encrypted data message is sent to the corresponding target device so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypts the encrypted data message after verification to obtain a decrypted Telnet protocol message, and converts the message format of the decrypted Telnet protocol message into a preset standard message format.
[0009] As a preferred solution, the calculating of the hash value corresponding to the Telnet protocol message and performing data tamper-proof processing on the Telnet protocol message according to the hash value includes:
[0010] Convert the Telnet protocol message into a corresponding binary data message, and perform a hash calculation on the converted binary data message according to a preset SM3 algorithm to obtain a corresponding first hash value;
[0011] According to the preset SM2 algorithm, the first hash value is signed to generate a corresponding hash signature value, and the binary data message and the hash signature value are combined into a first data message.
[0012] As a preferred solution, the method of performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm and signing the Telnet protocol message after SM4 encryption processing to obtain an encrypted data message to be transmitted includes:
[0013] Performing symmetrical encryption on the first data message according to the SM4 algorithm to obtain a symmetrically encrypted second data message;
[0014] Add corresponding timestamp information to the second data message, then sign the second data message with the timestamp information according to the SM2 algorithm to obtain a corresponding signature value, and combine the second data message and the signature value into an encrypted data message to be transmitted.
[0015] As a preferred solution, the data integrity verification and signature legitimacy verification are performed on the encrypted data message, and after the verification is passed, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message, including:
[0016] Performing signature legitimacy verification on the hash signature value and the signature value in the encrypted data message;
[0017] After the signature legitimacy verification of the encrypted data message passes, a hash calculation is performed on the encrypted data message according to the SM3 algorithm to obtain a corresponding second hash value, and the second hash value is compared with the first hash value. When the second hash value is consistent with the first hash value, the data integrity verification of the encrypted data message passes, and after the verification passes, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message.
[0018] On the basis of the above embodiment, another embodiment of the present invention provides a cross-security domain data transmission device based on the Telnet communication protocol, comprising: a data tamper-proof module, a data encryption module, and a data verification and decryption module;
[0019] The data tamper-proof module is used to obtain the original Telnet protocol message, calculate the hash value corresponding to the Telnet protocol message, and perform data tamper-proof processing on the Telnet protocol message according to the hash value;
[0020] The data encryption module is used to perform SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm, and to sign the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted;
[0021] The data verification and decryption module is used to send the encrypted data message to the corresponding target device so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypts the encrypted data message after verification to obtain a decrypted Telnet protocol message, and converts the message format of the decrypted Telnet protocol message into a preset standard message format.
[0022] As a preferred solution, the calculating of the hash value corresponding to the Telnet protocol message and performing data tamper-proof processing on the Telnet protocol message according to the hash value includes:
[0023] Convert the Telnet protocol message into a corresponding binary data message, and perform a hash calculation on the converted binary data message according to a preset SM3 algorithm to obtain a corresponding first hash value;
[0024] According to the preset SM2 algorithm, the first hash value is signed to generate a corresponding hash signature value, and the binary data message and the hash signature value are combined into a first data message.
[0025] As a preferred solution, the method of performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm and signing the Telnet protocol message after SM4 encryption processing to obtain an encrypted data message to be transmitted includes:
[0026] Performing symmetrical encryption on the first data message according to the SM4 algorithm to obtain a symmetrically encrypted second data message;
[0027] Add corresponding timestamp information to the second data message, then sign the second data message with the timestamp information according to the SM2 algorithm to obtain a corresponding signature value, and combine the second data message and the signature value into an encrypted data message to be transmitted.
[0028] As a preferred solution, the data integrity verification and signature legitimacy verification are performed on the encrypted data message, and after the verification is passed, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message, including:
[0029] Performing signature legitimacy verification on the hash signature value and the signature value in the encrypted data message;
[0030] After the signature legitimacy verification of the encrypted data message passes, a hash calculation is performed on the encrypted data message according to the SM3 algorithm to obtain a corresponding second hash value, and the second hash value is compared with the first hash value. When the second hash value is consistent with the first hash value, the data integrity verification of the encrypted data message passes, and after the verification passes, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message.
[0031] Based on the above embodiments, another embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the cross-security domain data transmission method based on the Telnet communication protocol described in the above invention embodiment.
[0032] Based on the above embodiment, another embodiment of the present invention provides a storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the cross-security domain data transmission method based on the Telnet communication protocol described in the above embodiment of the invention.
[0033] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0034] The present invention provides a cross-security domain data transmission method based on the Telnet communication protocol. The method comprises the following steps: obtaining an original Telnet protocol message, calculating a hash value corresponding to the Telnet protocol message, and performing data tamper-proof processing on the Telnet protocol message according to the hash value; performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm, and signing the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted; sending the encrypted data message to a corresponding target device so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypting the encrypted data message after the verification is passed to obtain a decrypted Telnet protocol message, and converting the message format of the decrypted Telnet protocol message into a preset standard message format. The present invention can perform tamper-proof and encryption processing on Telnet protocol messages before they are transmitted across domains. After the encrypted data message is sent to the target device, the encrypted data message is first verified for data integrity and signature legitimacy before being decrypted and subsequently used. This can overcome the problem of data being easily eavesdropped and tampered with during transmission. This solves the security issues in cross-domain communication of power monitoring systems and improves the security and reliability of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is a flow chart of a method for cross-security domain data transmission based on the Telnet communication protocol provided by one embodiment of the present invention;
[0036] Figure 2 The present invention provides a schematic diagram of a cross-security domain data transmission device based on the Telnet communication protocol according to an embodiment of the present invention. DETAILED DESCRIPTION
[0037] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions in this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0038] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned figure descriptions are intended to cover non-exclusive inclusions.
[0039] In the description of the embodiments of this application, the technical terms "first" and "second" are used only to distinguish different objects and should not be understood to indicate or imply relative importance or implicitly specify the quantity, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "plurality" is more than two, unless otherwise clearly and specifically defined.
[0040] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0041] In the description of the embodiments of this application, the term "and / or" is simply a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent the following three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.
[0042] In the description of the embodiments of the present application, the terms "multiple" and "several" refer to more than two (including two). Similarly, "multiple groups" refer to more than two groups (including two groups), and "multiple pieces" refer to more than two pieces (including two pieces).
[0043] In the description of the embodiments of the present application, unless otherwise expressly specified or limited, technical terms such as "installed," "connected," "connected," and "fixed" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integration; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; internal connections between two components or interactions between two components. Those skilled in the art can understand the specific meanings of the above terms in the embodiments of the present application based on specific circumstances.
[0044] Example 1
[0045] Please refer to Figure 1To address the problem of the lack of effective encryption and authentication mechanisms in the prior art, which makes data susceptible to eavesdropping and tampering during transmission, an embodiment of the present invention provides a flow chart of a method for cross-security domain data transmission based on the Telnet communication protocol, including the following specific steps:
[0046] S1. Obtain an original Telnet protocol message, calculate a hash value corresponding to the Telnet protocol message, and perform data tamper-proof processing on the Telnet protocol message according to the hash value;
[0047] Preferably, the calculating the hash value corresponding to the Telnet protocol message and performing data tamper-proof processing on the Telnet protocol message according to the hash value includes: converting the Telnet protocol message into a corresponding binary data message, and performing hash calculation on the converted binary data message according to a preset SM3 algorithm to obtain a corresponding first hash value; signing the first hash value according to a preset SM2 algorithm to generate a corresponding hash signature value, and combining the binary data message and the hash signature value into a first data message.
[0048] Specifically, the communication protocol used in the present invention is the Telnet protocol. A standard Telnet protocol message consists of the following main parts:
[0049] Command Bytes: Telnet protocol messages typically begin with command bytes, which control various Telnet session operations, such as "login" and "logout." Each command corresponds to a specific action. For example, "command byte 0xFF" represents "interpret as command" (IAC). These command bytes serve as instructions during protocol execution, determining how the session proceeds.
[0050] Data section: The data section is the core of the Telnet protocol message and contains the actual information being transmitted. This data may include usernames, passwords, control commands, or other types of messages. The length of the data section varies, depending on the amount of information being transmitted.
[0051] Checksum information: To ensure the integrity of data transmission, the Telnet protocol sometimes adds a checksum field (such as a checksum and length check). The checksum is used to verify the integrity of the data during transmission and ensure that the data has not been tampered with or lost.
[0052] Terminator: The end of a Telnet message usually has a specific terminator, such as "\r\n" which represents a carriage return and line feed. This is an important symbol for marking the end of a message in the Telnet protocol.
[0053] First, the present invention performs tamper-proof processing on the original Telnet protocol message through the instruction tamper-proof device. The specific implementation process is as follows:
[0054] Command tamper prevention devices: Deployed in the Zone I management and collection areas of the power monitoring system, these devices are used to sign Telnet protocol control commands using the SM3 hash algorithm. The Telnet protocol itself is based on a simple character transmission format, typically consisting of commands, data, and checksum information. During data transmission, commands are first processed by the command tamper prevention device. The specific process is as follows:
[0055] First, each control instruction is converted into binary data with a length of L bytes. Then, the SM3 hash algorithm is used to hash the instruction content to generate a 256-bit (32)-byte hash value, as shown in formula (1):
[0056] Hash SM3 (D) = H(D) where D = command data #(1)
[0057] The generated hash value will serve as the digital fingerprint of the instruction content to ensure the integrity and tamper-proof characteristics of the data. Next, the hash value is signed using the SM2 asymmetric encryption algorithm to generate a signature value S. The length of S is usually 256 bits (32 bytes), as shown in formula (2):
[0058] S=Sign SM2 (H(D),Private Key)where H(D)=Hash SM3 (D)#(2)
[0059] This signature value S will be sent to the target device together with the original instruction D to form an encrypted instruction message. Assuming that the length of the original control instruction is L bytes, the total length of the encrypted instruction message is L + 32 bytes (32 bytes is the length of the SM2 signature).
[0060] After the target device receives the command message with the signature, it first verifies the signature using the stored public key through the SM2 algorithm to ensure that the command has not been tampered with. The verification process can be expressed by formula (3)
[0061] Verify SM2 (S,H(D),Private Key)=True if signature is valid#(3)
[0062] If the verification is successful, Verify SM2Only if the value is True can the target device execute the control instruction; otherwise, execution is rejected and a warning message is issued. This encryption and verification process effectively prevents instructions from being tampered with or misoperated during transmission, thereby improving the overall security of the power monitoring system. For example, the original control instruction "SET CONTROL ON" is 14 bytes long. After the encryption process, it passes through the SM3 hash to generate a 32-byte hash value, which is then signed through the SM2 signature to produce a 32-byte signature. The final transmitted instruction message length is 14 bytes (original instruction) + 32 bytes (signature) = 46 bytes. This process ensures the integrity and security of the instruction.
[0063] S2. Performing SM4 encryption on the Telnet protocol message according to a preset SM4 algorithm, and signing the Telnet protocol message after the SM4 encryption process to obtain an encrypted data message to be transmitted;
[0064] Preferably, the performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm, and signing the Telnet protocol message after the SM4 encryption processing to obtain the encrypted data message to be transmitted, includes: performing symmetric encryption processing on the first data message according to the SM4 algorithm to obtain a second data message after the symmetric encryption processing; adding corresponding timestamp information to the second data message, and then signing the second data message with the timestamp information added according to the SM2 algorithm to obtain a corresponding signature value, and combining the second data message and the signature value into the encrypted data message to be transmitted.
[0065] After completing the anti-tampering process, the Telnet protocol message will also be encrypted by the cross-security domain front-end communication device. The specific implementation process is as follows:
[0066] Cross-security domain front-end communication device: This device is located at the boundary of the control area and the non-control area and is responsible for realizing cross-domain secure transmission of data. For data transmission of the Telnet protocol, the front-end communication device first encrypts and signs the original data message to ensure the confidentiality and integrity of the data and prevent replay attacks. Telnet protocol data usually includes commands, parameters and other information. Assume that the length of the original data message is L bytes. First, the front-end communication device uses SM4 to symmetrically encrypt the data message. The SM4 algorithm performs block encryption on the data, and the output ciphertext is C, which is L bytes long. Formula (4) describes the SM4 encryption process:
[0067] C=Encrypt SM4 (D, K) where D = original data message, K = SM4 key #(4)
[0068] The front-end communication device then appends timestamp information T (e.g., a 64-bit timestamp) to the ciphertext C to prevent data replay attacks. The message length after the appended message is L+8 bytes (8 bytes is the timestamp length). Next, the encrypted data and timestamp are signed using the SM2 algorithm to generate a 256-bit (32-byte) signature S, as shown in formula (5):
[0069] S=Sign SM2 (C||T,Private Key)#(5)
[0070] Among them, C||T means that the ciphertext and timestamp are concatenated and signed, and finally an encrypted and signed data message is formed, whose total length is L+8+32 bytes.
[0071] At the receiving end, the front-end communication device located in the non-control area first receives the data message containing the ciphertext and signature. The receiving end first uses the SM2 public key to verify the validity of the signature. Formula (6) describes the SM2 signature verification process:
[0072] Verify SM2 (S,C||T,Private Key)=True if signature is valid#(6)
[0073] After verification, the receiver uses the SM4 algorithm to decrypt the ciphertext C and restore the original data. Formula (4) is as follows:
[0074] D=Decrypt SM4 (C,Key)#(7)
[0075] If the signature verification fails, the data is considered invalid and the receiving end refuses to process it further. This process ensures the security of Telnet protocol data and prevents data tampering, replay attacks, and eavesdropping.
[0076] For example, if the original data message D is 100 bytes long, the encrypted ciphertext C is still 100 bytes, the additional timestamp is 8 bytes long, and the SM2 signature is 32 bytes long, then the length of the encrypted and signed data message is 100 + 8 + 32 = 140 bytes. In this way, the entire data transmission process is encrypted, signed, timestamped, and integrity verified, effectively preventing data tampering or replay attacks during transmission.
[0077] S3. Send the encrypted data message to the corresponding target device, so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypts the encrypted data message after the verification to obtain a decrypted Telnet protocol message, and converts the message format of the decrypted Telnet protocol message into a preset standard message format.
[0078] Preferably, the data integrity verification and signature legitimacy verification are performed on the encrypted data message, and the encrypted data message is decrypted after the verification is passed to obtain the Telnet protocol message after the decryption, including: performing signature legitimacy verification on the hash signature value and the signature value in the encrypted data message; after the signature legitimacy verification of the encrypted data message is passed, hash calculation is performed on the encrypted data message according to the SM3 algorithm to obtain a corresponding second hash value, and the second hash value is compared with the first hash value. When the second hash value is consistent with the first hash value, the data integrity verification of the encrypted data message is passed, and the encrypted data message is decrypted after the verification is passed to obtain the Telnet protocol message after the decryption.
[0079] After the Telnet protocol message is tamper-proof and encrypted, the encrypted message from the front-end communication device is received by the cross-security domain protocol message conversion device and converted into a standard message format that the target device can recognize and process. The specific implementation is as follows:
[0080] Cross-security domain protocol message conversion device: This device is located inside the non-control area and is used to receive encrypted messages from the front-end communication device and convert them into a standard message format that the target device can recognize and process. First, after the target device receives the data message encrypted and signed by the front-end communication device, the message contains the original data, timestamp and SM2 signature. Assume that the message length is L+8+32 bytes, where L is the number of original data bytes, 8 bytes are timestamps, and 32 bytes are SM2 signatures. The message will be processed by the protocol message conversion device. In the conversion device, the SM2 public key is first used to verify the signature in the message to ensure the legitimacy of the signature. The signature verification formula (7) is as follows:
[0081] Verify SM2 (S,D||T,Private Key)=True if signature is valid#(7)
[0082] Where D||T represents the concatenated data and timestamp, S is the SM2 signature, and Public Key is the SM2 public key. If the signature verification passes, the conversion device proceeds to verify the data integrity and authenticity.
[0083] Then, the SM3 algorithm is used to perform hash calculation on the data in the message (including the original data and timestamp) to generate the hash value H(D||T), as shown in formula (8):
[0084] H(D||T)=Hash SM3 (D||T)#(8)
[0085] The receiving end compares the calculated hash value with the SM3 hash value in the message to ensure that the data has not been tampered with. Assuming that the original data D is L bytes long, the timestamp is 8 bytes, and the result of the SM3 hash is 256 bits (32 bytes), the encryption and signing process for the entire message is as follows: 1. The original data D is L bytes long + the timestamp is 8 bytes long + the SM3 algorithm hashes the data to obtain the signature value of the 256-bit (32-byte) hash value + the SM2 signature (32 bytes) = L + 8 + 32 + 32 bytes; 2. The total length of the encrypted and signed message is: L + 72 bytes.
[0086] If both the SM3 checksum and the SM2 signature verification pass, the conversion device considers the message legal and converts it into a format suitable for the target device, ensuring data security during the conversion process. If the checksum fails, the message will be discarded or marked as illegal to prevent non-compliant data from entering the system.
[0087] For example, if the original data message D is 100 bytes long, the total message length after encryption and signing is 100 + 8 + 32 + 32 = 172 bytes. The conversion device will perform SM2 signature verification and SM3 integrity check on this 172-byte message to ensure data security.
[0088] This solution adds instruction tamper-proof devices in the management area and collection area of Zone I to encrypt, sign and verify the Telnet protocol message data of the communication equipment, ensuring the tamper-proof nature of the interactive message data and the security of the collection and control data.
[0089] Specifically, the present invention adds a command tamper-proofing device to the Zone I management area. This device primarily performs signature verification for Telnet protocol service messages in the secure Zone I distribution network control system and logs any abnormal events. The distribution network control system then uses the command tamper-proofing device to access the interface and perform Telnet protocol message signature verification. This provides tamper-proofing for Telnet protocol messages at the service source, without changing the existing network topology or compromising the load balancing performance of the Zone I management area.
[0090] The Zone I collection area utilizes two types of tamper-proof device deployment modes: Type 2A deployment in load-bearing mode and Type 2B deployment in master-slave mode. Type 2A mode adds N devices (depending on performance) and is installed behind the collection area firewall. Type A tamper-proof devices primarily verify the authenticity and confidentiality of messages sent by Zone I application servers. Type 2B mode adds one device, installed before the encryption gateway. Type B devices primarily ensure the confidentiality of data from Type A to Type B. Authenticity is confirmed by binding Type A's IP address, and any abnormal events are logged.
[0091] In general, the present invention solves the problem of insufficient cross-domain communication security in the prior art by adopting the national secret standard SM2, SM3 and SM4 algorithms. The present invention comprehensively guarantees the communication security between various security domains in the power monitoring system, especially in the process of cross-domain data transmission and instruction exchange, by introducing an instruction anti-tampering device, a cross-security domain pre-communication device and a cross-security domain protocol message conversion device. The present invention innovatively ensures the security of communication through encryption, signing and verification mechanisms when processing Telnet protocol data, and resists security threats including data tampering, replay attacks, eavesdropping and communication hijacking.
[0092] The present invention uses the SM3 hash algorithm to generate and verify data signatures, ensuring the authenticity and integrity of transmitted data. SM3 boasts efficient encryption performance. During cross-domain communication, by performing a hash operation on data, it effectively prevents tampering and forgery, while also providing a verification mechanism for encrypted data to ensure it has not been tampered with. The combination of data signatures and hash verification helps ensure the integrity of instruction and data information, preventing malicious modification during transmission. The present invention also uses the SM2 asymmetric encryption algorithm to safeguard data confidentiality and security. The SM2 algorithm provides high-strength encryption services for key exchange and encrypted communication. The SM2 algorithm performs asymmetric encryption on sensitive data in cross-domain communications, effectively preventing data eavesdropping or leakage during transmission. Particularly between the control and non-control areas of a power monitoring system, the SM2 algorithm ensures the security of data exchange and effectively prevents unauthorized access from external networks. The present invention further employs the SM4 symmetric encryption algorithm for efficient encryption of large amounts of data. The SM4 algorithm is suitable for large-scale data encryption and offers rapid encryption and decryption speeds, ensuring real-time performance and efficiency while ensuring data security. Especially in power monitoring systems, SM4's encryption processing of massive monitoring data can significantly improve the system's response speed and data processing capabilities, avoiding the impact of overly complex encryption algorithms on communication performance.
[0093] To ensure the integrity and security of the entire communication process, the present invention proposes a comprehensive protection scheme based on the above-mentioned encryption algorithm. During the transmission of Telnet protocol data, encryption, signature, and verification processes are applied to prevent security risks such as data tampering and replay attacks. By introducing an instruction anti-tampering device and a cross-security domain pre-communication device, the present invention can effectively intercept and identify illegally tampered communication data, ensuring the confidentiality, integrity, and validity of data during cross-domain communication. At the same time, the cross-security domain protocol message conversion device can ensure the compatibility of communication protocols between different security domains, avoiding security vulnerabilities caused by protocol differences.
[0094] The data processing architecture of this invention significantly enhances the communication security of the power monitoring system. Throughout the entire process, the SM3 algorithm is used to generate the data hash value, the SM2 algorithm is used to digitally sign the hash value, and combined with the SM4 encryption algorithm, this ensures the confidentiality and integrity of data during cross-security domain transmission. This improvement provides greater security for data transmission in the power monitoring system, effectively preventing data tampering, replay attacks, and other potential network threats.
[0095] It can be seen that the present invention provides a cross-security domain data transmission method based on the Telnet communication protocol. Through the present invention, the security problems in the cross-domain communication of the power monitoring system can be solved, and the security and reliability in the data transmission process can be improved. By introducing the instruction anti-tampering device, the cross-security domain pre-communication device and the cross-security domain protocol message conversion device in the I zone management area and the collection area, the integrity, authenticity and confidentiality of the Telnet protocol in the data processing, transmission and storage process of the power monitoring system are ensured. Through the technical solution of the present invention, the power monitoring system can ensure the secure transmission of data in a cross-security domain environment, improve the stability and reliability of the system, and ensure the integrity and confidentiality of key data. This solution is not only suitable for the power industry, but also has broad application prospects. It can be effectively applied in other fields that require high-security communication protection, such as intelligent manufacturing, smart cities, etc.
[0096] Example 2
[0097] Please refer to Figure 2 , is a schematic structural diagram of a cross-security domain data transmission device based on the Telnet communication protocol provided by an embodiment of the present invention, the device comprising: a data tamper-proof module, a data encryption module, and a data verification and decryption module;
[0098] The data tamper-proof module is used to obtain the original Telnet protocol message, calculate the hash value corresponding to the Telnet protocol message, and perform data tamper-proof processing on the Telnet protocol message according to the hash value;
[0099] The data encryption module is used to perform SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm, and to sign the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted;
[0100] The data verification and decryption module is used to send the encrypted data message to the corresponding target device so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypts the encrypted data message after verification to obtain a decrypted Telnet protocol message, and converts the message format of the decrypted Telnet protocol message into a preset standard message format.
[0101] Preferably, calculating the hash value corresponding to the Telnet protocol message and performing data tamper-proof processing on the Telnet protocol message according to the hash value includes:
[0102] Convert the Telnet protocol message into a corresponding binary data message, and perform a hash calculation on the converted binary data message according to a preset SM3 algorithm to obtain a corresponding first hash value;
[0103] According to the preset SM2 algorithm, the first hash value is signed to generate a corresponding hash signature value, and the binary data message and the hash signature value are combined into a first data message.
[0104] Preferably, the step of performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm, and signing the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted includes:
[0105] Performing symmetrical encryption on the first data message according to the SM4 algorithm to obtain a symmetrically encrypted second data message;
[0106] Add corresponding timestamp information to the second data message, then sign the second data message with the timestamp information according to the SM2 algorithm to obtain a corresponding signature value, and combine the second data message and the signature value into an encrypted data message to be transmitted.
[0107] Preferably, performing data integrity verification and signature legitimacy verification on the encrypted data message, and decrypting the encrypted data message after passing the verification to obtain a decrypted Telnet protocol message, includes:
[0108] Performing signature legitimacy verification on the hash signature value and the signature value in the encrypted data message;
[0109] After the signature legitimacy verification of the encrypted data message passes, a hash calculation is performed on the encrypted data message according to the SM3 algorithm to obtain a corresponding second hash value, and the second hash value is compared with the first hash value. When the second hash value is consistent with the first hash value, the data integrity verification of the encrypted data message passes, and after the verification passes, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message.
[0110] It should be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art can understand and implement the present invention without inventive effort.
[0111] Those skilled in the art will clearly understand that for the sake of convenience and brevity, the specific working process of the device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0112] Example 3
[0113] Accordingly, an embodiment of the present invention provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the cross-security domain data transmission method based on the Telnet communication protocol described in the above-mentioned embodiment of the invention is implemented.
[0114] The electronic device may be a computing device such as a desktop computer, a notebook computer, a PDA, a cloud server, etc. The device may include, but is not limited to, a processor and a memory.
[0115] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the device and connects various parts of the entire device using various interfaces and lines.
[0116] Example 4
[0117] Accordingly, an embodiment of the present invention provides a storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the cross-security domain data transmission method based on the Telnet communication protocol described in the above-mentioned embodiment of the invention.
[0118] The memory can be used to store the computer program, and the processor realizes various functions of the device by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc.; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (FlashCard), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0119] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by the processor, it can implement the steps of the above-mentioned various method embodiments. The computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0120] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A cross-security domain data transmission method based on Telnet communication protocol, characterized in that: include: Obtaining an original Telnet protocol message, calculating a hash value corresponding to the Telnet protocol message, and performing data tamper-proof processing on the Telnet protocol message according to the hash value; Performing SM4 encryption on the Telnet protocol message according to a preset SM4 algorithm, and signing the Telnet protocol message after the SM4 encryption process to obtain an encrypted data message to be transmitted; The encrypted data message is sent to the corresponding target device so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypts the encrypted data message after verification to obtain a decrypted Telnet protocol message, and converts the message format of the decrypted Telnet protocol message into a preset standard message format.
2. The cross-security domain data transmission method based on the Telnet communication protocol according to claim 1, characterized in that: The calculating a hash value corresponding to the Telnet protocol message, and performing data tamper-proof processing on the Telnet protocol message according to the hash value, includes: Convert the Telnet protocol message into a corresponding binary data message, and perform a hash calculation on the converted binary data message according to a preset SM3 algorithm to obtain a corresponding first hash value; According to the preset SM2 algorithm, the first hash value is signed to generate a corresponding hash signature value, and the binary data message and the hash signature value are combined into a first data message.
3. The cross-security domain data transmission method based on the Telnet communication protocol according to claim 2, characterized in that: The method of performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm and signing the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted includes: Performing symmetrical encryption on the first data message according to the SM4 algorithm to obtain a symmetrically encrypted second data message; Add corresponding timestamp information to the second data message, then sign the second data message with the timestamp information according to the SM2 algorithm to obtain a corresponding signature value, and combine the second data message and the signature value into an encrypted data message to be transmitted.
4. The cross-security domain data transmission method based on the Telnet communication protocol according to claim 3, characterized in that: The performing of data integrity verification and signature legitimacy verification on the encrypted data message, and decrypting the encrypted data message after passing the verification to obtain a decrypted Telnet protocol message, including: Performing signature legitimacy verification on the hash signature value and the signature value in the encrypted data message; After the signature legitimacy verification of the encrypted data message passes, a hash calculation is performed on the encrypted data message according to the SM3 algorithm to obtain a corresponding second hash value, and the second hash value is compared with the first hash value. When the second hash value is consistent with the first hash value, the data integrity verification of the encrypted data message passes, and after the verification passes, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message.
5. A cross-security domain data transmission device based on Telnet communication protocol, characterized in that: include: Data tamper-proof module, data encryption module, and data verification and decryption module; The data tamper-proof module is used to obtain the original Telnet protocol message, calculate the hash value corresponding to the Telnet protocol message, and perform data tamper-proof processing on the Telnet protocol message according to the hash value; The data encryption module is used to perform SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm, and to sign the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted; The data verification and decryption module is used to send the encrypted data message to the corresponding target device so that the target device performs data integrity verification and signature legitimacy verification on the encrypted data message, decrypts the encrypted data message after verification to obtain a decrypted Telnet protocol message, and converts the message format of the decrypted Telnet protocol message into a preset standard message format.
6. The cross-security domain data transmission device based on the Telnet communication protocol according to claim 5, characterized in that: The calculating a hash value corresponding to the Telnet protocol message, and performing data tamper-proof processing on the Telnet protocol message according to the hash value, includes: Convert the Telnet protocol message into a corresponding binary data message, and perform a hash calculation on the converted binary data message according to a preset SM3 algorithm to obtain a corresponding first hash value; According to the preset SM2 algorithm, the first hash value is signed to generate a corresponding hash signature value, and the binary data message and the hash signature value are combined into a first data message.
7. The cross-security domain data transmission device based on the Telnet communication protocol according to claim 6, characterized in that: The method of performing SM4 encryption processing on the Telnet protocol message according to a preset SM4 algorithm and signing the Telnet protocol message after the SM4 encryption processing to obtain an encrypted data message to be transmitted includes: Performing symmetrical encryption on the first data message according to the SM4 algorithm to obtain a symmetrically encrypted second data message; Add corresponding timestamp information to the second data message, then sign the second data message with the timestamp information according to the SM2 algorithm to obtain a corresponding signature value, and combine the second data message and the signature value into an encrypted data message to be transmitted.
8. The cross-security domain data transmission device based on the Telnet communication protocol according to claim 7, characterized in that: The performing of data integrity verification and signature legitimacy verification on the encrypted data message, and decrypting the encrypted data message after passing the verification to obtain a decrypted Telnet protocol message, including: Performing signature legitimacy verification on the hash signature value and the signature value in the encrypted data message; After the signature legitimacy verification of the encrypted data message passes, a hash calculation is performed on the encrypted data message according to the SM3 algorithm to obtain a corresponding second hash value, and the second hash value is compared with the first hash value. When the second hash value is consistent with the first hash value, the data integrity verification of the encrypted data message passes, and after the verification passes, the encrypted data message is decrypted to obtain a decrypted Telnet protocol message.
9. An electronic device, characterized in that: The invention comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the cross-security domain data transmission method based on the Telnet communication protocol according to any one of claims 1 to 4 is implemented.
10. A storage medium, characterized in that: The storage medium includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the cross-security domain data transmission method based on the Telnet communication protocol according to any one of claims 1 to 4.