Power grid terminal credible authentication system and method based on multiple identity authentication

By combining user and terminal feature information through a multi-factor authentication system, the problem that traditional single-factor authentication methods cannot meet the security requirements of the power grid system is solved, achieving efficient and secure authentication of power grid terminals and enhancing the defense capabilities and stability of the power grid system.

CN120856367APending Publication Date: 2025-10-28CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510834285.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Traditional single-factor authentication methods are insufficient to meet the growing security needs of power grid systems. The complexity and diversity of network attack methods have led to frequent identity theft, threatening the security and stability of power grid systems.

Method used

A trusted authentication system for power grid terminals based on multi-factor authentication is adopted, including a dedicated client and a unified identity authentication system. Through an authentication center, a security gateway, and a security audit center, multi-factor authentication is performed by combining user information, terminal feature information, and binding relationships to generate a digital identity certificate for the terminal, thereby realizing the binding of users, clients, and terminals.

Benefits of technology

It enhances the trustworthiness of power grid terminals, reduces security risks, effectively resists network threats, ensures that only authorized users and terminals can access the power grid system, and builds an efficient and secure trusted authentication system for power grid terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856367A_ABST
    Figure CN120856367A_ABST
Patent Text Reader

Abstract

The invention discloses a power grid terminal credible authentication system and method based on multiple identity authentication. The method comprises the steps that a user submits user information to a unified identity authentication system; the authentication center audits the user and grants access authority to the power grid system; a user installs a special client on a terminal, terminal feature information is submitted, a terminal digital identity certificate is generated by an authentication center, and the terminal is bound with the user and the special client; the terminal automatically performs terminal identity authentication through the special client; the user performs multi-factor authentication through the special client; the authentication center verifies the current access request according to the binding relationship among the user, the client and the terminal, and sends a result to the security gateway; the authentication center limits the access authority of the user and the terminal based on a role access control strategy; according to the invention, a set of efficient and safe power grid terminal credible authentication system is constructed based on multiple identity authentication in combination with measures of regular maintenance of authentication information, security audit and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a trusted authentication system and method for power grid terminals, and more particularly to a trusted authentication system and method for power grid terminals based on multi-identity authentication, belonging to the field of power grid information technology. Background Technology

[0002] With the rapid development of internet technology, cyberattack methods have become increasingly complex and diverse, highlighting the growing importance of network security and data security. Traditional single-factor authentication methods (such as using only usernames and passwords) are no longer sufficient to meet the increasing security demands. Frequent security incidents such as password cracking, data tampering, and identity theft pose serious threats to the information security of individuals, businesses, and the nation. As a core component of the national energy infrastructure, the power grid system's security and stability directly impact national energy security and socio-economic development. Therefore, it is necessary to build a more robust security defense line, enhance the power grid system's ability to defend against external attacks, and reduce the risk of hacker attacks or data breaches.

[0003] As cyberattack methods evolve, single authentication methods are becoming increasingly vulnerable to cracking, making identity theft a common tactic in cybercrime. Using stolen identity information for attacks and fraud poses a significant threat to power grid systems. However, with the development of cryptography, biometrics, and the Internet of Things (IoT), authentication methods have become more flexible and diverse. By combining different authentication factors (such as knowledge, ownership, and biometrics) for multi-factor authentication, the trustworthiness of access terminals and the defense capabilities of power grid systems can be improved. Summary of the Invention

[0004] Purpose of the invention: The purpose of this invention is to provide a trusted authentication system and method for power grid terminals based on multi-identity authentication, which can improve the security and reliability of power grid systems.

[0005] Technical solution: The present invention provides a trusted authentication system for power grid terminals based on multi-identity authentication, comprising a dedicated client and a unified identity authentication system;

[0006] The dedicated client is used to install on terminals that need to access the power grid system;

[0007] The unified identity authentication system includes an authentication center, a security gateway, and a security audit center, which are used to perform multi-factor authentication on terminals.

[0008] Based on the same inventive concept, the present invention also provides a power grid terminal trusted authentication method according to the above-mentioned power grid terminal trusted authentication system based on multiple identity authentication, comprising:

[0009] (1) Certification registration and authorization; including:

[0010] (11) The user submits user information to the unified identity authentication system, the user information including basic registration information and real-name authentication information;

[0011] (12) The certification center reviews users and grants access to the power grid system based on the user's circumstances;

[0012] (13) After the user is authorized, a dedicated client is installed on the terminal, the terminal feature information is submitted, the authentication center authenticates the terminal, generates a digital identity certificate for the terminal, and binds the terminal with the user and the dedicated client.

[0013] (2) Multi-factor authentication; including:

[0014] (21) The terminal automatically performs terminal authentication through a dedicated client. If the authentication is successful, access is allowed to continue; if the authentication fails, access is denied.

[0015] (22) Users perform multi-factor authentication through a dedicated client. If the authentication is successful, access is allowed to continue; if the authentication fails, access is denied.

[0016] (23) The authentication center verifies the current access request based on the binding relationship between the user, client and terminal, and sends the result to the security gateway. If the verification is successful, access is allowed; otherwise, access is denied.

[0017] (24) The Certification Center’s role-based access control policy restricts the access rights of users and terminals to ensure the security of data and operations.

[0018] Further, step (11) includes:

[0019] Users submit basic registration information when registering in the unified identity authentication system, including username, password, name, ID number, mobile phone number and user type, and are verified through dynamic verification code;

[0020] Users provide real-name authentication information in accordance with the requirements of the unified identity authentication system, specifically by providing a photo of their ID card and undergoing facial recognition.

[0021] The authentication center collects users' basic registration information and real-name authentication information.

[0022] Further, step (12) includes:

[0023] The authentication center reviews user information according to preset permissions. If the review fails, the user needs to modify the information and resubmit it according to the prompts. If the review passes, the authentication center will notify the user via SMS and store the user information in the database.

[0024] The authentication center determines the user's access permissions based on the user information and generates the corresponding authorization token, which is then stored in the authentication center.

[0025] Further, step (13) includes:

[0026] Users install a dedicated client on the terminal that needs to access the power grid system and generate a unique client ID. When the dedicated client runs for the first time on the current terminal, it requests the user's authorization to access the terminal device information. After obtaining authorization, the dedicated client scans the terminal device, obtains terminal feature information, including device ID, operating system type and version, firewall software and system processes, and submits it to the authentication center.

[0027] The certification center will review the terminal's feature information to determine if there are any security threats. If the review fails, a risk message will be displayed and the dedicated client will be closed. If the review passes, the certification center will generate a digital identity certificate for the terminal based on the terminal's feature information and bind the user, dedicated client, and terminal using the user ID, dedicated client ID, and terminal digital identity certificate ID.

[0028] Furthermore, step (1) also includes requiring the certification center to regularly update and maintain user information and terminal feature information to ensure user information security and reflect the status of the terminal device.

[0029] Further, step (21) includes:

[0030] The terminal runs a dedicated client, which automatically sends a verification request containing the dedicated client ID and the terminal's digital identity certificate to the security gateway of the unified identity authentication system. The security gateway receives the request submitted by the dedicated client.

[0031] The security gateway sends the dedicated client ID and terminal digital identity certificate to the certification center for verification. The certification center verifies the validity of the user information of the corresponding bound user and returns the verification result to the security gateway. Based on the verification result, the security gateway decides whether to allow continued access.

[0032] Further, step (22) includes:

[0033] The user enters a dynamic verification code pre-generated by the security gateway on the dedicated client. The dedicated client sends the code to the security gateway for verification asynchronously. If the verification is successful, a correct message is displayed and the process continues. If the verification fails, a new dynamic verification code is generated, and the user is prompted to re-enter it.

[0034] Once the dynamic verification code is successfully verified, the user submits their username and password to the security gateway through a dedicated client. The security gateway receives the information submitted by the dedicated client and sends it to the authentication center. The authentication center verifies the validity of the username and password and returns the verification result to the security gateway. If the verification is successful, the process continues; if the verification fails, an error message is displayed and the user is prompted to re-enter the information.

[0035] The security gateway requires the user to turn on their camera for facial recognition. The security gateway collects the user's facial information and sends it to the authentication center. The authentication center verifies the validity of the facial information and returns the verification result to the security gateway. If the verification is successful, the process continues; if the verification fails, an error message is displayed and access is denied.

[0036] Furthermore, step (2) also includes encrypting the communication between the terminal and the authentication center and security gateway of the unified identity authentication system using a security protocol.

[0037] Furthermore, step (2) also includes the unified identity authentication system's security audit center recording all authentication and access events for security auditing and anomaly detection.

[0038] Beneficial Effects: Compared with existing technologies, this invention enhances the trustworthiness of power grid terminals through multi-factor authentication, thereby reducing security risks to the power grid system. Considering the importance of the power grid system as an energy infrastructure, the authentication information of the terminal's multi-factor authentication not only includes multi-factor authentication information, but also terminal device characteristic information, professional client ID, and binding relationships, increasing the complexity and difficulty of identity verification and effectively resisting network threats such as password cracking and phishing attacks. Multi-factor authentication organically combines and binds various factors, avoiding security risks such as theft / borrowing of user accounts and devices. Multi-factor authentication ensures that only authorized personnel with the corresponding qualifications can access the power grid system. Based on multi-factor authentication, combined with measures such as regular maintenance of authentication information and security auditing, this invention constructs an efficient and secure trusted authentication system for power grid terminals, providing a solid guarantee for the safe and stable operation of the power grid system. Attached Figure Description

[0039] Figure 1 This is a system schematic diagram according to an embodiment of the present invention;

[0040] Figure 2 This is a flowchart of a method according to an embodiment of the present invention;

[0041] Figure 3 This is a schematic diagram of asynchronous verification of dynamic verification codes according to an embodiment of the present invention. Detailed Implementation

[0042] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0043] Identity authentication technology is a key method to ensure the authenticity of user or device identity. It plays an important role in many fields such as network security, trusted computing, e-commerce, and mobile applications. Common identity authentication technologies include: (1) Username / password authentication, which is the most traditional single identity authentication method. Users need to provide a unique username and corresponding password. This method is simple and easy to use, but has low security. (2) Two-factor authentication, which requires users to provide two different types of authentication information to increase security. Common two-factor authentication methods include: password + SMS verification code: In addition to username and password, the system sends an SMS containing a verification code. Users need to enter the verification code to log in; password + biometric recognition: such as fingerprint, facial recognition or iris scanning. These biometric features are difficult to copy or forget. (3) Multi-factor authentication, which is an extension of two-factor authentication. It requires users to provide three or more types of authentication information, such as: password + SMS verification code + biometric recognition + location information. This method can provide higher security, but it may be more complicated to use. (4) Device-based authentication, which uses the user's device for identity verification, such as using the device's specific hardware serial number, MAC address or device fingerprint. Device authentication can be combined with cryptography or biometrics to enhance security. (5) Digital certificate authentication: In the field of network security, digital certificates are used to verify the identities of both parties in network communication. Certificates are usually issued by authoritative certificate authorities (e.g., government-regulated third-party certification centers) to ensure the authenticity and credibility of the certificates.

[0044] Terminal characteristic information refers to data describing the hardware and software characteristics of terminal devices (such as smartphones, computers, tablets, etc.). Terminal device characteristic information used for identity authentication typically includes: (1) hardware information, such as device ID, CPU serial number, IMEI number, etc. This information is assigned during the terminal device manufacturing process and is unique; (2) software information, including operating system type and version, firewall / antivirus software, running system processes, browser type and version, etc.; (3) network information, such as MAC address, IP address, network type, etc., reflecting the device's network environment; (4) environmental information, such as the device's geographical location, time zone, language settings, etc.

[0045] An access token is a credential used to access protected resources. It allows applications to access specific resources or perform operations after user authorization, without directly exposing sensitive information (such as username and password). When a user is authenticated, the system generates an access token (access_token) and returns it to the requesting party. Any subsequent access requests must include this token to prove that the requesting party has legitimate permission to access the specific resource. Access token generation typically follows the OAuth 2.0 protocol, a widely accepted standard. OAuth 2.0 tokens can be used in various modern applications, including but not limited to third-party login, API access, and single sign-on scenarios. By using OAuth 2.0 tokens, applications can securely access a user's protected resources without exposing user credentials.

[0046] The unified identity authentication system consists of three main modules: the Authentication Center (AC), the Security Gateway (SG), and the Security Audit Center (SAC). The Authentication Center (AC) is the core of the system, responsible for user and device registration, authentication, and authorization. It centrally stores and manages user account information, passwords, and other identity information, ensuring accuracy and consistency. The Security Gateway (SG) protects the internal network of the power grid, allowing only authenticated terminal devices to access it. It also encrypts and decrypts transmitted data to ensure data security during transmission. The Security Audit Center (SAC) is an indispensable part of the unified identity authentication system, responsible for recording all authentication events and operational behaviors for auditing and anomaly detection analysis, ensuring system security and compliance. Through the collaborative work of these three modules, the unified identity authentication system achieves unified management and access control of user identities, improving system security and user experience.

[0047] Binding and authenticating users, dedicated clients, and terminals is a crucial step in a unified identity authentication system. After a user's registration information is approved by the authentication center, a unique user ID (UserID) is generated. When a user installs a dedicated client on their current terminal for the first time, the client automatically connects to the authentication center to register, providing relevant client information such as name, version, and developer. The authentication center then generates a unique client ID (ClientID) for this client. Similarly, after the terminal device is verified by the authentication center, the generated terminal digital identity certificate also has a unique serial number ID (CerID). The authentication center uses the user ID (UserID), dedicated client ID (ClientID), and terminal digital identity certificate serial number (CerID) to bind the user, dedicated client, and terminal, forming a triplet (UserID, ClientID, CerID) that defines the binding relationship between the three. Considering practical situations, each user can bind multiple clients and terminals, forming a binding relationship set for that user. For example, user A has installed a dedicated client on their mobile phone, laptop, and desktop computer. Their binding relationship set contains three elements, which can be represented as {(UserID...}} A ClientID m CerID m ),(UserID A ClientID n CerID n ),(UserID A ClientID d CerID d In this set, the UserID is the same for all three elements, while the ClientID and CerID are different. The corresponding superscripts are m for mobile, n for notebook, and d for desktop. Binding triples can effectively prevent security risks associated with user account and device theft / borrowing. For example, if user A uses other clients and terminals to access the power grid system, the resulting binding triple will not find a matching element in their binding set.

[0048] As attached Figure 1 As shown, the power grid terminal trusted authentication system based on multi-identity authentication in this embodiment includes a dedicated client and a unified identity authentication system;

[0049] The dedicated client is used to install on terminals that need to access the power grid system;

[0050] The unified identity authentication system includes an authentication center, a security gateway, and a security audit center, which are used to perform multi-factor authentication on terminals.

[0051] Given the importance of the power grid system as an energy infrastructure, the authentication information for multiple identities of terminals not only includes multi-factor authentication information, but also terminal device characteristic information, professional client ID, and binding relationships. By organically combining and binding various factors, the complexity and difficulty of identity verification are increased, thereby improving the trustworthiness of power grid terminals and effectively resisting network threats and risks. Through the three major modules of the unified identity authentication system—authentication center, security gateway, and security audit center—and the two stages of trusted authentication for power grid terminals—authentication registration and authorization and multi-identity access authentication—an efficient and secure trusted authentication system for power grid terminals is constructed. This enhances the power grid system's ability to defend against external attacks and ensures the safe and stable operation of the power grid system.

[0052] To further explain, with the rapid development of internet technology and the continuous evolution of cyberattack methods, single authentication methods are becoming increasingly easy to crack, making identity theft a common tactic in cybercrime. Attacks and fraud using stolen identity information pose a significant threat to the power grid system. However, with the development of cryptography, biometrics, and the Internet of Things (IoT), authentication methods have become more flexible and diverse. By combining different authentication factors for multi-factor authentication, the power grid system's defense against external attacks can be enhanced, reducing the risk of hacker attacks or data breaches. As a core component of the national energy infrastructure, the power grid system's security and stability directly impact national energy security and socio-economic development. Therefore, employing multi-factor authentication for terminals accessing the power grid system is a necessary measure to ensure terminal trustworthiness. This not only improves the security and reliability of the power grid system, adapts to its development needs, and complies with legal and regulatory requirements, but also enhances management efficiency and convenience.

[0053] like Figure 2 As shown in this embodiment, a power grid terminal trusted authentication method based on the above-described power grid terminal trusted authentication system based on multi-identity authentication includes:

[0054] (1) Certification registration and authorization; including:

[0055] (11) The user submits user information to the unified identity authentication system, the user information including basic registration information and real-name authentication information;

[0056] (12) The certification center reviews users and grants access to the power grid system based on the user's circumstances;

[0057] (13) After the user is authorized, a dedicated client is installed on the terminal, the terminal feature information is submitted, the authentication center authenticates the terminal, generates a digital identity certificate for the terminal, and binds the terminal with the user and the dedicated client.

[0058] (2) Multi-factor authentication; including:

[0059] (21) The terminal automatically performs terminal authentication through a dedicated client. If the authentication is successful, access is allowed to continue; if the authentication fails, access is denied.

[0060] (22) Users perform multi-factor authentication through a dedicated client. If the authentication is successful, access is allowed to continue; if the authentication fails, access is denied.

[0061] (23) The authentication center verifies the current access request based on the binding relationship between the user, client and terminal, and sends the result to the security gateway. If the verification is successful, access is allowed; otherwise, access is denied.

[0062] (24) The Certification Center’s role-based access control policy restricts the access rights of users and terminals to ensure the security of data and operations.

[0063] Specifically, the technical solution for the authentication, registration, and authorization phase is implemented as follows:

[0064] (11) When users access the unified identity authentication system, they first fill in basic registration information such as username, password, name, ID number, mobile phone number, and user type on the registration page, and enter the dynamic verification code randomly generated by the unified identity authentication system on the page. The username must be unique throughout the entire power grid system, the password must be at least 8 characters long and must contain uppercase letters, lowercase letters, numbers and special characters (such as !@#$%^&*), etc. The user type is mainly staff of power grid enterprises and related partners, etc. Users need to fill in their enterprise or department and role (position). After completing the form, the user submits the basic registration information; then, the unified identity authentication system requires the user to provide real-name information, including an ID card photo and facial feature information collection; the user's basic registration information and real-name information will be submitted together to the authentication center module.

[0065] (12) The authentication center reviews the user's identity information, mainly verifying real-name authentication and confirming that the submitted information is consistent with the facts. If the review fails, the user needs to modify the information and resubmit it according to the prompts; if the review passes, the authentication center will send a text message to the user and store all the user's information in the database; then, the authentication center determines the user's access permissions according to the user's role and generates the corresponding authorization token (such as an OAuth 2.0 token), which is stored in the authentication center's user token library.

[0066] (13) Users install a dedicated client on the terminal that needs to access the power grid system. The dedicated client generates a unique client ID during installation. When the client runs for the first time on the current terminal, it will request the user to authorize access to the terminal's device information. After obtaining the user's authorization, the client will scan the terminal device, obtain terminal characteristic information such as device ID, operating system type and version, firewall / antivirus software, and system processes, and submit it to the authentication center.

[0067] The certification center reviews the terminal's characteristic information. If there are security threats in this information, such as the terminal not having firewall / antivirus software installed or the system process information containing dangerous processes, the review will fail, a risk message will be displayed, and the client will be closed. If the review passes, the certification center will generate a digital identity certificate for the terminal based on the terminal's characteristic information and send it to the dedicated client. At the same time, it will be stored in the certification center's certificate store.

[0068] The authentication center uses UserID, ClientID, and CerID to bind users, clients, and terminals, forming a triple (UserID, ClientID, CerID) that determines the binding relationship between the three and storing it in the database. As mentioned earlier, in practice, a user can bind multiple clients and terminals, forming a set of binding relationships for that user.

[0069] Step (1) also includes: The certification center requires users to regularly update and maintain user and terminal information, generally every 3 months. Users need to update their passwords regularly to prevent leakage or cracking; if the user type changes, the corresponding user information needs to be updated, and the certification center will update the relevant content; if the terminal's device feature information is updated, the terminal needs to be re-registered to update the digital identity certificate, and the corresponding binding relationship needs to be updated to keep the information stored by the certification center consistent with the actual situation.

[0070] Furthermore, the specific technical solution for the multi-identity access authentication phase is implemented as follows:

[0071] The dedicated client uses security protocols (such as SSL / TLS) to encrypt the communication between the terminal and the unified identity authentication system (authentication center, security gateway) to ensure that data transmission is not eavesdropped during transmission.

[0072] (21) When a user runs a dedicated client on a terminal, the client automatically sends a verification request with the client ID and the terminal identity digital certificate to the security gateway module of the unified identity authentication system. The security gateway receives the information submitted by the client and sends it to the authentication center for verification. The authentication center verifies the validity of the user's client ID and the terminal identity digital certificate and returns the verification result to the security gateway. If the authentication is successful, the security gateway allows the terminal to access and continue execution; if the authentication fails, the security gateway refuses the terminal access, sends a prompt message to the dedicated client, and then closes the dedicated client.

[0073] (22) Users enter their username, password, and a dynamically generated verification code pre-randomized by the security gateway on the professional client login interface, such as... Figure 3 As shown, when entering the verification code, the client sends it asynchronously to the security gateway for verification. If the verification passes, a correct message is displayed and execution continues. If the verification fails, the user is prompted to re-enter the code. If the user cannot recognize the verification code, they can click on the verification code to request a regeneration. If the dynamic verification code is entered correctly, the user submits their username and password to the security gateway. The security gateway receives the username and password information submitted by the client and sends it to the authentication center. The authentication center verifies the validity of the username and password and returns the verification result to the security gateway. If the verification passes, the security gateway allows access to continue execution; if the verification fails, the security gateway sends an error message to the dedicated client and displays it, prompting the user to re-enter their username and / or password, as well as a newly generated dynamic verification code, on the login page.

[0074] After the username and password are verified, the security gateway requires the user to turn on the camera for facial recognition. The security gateway collects the user's facial information and sends it to the authentication center. The authentication center verifies the validity of the facial information and returns the verification result to the security gateway. If the verification is successful, the security gateway allows access to continue; if the verification fails, an error message is displayed on the client and access is denied.

[0075] (23) The authentication center verifies the current access request based on the binding triple (UserID, ClientID, CerID) of the user, client and terminal, and sends the result to the security gateway. If the verification is successful, the security gateway allows the terminal to continue accessing; otherwise, it refuses access.

[0076] (24) The security gateway obtains the current user's role access control policy from the authentication center, restricts the user and device's access permissions to the power grid system, and ensures the security of data and operations.

[0077] Step (2) also includes: the security audit center module of the unified identity authentication system records all authentication and access event logs during the multi-identity access authentication phase, so as to carry out subsequent security audits and anomaly detection.

[0078] In the embodiment, the authentication registration and authorization stage is usually performed only once for user registration. If a user uses multiple terminals, each terminal needs to be registered and bound. Step (6) of this stage is executed according to a set cycle or updated and maintained according to actual changes. The multi-identity access authentication stage needs to be executed every time a user uses a terminal to access the power grid system.

[0079] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0080] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A trusted authentication system for power grid terminals based on multi-identity authentication, characterized in that, This includes dedicated clients and a unified identity authentication system; The dedicated client is used to install on terminals that need to access the power grid system; The unified identity authentication system includes an authentication center, a security gateway, and a security audit center, which are used to perform multi-factor authentication on terminals.

2. A trusted authentication method for a power grid terminal in a power grid terminal trusted authentication system based on multi-identity authentication according to claim 1, characterized in that, include: (1) Certification registration and authorization; including: (11) The user submits user information to the unified identity authentication system, the user information including basic registration information and real-name authentication information; (12) The certification center reviews users and grants access to the power grid system based on the user's circumstances; (13) After the user is authorized, a dedicated client is installed on the terminal, the terminal feature information is submitted, the authentication center authenticates the terminal, generates a digital identity certificate for the terminal, and binds the terminal with the user and the dedicated client. (2) Multi-factor authentication; including: (21) The terminal automatically performs terminal authentication through a dedicated client. If the authentication is successful, access is allowed to continue; if the authentication fails, access is denied. (22) Users perform multi-factor authentication through a dedicated client. If the authentication is successful, access is allowed to continue; if the authentication fails, access is denied. (23) The authentication center verifies the current access request based on the binding relationship between the user, client and terminal, and sends the result to the security gateway. If the verification is successful, access is allowed; otherwise, access is denied. (24) The Certification Center’s role-based access control policy restricts the access rights of users and terminals to ensure the security of data and operations.

3. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (11) includes: Users submit basic registration information when registering in the unified identity authentication system, including username, password, name, ID number, mobile phone number and user type, and are verified through dynamic verification code; Users provide real-name authentication information in accordance with the requirements of the unified identity authentication system, specifically by providing a photo of their ID card and undergoing facial recognition. The authentication center collects users' basic registration information and real-name authentication information.

4. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (12) includes: The authentication center reviews user information according to preset permissions. If the review fails, the user needs to modify the information and resubmit it according to the prompts. If the review passes, the authentication center will notify the user via SMS and store the user information in the database. The authentication center determines the user's access permissions based on the user information and generates the corresponding authorization token, which is then stored in the authentication center.

5. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (13) includes: Users install a dedicated client on the terminal that needs to access the power grid system and generate a unique client ID. When the dedicated client runs for the first time on the current terminal, it requests the user's authorization to access the terminal device information. After obtaining authorization, the dedicated client scans the terminal device, obtains terminal feature information, including device ID, operating system type and version, firewall software and system processes, and submits it to the authentication center. The certification center will review the terminal's feature information to determine if there are any security threats. If the review fails, a risk message will be displayed and the dedicated client will be closed. If the review passes, the certification center will generate a digital identity certificate for the terminal based on the terminal's feature information and bind the user, dedicated client, and terminal using the user ID, dedicated client ID, and terminal digital identity certificate ID.

6. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (1) further includes requiring the certification center to regularly update and maintain user information and terminal feature information to ensure user information security and reflect the status of terminal devices.

7. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (21) includes: The terminal runs a dedicated client, which automatically sends a verification request containing the dedicated client ID and the terminal's digital identity certificate to the security gateway of the unified identity authentication system. The security gateway receives the request submitted by the dedicated client. The security gateway sends the dedicated client ID and terminal digital identity certificate to the certification center for verification. The certification center verifies the validity of the user information of the corresponding bound user and returns the verification result to the security gateway. Based on the verification result, the security gateway decides whether to allow continued access.

8. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (22) includes: The user enters a dynamic verification code pre-generated by the security gateway on the dedicated client. The dedicated client sends the code to the security gateway for verification asynchronously. If the verification is successful, a correct message is displayed and the process continues. If the verification fails, a new dynamic verification code is generated, and the user is prompted to re-enter it. Once the dynamic verification code is successfully verified, the user submits their username and password to the security gateway through a dedicated client. The security gateway receives the information submitted by the dedicated client and sends it to the authentication center. The authentication center verifies the validity of the username and password and returns the verification result to the security gateway. If the verification is successful, the process continues; if the verification fails, an error message is displayed and the user is prompted to re-enter the information. The security gateway requires the user to turn on their camera for facial recognition. The security gateway collects the user's facial information and sends it to the authentication center. The authentication center verifies the validity of the facial information and returns the verification result to the security gateway. If the verification is successful, the process continues; if the verification fails, an error message is displayed and access is denied.

9. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (2) further includes encrypting the communication between the terminal and the authentication center and security gateway of the unified identity authentication system using a security protocol.

10. The power grid terminal trusted authentication method according to claim 2, characterized in that, Step (2) further includes the unified identity authentication system's security audit center recording all authentication and access events for security auditing and anomaly detection.