Trusted security detection method and system
By constructing a hardware-level root of trust and multi-dimensional data detection in the power system, the problems of easy breach and data tampering in the startup phase of traditional protection methods are solved, realizing full-process security protection and rapid response of the power system, and improving the system's security and anti-attack capabilities.
Patent Information
- Application Number
- CN202511139150.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-11-11
AI Technical Summary
The security protection of existing power systems mainly relies on traditional technical means such as firewalls, which are difficult to deal with internal intrusions after attackers bypass the boundary, and lack effective data detection methods, resulting in insufficient system security.
A hardware-level root of trust is constructed, the startup chain hash value is verified through the TCM trusted chip, login, communication and operation data are collected and encrypted, the trust value is calculated and compared with the preset threshold, and alarm response is triggered in real time, forming a multi-dimensional security detection mechanism.
This ensures the immutability of power system startup from the source, guarantees data integrity and confidentiality, quickly identifies potential risks, shortens risk handling cycles, and enhances the system's real-time security protection capabilities.
Smart Images

Figure CN120934840A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power system security detection technology, and in particular to a reliable security detection method and system. Background Technology
[0002] With the increasing digitalization, networking, and intelligence of power systems, modern power grids have evolved into highly complex cyber-physical systems. The deployment of numerous smart terminals and the widespread application of communication networks have significantly improved the operational efficiency and management sophistication of power systems, but have also dramatically expanded the system's network attack surface. Currently, power system security primarily relies on traditional technologies such as firewalls. However, firewalls can only provide perimeter protection and are insufficient to address internal intrusion attempts by attackers who have bypassed the perimeter, lacking effective detection of malicious operations that have already penetrated the system.
[0003] Therefore, improving the security of power systems has become an urgent technical problem to be solved. Summary of the Invention
[0004] The purpose of this application is to provide a reliable and secure detection method and system that can effectively improve the security of power systems.
[0005] To achieve the above objectives, a first aspect of this application provides a trusted security detection method, comprising:
[0006] Construct a hardware-level root of trust for the target power system to enable the target power system to start in a trusted manner;
[0007] The login data, communication data, and operation data of the target power system are collected, and the login data, communication data, and operation data are encrypted respectively to obtain encrypted login data, encrypted communication data, and encrypted operation data.
[0008] Based on the login encrypted data, the communication encrypted data, and the operation encrypted data, a login trust value, a communication trust value, and an operation trust value are calculated respectively. The login trust value, the communication trust value, and the operation trust value are compared with a preset login threshold, a preset communication threshold, and a preset operation threshold respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy.
[0009] An alarm response is triggered based on the first judgment result.
[0010] Compared with existing technologies, the trusted security detection method provided in this application has the following advantages: By constructing a hardware-level root of trust for the target power system, the immutability of the target power system's startup process is ensured from the bottom layer, solving the problem that the startup stage is easily breached in traditional protection, and laying a trusted foundation for the entire target power system; the encryption processing of login data, communication data, and operation data ensures the integrity and confidentiality of data during the collection and transmission stages, avoiding the risk of data tampering or leakage, and providing a reliable basis for security assessment; the multi-dimensional evaluation mechanism based on calculating the trust value of the three types of data and comparing it with the corresponding threshold can comprehensively cover scenarios such as login anomalies, communication risks, and operational failures, breaking through the limitations of single protection methods; and the real-time alarm response based on the judgment results can quickly trigger the handling mechanism, shorten the risk handling cycle, and effectively reduce the impact of security incidents. In summary, this method forms a complete security chain from source trust to end-to-end protection and timely response. It can quickly identify potential risks (such as abnormal login, malicious communication, abnormal operating status, etc.), make up for the lag in real-time detection and response of traditional protection methods, and thus improve the real-time security protection capability of the target power system to deal with dynamic threats.
[0011] In some embodiments, the construction of the hardware-level root of trust for the target power system includes:
[0012] The target power system has a built-in TCM trusted chip. When the target power system starts up, the TCM trusted chip detects the startup chain hash value.
[0013] If the startup chain hash value matches the preset hash value, the hardware-level root of trust is constructed based on the startup chain hash value.
[0014] In some embodiments, the method further includes:
[0015] During the process of constructing the hardware-level root of trust for the target power system, if the startup chain hash value does not match the preset hash value, a startup failure will be triggered and an alarm will be issued to ensure the trustworthiness of the startup chain and operating environment of the target power system.
[0016] In some embodiments, the login trust value, communication trust value, and operation trust value are calculated based on the login encrypted data, the communication encrypted data, and the operation encrypted data, respectively. These values are then compared with preset login thresholds, preset communication thresholds, and preset operation thresholds, respectively. If at least one trust value is lower than its corresponding threshold, the first judgment result is that the value is untrustworthy, including:
[0017] From the encrypted login data, obtain the current login time, the preset normal login interval, and the number of failed login attempts (N) for the login account. cNumber of login attempts (N) V Each failed login attempt consumes time t. i And the maximum time value maxt among all failed login attempts;
[0018] Based on the degree of deviation between the current login time and the preset normal login interval, the deviation value α is calculated, where α∈[0,1];
[0019] Through formula Calculate the login trust value R D ;
[0020] The login trust value R D With preset login threshold In comparison, if An anomaly was detected during the login process, and the initial assessment was that the login was untrustworthy.
[0021] In some embodiments, the login trust value, communication trust value, and operation trust value are calculated based on the login encrypted data, the communication encrypted data, and the operation encrypted data, respectively. These values are then compared with preset login thresholds, preset communication thresholds, and preset operation thresholds, respectively. If at least one trust value is lower than its corresponding threshold, the first judgment result is that the value is untrustworthy, including:
[0022] Extract various communication data parameters G from the encrypted communication data. j Optimal operating values for various communication data Deviation comparison value GS of various communication data j ;
[0023] Based on the degree of impact of communication data anomalies on the system, each communication data G is assigned a specific value. j Determine the weight ε j ;
[0024] Through formula Calculate the communication trust value R G ;
[0025] The communication trust value R G With preset communication threshold In comparison, if The communication was determined to be abnormal, and the first conclusion was that it was unreliable.
[0026] In some embodiments, the encrypted operational data includes encrypted system operational data and encrypted power equipment operational data. The process involves calculating a login trust value, a communication trust value, and an operational trust value based on the login encrypted data, the communication encrypted data, and the operational encrypted data, respectively. These values are then compared with preset login thresholds, preset communication thresholds, and preset operational thresholds. If at least one trust value is lower than its corresponding threshold, the first judgment result is that the data is untrustworthy, including:
[0027] Obtain normal operating data of the target power system;
[0028] The encrypted data of the system operation is compared with the data during normal operation to calculate the system operation deviation BF; the encrypted data of the power equipment operation is compared with the data during normal operation to calculate the equipment operation deviation BS; and the equipment operation deviation status value BFS corresponding to the system operation deviation is calculated.
[0029] Through formula Calculate the running confidence value R B ; R B Compared with the system's preset judgment threshold In comparison, if An anomaly was detected during operation, and the first assessment result was that the operation was unreliable.
[0030] In some embodiments, the calculation system operating deviation corresponds to the device operating deviation status value (BFS), including:
[0031] Based on the encrypted data, the system operation deviation function BF(t) and standard function BF0(t) of the target power system are obtained, as well as the equipment operation deviation function BS(t) and standard function BS0(t) of the target power system within the corresponding time period; the equipment operation deviation status value BFS corresponding to the system operation deviation is calculated using the formula.
[0032]
[0033] Where a is the start point of the time period, b is the end point of the time period, ΔBFS is the preset standard comparison value, and P is the preset system control equipment operation deviation function.
[0034] In some embodiments, triggering an alarm response based on the first determination result includes:
[0035] Based on the initial judgment result, generate text alarm information and sound alarm signals;
[0036] Text alarm messages are sent to the management terminal, triggering an audible alarm to alert personnel, thereby ensuring the safe response of the target power system.
[0037] To achieve the above objectives, a second aspect of this application provides a trusted security detection system applied to the trusted security detection method as described in the first aspect, the trusted security detection system comprising:
[0038] The terminal trusted module is used to construct a hardware-level root of trust for the target power system, enabling the target power system to start in a trusted manner.
[0039] The acquisition and transmission module is connected to the terminal trust module and the detection module. The acquisition and transmission module is used to acquire login data, communication data and operation data of the target power system, and to encrypt the login data, communication data and operation data respectively to obtain encrypted login data, encrypted communication data and encrypted operation data.
[0040] The detection module is used to calculate the login trust value, communication trust value, and operation trust value based on the login encrypted data, the communication encrypted data, and the operation encrypted data, respectively, and compare the login trust value, communication trust value, and operation trust value with the preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy.
[0041] The response module, connected to the detection module, is used to trigger an alarm response based on the first judgment result.
[0042] In some embodiments, the detection module includes:
[0043] The data processing unit is used to calculate the login trust value, communication trust value, and operation trust value based on the login encrypted data, the communication encrypted data, and the operation encrypted data, respectively.
[0044] The analysis unit is used to compare the login trust value, the communication trust value, and the operation trust value with preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy. Attached Figure Description
[0045] Figure 1 This is a flowchart of a trusted security detection method provided in an embodiment of this application;
[0046] Figure 2 yes Figure 1 A flowchart of step S101 in the process;
[0047] Figure 3 yes Figure 1 A flowchart of step S104 in the process;
[0048] Figure 4This is a schematic diagram of a trusted security detection system provided in an embodiment of this application;
[0049] Figure 5 This is another structural schematic diagram of a trusted security detection system provided in an embodiment of this application. Detailed Implementation
[0050] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0051] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0052] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0053] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0054] First, let's analyze some of the terms used in this application:
[0055] The power system is a complex system consisting of power generation, transmission, transformation, distribution, and consumption. It converts primary energy sources from nature (such as coal, hydropower, wind power, and solar energy) into electrical energy through power generation equipment, and then transmits and distributes the electrical energy to various power-consuming places such as factories and homes through transmission lines, substations, and other facilities. It ensures the power supply for social production and life and is a key infrastructure for maintaining the normal operation of society.
[0056] With the continuous advancement of digitalization, networking, and intelligentization of power systems, modern power grids have evolved into highly complex cyber-physical systems. The widespread deployment of numerous smart terminals and the deep application of communication networks, while improving system operating efficiency and management effectiveness, have also significantly expanded the network attack surface, posing more severe security threats to power systems.
[0057] Currently, power system security protection mainly relies on traditional technologies such as firewalls, log detection, and vulnerability scanning. However, these technologies have significant limitations: firewalls focus on network boundary protection and can only block unauthorized external access. Once attackers breach the boundary and penetrate into the system, firewalls are unable to effectively protect against subsequent intrusions. Log detection technology relies on complete and accurate log data. If attackers tamper with logs to cover up their tracks, it is impossible to detect intrusion risks in real time, and it also leads to a lack of reliable evidence for subsequent tracing and fault location, making it difficult to ensure the comprehensiveness and reliability of power system security protection.
[0058] Based on this, this application provides a reliable security detection method and system that can effectively improve the security of power systems.
[0059] Please see Figure 1 , Figure 1 This is an optional flowchart of the trusted security detection method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S104.
[0060] Step S101: Construct a hardware-level root of trust for the target power system to enable the target power system to start in a trusted manner;
[0061] Step S102: Collect login data, communication data and operation data of the target power system, and encrypt the login data, communication data and operation data respectively to obtain encrypted login data, encrypted communication data and encrypted operation data;
[0062] Step S103: Calculate the login trust value, communication trust value, and operation trust value based on the login encrypted data, communication encrypted data, and operation encrypted data, respectively. Then compare the login trust value, communication trust value, and operation trust value with the preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy.
[0063] Step S104: Trigger an alarm response based on the first judgment result.
[0064] Steps S101 to S104, as illustrated in this embodiment, construct a hardware-level root of trust for the target power system, ensuring the immutability of the target power system's startup process from the ground up. This solves the problem of easy breaches in the startup phase of traditional protection, laying a trustworthy foundation for the entire target power system. Encryption of login data, communication data, and operational data ensures the integrity and confidentiality of data during collection and transmission, avoiding the risk of data tampering or leakage, and providing a reliable basis for security assessment. A multi-dimensional assessment mechanism, based on calculating trust values for the three types of data and comparing them with corresponding thresholds, comprehensively covers scenarios such as login anomalies, communication risks, and operational failures, overcoming the limitations of single protection methods. Real-time alarm responses based on the judgment results can quickly trigger the handling mechanism, shortening the risk handling cycle and effectively reducing the impact of security incidents. In summary, this method forms a complete security chain from source trust to end-to-end protection to timely response, enabling rapid identification of potential risks (such as abnormal login, malicious communication, abnormal operating states, etc.), compensating for the lag in real-time detection and response of traditional protection methods, thereby improving the real-time security protection capability of the target power system against dynamic threats.
[0065] In step S101 of some embodiments, the target power system can be a power system requiring security testing, such as an overall system including power generation, transmission, distribution equipment, and control terminals. A hardware-level root of trust refers to an immutable source of trust built on hardware (such as a TCM trusted chip), which is the basis for verifying the trustworthiness of the target power system's startup and operation. Trusted startup refers to verifying the integrity of the startup chain (such as BIOS or operating system kernel) through the hardware-level root of trust during the startup process of the target power system, ensuring a startup state that has not been maliciously tampered with.
[0066] Please see Figure 2 In some embodiments, step S101 may include, but is not limited to, steps S201 to S202:
[0067] Step S201: A TCM trusted chip is built into the target power system. When the target power system starts up, the TCM trusted chip detects the startup chain hash value.
[0068] Step S202: If the startup chain hash value matches the preset hash value, a hardware-level root of trust is constructed based on the startup chain hash value.
[0069] In step S201 of some embodiments, the TCM trusted chip can be a hardware chip with cryptographic operations and secure storage functions. It is a core hardware component for implementing trusted computing and can provide security services such as data encryption, identity authentication, and integrity verification. The boot chain hash value refers to a unique value calculated using a hash algorithm (such as SHA-256) for each level of programs (such as BIOS, bootloader, and operating system kernel) involved in the boot process of the target power system, used to characterize the integrity of the programs. By embedding the TCM trusted chip in the core equipment of the target power system, when the system boots up, the chip automatically calculates the hash values of each link in the boot chain, completing a preliminary check of the boot program integrity.
[0070] In step S202 of some embodiments, the preset hash value can be a certified startup chain standard hash value pre-stored in the TCM trusted chip, which serves as the benchmark for determining whether the startup program has been tampered with. The hardware-level root of trust refers to the underlying source of trust established by verifying the integrity of the startup chain using the TCM trusted chip as the physical carrier; all subsequent trust relationships are established based on this root node. If the TCM trusted chip detects that the startup chain hash value matches the preset hash value, it indicates that the startup program is complete and trustworthy. Based on this verification result, the hardware-level root of trust for the target power system is constructed using the TCM chip.
[0071] This application embodiment ensures the integrity and trustworthiness of the system startup process at the hardware level by embedding a TCM trusted chip in the target power system and constructing a hardware-level trust root based on startup chain hash value matching. This effectively resists malicious tampering attacks targeting the startup phase and lays an immutable trust foundation for the safe operation of the entire power system.
[0072] In some embodiments, if the startup chain hash value does not match the preset hash value during the construction of the hardware-level root of trust for the target power system, a startup failure is triggered and an alarm is issued to ensure the trustworthiness of the startup chain and operating environment of the target power system.
[0073] Startup failure refers to the target power system terminating the startup process and preventing untrusted programs from running. Alarms can be issued to maintenance personnel through audible and visual prompts, push notifications, or other means to notify them of the anomaly. For example, when building a hardware-level root of trust for the target power system, if the startup chain hash value is detected to be inconsistent with the preset hash value (indicating that the startup program may have been tampered with), the system startup will be immediately terminated and an alarm will be issued to ensure the trustworthiness of the startup chain and the subsequent operating environment.
[0074] This application embodiment blocks the execution of tampered programs from the startup stage by responding to abnormal responses to mismatched hash values, preventing malicious code intrusion and further strengthening the hardware-level root of trust's ability to guarantee system startup trustworthiness, thus forming a more complete startup security protection closed loop.
[0075] In step S102 of some embodiments, login data refers to the login information of users or terminals in the target power system, including login account, time, IP address, authentication result, number of failures, etc. Communication data is network interaction information between devices within the system (such as substation terminals and dispatch centers) or with external systems, including communication protocols, data transmission volume, connection objects, interaction frequency, etc. Operational data includes system operation data and power equipment operation data, specifically the real-time operating parameters of the target power system and equipment, such as voltage, current, power, equipment temperature, load rate, fault codes, etc. Encrypted login data / encrypted communication data / encrypted operational data refers to the corresponding data after encryption processing, which can only be restored using a decryption key.
[0076] The system collects login data, communication data, and operational data from the target power system. Login data is processed using encryption algorithms to obtain encrypted login data; communication data is processed using encryption algorithms to obtain encrypted communication data; and operational data is processed using encryption algorithms to obtain encrypted operational data. This ensures the security and reliability of the data during transmission and storage. During implementation, the encrypted login data, encrypted communication data, and encrypted operational data can be obtained after encryption processing via an edge gateway. Encryption ensures that the data is not accessed without authorization (confidentiality) and is not maliciously tampered with (integrity), solving the problems of easy leakage and tampering in traditional data collection. This provides a reliable data foundation for subsequent trusted value calculations and protects the security of sensitive power system information (such as dispatch instructions and equipment status).
[0077] In step S103 of some embodiments, the login trust value / communication trust value / operation trust value are numerical values (ranging from [0,1], with higher values indicating greater trustworthiness) calculated based on the corresponding encrypted data, quantifying the trustworthiness of login behavior, communication process, and operational status. The preset login threshold / preset communication threshold / preset operation threshold can be a pre-set trust threshold (e.g., 0.6) within the target system; values below this threshold indicate that the corresponding dimension is untrustworthy. The first judgment result is the final judgment on the overall trustworthiness of the target power system ("untrustworthy" or "trustworthy").
[0078] The corresponding trust values are calculated using encrypted login data, encrypted communication data, and encrypted operation data, and then compared with preset thresholds. If any trust value is lower than the threshold, the entire system is determined to be untrustworthy (the first judgment result is untrustworthy).
[0079] It should be noted that before calculating each trusted value, this application also processes the obtained login encrypted data, communication encrypted data, and operation encrypted data, including but not limited to data cleaning, timestamp unification, format conversion, and normalization, in order to obtain clear, complete, and dimensionless data for subsequent analysis and calculation.
[0080] Specifically, in some embodiments, step S103 includes:
[0081] From the encrypted login data, obtain the current login time, the preset normal login interval, and the number of failed login attempts (N) for the login account. c Number of login attempts (N) V Each failed login attempt consumes time t. i And the maximum time value maxt among all failed login attempts;
[0082] Based on the degree of deviation between the current login time and the preset normal login interval, the deviation value α is calculated, where α∈[0,1];
[0083] Through formula Calculate the login trust value R D ;
[0084] Login trust value R D With preset login threshold In comparison, if An anomaly was detected during the login process, and the initial assessment was that the login was untrustworthy.
[0085] It should be noted that the current login time refers to the specific time when the login attempt occurred. The preset normal login interval is a regular login time period set based on the login account's historical login habits. Number of failed login attempts N c This refers to the total number of failed login attempts for an account within the statistical period. Number of login attempts N V This refers to the total number of login attempts (including successful and failed attempts) made by an account within the statistical period. The time consumed during failed login attempts is t. i This refers to the time elapsed from the input of information to the system returning a failure result during the i-th login failure. Maximum time value maxt: the longest time t among all failed login records. i value.
[0086] Additionally, the deviation value α represents the degree of deviation between the current login time and the normal login interval, ranging from [0,1] (0 within the normal interval, with a larger value as the deviation increases, up to a maximum of 1). Login reliability value R D A numerical value is used to quantify the credibility of login behavior; a higher value indicates a more credible login behavior. A preset login threshold is also included. It refers to the threshold value set by the target power system based on historical data and safety experience, used to determine whether the login is abnormal.
[0087] This application embodiment integrates login time deviation (α) and failure rate percentage. This method utilizes multi-dimensional data on failure time characteristics (average time + maximum time) to construct a quantitative login trust value calculation model, overcoming the limitations of traditional single-factor judgments (such as judging solely by the number of failures). This approach can accurately identify abnormal login behaviors (such as logins outside of working hours, high-frequency brute-force attacks, and probing logins with abnormally long latency), significantly improving the accuracy and comprehensiveness of security detection during the login process.
[0088] Specifically, in some embodiments, step S103 includes:
[0089] Extract various communication data parameters G from the encrypted communication data. j Optimal operating values for various communication data Deviation comparison value GS of various communication data j ;
[0090] Based on the degree of impact of communication data anomalies on the system, each communication data G is assigned a specific value. j Determine the weight ε j ;
[0091] Through formula Calculate the communication trust value R G ;
[0092] The communication trust value R G With preset communication threshold In comparison, if The communication was determined to be abnormal, and the first conclusion was that it was unreliable.
[0093] It should be noted that the communication data parameter G j This represents the real-time value of the j-th specific communication metric (e.g., j=1 represents network traffic, G1=100Mbps). Optimal operating value. Based on the historical data of normal operation of the target power system, a standard reference value (such as the optimal value of network traffic) is set for the j-th communication parameter. Deviation comparison value GS j This serves as the baseline for the allowable normal fluctuation range of the j-th communication parameter (e.g., GS1 = 20Mbps, meaning that traffic fluctuations within 60-100Mbps are reasonable). Weight ε j It is a weight value set according to the degree of impact of the abnormality of the j-th communication parameter on the system; for example, the communication weight ε of the core device. j =0.8, secondary equipment ε j =0.2; For example, weights can be determined using the Analytic Hierarchy Process (AHP) or expert scoring (the sum of all weights is 1). Communication reliability value R GThis can be a numerical value that quantifies the reliability of communication status; a higher value indicates more reliable communication and a more normal communication process. A preset communication threshold is also available. It refers to a pre-set reliable threshold value for the target power system based on security experience, used to determine whether communication is abnormal.
[0094] This application embodiment achieves a quantitative assessment of communication status by analyzing the deviation of multi-dimensional communication parameters (such as traffic and bandwidth) and combining them with influence weights. This method overcomes the limitations of single-parameter detection, accurately identifies covert intrusion behaviors (such as abnormal traffic caused by data theft after legitimate login), supplements the deficiencies of login detection at the communication level, forms multiple layers of protection, and significantly improves the comprehensiveness and accuracy of power system security detection.
[0095] Specifically, in some embodiments, the encrypted data operation includes encrypted system operation data and encrypted power equipment operation data, and step S103 includes:
[0096] Acquire normal operating data of the target power system;
[0097] The system operation encrypted data is compared with the data during normal operation to calculate the system operation deviation BF; the power equipment operation encrypted data is compared with the data during normal operation to calculate the equipment operation deviation BS; and the corresponding equipment operation deviation status value BFS is calculated.
[0098] Through formula Calculate the running confidence value R B ; R B Compared with the system's preset judgment threshold In comparison, if An anomaly was detected during operation, and the first assessment result was that the operation was unreliable.
[0099] It should be noted that encrypted operational data includes encrypted system operational data (such as system-level parameters like total network voltage and total load) and encrypted power equipment operational data (such as equipment-level parameters like transformer temperature and line current). Normal operating data refers to the baseline operating parameters of the target power system and equipment under historical normal operating conditions (e.g., determined through statistical analysis of historical data). System operational deviation (BF) represents the degree of deviation between the encrypted system operational data and the normal operating data (e.g., the percentage difference between the current network frequency and the baseline frequency). Equipment operational deviation (BS) represents the degree of deviation between the encrypted power equipment operational data and the normal operating data (e.g., the percentage difference between the current circuit breaker temperature and the baseline temperature). The corresponding equipment operational deviation status value (BFS) is a quantitative correlation value established based on historical data between system deviation and equipment deviation (e.g., the typical correlation between an abnormal voltage in the target power system and an abnormal current in a specific line).
[0100] Running Trust Value R B This is a quantitative value reflecting the reliability of the target power system and equipment's operating status; a higher value indicates more normal operation. Preset judgment threshold. These are pre-set trusted thresholds based on security experience, used to determine whether the operating status is abnormal.
[0101] This application achieves a comprehensive quantitative assessment of the power system's operational status by integrating system-level and equipment-level operational deviations and their interrelationships. This method overcomes the limitations of single-dimensional security detection, identifying not only independent system or equipment anomalies but also complex risks arising from the linkage between system and equipment anomalies (such as equipment overload caused by system frequency fluctuations). This significantly improves the accuracy and comprehensiveness of anomaly detection in operational processes, providing a more reliable safety barrier for the stable operation of the power system.
[0102] The calculation of the system operating deviation corresponding to the equipment operating deviation status value (BFS) includes:
[0103] Based on the encrypted data, the system operation deviation function BF(t) and standard function BF0(t) of the target power system are obtained, as well as the equipment operation deviation function BS(t) and standard function BS0(t) of the target power system within the corresponding time period; the equipment operation deviation status value BFS corresponding to the system operation deviation is calculated using the formula.
[0104]
[0105] Where a is the start point of the time period, b is the end point of the time period, ΔBFS is the preset standard comparison value, and P is the preset system control equipment operation deviation function.
[0106] It should be noted that the system operation deviation function BF(t) describes the change in the operation deviation of the target power system at time t over time (e.g., the degree to which the total network load deviates from the benchmark value at time t). The standard function BF0(t) is a standard reference function for the change in operation deviation over time when the system is operating normally (obtained by fitting historical normal data). The equipment operation deviation function BS(t) describes the change in the operation deviation of power equipment at time t over time (e.g., the degree to which the transformer temperature deviates from the benchmark value at time t). The standard function BS0(t) is a standard reference function for the change in operation deviation over time when the equipment is operating normally (obtained by fitting historical normal data). The time period [a, b] is the time interval for analyzing the correlation between system and equipment operation (a is the start time, b is the end time, for example, [a = 8:00, b = 9:00] within a certain hour). The preset standard comparison value ΔBFS can be a standard threshold for the correlation between system and equipment deviation set based on historical normal correlation data (reflecting the typical value of the correlation between the two under normal operating conditions). The preset system reference equipment operation deviation function P can be a function obtained by linear regression fitting through a large amount of historical data. It is used to establish the benchmark correlation between system deviation and equipment deviation (such as the correlation rule that when the system load deviates by 10%, the corresponding line current should deviate by 5%).
[0107] This application's embodiments, by introducing time-dimensional function analysis and integral calculations, enable BFS calculation to accurately quantify the dynamic correlation between system and device operational deviations, overcoming the limitations of static single-value comparisons. Its core value lies in its ability to capture both anomalies arising from mismatches between system and device deviations and to identify the cumulative risks of long-term correlated anomalies. This method provides a reliable operating value R. B It provides quantitative evidence for system and equipment linkage anomalies, significantly improves the detection accuracy of complex operational anomalies, and further improves the multi-dimensional protection system for power system operation safety.
[0108] In step S104 of some embodiments, the alarm response is a warning and response measure triggered when the system is determined to be untrustworthy (such as issuing an audible and visual alarm, pushing abnormal information to the management terminal, etc.). If the first judgment result is untrustworthy, an alarm response is immediately triggered to notify the operation and maintenance personnel to handle the situation in a timely manner.
[0109] Please see Figure 3 In some embodiments, step S104 may include, but is not limited to, steps S301 to S302:
[0110] Step S301: Based on the first judgment result, generate text alarm information and sound alarm signal;
[0111] Step S302: Send the text alarm information to the management terminal and trigger the sound alarm to remind personnel to ensure the safe response of the target power system.
[0112] In step S301 of some embodiments, the first judgment result refers to the "untrustworthy" judgment (i.e., an anomaly exists) derived from the comparison result of login, communication, and operational trust values with corresponding thresholds. Text alarm information refers to alarm notifications that describe the type, location, and degree of the anomaly in text form. For example, "Device X's operational trust value is below the threshold, suspected anomaly." Sound alarm signals can be warning sounds (such as buzzers or voice prompts) emitted through audio devices to quickly alert on-site personnel.
[0113] In step S302 of some embodiments, the management terminal refers to the management device (such as a computer or mobile phone) used by maintenance personnel to receive and process alarm information.
[0114] When the initial assessment result is "unreliable," the target power system can automatically generate a text alarm message containing information such as the anomaly type (e.g., login / communication / operational anomaly) and specific location, along with a corresponding audible alarm signal. The text alarm message is sent to the management terminal for maintenance personnel to view and take automatic or manual responses, while the audible alarm is triggered to alert on-site personnel. Furthermore, alarm levels can be set based on the difference between the reliability value and a threshold (the smaller the reliability value, the higher the level), clearly defining the urgency of the response and ultimately ensuring the safety and efficiency of the target power system's response.
[0115] This embodiment achieves both accurate information transmission to remote maintenance personnel (text alarm) and rapid perception by on-site personnel (audio alarm) through dual alarm methods of text and sound, avoiding the risk of omissions caused by a single alarm method; while the hierarchical alarm mechanism helps managers prioritize high-risk anomalies and optimize response resource allocation by differentiating the urgency level.
[0116] This application embodiment ensures system startup trust by constructing a hardware-level root of trust, protects data security through encryption, and covers the entire scenario of login, communication, and operation with multi-dimensional trust value assessment. Combined with real-time alarm response, it forms a complete security chain from source to disposal, effectively solving problems such as vulnerability in the startup process, easy data tampering, incomplete detection, and delayed response in traditional protection, and significantly improving the security and anti-attack capability of the target power system.
[0117] See Figure 4 This is a schematic diagram of the structure of a trusted security detection system provided in an embodiment of this application.
[0118] This application provides a trusted security detection system applied to the trusted security detection method described above. The trusted security detection system includes:
[0119] The terminal trusted module 410 is used to construct a hardware-level root of trust for the target power system, enabling the target power system to start in a trusted manner.
[0120] The acquisition and transmission module 420 is connected to the terminal trust module 410 and the detection module 430. The acquisition and transmission module is used to acquire login data, communication data and operation data of the target power system, and to encrypt the login data, communication data and operation data respectively to obtain encrypted login data, encrypted communication data and encrypted operation data.
[0121] The detection module 430 is used to calculate the login trust value, communication trust value, and operation trust value based on the login encrypted data, communication encrypted data, and operation encrypted data, respectively, and compare the login trust value, communication trust value, and operation trust value with the preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy.
[0122] The response module 440, connected to the detection module 430, is used to trigger an alarm response based on the first judgment result.
[0123] It should be noted that the terminal trust module 410, through its built-in hardware-level root of trust, verifies the integrity of the startup chain (such as by comparing hash values) when the terminal device / target power system starts up, ensuring that the startup program has not been tampered with, thus laying a trustworthy foundation for the terminal's operating environment. The acquisition and transmission module 420 collects key data such as login, communication, and operation data, encrypts it, and transmits it to the detection module 430, ensuring the confidentiality and integrity of the data during acquisition and transmission, and preventing it from being stolen or tampered with.
[0124] Among them, see Figure 5 The detection module includes:
[0125] Data processing unit 431 is used to calculate login trust value, communication trust value and operation trust value based on login encrypted data, communication encrypted data and operation encrypted data respectively;
[0126] Analysis unit 432 is used to compare the login trust value, communication trust value, and operation trust value with the preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy.
[0127] The data processing unit 431 of the detection module 430 performs preprocessing such as decryption and cleaning on the received encrypted data to provide standardized data for analysis. The analysis unit 432 calculates login, communication, and operational trust values based on the processed data and compares them with preset thresholds to determine whether there are any anomalies in the system. When the analysis module identifies an anomaly, the response module 440 triggers real-time defense actions (such as generating alarm information or blocking abnormal connections) to quickly respond and ensure system security.
[0128] The specific implementation of this trusted security detection system is basically the same as the specific implementation of the trusted security detection method described above, and will not be repeated here.
[0129] The technical solution of this application achieves full-link security protection for the power system through multi-module collaboration. First, a hardware-level root of trust is constructed based on the terminal trusted module. When the terminal starts up, the chip automatically detects the startup chain hash value. If it does not match the preset value, a startup failure is immediately triggered and an alarm is issued, blocking malicious tampering attacks at the source and ensuring the underlying trustworthiness of the startup chain and operating environment. Second, the acquisition and transmission module 420 collects login data, communication data, and operating data, which are then encrypted by the edge gateway before being uploaded to the detection module 430. Encryption effectively prevents tampering or forgery during data transmission, providing a reliable data source for subsequent analysis and avoiding the problems of easy leakage and difficulty in tracing traditional data transmission. The data processing unit 431 of the detection module 430 performs preprocessing on the received data, including cleaning, timestamp unification, format conversion, and normalization, to eliminate dimensional interference and obtain a standardized and complete analysis sample. The analysis unit 432, based on the processed data, calculates credibility values from three dimensions: login, communication, and operation. Login anomalies are judged by characteristics such as login time deviation and failure count; communication anomalies are judged by the deviation and weight analysis of communication parameters from standard values; and operation anomalies are judged by the deviation of system / equipment operation and the correlation between the two. This multi-dimensional assessment covers the entire scenario from before login (e.g., identity verification) to after login (e.g., data interaction, equipment operation), breaking through the limitations of single data detection and achieving accurate identification of anomalies. Finally, based on the credibility value judgment results, the response module 440 triggers tiered alarms and defensive actions, clearly identifying the anomaly type (login / communication / operation) for easy follow-up problem tracing and curbing risk spread through timely response. The overall solution forms a closed loop of "source credibility → data security → multi-dimensional detection → accurate response," comprehensively improving the power system's security protection capabilities and anomaly handling efficiency.
[0130] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0131] The above description is the preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications are also considered to be within the scope of protection of this application.
Claims
1. A reliable security detection method, characterized in that, include: Construct a hardware-level root of trust for the target power system to enable the target power system to start in a trusted manner; The login data, communication data, and operation data of the target power system are collected, and the login data, communication data, and operation data are encrypted respectively to obtain encrypted login data, encrypted communication data, and encrypted operation data. Based on the login encrypted data, the communication encrypted data, and the operation encrypted data, a login trust value, a communication trust value, and an operation trust value are calculated respectively. The login trust value, the communication trust value, and the operation trust value are compared with a preset login threshold, a preset communication threshold, and a preset operation threshold respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy. An alarm response is triggered based on the first judgment result.
2. The method as described in claim 1, characterized in that, The hardware-level root of trust for constructing the target power system includes: The target power system has a built-in TCM trusted chip. When the target power system starts up, the TCM trusted chip detects the startup chain hash value. If the startup chain hash value matches the preset hash value, the hardware-level root of trust is constructed based on the startup chain hash value.
3. The method as described in claim 2, characterized in that, The method further includes: During the process of constructing the hardware-level root of trust for the target power system, if the startup chain hash value does not match the preset hash value, a startup failure will be triggered and an alarm will be issued to ensure the trustworthiness of the startup chain and operating environment of the target power system.
4. The method as described in claim 1, characterized in that, The system calculates a login trust value, a communication trust value, and a running trust value based on the login encrypted data, the communication encrypted data, and the running encrypted data, respectively. These values are then compared with preset login thresholds, preset communication thresholds, and preset running thresholds. If at least one trust value is lower than its corresponding threshold, the first judgment result is that the system is untrustworthy, including: From the encrypted login data, obtain the current login time, the preset normal login interval, and the number of failed login attempts (N) for the login account. c Number of login attempts (N) V Each failed login attempt consumes time t. i And the maximum time value maxt among all failed login attempts; Based on the degree of deviation between the current login time and the preset normal login interval, the deviation value α is calculated, where α∈[0,1]; Through formula Calculate the login trust value R D ; The login trust value R D With preset login threshold In comparison, if An anomaly was detected during the login process, and the initial assessment was that the login was untrustworthy.
5. The method as described in claim 1, characterized in that, The system calculates a login trust value, a communication trust value, and a running trust value based on the login encrypted data, the communication encrypted data, and the running encrypted data, respectively. These values are then compared with preset login thresholds, preset communication thresholds, and preset running thresholds. If at least one trust value is lower than its corresponding threshold, the first judgment result is that the system is untrustworthy, including: Extract various communication data parameters G from the encrypted communication data. j Optimal operating values for various communication data Deviation comparison value GS of various communication data j ; Based on the degree of impact of communication data anomalies on the system, each communication data G is assigned a specific value. j Determine the weight ε j ; Through formula Calculate the communication trust value R G ; The communication trust value R G With preset communication threshold In comparison, if The communication was determined to be abnormal, and the first conclusion was that it was unreliable.
6. The method as described in claim 1, characterized in that, The encrypted operational data includes system operational encrypted data and power equipment operational encrypted data. Based on the encrypted login data, the encrypted communication data, and the encrypted operational data, a login trust value, a communication trust value, and an operational trust value are calculated respectively. These values are then compared with preset login thresholds, preset communication thresholds, and preset operational thresholds, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy, including: Obtain normal operating data of the target power system; The encrypted data of the system operation is compared with the data during normal operation to calculate the system operation deviation BF; the encrypted data of the power equipment operation is compared with the data during normal operation to calculate the equipment operation deviation BS; and the equipment operation deviation status value BFS corresponding to the system operation deviation is calculated. Through formula Calculate the running confidence value R B ; R B Compared with the system's preset judgment threshold In comparison, if An anomaly was detected during operation, and the first conclusion was that the operation was unreliable.
7. The method as described in claim 6, characterized in that, The calculation system's operational deviation corresponds to the device operational deviation status value (BFS), including: Based on the encrypted data, the system operation deviation function BF(t) and standard function BF0(t) of the target power system are obtained, as well as the equipment operation deviation function BS(t) and standard function BS0(t) of the target power system within the corresponding time period; the equipment operation deviation status value BFS corresponding to the system operation deviation is calculated using the formula. Where a is the start point of the time period, b is the end point of the time period, ΔBFS is the preset standard comparison value, and P is the preset system control equipment operation deviation function.
8. The method as described in claim 1, characterized in that, The step of triggering an alarm response based on the first judgment result includes: Based on the initial judgment result, generate text alarm information and sound alarm signals; Text alarm messages are sent to the management terminal, triggering an audible alarm to alert personnel, thereby ensuring the safe response of the target power system.
9. A trusted security detection system, applied to the trusted security detection method as described in any one of claims 1 to 8, characterized in that, The trusted security detection system includes: The terminal trusted module is used to construct a hardware-level root of trust for the target power system, enabling the target power system to start in a trusted manner. The acquisition and transmission module is connected to the terminal trust module and the detection module. The acquisition and transmission module is used to acquire login data, communication data and operation data of the target power system, and to encrypt the login data, communication data and operation data respectively to obtain encrypted login data, encrypted communication data and encrypted operation data. The detection module is used to calculate the login trust value, communication trust value, and operation trust value based on the login encrypted data, the communication encrypted data, and the operation encrypted data, respectively, and compare the login trust value, communication trust value, and operation trust value with the preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy. The response module, connected to the detection module, is used to trigger an alarm response based on the first judgment result.
10. The system as described in claim 9, characterized in that, The detection module includes: The data processing unit is used to calculate the login trust value, communication trust value, and operation trust value based on the login encrypted data, the communication encrypted data, and the operation encrypted data, respectively. The analysis unit is used to compare the login trust value, the communication trust value, and the operation trust value with preset login threshold, preset communication threshold, and preset operation threshold, respectively. If at least one trust value is lower than the corresponding threshold, the first judgment result is untrustworthy.