Nuclear power plant network security alarm management method, system, device and medium
By introducing an out-of-band management network and hard-wired loops into the instrumentation and control system of a nuclear power plant, and combining this with encrypted communication using national cryptographic algorithms, the problem of network security alarms not being transmitted in real time under network attacks has been solved, enabling real-time, independent, and reliable network security alarm indications in the main control room.
Patent Information
- Application Number
- CN202511209863.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-11-11
AI Technical Summary
When the instrumentation and control system of a nuclear power plant is subjected to a cyberattack, the alarm information of the network security management equipment cannot be transmitted to the main control room in real time, and there is a risk that it may be tampered with by attackers, resulting in insufficient reliability of network security alarm management.
The alarm signal is transmitted to an independent system through the network security management equipment in the out-of-band management network, and the alarm indicator light in the main control room is lit through a hard-wired circuit. The national cryptographic algorithm is used for encrypted communication and identity authentication to ensure the real-time performance and independence of the signal.
It enables real-time, independent, and reliable transmission of network security alarms to the main control room, improving the reliability of network security alarm management in nuclear power plants and ensuring that operators receive clear network security alarm instructions.
Smart Images

Figure CN120934869A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of nuclear power plant network security alarm technology, specifically relating to a nuclear power plant network security alarm management method, system, device and medium. Background Technology
[0002] The statements herein provide only background information in relation to this invention and do not necessarily constitute prior art.
[0003] The instrumentation and control system (ICS) of a nuclear power plant serves as its nerve center, enabling control and monitoring functions. ICS typically employs a distributed control system (DCS), consisting of field instruments and actuators, control and monitoring equipment and communication networks, human-machine interface resources, and operational facilities.
[0004] Nuclear power plant instrumentation and control systems, which are based on digital technology, are vulnerable to cyberattacks. After a cyberattack, the attacker may tamper with control commands or monitoring feedback parameters, preventing operators in the main control room from accurately sensing the plant's actual operating status. Therefore, cybersecurity-related alarms should be fed back to the nuclear power plant's main control room in real time, providing operators with clear cybersecurity warnings.
[0005] In accordance with the requirements of network security level protection, nuclear power plant instrumentation and control systems are generally equipped with network security management equipment. By dividing specific management areas, out-of-band control is carried out on security devices or security components distributed in the network. The operation status of network links, security devices, network devices and servers is centrally monitored, and various security events occurring in the network are identified, alarmed and analyzed.
[0006] However, the inventors discovered that network security management equipment is typically installed in the computer room housing the instrumentation and control cabinets of nuclear power plants, and is maintained and managed by instrumentation and control maintenance personnel. Network security attack warnings are only discovered during routine inspections by these personnel, ultimately serving only a retrospective function and failing to provide real-time notification to the main control room operators about potential network security attacks on the power plant. Furthermore, because the instrumentation and control system is vulnerable to network attacks, the system itself becomes untrusted, and transmitting network security alarms through its own network is susceptible to tampering by attackers. Therefore, there is an urgent need to establish an independent and secure alarm pathway to transmit alarm information generated by network security management equipment to the main control room, thereby improving the reliability of network security alarm management in nuclear power plants. Summary of the Invention
[0007] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method, system, device and medium for network security alarm management in nuclear power plants. The alarm signal is transmitted to an independent system through network security management equipment in the out-of-band management network, and then the alarm indicator light located in the main control room is lit through a hard-wired circuit. This realizes the function of sending network security alarms of the nuclear power plant instrumentation and control system to the main control room for indication in real time, thereby improving the reliability of network security alarm management in nuclear power plants.
[0008] To achieve the above objectives, the present invention is implemented through the following technical solution: In a first aspect, the technical solution of the present invention provides a method for managing network security alarms in nuclear power plants, including: Based on network security management equipment, monitor security events in the nuclear power plant instrumentation and control system network, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. The network security alarm signal is encrypted based on the national cryptographic algorithm and sent to the central control processor through the out-of-band management network. The communication process uses an SSL / TLS connection that supports the national cryptographic algorithm. The national cryptographic algorithm is used to authenticate the identities and verify the integrity of the communicating parties, and timestamps and random numbers are used to prevent replay attacks. The encrypted network security alarm signal is processed by the central control processor and converted into a dry contact relay signal to control the network security alarm indicator in the main control room to sound an alarm. When the network security event that triggered the alarm signal is marked as processed, the network security alarm indicator in the main control room turns off.
[0009] In at least one embodiment, the preset rules include one or more of the following: type, level, and scope of impact of security events.
[0010] In at least one embodiment, the national cryptographic algorithm includes the SM2 elliptic curve public key cryptography algorithm, the SM3 cryptographic hash algorithm, and the SM4 symmetric encryption algorithm.
[0011] In at least one embodiment, network security alarm signals are encrypted using the SM4 symmetric encryption algorithm, the identities of both communicating parties are authenticated using a bidirectional SM2 elliptic curve public key cryptography algorithm certificate, data is encrypted using the SM2 elliptic curve public key cryptography algorithm, and integrity is verified using the SM3 cryptographic hash algorithm.
[0012] In at least one embodiment, the central control processor obtains and decrypts the encrypted network security event alarm signal through the API interface, converts the alarm signal into a dry contact relay contact signal, and sends it out to the main control room indicator light circuit through a long-distance hardwire. This controls the dry contact to close and connect the main control room network security alarm indicator light circuit, illuminating the indicator light and alerting the main control room operator to a potential network security attack.
[0013] In at least one embodiment, a network security alarm indicator light is located on the main control room panel and is illuminated when the network security management device generates an alarm signal; it is only turned off when all network security events that triggered the alarm signal have been marked as processed.
[0014] Secondly, the technical solution of the present invention also provides a nuclear power plant network security alarm management system, comprising: The safety monitoring module is configured to: monitor safety events in the nuclear power plant's instrumentation and control system network based on network security management equipment, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. The encrypted transmission module is configured to: encrypt network security alarm signals based on national cryptographic algorithms and send them to the central control processor through the out-of-band management network. The communication process uses an SSL / TLS connection that supports national cryptographic algorithms, uses national cryptographic algorithms to authenticate the identities and verify the integrity of the communicating parties, and uses timestamps and random numbers to prevent replay attacks. The alarm processing module is configured to: process encrypted network security alarm signals based on the central control processor, convert the alarm signals into dry contact relay contact signals, and control the network security alarm indicator in the main control room to sound an alarm; when all network security events that trigger alarm signals are marked as processed, the network security alarm indicator in the main control room will turn off.
[0015] Thirdly, the technical solution of the present invention also provides a network security alarm management device for nuclear power plants, comprising: network security management equipment, a central control processor, and a main control room panel; the network security management equipment is used to monitor security events in the nuclear power plant instrumentation and control system network and generate network security alarm signals; the central control processor is used to receive network security alarm signals through an out-of-band management network and convert them into dry contact relay contact signals; the main control room panel is equipped with a network security alarm indicator light and a hard-wired circuit, responding to the dry contact relay contact signals and illuminating the network security alarm indicator light; Among them, the network security management device communicates with the central control processor through an API interface protected by the national cryptographic algorithm. It transmits network security alarm signals to the central control processor via HTTPS. During the communication process, it uses an SSL / TLS connection that supports the national cryptographic algorithm, uses the national cryptographic algorithm to authenticate the identities and verify the integrity of both parties in the communication, and uses timestamps and random numbers to prevent replay attacks.
[0016] In at least one embodiment, an intrusion detection system and a vulnerability scanning system are also included, which are used to perform intrusion detection and vulnerability detection on the nuclear power plant instrumentation and control system, respectively, and transmit the detection results to the network security management equipment for judgment.
[0017] Fourthly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the nuclear power plant network security alarm management method as described in the first aspect.
[0018] The beneficial effects of the above-described technical solution of the present invention are as follows: 1) The nuclear power plant network security alarm management method of the present invention transmits alarm signals to an independent system through network security management equipment in the out-of-band management network, and then illuminates the alarm indicator light located in the main control room through a hard-wired circuit. This achieves a real-time, independent, and reliable function of sending network security alarms from the nuclear power plant instrumentation and control system to the main control room for indication. Through this scheme, network security-related alarms are fed back to the main control room of the nuclear power plant in real time, providing operators with clear network security alarm indications and ensuring the reliability of network security alarms when the instrumentation and control system suffers a network security attack that renders it untrustworthy.
[0019] 2) The API interface communication between the network security management device and the central control processor of this invention is protected by domestic cryptographic algorithms to realize the authentication of the identities of both parties and the encrypted transmission of data communication.
[0020] 3) The network security alarm indicator light in the main control room of this invention is set on the main control room panel, which occupies very little space and does not require the installation of human-machine interface terminals such as displays, thus having little impact on the existing layout of the nuclear power plant's main control room. Attached Figure Description
[0021] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.
[0022] Figure 1 This is a schematic diagram of a nuclear power plant network security alarm management method disclosed in Embodiment 1 of the present invention; Figure 2This is a system architecture diagram of a nuclear power plant network security alarm management device disclosed in Embodiment 3 of the present invention; Figure 3 This is a schematic diagram of the encrypted communication process between the central control processor and the network security management device disclosed in Embodiment 1 of the present invention. Detailed Implementation
[0023] It should be noted that the following detailed description is illustrative and intended to provide further explanation of the invention. Unless otherwise specified, all technical and scientific terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0024] As described in the background section, the purpose of this invention is to overcome the shortcomings of the prior art and provide a method, system, device, and medium for managing network security alarms in nuclear power plants. This method transmits alarm signals to an independent system via network security management equipment in an out-of-band management network, and then illuminates alarm indicator lights in the main control room through a hard-wired circuit. This achieves a real-time, independent, and reliable function of sending network security alarms from the nuclear power plant's instrumentation and control system to the main control room for indication, thereby improving the reliability of network security alarm management in nuclear power plants.
[0025] Example 1 In a typical embodiment of the present invention, such as Figure 1 As shown in the figure, this embodiment discloses a method for managing network security alarms in nuclear power plants, including the following steps: S100. Based on network security management equipment, monitor security events in the nuclear power plant instrumentation and control system network, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. S200. Encrypts network security alarm signals based on national cryptographic algorithms and sends them to the central control processor through the out-of-band management network. This communication process uses an SSL / TLS connection that supports national cryptographic algorithms. It uses national cryptographic algorithms to authenticate the identities and verify the integrity of both communicating parties, and uses timestamps and random numbers to prevent replay attacks. S300. The central control processor processes encrypted network security alarm signals and converts them into dry contact relay signals to control the network security alarm indicator in the main control room to sound an alarm; when the network security event that triggered the alarm signal is marked as processed, the network security alarm indicator in the main control room turns off.
[0026] The above-mentioned method for managing network security alarms in nuclear power plants will be described in detail below with reference to specific implementation methods.
[0027] S100. Based on network security management equipment, monitor security events in the nuclear power plant instrumentation and control system network, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined.
[0028] To identify, alert on, and analyze various security incidents occurring in the network, nuclear power plants configure network security management equipment in accordance with the requirements of Level 3 of the Cybersecurity Classified Protection System. In this step, the network security management equipment incorporates a log analysis module and a threat database. It analyzes abnormal network security events based on logs and assesses the threat level of the event according to the threat database. It can be configured to generate alarm signals for security events of a specific scope, level, and type. Through real-time monitoring and analysis of various security events in the network, it determines whether to trigger an alarm based on preset rules regarding the type, level, and scope of impact of the security event.
[0029] Specifically, when the network security management device identifies a high-priority network security event or other network security events that may affect the DCS's execution of power plant control, the device can send a network security event alarm signal. For example, when a malicious code attack event targeting the DCS control process is detected, and the event level reaches a preset high priority, the network security management device generates a corresponding network security alarm signal. As a further implementation, the network security management device can configure the types of events that can trigger network security alarms. When there are multiple network security events that can trigger alarms, an "OR" logic is used to generate an alarm signal; as long as at least one network security event meets the triggering conditions, a network security alarm signal is generated.
[0030] S200. Encrypts network security alarm signals based on national cryptographic algorithms and sends them to the central control processor through the out-of-band management network. This communication process uses an SSL / TLS connection that supports national cryptographic algorithms. It uses national cryptographic algorithms to authenticate the identities and verify the integrity of both communicating parties, and uses timestamps and random numbers to prevent replay attacks.
[0031] In this step, the network security equipment in the nuclear power plant's instrumentation and control system is networked separately, called an out-of-band management network, to detect network security events in the instrumentation and control system, such as... Figure 2 As shown, the network security management device communicates with the central control processor via an API (Application Programming Interface) to send network security alarm signals. For example... Figure 3As shown, the API interface communication between the network security management device and the central control processor is protected using domestically developed cryptographic algorithms to achieve authentication of the identities of both communicating parties and encrypted data transmission. Domestically developed cryptographic algorithms (hereinafter referred to as "national cryptographic algorithms") are a series of commercial cryptographic standards issued by the State Cryptography Administration. The national cryptographic algorithms used in this step include: SM2 elliptic curve public key cryptography algorithm, SM3 cryptographic hash algorithm, and SM4 symmetric encryption algorithm.
[0032] Specifically, the network security management equipment uses the SM4 symmetric encryption algorithm to encrypt network security alarm signals. The encrypted data is transmitted via HTTPS and sent using an SSL / TLS connection that supports Chinese national cryptographic algorithms. The central control processor receives the encrypted information and decrypts it. The security control points in this communication process include: 1) using Chinese national cryptographic SSL / TLS to achieve transport layer security; 2) using bidirectional SM2 elliptic curve public key cryptography algorithm certificate authentication to achieve identity authentication between the communicating parties; 3) using the SM4 symmetric encryption algorithm to achieve data encryption; 4) using the SM3 cryptographic hash algorithm to achieve integrity verification; and 5) using timestamp + random number verification to prevent replay attacks.
[0033] S300. The central control processor processes encrypted network security alarm signals and converts them into dry contact relay signals to control the network security alarm indicator in the main control room to sound an alarm; when the network security event that triggered the alarm signal is marked as processed, the network security alarm indicator in the main control room turns off.
[0034] like Figure 2 As shown, the central control processor obtains the encrypted network security event alarm signal through the API interface, decrypts it, and converts the decrypted alarm signal into a dry contact relay contact signal. This dry contact relay contact signal is then sent to the indicator light circuit in the main control room via a long-distance hardwired connection. This controls the dry contact to close, connecting the network security alarm indicator light circuit in the main control room, illuminating the indicator light, and alerting the operator in the main control room to potential network security attacks.
[0035] In this embodiment, the network security alarm indicator light in the main control room is set on the main control room panel, with a space of approximately 150mm × 200mm. It occupies very little space and does not require the installation of human-machine interface terminals such as displays, thus having minimal impact on the existing layout of the nuclear power plant's main control room.
[0036] In this step, the working logic of the network security alarm indicator in the main control room is as follows: when the network security management device generates an alarm signal, the network security alarm indicator in the main control room is lit; after the network security alarm indicator in the main control room is lit, it will be turned off only when all network security events that triggered the alarm signal have been marked as processed.
[0037] In this step, after the network security alarm indicator light in the main control room is turned on, the operator in the main control room notifies the instrument control and maintenance personnel and the network security maintenance personnel to check and handle the alarm. After a network security event that triggered an alarm signal is handled, the event is manually marked as handled on the network security management device. After all network security events that triggered alarm signals are marked as handled, the network security alarm indicator light in the main control room is turned off.
[0038] In this step, the alarm signal is triggered and reset by the network security management device. If there are two high-risk events, Event 1 and Event 2, the maintenance personnel can manually set these events to "processed" in the network security management device. When both events are set to "processed", the trigger signal issued by the network security management device will be reset and transmitted to the central controller through the API interface. Then the central controller will disconnect the relay contacts, thereby turning off the indicator light.
[0039] When the instrumentation and control system (ISC) is subjected to cybersecurity attacks, the ISC itself becomes untrustworthy, and there is a possibility that its signals can be tampered with by attackers. The nuclear power plant cybersecurity alarm management method in this embodiment transmits alarm signals to an independent system through a cybersecurity management device in the out-of-band management network. Then, a hard-wired circuit illuminates the alarm indicator light located in the main control room, thereby achieving a real-time, independent, and reliable function of sending cybersecurity alarms from the nuclear power plant's ISC to the main control room for indication. Through this scheme, cybersecurity-related alarms are fed back to the nuclear power plant's main control room in real time, providing operators with clear cybersecurity alarm instructions.
[0040] Example 2 In a typical embodiment of the present invention, this embodiment discloses a nuclear power plant network security alarm management system, comprising: The safety monitoring module is configured to: monitor safety events in the nuclear power plant's instrumentation and control system network based on network security management equipment, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. The encrypted transmission module is configured to: encrypt network security alarm signals based on national cryptographic algorithms and send them to the central control processor through the out-of-band management network. The communication process uses an SSL / TLS connection that supports national cryptographic algorithms, uses national cryptographic algorithms to authenticate the identities and verify the integrity of the communicating parties, and uses timestamps and random numbers to prevent replay attacks. The alarm processing module is configured to: process encrypted network security alarm signals based on the central control processor, convert the alarm signals into dry contact relay contact signals, and control the network security alarm indicator in the main control room to sound an alarm; when all network security events that trigger alarm signals are marked as processed, the network security alarm indicator in the main control room will turn off.
[0041] Example 3 In a typical embodiment of the present invention, such as Figure 2 As shown, this embodiment provides a nuclear power plant network security alarm management device, including: network security management equipment, a central control processor, and a main control room panel; the network security management equipment is used to monitor security events in the nuclear power plant instrumentation and control system network and generate network security alarm signals; the central control processor is used to receive network security alarm signals through the out-of-band management network and convert them into dry contact relay contact signals; the main control room panel is equipped with network security alarm indicator lights and hard-wired circuits, responding to dry contact relay contact signals and illuminating the network security alarm indicator lights; Among them, the network security management device communicates with the central control processor through an API interface protected by the national cryptographic algorithm. It transmits network security alarm signals to the central control processor via HTTPS. During the communication process, it uses an SSL / TLS connection that supports the national cryptographic algorithm, uses the national cryptographic algorithm to authenticate the identities and verify the integrity of both parties in the communication, and uses timestamps and random numbers to prevent replay attacks.
[0042] Furthermore, the device also includes an intrusion detection system and a vulnerability scanning system, which are used to perform intrusion detection and vulnerability scanning on the nuclear power plant's instrumentation and control system, respectively, and transmit the detection results to the network security management equipment for judgment.
[0043] Example 4 In a typical embodiment of the present invention, this embodiment provides a computer-readable storage medium storing a computer program thereon. When executed by a processor, the program implements the steps of a nuclear power plant network security alarm management method as described in Embodiment 1. These steps include: S100. Based on network security management equipment, monitor security events in the nuclear power plant instrumentation and control system network, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. S200. Encrypts network security alarm signals based on national cryptographic algorithms and sends them to the central control processor through the out-of-band management network. This communication process uses an SSL / TLS connection that supports national cryptographic algorithms. It uses national cryptographic algorithms to authenticate the identities and verify the integrity of both communicating parties, and uses timestamps and random numbers to prevent replay attacks. S300. The central control processor processes encrypted network security alarm signals and converts them into dry contact relay signals to control the network security alarm indicator in the main control room to sound an alarm; when the network security event that triggered the alarm signal is marked as processed, the network security alarm indicator in the main control room turns off.
[0044] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for managing network security alarms in nuclear power plants, characterized in that, include: Based on network security management equipment, monitor security events in the nuclear power plant instrumentation and control system network, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. The network security alarm signal is encrypted based on the national cryptographic algorithm and sent to the central control processor through the out-of-band management network. The communication process uses an SSL / TLS connection that supports the national cryptographic algorithm. The national cryptographic algorithm is used to authenticate the identities and verify the integrity of the communicating parties, and timestamps and random numbers are used to prevent replay attacks. The encrypted network security alarm signal is processed by the central control processor and converted into a dry contact relay signal to control the network security alarm indicator in the main control room to sound an alarm. When the network security event that triggered the alarm signal is marked as processed, the network security alarm indicator in the main control room turns off.
2. The nuclear power plant network security alarm management method as described in claim 1, characterized in that, The preset rules include one or more of the following: type, level, and scope of impact of security events.
3. The nuclear power plant network security alarm management method as described in claim 1, characterized in that, The national cryptographic algorithms include the SM2 elliptic curve public key cryptography algorithm, the SM3 cryptographic hash algorithm, and the SM4 symmetric encryption algorithm.
4. The nuclear power plant network security alarm management method as described in claim 3, characterized in that, The network security alarm signal is encrypted using the SM4 symmetric encryption algorithm. The identities of the two communicating parties are authenticated using the bidirectional SM2 elliptic curve public key cryptography algorithm certificate. The data is encrypted using the SM2 elliptic curve public key cryptography algorithm and the integrity is verified using the SM3 cryptographic hash algorithm.
5. The nuclear power plant network security alarm management method as described in claim 1, characterized in that, The central control processor obtains and decrypts encrypted network security event alarm signals through the API interface, converts the alarm signal into a dry contact relay contact signal, and sends it to the indicator light circuit in the main control room through a long-distance hardwire. This controls the dry contact to close and connect the network security alarm indicator light circuit in the main control room, illuminating the indicator light and alerting the operator in the main control room to a potential network security attack.
6. The nuclear power plant network security alarm management method as described in claim 1, characterized in that, The network security alarm indicator light in the main control room is located on the main control room panel and is lit when the network security management equipment generates an alarm signal; it will only be turned off when all network security events that triggered the alarm signal have been marked as processed.
7. A network security alarm management system for nuclear power plants, characterized in that, include: The safety monitoring module is configured to: monitor safety events in the nuclear power plant's instrumentation and control system network based on network security management equipment, determine whether an alarm signal is triggered according to preset rules, and generate a corresponding network security alarm signal if a trigger is determined. The encrypted transmission module is configured to: encrypt network security alarm signals based on national cryptographic algorithms and send them to the central control processor through the out-of-band management network. The communication process uses an SSL / TLS connection that supports national cryptographic algorithms, uses national cryptographic algorithms to authenticate the identities and verify the integrity of the communicating parties, and uses timestamps and random numbers to prevent replay attacks. The alarm processing module is configured to: process encrypted network security alarm signals based on the central control processor, convert the alarm signals into dry contact relay contact signals, and control the network security alarm indicator in the main control room to sound an alarm; when all network security events that trigger alarm signals are marked as processed, the network security alarm indicator in the main control room will turn off.
8. A network security alarm management device for nuclear power plants, characterized in that, include: The system includes network security management equipment, a central control processor, and a main control room panel. The network security management equipment is used to monitor security events in the nuclear power plant's instrumentation and control system network and generate network security alarm signals. The central control processor is used to receive network security alarm signals through the out-of-band management network and convert them into dry contact relay contact signals. The main control room panel is equipped with network security alarm indicator lights and hard-wired circuits, which respond to dry contact relay contact signals and illuminate the network security alarm indicator lights. Among them, the network security management device communicates with the central control processor through an API interface protected by the national cryptographic algorithm. It transmits network security alarm signals to the central control processor via HTTPS. During the communication process, it uses an SSL / TLS connection that supports the national cryptographic algorithm, uses the national cryptographic algorithm to authenticate the identities and verify the integrity of both parties in the communication, and uses timestamps and random numbers to prevent replay attacks.
9. A nuclear power plant network security alarm management device as described in claim 8, characterized in that, It also includes an intrusion detection system and a vulnerability scanning system, which are used to perform intrusion detection and vulnerability scanning on the instrumentation and control system of nuclear power plants, respectively, and transmit the detection results to the network security management equipment for judgment.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps in the nuclear power plant network security alarm management method as described in any one of claims 1-6.