Network security protection system
By constructing a four-in-one defense-in-depth system in the new energy control center, security zoning, dedicated network isolation, and vertical authentication were achieved. This addressed the weaknesses in the control center's network security system, enhanced its ability to protect against external intrusions and internal threats, and ensured the safe and stable operation of the new energy cluster.
Patent Information
- Application Number
- CN202511057538.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-11-14
AI Technical Summary
The cybersecurity system of the new energy control center suffers from problems such as unclear security zoning, ambiguous network boundaries, weak horizontal isolation, and lack of encryption and authentication in vertical communication. This leads to serious threats such as unauthorized access, lateral penetration, command forgery, and data tampering, affecting the safe and stable operation of the entire new energy cluster.
A four-in-one defense-in-depth system of "security partitioning + dedicated network + horizontal isolation + vertical authentication" is constructed. The security partitioning module subdivides the nodes into independent first, second and third security zones, and adopts dedicated network channels with physical and logical isolation. Combined with hardware firewalls and forward/reverse isolation devices, a vertical encryption authentication mechanism is introduced to ensure the integrity and security of the communication link.
Completely blocking unauthorized cross-regional access and lateral infiltration enhances the ability of the new energy control center to resist external intrusion and internal misoperation, ensuring continuous, safe, and economical operation under unattended or minimally staffed modes.
Smart Images

Figure CN120956458A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system network security technology, and more specifically, to a network security protection system. Background Technology
[0002] With the continuous expansion of the scale of new energy power stations and the increasing demand for centralized monitoring, the centralized control center, as the unified dispatch and control center for multiple new energy power stations, undertakes key tasks such as real-time monitoring of the station's operating status, data collection, fault handling, and dispatch command issuance.
[0003] In the process of unified scheduling and centralized monitoring of multiple distributed power stations, the network security system of the new energy centralized control center often adopts a "flat" architecture: various business systems share the same network plane, lacking in-depth partitioning based on importance or functional differences; production control networks, management information networks, and video surveillance networks are neither physically isolated nor do they form effective isolation zones at the logical level. Boundary protection generally relies on traditional firewalls or simple VLAN policies, allowing lateral traffic to directly traverse different security domains, resulting in a single intrusion spreading laterally to critical control areas. In terms of vertical links, communication between the center and power stations, as well as higher-level dispatching agencies, mostly uses plaintext protocols or channels without two-way authentication, making it difficult to guarantee data integrity and command credibility. These architectural defects make it extremely easy for threats such as unauthorized access, lateral penetration, command forgery, and data tampering to breach single-point protection, thereby affecting the secure and stable operation of the entire new energy cluster.
[0004] In summary, existing centralized control centers suffer from technical problems in network security protection, such as unclear security zoning, ambiguous network boundaries, weak horizontal isolation, and lack of encryption and authentication in vertical communication. There is an urgent need for a systematic and standardized network security protection system to achieve comprehensive and multi-layered security protection for the centralized control center and its subordinate sites. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a network security protection system, which aims to solve at least one of the above-mentioned technical problems.
[0006] In a first aspect, the technical solution of the present invention to solve the above-mentioned technical problems is as follows: a network security protection system, the system comprising a security partitioning module, a network-specific module, a horizontal isolation module, and a vertical authentication module, all connected to a central control center, wherein: The security partitioning module is used to partition the nodes corresponding to the central control center into security zones based on the characteristics of business applications, the importance of functions, and the functional differences of each node, resulting in the first security zone, the second security zone, and the third security zone for each node. Each node corresponds to the station automation system in a station of the central control center. A dedicated network module is used to physically isolate at least two networks used by the central control center and to configure logical isolation on the scheduling data networks corresponding to at least two networks. The lateral isolation module is used to securely isolate the first, second, and third security zones. The vertical authentication module is used to employ vertical encryption authentication between various networks used by the central control center.
[0007] The beneficial effects of this invention are as follows: This application constructs a four-in-one defense-in-depth system of "security partitioning + dedicated network + horizontal isolation + vertical authentication," subdividing the central control center and its subordinate station nodes into independent first, second, and third security zones with differentiated protection strategies. Combined with the deployment of dedicated network channels that integrate physical and logical isolation, it completely blocks unauthorized cross-zone access and horizontal penetration. Simultaneously, dedicated power-specific forward / reverse isolation devices and hardware firewalls are connected in series at the security zone boundaries to form a high-strength horizontal isolation barrier. Furthermore, a vertical encryption authentication mechanism is introduced to implement two-way identity verification and data encryption on all communication links, ensuring that dispatch instructions and monitoring data are complete, reliable, tamper-proof, and replayable between upper and lower level nodes. This comprehensively enhances the ability of the new energy central control center to resist external intrusion, internal misoperation, and malicious instruction injection, ensuring the continuous, safe, and economical operation of the new energy power station cluster in unattended or minimally staffed modes.
[0008] Based on the above technical solution, the present invention can be further improved as follows.
[0009] Furthermore, the aforementioned lateral isolation module is specifically used for: A hardware firewall is used for security isolation between the first and second security zones. Security isolation is achieved between the first security zone, the second security zone, and the third security zone using forward and reverse physical isolation devices.
[0010] The beneficial effect of adopting the above-mentioned further solution is that the lateral isolation module completely cuts off the illegal data flow between security zones through the dual blocking of "firewall + forward and reverse physical isolation devices", thus eliminating the risk of lateral penetration.
[0011] Furthermore, the aforementioned network security protection system also includes an intrusion detection module. The intrusion detection module is located at the boundary between the production control area and the management information area of the central control center, and is used to monitor the network and system operation status of the central control center in real time according to the preset security policy.
[0012] The beneficial effect of adopting the above-mentioned further solution is that the intrusion detection module can monitor and accurately block abnormal traffic in real time at the boundary, significantly improving the control center's ability to detect and respond to covert intrusions and unknown threats.
[0013] Furthermore, the aforementioned network security protection system also includes two operation and maintenance security management modules, which are set up in the first security zone and the third security zone. Each operation and maintenance security management module is used to provide operation and maintenance management and behavior auditing functions for the operation and maintenance objects in the first security zone, the second security zone and the third security zone of the central control center.
[0014] The beneficial effect of adopting the above-mentioned further solutions is that the operation and maintenance security management module deployed in the dual zones incorporates operation and maintenance operations into a "manageable, controllable, and traceable" closed loop through centralized access control and full behavior auditing, completely blocking the risks of internal unauthorized access and misoperation.
[0015] Furthermore, the aforementioned network security protection system also includes a hardware security module, which is used to perform at least one security hardening on the network devices in the central control center. The at least one security hardening includes security hardening of access management, access control, data protection, network function, operation monitoring, and log recording.
[0016] The beneficial effect of adopting the above-mentioned further solutions is that the hardware security module strengthens network devices in an integrated manner from six dimensions: permissions, access, data, network, monitoring and logs, completely eliminating single point configuration defects and enabling the central control center infrastructure to have a solid defense line that is resistant to attacks, tamper-proof and traceable.
[0017] Furthermore, the aforementioned network security protection system also includes a vulnerability scanning module, which is used to perform vulnerability scans on the first security zone, the second security zone, and the third security zone according to preset scanning strategies. The preset scanning strategies include not allowing vulnerable devices to connect to data network switches, not scanning data network address ranges, not scanning data network segments, and not scanning across zones.
[0018] The beneficial effect of adopting the above-mentioned further solutions is that the vulnerability scanning module can accurately identify vulnerabilities without introducing scanning traffic risks through the "offline, partitioned, and cross-domain" strategy, ensuring zero conflict and zero disturbance between vulnerability discovery in each security zone of the central control center and production operation.
[0019] Furthermore, the aforementioned network security protection system also includes a trusted verification module, which is used to configure trusted verification software on the computer monitoring server in the first security zone, the power prediction statistical analysis server, the protection information and fault recording information management server, and the power metering management server in the second security zone, so as to carry out security protection based on the trusted verification software.
[0020] The beneficial effect of adopting the above-mentioned further solution is that the trusted verification module implants a root of trust in the critical business server, verifies the integrity of the system and the trustworthiness of the data in real time, and blocks the threat of malicious tampering and unknown attacks to the core business of centralized control from the source.
[0021] Furthermore, the aforementioned network security protection system also includes two log auditing modules, which are respectively located in the first security zone and the second security zone. Each log auditing module is used to centrally collect and automatically analyze network operation logs, operating system operation logs, business application system operation logs, and security facility operation logs, and monitor network attack behavior based on the analysis results.
[0022] The beneficial effect of adopting the above-mentioned further solution is that the dual-zone log audit module centrally captures and intelligently analyzes logs from multiple sources, discovers abnormal trajectories in seconds, and provides the central control center with all-weather, all-round security situation awareness and attack tracing capabilities.
[0023] Furthermore, the aforementioned network security protection system also includes a network security management platform, which is used to perform unified security management of the monitored devices by aggregating and analyzing the operation logs and event logs pushed by all host servers, network devices, and security devices in the central control center.
[0024] The beneficial effect of adopting the above-mentioned further solutions is that the network security management platform can achieve centralized visibility of all devices in the control center, unified policy distribution and rapid linkage response by uniformly aggregating and intelligently analyzing logs across the entire network, which significantly improves the overall security operation efficiency and response speed.
[0025] Furthermore, the aforementioned network security protection system also includes situational awareness modules set up in the first security zone, the second security zone, and the third security zone. Each situational awareness module is used to monitor and respond to network risk behaviors, including attacks on protected objects, attacks on internal network assets, unauthorized access, intelligent web detection, weak password detection, website exploitation attack detection, abnormal traffic detection, violations of security policies, and botnet behavior.
[0026] The beneficial effect of adopting the above-mentioned further solution is that the situational awareness modules in the three regions can capture and coordinate the handling of various network risks such as attack protection targets, unauthorized access, and botnets in real time, enabling the central control center to have an integrated proactive defense and rapid self-healing capability of "seeing-locating-blocking".
[0027] Additional aspects and advantages of this application will be set forth in part in the description which follows, and will become apparent from the description or may be learned by practice of this application. Attached Figure Description
[0028] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments of the present invention will be briefly introduced below.
[0029] Figure 1 This is a schematic diagram of a network security protection system provided in one embodiment of the present invention. Detailed Implementation
[0030] The principles and features of the present invention are described below. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0031] The technical solution of the present invention and how the technical solution of the present invention solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present invention will now be described with reference to the accompanying drawings.
[0032] This invention provides a possible implementation, such as... Figure 1 The diagram illustrates a network security protection system. This system may include a security partitioning module, a dedicated network module, a horizontal isolation module, and a vertical authentication module, all connected to a central control center. The security partitioning module is used to partition the nodes corresponding to the central control center into security zones based on the characteristics of business applications, the importance of functions, and the functional differences of each node, resulting in the first security zone, the second security zone, and the third security zone for each node. Each node corresponds to the station automation system in a station of the central control center. A dedicated network module is used to physically isolate at least two networks used by the central control center and to configure logical isolation on the scheduling data networks corresponding to at least two networks. The lateral isolation module is used to securely isolate the first, second, and third security zones. The vertical authentication module is used to employ vertical encryption authentication between various networks used by the central control center.
[0033] This application constructs a four-in-one defense-in-depth system of "security partitioning + dedicated network + horizontal isolation + vertical authentication," subdividing the central control center and its subordinate site nodes into independent first, second, and third security zones with differentiated protection strategies. Combined with the deployment of dedicated network channels that integrate physical and logical isolation, this completely blocks unauthorized cross-zone access and lateral penetration. Simultaneously, dedicated power-specific forward / reverse isolation devices and hardware firewalls are connected at the boundaries of the security zones to form a high-strength horizontal isolation barrier. A vertical encryption authentication mechanism is introduced to implement two-way identity verification and data encryption on all communication links, ensuring that dispatch commands and monitoring data are complete, reliable, tamper-proof, and replayable between upper and lower level nodes. This comprehensively enhances the new energy central control center's ability to resist external intrusion, internal misoperation, and malicious command injection, ensuring the continuous, safe, and economical operation of the new energy power plant cluster in unattended or minimally staffed modes.
[0034] The following specific embodiments further illustrate the solution of the present invention. In this embodiment, the provided network security protection system may include a security partitioning module, a dedicated network module, a horizontal isolation module, and a vertical authentication module, all connected to the central control center, wherein: The security partitioning module is used to partition the nodes corresponding to the central control center into security zones based on the characteristics of business applications, the importance of functions, and the functional differences of each node, resulting in the first security zone, the second security zone, and the third security zone for each node. Each node corresponds to the station automation system in a station of the central control center. Each station is used to collect field data from the central control center. A station refers to a local data acquisition and transmission node of each new energy power station in the central control center. The station automation system can be understood as a whole hardware and software system deployed locally at the new energy power station for real-time sensing, control, protection and management of all primary and secondary equipment at the station. This includes, but is not limited to, SCADA subsystem, AGC / AVC substation, power prediction substation, power acquisition substation, protection and fault recording substation, as well as supporting measurement and control devices, communication interfaces, data acquisition servers, etc. Through the coordinated work of internal functional modules, it completes the unified acquisition of the operating status of the equipment at the station, local control, safety protection and data preprocessing, and then sends the required information to the main station of the central control center through the data channel.
[0035] Each site's automation system can be divided into three security zones according to its security level: the first security zone, the second security zone, and the third security zone. Each security zone has its own functional modules and data acquisition servers. The data involved in the functional modules of each security zone during the completion of their respective tasks is processed by the corresponding data acquisition server and then sent to the central control center. This allows the central control center to receive field data sent by multiple site substations and to uniformly monitor and manage the field data sent by each site.
[0036] A task can be implemented by calling the functions of multiple functional modules, or by a single functional module, depending on the specific task settings. A task can also be referred to as an event. A security zone can correspond to at least one functional module and at least one data acquisition server.
[0037] Optionally, each substation has at least one safety zone including a first safety zone, a second safety zone, and a third safety zone. The functional modules corresponding to the first safety zone include a first data acquisition module, a first data processing module, a first data storage module, an operation monitoring module, a control and adjustment module, a comprehensive alarm module, an anti-misoperation interlocking module, and an AGC / AVC monitoring module. The functional modules corresponding to the second safety zone include a second data acquisition module, a second data processing module, a second data storage module, a power prediction and statistical analysis module, a protection information and fault recording information management module, and an electrical energy metering management module. The functional modules corresponding to the third security zone include an information management module, an automated reporting module, a video surveillance module, and a fire monitoring module.
[0038] A dedicated network module is used to physically isolate at least two networks used by the central control center and to configure logical isolation on the scheduling data networks corresponding to at least two networks. Among them, at least two networks include a dedicated power dispatch data network and a power enterprise data network. Thus, the dedicated power dispatch data network and the power enterprise data network are physically isolated, and real-time subnets and non-real-time subnets that are logically isolated from each other are formed on the dispatch data network by technical means, so as to ensure that the vertical interconnection of each security zone at different levels takes place only in the same security zone and avoids vertical cross-connection of security zones.
[0039] The logical isolation is achieved through a two-level encapsulation of "real-time subnet + non-real-time subnet" dual-plane VLAN slicing and MPLS-TE tunnel: First, on the core switch of the scheduling data network, the same physical link is divided into VLAN 10 (real-time SCADA flow) and VLAN 20 (non-real-time management flow), and ACL rules based on 802.1Q tags are enabled to allow only hosts within the same VLAN to communicate with each other and prohibit cross-VLAN communication; then, on the MPLS edge router, independent LSP tunnels are established for the two types of VLANs respectively. The real-time subnet is bound to the EF flow category and bandwidth + low-latency queue is reserved, while the non-real-time subnet is bound to the BE flow category and distinguished by the EXP bit mark. On the router side, the two LSPs are mapped to completely isolated routing tables through VR F instances, so that even if the physical link, switching chip and even MPLS tag stack are shared, the production control area and management information area of the central control center are "physically on the same cable but logically on different networks" on the same scheduling data network.
[0040] The lateral isolation module is used to securely isolate the first, second, and third security zones. The vertical authentication module is used to implement vertical encrypted authentication between various networks used by the central control center. The vertical encrypted authentication methods that can be used include, but are not limited to, authentication, encryption, and access control. These methods ensure secure remote data transmission and vertical boundary security, establishing a login trust chain mechanism. For other communication gateways located at the external network boundary, operating system security hardening should be implemented, and newly implemented systems should support encrypted authentication functionality.
[0041] Among them, the centralized control center refers to the new energy centralized control center. The new energy centralized control center is an integrated intelligent management and control platform with the remote centralized management of new energy power stations in the target area as the core, and unified access to photovoltaic, wind power and other new energy power stations. It provides 24 / 7 centralized monitoring, remote dispatching, fault early warning, data analysis and external display.
[0042] The horizontal isolation module can also strictly prohibit high-security general network services such as E-mail, Web, Telnet, Rlogin, and FTP, as well as database access in B / S or C / S mode, from passing through the dedicated horizontal one-way security isolation device, allowing only one-way secure transmission of pure data.
[0043] Optionally, the aforementioned lateral isolation module is specifically used for: A hardware firewall (two hardware firewalls) is used for logical security isolation between the first security zone and the second security zone; Security isolation is achieved between the first, second, and third security zones using forward and reverse physical isolation devices (e.g., two dedicated power forward physical isolation devices and two dedicated power reverse physical isolation devices).
[0044] Specifically, the functions of each security zone can be found in Table 1.
[0045] Table 1 Among them, security zone I is the first security zone, security zone II is the second security zone, and security zone III is the third security zone.
[0046] Hardware firewalls can control the flow of information into and out of the network according to security policies (allow, deny, monitor), and they themselves have strong resistance to attacks. Firewall systems can restrict unauthorized external access to system resources, as well as unauthorized internal access to external systems, especially unauthorized access from low-security systems to high-security systems.
[0047] During the vertical authentication process, the various networks may include the centralized control data network, the dispatching data network, and the integrated centralized control data network. The centralized control data network between the station and the centralized control center can use a vertical encryption authentication device for two-way authentication and data encryption. The dispatching data network between the centralized control center and the dispatching network can also use a vertical encryption authentication device for two-way authentication and data encryption. The integrated centralized control data network between the station and the centralized control center can use a hardware firewall for access control.
[0048] Optionally, the aforementioned network security protection system also includes an intrusion detection module. The intrusion detection module is located at the boundary between the production control area and the management information area of the central control center, and is used to monitor the network and system operation status of the central control center in real time according to a preset security policy.
[0049] Specifically, one network intrusion detection system is deployed at the boundary between the production control area and the management information area of the centralized control center. Its main function is to monitor the operation of the network and network security protection system in real time according to certain security policies, focusing on detecting boundary traffic of the data network, analyzing illegal activities on the network, and helping network administrators detect and defend against the two major threats to the network. The network intrusion detection system includes all the hardware equipment that makes up the system, such as detection devices, rack-mounted servers, and aggregation switches.
[0050] Furthermore, the aforementioned preset security strategy includes at least: 1. Abnormal instruction detection strategy based on industrial protocol whitelist: The legal instruction set and field range of commonly used protocols for new energy centralized control such as IEC 60870-5-104, IEC61850 MMS, and DNP3 are pre-fixed. The IDS engine parses the application layer payload in real time. If there is an unregistered instruction code, out-of-bounds register address, excessively long ASDU, abnormal function code, or session initiated during an unauthorized period / source IP, a high-priority alarm will be triggered and the horizontal isolation module will be linked to temporarily block the source MAC. 2. Lateral movement discovery strategy based on multi-dimensional traffic baseline: The normal communication matrix between hosts within each security zone is generated through 24 / 7 self-learning (source-destination IP, port, protocol, session frequency, average packet length, uplink and downlink traffic ratio). The baseline is continuously updated using a sliding time window Kalman filter. Once a host on the internal network is detected to have high-concurrency TCP / UDP connections or SMB / RDP probe sequences to ≥5 unfamiliar hosts in Zone 1 or Zone 2 within 30 seconds, it is determined to be a lateral movement behavior, and the network security management platform is immediately reported and ACL is issued to block it.
[0051] Optionally, the aforementioned network security protection system also includes two operation and maintenance security management modules, which are set up in the first security zone and the third security zone. Each operation and maintenance security management module is used to provide operation and maintenance management and behavior auditing functions for the operation and maintenance objects in the first security zone, the second security zone and the third security zone of the central control center.
[0052] Specifically, one bastion host is deployed in Security Zone I and Security Zone III respectively to provide operation and maintenance control and behavior auditing functions for the operation and maintenance objects such as hosts (computer hosts), network devices, and security devices in Security Zone I, Security Zone II, and Security Zone III. The main functions include: access control, identity authentication, protocol proxy, behavior control, and operation and maintenance auditing. Alarm logs, session logs, security operation logs and other logs generated during the operation and maintenance process are uniformly managed by the network security management platform.
[0053] Optionally, the aforementioned network security protection system also includes a hardware security module for performing at least one security hardening on network devices in the central control center. The at least one security hardening includes security hardening of access management, access control, data protection, network function, operation monitoring, and log recording.
[0054] The computer host and other equipment support the installation and operation of power-specific security components (encryption cards, trusted verification modules, etc.) and general security components (encryption authentication Ukeys, fingerprint recognition devices, facial recognition devices, etc.), and support the installation and operation of an independently controllable secure operating system. Key components of the equipment, such as power modules and hard drives, have fault-tolerant, redundant, or hot-swappable security features.
[0055] The central control center is equipped with secure, independent, and controllable host equipment, with redundant configurations of components such as CPU, memory, hard drives, and power supplies. Hard drives support hot-swapping, and data storage adopts RAID technology to store data on different hard drives. The failure of a single hard drive will not affect data reading and writing.
[0056] Before the system security level assessment, professional operating system security hardening software was used to harden the operating systems of the system servers and workstations in Security Zone I and Security Zone II. Unused ports were closed by taking measures such as software shutdown, driver restriction, and physical blocking. When using the KVM system to manage host devices, the KVM system network was prohibited from being shared with the business network.
[0057] Specifically, the control center is equipped with secure, autonomous, and controllable network equipment, with redundant configurations for main control, power supplies, and other components. Key components have redundancy and hot-swappable security features, and security protection equipment is hardened, including but not limited to: (1) Access control: Set user permissions according to the principle of least privilege, disable the default management account; set password complexity requirements; configure automatic logout when the account is idle, number of login attempts, and lock the account after a set value of consecutive failed login attempts.
[0058] The two implementation methods for setting password complexity requirements are as follows: Option 1: Dynamic password strategy based on adjustable entropy value: First, an initial password is generated based on the requirements that the password length is 8-32 characters and must contain at least four types of characters: uppercase, lowercase, numbers, and special symbols. Then, the password information entropy (information entropy of the initial password) is calculated in real time and the threshold is dynamically increased (where the threshold refers to a "pass line" to ensure account security). At the same time, the offline Pwned Passwords library is integrated for comparison to reject leaked weak passwords. Option 2: Multi-factor hierarchical password system: The main password is a randomly generated string of more than 12 characters, with an additional graphic slider + UKey challenge response. The server performs Argon2id hashing and salt value storage on the main password and dynamically adjusts the retry lock threshold and expiration period according to the role risk level.
[0059] The core purpose of real-time password entropy calculation and dynamic threshold raising is to maximize the password space while ensuring user experience, making it impossible for attackers to complete brute-force or dictionary attacks within an acceptable timeframe. By continuously quantifying the actual password strength (password entropy value), the "password threshold" can be adaptively raised based on current threat intelligence, user behavior risks, or policy changes, forcing users with weak passwords to upgrade to higher complexity. This dynamically increases the average cracking cost for attackers, achieving real-time elastic defense where "the more dangerous the password, the stronger it is."
[0060] For Option 1, an adaptive entropy regulator based on user behavior profiles is introduced into the dynamic entropy password strategy. By continuously collecting multi-dimensional features such as user keyboard rhythm, mouse trajectory, login time and geographical offset, a lightweight LSTM model is used to evaluate the account anomaly in real time. The higher the anomaly, the entropy threshold is increased immediately, and a one-time TOTP code is forced to be added to the next login. At the same time, an offline Pwned Passwords library accelerated by edge-side Bloom Filter is deployed, which incrementally synchronizes the latest leaked list every 24 hours to achieve millisecond-level rejection and supports local fuzzy matching of the national cryptographic SM3 hash algorithm, which not only prevents leakage but also eliminates the need to upload the original password.
[0061] For Option 2: Add a "revocable secondary factor" mechanism to the multi-factor hierarchical password system, upgrade the UKey challenge response to a FIDO2 passwordless token, and the token has built-in dual certificates (signature + encryption). During authentication, the identity of the subject is first verified by elliptic curve SM2 signature, and then a one-time session key is issued by the server SM4 encrypted channel. When the risk of brute-force attack or token loss is detected, the administrator can revoke the token with one click on the network security management platform and trigger the emergency password mode. The emergency password is a 32-byte quantum random number generated by Base58 transcoding, which is valid for 30 minutes and only allows login from the internal network bastion host IP range, realizing second-level demotion and seamless recovery in high-risk scenarios.
[0062] (2) Access control: Device management uses username and password authentication; unused ports are blocked at the physical layer; a horizontal unidirectional isolation device implements data flow control based on MAC address, IP address, port, transmission protocol and communication direction; (3) Data Protection: Backup device configuration files; configure encryption algorithms and key lengths that meet preset requirements; adapt and schedule digital authentication certificates for horizontal one-way security isolation devices and vertical encryption authentication devices to realize the signature function of data and ensure the authenticity and integrity of data; reverse isolation devices check E-text format. Among them, the vertical encryption authentication device blocks data streams that do not conform to the security policy; the firewall blocks data streams that do not conform to the security policy, can resist attacks such as IP fragment packets and source IP address spoofing, detect and record port scanning behavior, and does not return information.
[0063] When configuring encryption algorithms and key lengths that meet preset requirements for data protection, the following steps are taken: First, a preset list of algorithms (such as SM2 / SM3 / SM4, AES-256, RSA-3072) is built into and locked in the cryptographic module. Any write operation must pass a compliance check by calling the hardware cryptographic machine. Subsequently, the key is generated by a true random source inside the server cryptographic machine, with a length strictly matching the algorithm specifications (SM4-128bit, SM2-256bit, RSA-3072bit). The private key / symmetric key exists only within the security boundaries of the cryptographic machine and is written to the hardware encryption UKey or PCI after being encrypted in ciphertext form using SM4-CBC or AES-GCM fragmentation. -E cryptographic cards use TLS1.3 / SM9 key encapsulation for end-to-end protection during transmission. Before data is written to disk, a kernel-level transparent encryption driver calls cryptographic machine instructions to perform real-time encryption using the session key via SM4-XTS or AES-256-XTS. The session key is derived from the cryptographic machine's master key and changes every hour. The derivation factors include a timestamp, a random number, and a user identity tag, ensuring that even if the entire disk is copied, it cannot be decrypted. During reading, the driver verifies the integrity tag (SM3-HMAC or AES-GMAC) internally through the cryptographic machine. If the verification fails, access is immediately denied and an alarm is triggered, achieving dual protection of confidentiality and integrity throughout the entire lifecycle of data storage, transmission, and use.
[0064] (4) Network functions: Check the security policy configuration, eliminate the open tunnel of the vertical encryption authentication device, and block the default passage of the firewall.
[0065] (5) Operation monitoring: Collect security events and access the network security management platform.
[0066] (6) Log recording: Record event logs, including equipment operating conditions, configuration change records, user operation behavior, etc. The content includes the date, time, and description of the event.
[0067] Optionally, the aforementioned network security protection system also includes a vulnerability scanning module, which is used to perform vulnerability scanning on the first security zone, the second security zone, and the third security zone according to a preset scanning strategy. The preset scanning strategy includes not connecting vulnerable devices to data network switches, not scanning data network address ranges, not scanning data network segments, and not scanning across zones.
[0068] Specifically, one vulnerability scanning system is deployed in Security Zone I and Security Zone III of the central control center. These systems comprehensively utilize various vulnerability scanning and detection technologies to quickly discover network assets, accurately identify asset attributes, comprehensively scan for security vulnerabilities, clearly characterize security risks, and provide remediation suggestions and preventative measures. This helps network administrators achieve autonomous security control based on a comprehensive vulnerability assessment. The vulnerability scanning equipment must not be connected to the data network switch, must not scan data network address ranges, must disable automatic scanning and use manual scanning, must not scan data network segments, must not scan across zones, and must not operate without a permit.
[0069] Optionally, the aforementioned network security protection system also includes an antivirus and malware module, which is used to deploy one anti-malware system in Security Zone I and Security Zone III of the central control center, respectively. It comprehensively utilizes a variety of computer virus detection technologies to quickly detect network viruses and malware, comprehensively scan for security vulnerabilities, and provide remediation suggestions and preventive measures, thereby achieving unified virus and malware detection and protection for terminals within the network.
[0070] The following approach can be used to rapidly detect network viruses and malicious code, and comprehensively scan for security vulnerabilities by comprehensively utilizing multiple computer virus detection technologies: Option 1: Integrate a dual-engine approach of "static signature + dynamic sandbox" into the antivirus and malware system: The terminal has a built-in national cryptographic SM3 hash signature library and YARA rule cloud library to perform second-level static fingerprint comparison of all executable files, drivers, and macro scripts on the entire disk, and immediately isolate high-risk samples; at the same time, all unknown PE / ELF files are automatically uploaded to the lightweight QEMU-KVM sandbox on the intranet, which simulates the running trajectory of real new energy centralized control software stack within 2 minutes, and captures file, registry, process injection, and network external connection behaviors through API hooks. If there are signs of SCADA protocol detection, lateral scanning, or encrypted external transmission, it is marked as malicious and a network-wide blocking policy is issued, realizing a closed loop of static rapid judgment and dynamic deep verification. Among them, "terminal" refers to all computing entities within Security Zone I and Security Zone III of the New Energy Central Control Center that can directly run executable code and need to undergo virus scanning and protection, including but not limited to: central control front-end machine, SCADA operator station, engineer workstation, remote machine, power prediction server, video surveillance management host, security system host computer, operation and maintenance bastion host client, and all portable operation and maintenance laptops connected to the above areas.
[0071] Option 2: Adopt a collaborative mechanism of "memory protection + AI anomaly detection": Deploy EDR probes at the terminal driver layer, and use hardware virtualization extensions (Intel VT-x / EPT) to perform memory integrity verification on key functions in the kernel and user space, and intercept ROP / JOP, driver tampering, and DLL sideloading in real time; At the same time, process behavior logs (file read and write sequences, network session quintuples, system call vectors) are collected and fed into a lightweight XGBoost model for offline training. The model is updated incrementally every 6 hours, and anomalies that deviate from the historical baseline (such as PowerShell downloading payloads during non-whitelisted periods) are alerted in time and the cloud scanning interface is triggered, achieving millisecond-level interception of zero-day exploits and continuous adaptive detection of unknown malicious code. The "Terminal Driver Layer" refers to the EDR (Endpoint Detection and Response) driver deployed in the kernel mode of the terminal operating system in the new energy control center. It is loaded as a kernel-mode driver, located between the Hardware Abstraction Layer (HAL) and the operating system kernel. It has Ring0 privileges and can directly access the CPU virtualization extension (Intel VT-x, EPT) and the Memory Management Unit (MMU). It can monitor and intercept processes, threads, system calls, memory page tables and hardware events (such as interrupts and DMA) at a low level, and provide the upper-layer EDR agent with real-time behavioral data collection, memory integrity verification and malicious operation blocking capabilities.
[0072] Optionally, the aforementioned network security protection system also includes a trusted verification module, which is used to configure trusted verification software on the computer monitoring server in the first security zone, the power prediction statistical analysis server, the protection information and fault recording information management server, and the power metering management server in the second security zone, so as to perform security protection based on the trusted verification software.
[0073] Specifically, the trusted verification module can strengthen its own security protection by adopting security immunity technology based on trusted verification. Trusted verification software is configured on the computer monitoring server in Security Zone I, the power prediction statistical analysis server, the protection information and fault recording information management server, and the power metering management server in Security Zone II to prevent malicious attacks from damaging, tampering with, or stealing critical programs and data of the centralized control center system. One trusted verification management workstation is configured in Security Zone II to deploy relevant software for the trusted verification management center, enabling centralized management of the trusted verification nodes.
[0074] Optionally, the aforementioned network security protection system also includes two log auditing modules, which are respectively set in the first security zone and the second security zone. Each log auditing module is used to centrally collect and automatically analyze network operation logs, operating system operation logs, business application system operation logs and security facility operation logs, and monitor network attack behavior based on the analysis results.
[0075] Specifically, one log auditing module is deployed in Security Zone I and Security Zone II respectively. This module can centrally collect and automatically analyze network operation logs, operating system operation logs, business application system operation logs, and security facility operation logs, promptly detecting various violations, viruses, and hacker attacks. Furthermore, it protects the integrity of log records by invoking the server's cryptographic machine and employing SM3 or SM2 algorithm digital signature technology.
[0076] Optionally, the aforementioned network security protection system also includes a network security management platform, which is used to perform unified security management of the monitored devices by aggregating and analyzing the operation logs and event logs pushed by all host servers, network devices, and security devices in the central control center.
[0077] Specifically, the network security management platform includes hardware devices such as the Zone I network security monitoring device, the network security management platform server, and workstations. The network security monitoring device is a Type I network security monitoring device, used to collect security data and network security events perceived by the servers, workstations, network devices, and security devices in the local production control area of the new energy centralized control system. This enables local monitoring and management of network security events in the new energy centralized control system, while simultaneously transmitting the network security operation status and suspicious behavior alarm information of the centralized control center to the superior network security management platform.
[0078] Optionally, the aforementioned network security protection system also includes situational awareness modules respectively located in the first, second, and third security zones. Each situational awareness module is used to monitor and respond to network risk behaviors, enabling timely detection and rapid response to potential security threats in the network, reducing the risks posed by attacks, improving security operation levels, and enhancing proactive defense capabilities. These network risk behaviors include attacks on protected targets, attacks on internal network assets, unauthorized access, intelligent web detection, weak password detection, website exploitation attack detection, abnormal traffic detection, violations of security policies, and botnet behavior.
[0079] Optionally, one server cryptographic machine can be configured in each of Security Zone I and Security Zone II to provide data encryption and decryption, key generation, and access control information integrity verification for the application system.
[0080] One signature verification server is configured in each of Security Zone I and Security Zone II to provide digital certificate verification services, and user authentication is performed through digital certificates and signature verification. A total of 30 smart cryptographic keys (Ukeys) are configured for the central control center server and maintenance personnel for digital certificate storage, authentication signature calculation, non-repudiation signature calculation, etc.
[0081] Configure one digital certificate authentication system in security zone I for lifecycle management of various digital certificates.
[0082] The aforementioned equipment, together with access control systems, video surveillance systems, forward (reverse) physical isolation devices, power-specific vertical encryption authentication devices, trusted verification modules, and maintenance bastion hosts, jointly completes the systematic construction of commercial cryptography applications in terms of physical and environmental security, network and communication security, equipment and computing security, and application and data security.
[0083] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this invention.
Claims
1. A network security protection system, characterized in that, This includes a security partitioning module, a dedicated network module, a horizontal isolation module, and a vertical authentication module, all connected to the central control center. The security partitioning module is used to perform security partitioning on each node corresponding to the central control center based on the characteristics of business applications, the importance of functions, and the functional differences of each node, to obtain the first security zone, the second security zone, and the third security zone corresponding to each node. Each node corresponds to the site automation system in a site of the central control center. A dedicated network module is used to physically isolate at least two networks used by the central control center and to configure logical isolation on the scheduling data networks corresponding to the at least two networks. A lateral isolation module is used to securely isolate the first security zone, the second security zone, and the third security zone. The vertical authentication module is used to employ vertical encryption authentication between the various networks used by the central control center.
2. The network security protection system according to claim 1, characterized in that, The lateral isolation module is specifically used for: A hardware firewall logic is used for security isolation between the first security zone and the second security zone; Security isolation is achieved between the first security zone, the second security zone, and the third security zone using forward and reverse physical isolation devices.
3. The network security protection system according to claim 1, characterized in that, The network security protection system also includes an intrusion detection module, which is set at the boundary between the production control area and the management information area of the central control center. The intrusion detection module is used to monitor the network and system operation status of the central control center in real time according to the preset security policy.
4. The network security protection system according to claim 1, characterized in that, The network security protection system also includes two operation and maintenance security management modules, which are set in the first security zone and the third security zone. Each operation and maintenance security management module is used to provide operation and maintenance management and behavior auditing functions for operation and maintenance objects in the first security zone, the second security zone and the third security zone of the central control center.
5. The network security protection system according to claim 1, characterized in that, The network security protection system also includes a hardware security module for performing at least one security hardening on the network devices in the central control center. The at least one security hardening includes security hardening of permission management, access control, data protection, network function, operation monitoring, and log recording.
6. The network security protection system according to claim 1, characterized in that, The network security protection system also includes a vulnerability scanning module, which is used to perform vulnerability scanning on the first security zone, the second security zone and the third security zone respectively according to a preset scanning strategy. The preset scanning strategy includes not allowing vulnerable devices to connect to the data network switch, not scanning data network address ranges, not scanning data network segments and not scanning across zones.
7. The network security protection system according to claim 1, characterized in that, The network security protection system also includes a trusted verification module, which is used to configure trusted verification software on the computer monitoring server in the first security zone, the power prediction statistical analysis server, the protection information and fault recording information management server, and the power metering management server in the second security zone, so as to carry out security protection based on the trusted verification software.
8. The network security protection system according to claim 1, characterized in that, The network security protection system also includes two log auditing modules, which are respectively set in the first security zone and the second security zone. Each log auditing module is used to centrally collect and automatically analyze network operation logs, operating system operation logs, business application system operation logs and security facility operation logs, and monitor network attack behavior based on the analysis results.
9. The network security protection system according to claim 1, characterized in that, The network security protection system also includes a network security management platform, which is used to perform unified security management of the monitored devices by aggregating and analyzing the operation logs and event logs pushed by all host servers, network devices and security devices in the central control center.
10. The network security protection system according to claim 1, characterized in that, The network security protection system also includes situational awareness modules respectively set in the first security zone, the second security zone, and the third security zone. Each situational awareness module is used to monitor and respond to network risk behaviors, including attacks on protected objects, attacks on internal network assets, unauthorized access, intelligent web detection, weak password detection, website exploitation attack detection, abnormal traffic detection, violation of security policies, and botnet behavior.