Remote control method and system for relay protection system
By determining operational priorities and granting temporary task tokens in the relay protection system, the problem of conflicting control among multiple authorized personnel is resolved, enabling secure control of risk management nodes, preventing network attacks, and ensuring the stability of the power system.
Patent Information
- Application Number
- CN202511055288.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-12-23
AI Technical Summary
In the remote control of relay protection systems, when multiple authorized personnel manage the same risk control node, conflicts in access control can easily occur, and the system is vulnerable to network attacks that could lead to functional paralysis, threatening the safe and stable operation of the power system.
By determining the operational priority of risk operators, a temporary task token is granted to the risk operator with the highest operational priority, giving them exclusive control over the risk management node. The temporary task token is generated and verified using blockchain technology, and combined with the defense system, abnormal traffic is monitored and defended against to avoid permission conflicts and network attacks.
This effectively avoids functional errors and network attack risks caused by permission conflicts at risk control nodes, ensuring the safe and stable operation of the power system.
Smart Images

Figure CN121192918A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power systems, and in particular to a remote control method and system for a relay protection system. Background Technology
[0002] During the operation of power systems, relay protection systems bear critical safety responsibilities. In remote control scenarios of relay protection systems, cybersecurity threats constitute a major risk and challenge. Network intrusion, which uses communication networks to illegally operate secondary equipment remotely, is currently the most serious security risk.
[0003] In the remote control of relay protection systems, granting different levels of permissions to personnel at different levels (e.g., system administrators—relay protection professionals—operation staff with decreasing permissions in that order) ensures that authorized personnel can perform safe remote control operations within their scope of responsibility. This also helps prevent unauthorized personnel from misoperating or maliciously manipulating systems, which could lead to the escalation of power system faults or power outages. However, because there is some overlap in permissions among different levels of authorized personnel, multiple authorized personnel controlling the same risk management node can easily lead to conflicts at that node. Furthermore, this makes the system vulnerable to high-intensity cyberattacks, potentially causing it to malfunction and lose its ability to block subsequent intrusions, severely threatening the safe and stable operation of the power system. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a remote control method and system for a relay protection system, which solves the problem of conflict in the risk control nodes of the relay protection system when multiple authorized personnel are in charge of control.
[0005] In a first aspect, this application provides a remote control method for a relay protection system, the relay protection system including multiple risk management nodes, the method comprising: The risk control node that triggers the permission management conflict is marked as the target risk control node, and multiple risk operators corresponding to the target risk control node are identified; Obtain the current risk management task of the target risk management node, and determine the operation priority of multiple risk operators based on the risk management task; Based on the order of the operation priorities, a first target risk operator is determined among the multiple risk operators, and a temporary task token is granted to the first target risk operator for the risk management task; the temporary task token allows the first target risk operator to temporarily monopolize the control permissions of the target risk management node; In response to the remote control command issued by the first target risk operator based on the temporary task token, the target risk management node is remotely controlled.
[0006] In one embodiment, before marking the risk control node that triggers the permission management conflict as the target risk control node, the method further includes: When the same risk control node is granted mutually exclusive permissions simultaneously, it is determined that a permission management conflict has occurred among the risk control nodes; and / or When multiple risk operators issue conflicting remote control commands to the same risk management node, it is determined that the risk management node has a permission management conflict.
[0007] In one embodiment, determining a first target risk operator among a plurality of risk operators based on the order of operation priorities specifically includes: The operation priority of each risk operator is determined based on the static priority of each risk operator, the urgency of each risk operator's task for the risk management task, and the operation timestamp of each risk operator in response to the risk management task. The multiple risk operators are sorted according to the operation priority, and the first target risk operator is determined according to the sorting of the operation priorities.
[0008] In one embodiment, determining the operation priority of each risk operator based on the static priority of each risk operator, the urgency of each risk operator's task in relation to the risk management task, and the timestamp of each risk operator's operation in response to the risk management task specifically includes: The operation time node for each risk operator in response to the risk management task is determined based on the operation timestamp; Calculate the operation time difference for each risk operator by comparing the operation time node with the current time node; The static priority, the task urgency, and the operation time difference are weighted and accumulated based on a preset priority calculation function to determine the operation priority of each risk operator.
[0009] In one embodiment, the expression for the preset priority calculation function is:
[0010] Where P is the operation priority; W is the static priority of each of the risk operators; W max E represents the highest static priority; E is the urgency of the risk management task for each of the aforementioned risk operators. The time difference of operation for each of the aforementioned risk operators; , and These are the weighting coefficients.
[0011] In one embodiment, after granting the first target risk operator a temporary task token for the risk management task, the method further includes: When the target risk control node detects that the first target risk operator is engaging in abnormal traffic, it cancels the temporary task token granted to the first target risk operator. A restart command is sent to the pre-activated defense system to initiate the self-test and initialization procedures of the defense system and restore the defense system to normal working state; after the defense system initiates the self-test and initialization procedures, the permission granting relationship of the corresponding risk operators associated with all the target risk control nodes is cancelled.
[0012] In one embodiment, after sending a restart command to the pre-activated defense system to initiate the self-test and initialization procedures of the defense system, the method further includes: When a full management operation request is received from the second risk operator, an authorization verification request is sent to the second risk operator. Obtain the private key information input by the second risk operator based on the permission verification request, and verify the user identity information associated with the private key information through format check and digital signature; When the user's identity information matches the second risk operator, the second risk operator is granted the highest control authority over the target risk management node.
[0013] In one embodiment, verifying the user identity information associated with the private key information through format checking and digital signature specifically includes: The format of the private key information is checked based on a preset standard format. If the private key information passes the format verification, a digital signature is generated for the current risk management task based on the private key information, and the validity of the digital signature is verified by a preset public key. If the digital signature is valid, the user identity information corresponding to the private key information is queried through the permission database.
[0014] In a second aspect, this application provides a remote control system for a relay protection system, characterized in that it includes a processor and a memory; wherein the memory stores a computer program, the computer program being loaded by the processor and executed as described in any one of the first aspects of a remote control method for a relay protection system.
[0015] Thirdly, this application provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores instructions for being loaded by a processor and executed as described in any one of the first aspects: a remote control method for a relay protection system.
[0016] In the remote control method and system of a relay protection system in this embodiment, the target risk control node that triggers the permission management conflict is authorized and controlled by the operation priority of the risk operator. This ensures that only the risk operator with the highest operation priority is the target risk operator and is granted a temporary task token for the risk control task. This avoids the risk control node responding to remote control commands from multiple risk operators for the risk control task at the same time, thereby avoiding the risk of functional errors and network attacks caused by permission conflicts. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 A flowchart illustrating a remote control method for a relay protection system provided in one embodiment of this application.
[0019] Figure 2 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation
[0020] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some, not all, of the embodiments of the present invention. Based on the description of the present invention, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of the present invention.
[0021] In the description of this invention, unless otherwise explicitly specified and limited, the terms "set," "install," "connect," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can understand the specific meaning of the above terms according to the specific circumstances.
[0022] The terms “upper,” “lower,” “left,” “right,” “front,” “back,” “top,” “bottom,” “inner,” and “outer,” etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship commonly used when the product of the invention is in use. They are only for the convenience of description and simplification, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the present invention.
[0023] The terms “first,” “second,” “third,” etc., are used merely to distinguish elements with similar attributes, not to indicate or imply relative importance or a specific order.
[0024] The terms “include,” “comprising,” or any other variation thereof are intended to cover non-exclusive inclusion, which includes not only the elements listed but also other elements not expressly listed.
[0025] like Figure 1 As shown in the figure, this embodiment provides a remote control method for a relay protection system, the relay protection system including multiple risk management nodes, and the method includes: Step S10: Mark the risk control node that triggers the permission management conflict as the target risk control node, and determine the multiple risk operators corresponding to the target risk control node; Step S20: Obtain the current risk management task of the target risk management node, and determine the operation priority of multiple risk operators based on the risk management task; Step S30: Determine the first target risk operator among the multiple risk operators according to the order of the operation priority, and grant the first target risk operator a temporary task token for the risk management task; the temporary task token allows the first target risk operator to temporarily monopolize the control rights of the target risk management node; Step S40: In response to the remote control instruction issued by the first target risk operator based on the temporary task token, remote control is performed on the target risk management node.
[0026] In a remote control method for a relay protection system in this embodiment, the target risk management node that triggers a conflict of access rights is authorized and controlled by the operation priority of the risk operator. This ensures that only the risk operator with the highest operation priority is the target risk operator and is granted a temporary task token for the risk management task. This avoids the risk management node responding to remote control commands from multiple risk operators for the risk management task at the same time, thereby avoiding the risk of functional errors and network attacks caused by the risk management node due to access rights conflicts.
[0027] Step S10: Mark the risk control node that triggers the permission management conflict as the target risk control node, and determine the multiple risk operators corresponding to the target risk control node.
[0028] The remote operation and maintenance network of the relay protection system consists of a master station, substations, channels, and terminal equipment. Each link may be subject to intrusion security threats, affecting the normal operation of the relay protection system and even causing damage to the power grid.
[0029] The risk control nodes in the remote operation and maintenance network adopt a three-tier architecture of "master station - substation - terminal device" to form a three-dimensional protection system. At the core layer, the master station is interconnected through dual redundant local area networks and configured with security devices such as firewalls, intrusion detection systems, and secure access gateways to achieve centralized monitoring and policy management of all network nodes. At the regional layer, the substations are connected to the master station through the power dispatch data network and deploy vertical encryption authentication devices and horizontal isolation devices to build regional security boundaries and achieve localized risk control. At the terminal layer, the terminal devices are connected to the interval layer devices through process layer networks (such as GOOSE and SV networks) and configured with device-level hardware encryption chips and digital certificate authentication modules to achieve device-level access control and data encryption.
[0030] Risk operators are professionals with a combined knowledge background in power systems and cybersecurity. Each risk management node is equipped with a risk operator, who is responsible for real-time monitoring and emergency response to risk management tasks of a specified category at that risk management node.
[0031] In the risk control table, each risk control node has different categories and levels of risk control tasks associated with corresponding risk operators. Multiple risk operators corresponding to a target risk control node can be identified based on the risk control table. For example, for the tasks of the main station's risk control node, the data integrity verification value task and the access log anomaly rate task are handled by three risk operators: the main operator, the relay protection engineer, and the system architect engineer. The system architect engineer has the highest static priority, followed by the relay protection engineer, and the main operator has the lowest static priority. Typically, the data integrity verification value task and the access log anomaly rate task are completed by the system architect engineer. As another example, for the tasks of the terminal device's risk control node, the physical access log task and the external device access record task are handled by two risk operators: the network security officer and the equipment manufacturer engineer. The network security officer has a higher static priority than the equipment manufacturer engineer, so the network security officer is typically responsible for the physical access log task and the external device access record task.
[0032] Before marking the risk control node that triggers the permission management conflict as the target risk control node, the following is also included: Step S101: When the same risk control node is granted mutually exclusive permissions simultaneously, it is determined that a permission management conflict has occurred among the risk control nodes; and / or Step S102: When multiple risk operators issue conflicting remote control commands to the same risk control node, it is determined that the risk control node has a permission management conflict.
[0033] In step S101, mutually exclusive permissions refer to two or more operational permissions targeting the same risk control node, or a combination of permissions that cannot be effective simultaneously or executed in parallel due to conflicts in functional attributes, execution conditions, or security objectives. Specifically, mutually exclusive permissions typically include three main types: "operation type mutual exclusion," "status mutual exclusion," and "time window mutual exclusion."
[0034] Mutually exclusive operation types refer to situations where risk operators grant conflicting operation permissions, leading to execution conflicts at risk control nodes. For example, risk operator A obtains "batch import permission for main station security policies," which requires locking the policy database; while risk operator B requests "remote reset permission for line protection," which requires opening the policy database to read the latest policies.
[0035] State mutual exclusion refers to the conflict in the operational state of risk control nodes due to different permissions. For example, a terminal device may be granted both "firmware upgrade permission" and "protection function enable permission". Firmware upgrade permission requires the terminal device to disconnect the trip output and enter debug mode, while protection function enable permission does not allow the terminal device to disconnect the trip output, but instead keeps the protection function in real-time operation.
[0036] Time window mutual exclusion refers to the execution of conflicting permission commands within the same time period. For example, a regional operator initiates a "220kV channel bandwidth stress test" command at 19:30 (execution time is usually during the off-load period of 00:00-05:00). At the same time, this channel is carrying cross-site differential protection signal transmission. However, the time policy engine detects that the current time period belongs to the "differential protection high priority transmission window" command and automatically blocks the bandwidth test task.
[0037] In step S102, a conflict in remote control instructions refers to a situation where multiple risk operators issue legitimate operation instructions for the same risk control node, but due to differences in operation objectives, parameter configurations, execution logic, or timing conditions, the instructions cannot be executed simultaneously or cause system anomalies. For example, a risk operator issues an instruction to "allow IP 10.0.0.5 to access the main station management port," while operator B simultaneously issues an instruction to "prohibit IP range 10.0.0.0 / 24 from accessing all ports." This causes a containment relationship between the individual IP permission and the IP range permission in the network access control list, resulting in policy failure and a conflict in remote control instructions.
[0038] Step S20: Obtain the current risk management task of the target risk management node, and determine the operation priority of multiple risk operators based on the risk management task.
[0039] Risk management tasks are categorized into four main types: real-time monitoring tasks, configuration management tasks, emergency response tasks, and audit and verification tasks. Real-time monitoring tasks include subcategories such as real-time node log analysis and abnormal traffic detection; configuration management tasks include subcategories such as security policy distribution and device parameter adjustment; emergency response tasks include subcategories such as node isolation and emergency vulnerability patching; and audit and verification tasks include subcategories such as operation log auditing and policy compliance auditing. Furthermore, risk management tasks without subcategorization are further classified into Level I, Level II, and Level III based on their risk level.
[0040] The first target risk operator is determined from among the multiple risk operators based on the order of operation priorities, specifically including: Step S201: Determine the operation priority of each risk operator based on the static priority of each risk operator, the task urgency of each risk operator for the risk management task, and the operation timestamp of each risk operator in response to the risk management task; Step S202: Sort the multiple risk operators according to the operation priority, and determine the first target risk operator according to the sorting of the operation priorities.
[0041] In step S201, the static priority is a pre-set priority based on the inherent attributes of the risk operator. It does not change frequently due to the characteristics of a single risk management task and is usually determined by attributes such as the risk operator's position and responsibilities, professional qualifications, skill level, and the importance of the department to which they belong. For example, the relay protection system sets up three levels of risk operators: headquarters level, regional level, and field level. Headquarters-level operators are responsible for core tasks such as formulating the security strategy for the entire network and coordinating cross-regional emergency responses, and are assigned a static priority of 5 (the highest level is 5, and the lowest level is 1). Regional-level operators are responsible for the daily operation and maintenance of substation systems within their respective regions and troubleshooting, and have a static priority of 3. Field-level operators mainly perform tasks such as on-site inspection of secondary equipment and simple fault handling, and have a static priority of 1.
[0042] Task urgency reflects the urgency and importance of a specific risk management task for the safe operation of the system, and is usually determined based on indicators such as the type of risk event, the potential loss, and the development trend of the event. For example, when a serious malicious code injection attack is detected on the main station system, which may cause the entire network protection strategy to fail and trigger a large-scale power outage, this type of risk event is a Level I risk event, with a high degree of danger. In this case, the risk operators associated with the risk management node on the main station are Risk Operator A, Risk Operator B, and Risk Operator C, who are respectively the main operator, relay protection engineer, and system architect engineer. Since the malicious code directly attacks the system architecture of the main station system, the task urgency of Risk Operator C (system architect engineer) for this risk is 5 (the highest level is 5, and the lowest level is 1), the task urgency of Risk Operator A (main operator) for this risk is 3, and the task urgency of Risk Operator B (relay protection engineer) for this risk is 1.
[0043] The operation timestamp records the specific time when a risk operator initiates an operation request for a risk management task. For example, when handling an abnormal event in the configuration file of a substation system, two regional operators receive a notification and initiate an operation request at the same time. Risk operator A initiates the request at 9:00:00, and risk operator B initiates it at 9:00:05. Under similar conditions, risk operator A's operation timestamp is earlier.
[0044] Since operation timestamps record specific times, they cannot be directly used for weighting analysis of operation priorities. Therefore, operation timestamps are converted into operation time differences. The operation priority of each risk operator is determined by combining the operation time differences with static priority and task urgency.
[0045] The operation priority of each risk operator is determined based on its static priority, the urgency of its task in relation to the risk management task, and the timestamp of its operation in response to the risk management task. Specifically, this includes: Step S2011: Determine the operation time node of each risk operator in response to the risk management task based on the operation timestamp; Step S2012: Calculate the operation time difference for each risk operator by comparing the operation time node with the current time node; Step S2013: Based on a preset priority calculation function, the static priority, the task urgency, and the operation time difference are weighted and accumulated to determine the operation priority of each risk operator.
[0046] In steps S2011 and S2012, the operation time node refers to the starting time when the risk operator sends a complete and specific operation instruction to the target risk control node after receiving the risk control task. Some risk operators, upon receiving a risk control task, will typically reply with a confirmation command indicating receipt of the task, signifying that they are online and capable of handling it. Although they respond to the risk control task, they do not provide specific operation instructions; therefore, their response time cannot be considered an operation time node. Furthermore, some operations are interconnected, requiring multiple operation instructions to complete the risk control task. In such cases, a risk operator who cannot send all operation instructions cannot be considered a respondent to the risk control task's operation time node. For example, in a firmware upgrade task for a secondary device, the first step is backing up the device configuration file, the second step is downloading the firmware, and the third step is performing the upgrade operation. Risk operator C, after completing the first step (backup), initiates the second step (firmware download) within a reasonable time but does not perform the third step (upgrade). If risk operator D completes the first, second, and third steps of the above tasks sequentially at a later time, then the starting time of risk operator D's response to the risk management task is the operation time node.
[0047] Furthermore, in cybersecurity risk management, the cyberattack situation may change rapidly over time, and new vulnerabilities or threats may emerge at any time. Calculating the time difference with the current time as a reference allows for dynamic adjustment of the assessment of different operators' operations based on the latest system risk status, and timely allocation of resources and permissions to the risk operators who respond most promptly and effectively to the current situation.
[0048] In step S2013, the expression for the preset priority calculation function is:
[0049] Where P is the operation priority; W is the static priority of each of the risk operators; W max E represents the highest static priority (which can be customized as needed); E is the urgency of the risk management task for each of the aforementioned risk operators. The time difference of operation for each of the aforementioned risk operators; , and These are the weighting coefficients.
[0050] Step S30: Determine the first target risk operator among the multiple risk operators according to the order of the operation priority, and grant the first target risk operator a temporary task token for the risk management task; the temporary task token allows the first target risk operator to temporarily monopolize the control rights of the target risk management node.
[0051] To ensure risk management tasks are processed as quickly as possible, the risk operator with the highest priority is typically designated as the primary target risk operator. Understandably, to prevent the highest-ranked risk operator from being unable to process a risk management task in a timely manner due to other tasks or unforeseen circumstances, a response time threshold is set for each risk operator. If the primary target risk operator fails to respond to the risk management task within the response time threshold, the temporary task token granted to the primary target risk operator is revoked, and a temporary task token is then granted to the second-ranked risk operator in sequence. If the second-ranked risk operator also fails to respond to the risk management task in a timely manner, other risk operators can be selected in order of priority.
[0052] Temporary task tokens are implemented using blockchain-based digital certificate technology, employing asymmetric encryption algorithms (such as RSA or the Chinese national cryptographic algorithm SM2) to generate a unique digital signature. Typically, a temporary task token contains a unique identifier for the target risk management node, the identity information of the first target risk operator, a detailed description of the risk management task, the token's validity period (e.g., valid for 30 minutes from the time of grant), and a digital signature.
[0053] Step S40: In response to the remote control instruction issued by the first target risk operator based on the temporary task token, remote control is performed on the target risk management node.
[0054] Once the system identifies the primary target risk operator, the access control module of the target risk management node's master station generates a temporary task token. For example, if risk operator A is identified as the primary target risk operator, the master station system generates a temporary task token containing A's identity information, the target risk management node, and task details, and digitally signs it using the master station's private key. The token is then recorded in the blockchain ledger and sent to risk operator A's terminal via a secure communication channel. When performing a risk management task, risk operator A sends the temporary task token along with remote control instructions to the target risk management node. Upon receiving the instructions and token, the target risk management node first verifies the token's validity through the blockchain network, including whether the token is valid, whether the digital signature is correct, and whether the target node and operator information in the token match. If verification is successful, the node allows operator A's remote control instructions to execute, thus granting temporary exclusive control over the target risk management node.
[0055] When a temporary task token expires or a risk management task is completed, the system automatically reclaims the token. The main station system sends a token reclamation command to the blockchain network, marks the token as invalid, and removes the token information from the risk operator's terminal, ensuring the timely release of control permissions and preventing abuse of permissions.
[0056] Furthermore, to prevent the first target risk operator's terminal from being attacked from outside the domain and from being impersonated as a maintenance personnel of the remote operation and maintenance network within the relay protection system domain, this embodiment monitors the traffic information of the first target risk operator in real time during the period when a temporary task token is granted, and combines this with the defense system to protect the relay protection system.
[0057] After granting the first target risk operator a temporary task token for the risk management task, the process also includes: Step S50: When the target risk control node detects that the first target risk operator is abnormal traffic, it cancels the temporary task token granted to the first target risk operator; Step S60: Send a restart command to the pre-activated defense system to start the self-test and initialization program of the defense system and restore the defense system to normal working state; after the defense system starts the self-test and initialization program, cancel the permission granting relationship of the corresponding risk operators associated with all the target risk control nodes.
[0058] In step S50, the operation of the first target risk operator can be determined as abnormal traffic by means of information such as source legality detection, time window compliance detection, protocol and instruction legality detection, traffic behavior pattern analysis, and device fingerprint and token binding verification.
[0059] Source legitimacy detection verifies whether the network access source of the operating terminal belongs to a trusted network within the relay protection system domain (such as a dedicated maintenance VPN or a fixed IP whitelist). For example, if the temporary task token of the operator of the first target risk authorizes them to access the target risk control node through the company's internal maintenance network (IP range: 192.168.10.0 / 24), if the traffic source IP is detected to be an external public network (such as 47.XX.XX.XX) or an unregistered temporary terminal MAC address, it is determined to be abnormal traffic, triggering the token cancellation mechanism.
[0060] The time window compliance check analyzes whether the operation time conforms to the preset legal time period based on the operation and maintenance time rules of the relay protection system. For example, if the normal operation and maintenance time of the relay protection system is set to 9:00-17:00 on weekdays, and a risky operator initiates a parameter modification request for the protection device at 2:00 AM using a temporary token, and there is no matching emergency fault work order, then the operation traffic during that time period is considered abnormal, which may be an illegal attempt disguised as an external attack.
[0061] The legitimacy of protocols and instructions is verified by detecting and parsing the communication protocols and operational instructions in the traffic to confirm whether they comply with the business rules of the relay protection system. For example, when a risk operator accesses a target node through a temporary token, if the traffic contains instructions that exceed their authority (such as a regular maintenance operator sending a "modify protection settings" instruction when their authority is only "status query"), or uses a non-standard protocol (such as HTTP replacing a dedicated communication protocol), it is determined to be abnormal traffic.
[0062] Traffic behavior pattern analysis uses machine learning to establish a traffic baseline for normal operations and maintenance, and compares the current traffic in real time to see if it deviates from the baseline. For example, during normal operations and maintenance, the traffic for a single parameter query on a single risk control node is approximately 10KB, and the session duration does not exceed 30 seconds. If a risk operator sends extremely large traffic data packets frequently within a short period of time (e.g., continuously for 5 minutes, with a single packet exceeding 1MB), and there are no batch configuration task tickets, it may be due to data theft or malicious code injection through abnormal traffic.
[0063] Device fingerprint and token binding verification establishes an association between a temporary task token and the hardware fingerprint of the operating terminal, preventing the token from being intercepted and used on unauthorized terminals. For example, if the token binding terminal of the first target risk operator is maintenance laptop A (hardware fingerprint: 001), but traffic is detected from another unregistered terminal B (hardware fingerprint: 002), even if the IP and account are correct, it is still considered abnormal traffic because the token-terminal binding relationship has been broken.
[0064] In step S60, once abnormal traffic is detected, the connection between the operating terminal and the target risk control node is immediately cut off, the temporary task token is canceled, and the abnormality log is recorded. A restart command is sent to the defense system to trigger self-check and initialization procedures, clear all associated risk operator permissions, and no longer grant temporary task tokens according to the order of operation priority, so as to prevent the operating terminals of other risk operators who have permission granting relationships with the target risk control node from being attacked from outside the domain and disguised as maintenance personnel within the domain.
[0065] When the defense system initiates a restart command, triggering self-checks and initialization procedures, in order to ensure that the risk control tasks of the target risk control node can still be managed, the highest-level administrator can obtain the highest control authority of the target risk control node through private key verification.
[0066] After sending a restart command to the pre-activated defense system to initiate the self-test and initialization procedures of the defense system, the method further includes: Step S601: When a full management operation request is received from the second risk operator, an authorization verification request is sent to the second risk operator; Step S602: Obtain the private key information input by the second risk operator based on the permission verification request, and verify the user identity information associated with the private key information through format checking and digital signature; Step S603: When the user identity information matches the second risk operator, grant the second risk operator the highest control authority over the target risk management node.
[0067] In step S601, the full management operation request is a privileged operation application initiated by the second risk operator (usually the highest-level administrator) after the defense system restarts in order to restore the management authority of the target risk control node. Its core components usually include: request type, target node ID, operator ID, timestamp, operation purpose and additional information.
[0068] The defense system can respond to the full management operation request of the second risk operator by sending an authorization verification window to the second risk operator's operating device. The second risk operator needs to enter the correct private key information in the corresponding field of the authorization verification window and pass the authorization verification.
[0069] In step S602, the verification of the user identity information associated with the private key information through format checking and digital signature specifically includes: Step S6021: Perform format verification on the private key information based on a preset standard format; Step S6022: If the private key information passes the format verification, a digital signature is generated for the current risk control task based on the private key information, and the validity of the digital signature is verified by a preset public key; Step S6023: If the digital signature is valid, query the user identity information corresponding to the private key information through the permission database.
[0070] In step S6021, the private key information must conform to the X.509v3 certificate standard. This can be achieved by comparing each item in the private key information entered by the second risk operator with a preset standard format. Only when the format verification of the private key information passes can the next step of verifying the validity of the digital signature proceed.
[0071] In steps S6021 and S6023, the defense system generates a unique challenge value (typically including target node ID, timestamp, and task summary) based on the current risk management task. The second risk operator can sign the challenge information using the SM2 private key in the hardware security module. Then, the defense system extracts the public key information from the certificate storing the public key and verifies the validity of the digital signature. After the digital signature is verified, the user identity information corresponding to the private key information can be extracted from the permission database table, and the extracted user identity information can be compared with the pre-stored user identity information of the highest-privilege user (operating terminal ID, user role, permission level, etc.) to prevent the private key from being leaked or altered.
[0072] In step S603, after confirming that the second risk operator is the highest-authority user through the private key, the defense system grants the second risk operator the highest control authority over the target risk management node, enabling it to continue managing the risk management tasks of the target risk management node.
[0073] Understandably, when verifying the format of private key information and the validity of digital signatures, if there is a format mismatch, a mismatch between the private and public keys, or tampering with the challenge information, secondary verification (and tertiary verification) will be triggered. If all three verifications fail, the account of the second risk operator will be locked.
[0074] In summary, the remote control method for the relay protection system in this embodiment, on the one hand, authorizes and controls the target risk management node that triggers permission management conflicts by controlling the operation priority of risk operators. This ensures that only the risk operator with the highest operation priority is the target risk operator and is granted a temporary task token for the risk management task. This avoids the risk management node simultaneously responding to remote control commands from multiple risk operators regarding risk management tasks, thereby preventing the risk management node from malfunctioning due to permission conflicts and being attacked by the network. On the other hand, the relay protection system is protected by a defense system. When abnormal traffic is detected, all associated risk operator permissions are cleared to prevent the target risk management node from being attacked from outside the domain. The permission management of the highest-privilege user is retained through private key verification.
[0075] Based on the same inventive concept as the above embodiments, this embodiment also provides a remote control system for a relay protection system, which further includes a processor and a memory; wherein, the memory stores a computer program, which is used by the processor to load and execute the remote control method of the relay protection system as described above.
[0076] like Figure 2 As shown, based on the same inventive concept as the above embodiments, this embodiment also provides a computer-readable storage medium storing instructions for loading and executing by a processor the remote control method of the relay protection system as described above.
[0077] The embodiments of the mobile terminal and computer-readable storage medium provided in this application include all the technical features of the embodiments of the above control method. The extended and explanatory content of the specification is basically the same as that of the embodiments of the above method, and will not be repeated here.
[0078] This application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to perform the methods described in the various possible implementations above.
[0079] This application also provides a chip, including a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that a device with the chip installed performs the methods described in the various possible implementations above.
[0080] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0081] In this application, the same or similar terms, concepts, technical solutions and / or application scenario descriptions are generally described in detail only when they appear for the first time. When they appear again, they are generally not repeated for the sake of brevity. When understanding the technical solutions and other contents of this application, the same or similar terms, concepts, technical solutions and / or application scenario descriptions that are not described in detail later can be referred to their previous relevant detailed descriptions.
[0082] In this application, the descriptions of the various embodiments have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0083] The technical features of the present application can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of the present application.
[0084] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in the above-mentioned storage medium and includes several instructions to cause a terminal device to execute the methods of each embodiment of this application. The above are only preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made based on the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
[0085] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0086] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the appended claims.
Claims
1. A remote control method for a relay protection system, wherein the relay protection system includes multiple risk control nodes, characterized in that, The method includes: The risk control node that triggers the permission management conflict is marked as the target risk control node, and multiple risk operators corresponding to the target risk control node are identified; Obtain the current risk management task of the target risk management node, and determine the operation priority of multiple risk operators based on the risk management task; Based on the order of the operation priorities, a first target risk operator is determined among the multiple risk operators, and a temporary task token is granted to the first target risk operator for the risk management task; the temporary task token allows the first target risk operator to temporarily monopolize the control permissions of the target risk management node; In response to the remote control command issued by the first target risk operator based on the temporary task token, the target risk management node is remotely controlled.
2. The remote control method for a relay protection system according to claim 1, characterized in that, Before marking the risk control node that triggers the permission management conflict as the target risk control node, the following is also included: When the same risk control node is granted mutually exclusive permissions simultaneously, it is determined that a permission management conflict has occurred among the risk control nodes; and / or When multiple risk operators issue conflicting remote control commands to the same risk management node, it is determined that the risk management node has a permission management conflict.
3. The remote control method for a relay protection system according to claim 1, characterized in that, The first target risk operator is determined from among the multiple risk operators based on the order of operation priorities, specifically including: The operation priority of each risk operator is determined based on the static priority of each risk operator, the urgency of each risk operator's task for the risk management task, and the operation timestamp of each risk operator in response to the risk management task. The multiple risk operators are sorted according to the operation priority, and the first target risk operator is determined according to the sorting of the operation priorities.
4. The remote control method for a relay protection system according to claim 3, characterized in that, The step of determining the operation priority of each risk operator based on the static priority of each risk operator, the urgency of each risk operator's task in relation to the risk management task, and the timestamp of each risk operator's operation in response to the risk management task specifically includes: The operation time node for each risk operator in response to the risk management task is determined based on the operation timestamp; Calculate the operation time difference for each risk operator by comparing the operation time node with the current time node; The static priority, the task urgency, and the operation time difference are weighted and accumulated based on a preset priority calculation function to determine the operation priority of each risk operator.
5. The remote control method for a relay protection system according to claim 4, characterized in that, The default expression for the priority calculation function is: Where P is the operation priority; W is the static priority of each of the risk operators; W max E represents the highest static priority; E is the urgency of the risk management task for each of the aforementioned risk operators. The time difference of operation for each of the aforementioned risk operators; , and These are the weighting coefficients.
6. The remote control method for a relay protection system according to claim 1, characterized in that, After granting the first target risk operator a temporary task token for the risk management task, the process also includes: When the target risk control node detects that the first target risk operator is engaging in abnormal traffic, it cancels the temporary task token granted to the first target risk operator. A restart command is sent to the pre-activated defense system to initiate the self-test and initialization procedures of the defense system and restore the defense system to normal working state; after the defense system initiates the self-test and initialization procedures, the permission granting relationship of the corresponding risk operators associated with all the target risk control nodes is cancelled.
7. The remote control method for a relay protection system according to claim 6, characterized in that, After sending a restart command to the pre-activated defense system to initiate the self-test and initialization procedures of the defense system, the method further includes: When a full management operation request is received from the second risk operator, an authorization verification request is sent to the second risk operator. Obtain the private key information input by the second risk operator based on the permission verification request, and verify the user identity information associated with the private key information through format check and digital signature; When the user's identity information matches the second risk operator, the second risk operator is granted the highest control authority over the target risk management node.
8. The remote control method for a relay protection system according to claim 7, characterized in that, The verification of the user identity information associated with the private key information through format checking and digital signature specifically includes: The format of the private key information is checked based on a preset standard format. If the private key information passes the format verification, a digital signature is generated for the current risk management task based on the private key information, and the validity of the digital signature is verified by a preset public key. If the digital signature is valid, the user identity information corresponding to the private key information is queried through the permission database.
9. A remote control system for a relay protection system, characterized in that, It includes a processor and a memory; wherein the memory stores a computer program for being loaded by the processor and executed as described in any one of claims 1-8, a remote control method for a relay protection system.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions for loading by a processor and executing a remote control method for a relay protection system as described in any one of claims 1-8.
Citation Information
Cited By
Intelligent anti-misoperation control method of power dispatching command digital interaction system
CN121395683A