Relay protection tester security system based on electric power horcrux system
By constructing a safety system for relay protection testers based on the HarmonyOS power system, the problem of difficulty in achieving reliable and controllable test data during the acquisition, verification, and storage processes in existing technologies has been solved. This has enabled full-chain security protection and improved data security and operation and maintenance response efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-04-10
AI Technical Summary
Existing relay protection testers lack deep integration with the inherent security mechanisms of the power HarmonyOS system and the hardware root of trust, making it difficult to ensure the reliability and controllability of test data throughout the entire process of acquisition, verification, and storage. This results in security threats such as device identity forgery, data tampering, and unauthorized access.
A security system for relay protection testers based on the Power HarmonyOS system is constructed, including a data extraction module, a data verification module, a risk assessment module, a scheme generation module, an information push module, and a secure storage module. Through the deep integration of the Power HarmonyOS system's built-in security mechanism and the hardware root of trust, a full-chain security protection is achieved, from device identity authentication and data integrity verification to dynamic risk assessment and intelligent protection response.
It achieves reliable and controllable test data throughout the entire process of collection, verification, and storage, significantly improving the data's anti-tampering, anti-leakage, and anti-attack capabilities, enhancing the system's proactive defense capabilities and operation and maintenance response efficiency, and is suitable for complex and ever-changing power grid testing scenarios.
Smart Images

Figure CN121479848B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of relay protection, in particular to a relay protection tester security system based on a power Hongmeng system. BACKGROUND
[0002] With the rapid development of smart grids, as a key link to ensure the safe and stable operation of power systems, the security, integrity and reliability of test data of relay protection testing are increasingly valued. In the process of data acquisition, transmission and storage, traditional relay protection testers generally face security threats such as device identity forgery, data tampering and unauthorized access, and lack of system-level security protection mechanisms, making it difficult to adapt to complex and variable field test environments. In the prior art, most test devices rely on external encryption modules or independent security protocols for data protection, which has problems such as low system coupling degree, response lag and incomplete trust chain, and cannot realize full-link security and trust from the hardware bottom layer to the application layer.
[0003] In recent years, the power Hongmeng system has gradually been popularized and applied in power terminal devices due to its microkernel architecture, distributed security and trusted execution environment, providing a technical basis for building an endogenous security mechanism. At the same time, the hardware root of trust has been deployed in high-security level devices as a trusted source for device identity authentication and firmware integrity verification. However, how to deeply integrate the built-in security capabilities of the power Hongmeng system with the hardware root of trust of the relay protection tester to realize the trusted and controllable test data in the whole process of acquisition, verification and storage still lacks a systematic solution.
[0004] The above content is only used to assist in understanding the technical solutions of the present application and does not represent the acknowledgement of the above content as prior art. SUMMARY
[0005] The main purpose of the present application is to provide a relay protection tester security system based on a power Hongmeng system, which aims to solve the technical problem that the existing relay protection tester lacks a full-link security protection system that deeply integrates the endogenous security mechanism of the power Hongmeng system with the hardware root of trust, and is difficult to realize the trusted and controllable test data in the whole process of acquisition, verification and storage.
[0006] To achieve the above purpose, the present application provides a relay protection tester security system based on a power Hongmeng system, which comprises a data extraction module, a data verification module, a risk assessment module, a scheme generation module, an information pushing module and a secure storage module.
[0007] The data extraction module is used to determine the power grid test scene and record it as a to-be-tested test scene, extract the power grid basic information data of the to-be-tested test scene from the power Hongmeng system, and extract the device identity authentication information from the hardware root of trust of the relay protection tester.
[0008] a data verification module, configured to collect power grid test data of a test scene to be tested, and determine whether the power grid test data is safe in combination with power grid basic information data and a hardware root-of-trust verification result;
[0009] a risk assessment module, configured to extract safe risk data from the power grid basic information data and the hardware root-of-trust information if the test data is unsafe, and assess a safe risk level of the test data according to the safe risk data and record the safe risk level as a safe risk degree;
[0010] a scheme generation module, configured to extract a risk factor affecting safety of the test data according to the safe risk degree, acquire historical protection data of the risk factor, and generate a protection scheme according to the historical protection data;
[0011] an information pushing module, configured to send the safe risk degree and the corresponding protection scheme to an operation and maintenance terminal to remind an operation and maintenance personnel to protect safety of the power grid test data;
[0012] a secure storage module, configured to encrypt and store the power grid test data if the test data is safe, and continuously monitor and update the power grid test data.
[0013] Optionally, the step of collecting the power grid test data of the test scene to be tested, and determining whether the power grid test data is safe in combination with the power grid basic information data and the hardware root-of-trust verification result specifically comprises:
[0014] extracting standard test data features of the test scene to be tested according to the power grid basic information data and recording the standard test data features as standard data features; and calculating a hash similarity of the power grid test data and the standard data features to obtain a data integrity similarity;
[0015] setting a data integrity standard threshold, determining whether the data integrity similarity reaches the data integrity standard threshold, and if so, verifying an identity of a test device through a hardware root-of-trust verification device of a relay protection test instrument to determine whether the test device is a trusted test device;
[0016] if the test device is the trusted test device, extracting an access control log according to a built-in security mechanism of a power Hongmeng system to detect whether there is an unauthorized access record; if there is no unauthorized access record, detecting whether an encrypted transmission protocol of the power Hongmeng system is used in a transmission process of the test data; and if the encrypted transmission protocol is used, determining that the test data is safe;
[0017] if the data integrity similarity does not reach the data integrity standard threshold, or the identity of the device is not trusted, or there is an unauthorized access record, or the encrypted transmission protocol is not used, determining that the test data is not safe.
[0018] Optionally, if the test data is not secure, the safe risk data is extracted from the power grid basic information data and the hardware root of trust information, the safe risk level of the test data is evaluated according to the safe risk data, and the step is recorded as the safe risk degree.
[0019] According to the safe risk data, the affected test data in the power grid test environment is extracted, and the standard safe state of the affected test data is obtained.
[0020] According to the safe risk data, the affected test data in the power grid test environment is extracted, and the standard safe state of the affected test data is obtained.
[0021] According to the hardware root of trust information, the device trust level of the relay protection tester is extracted.
[0022] The sensitivity of the affected test data in the power grid safety test is evaluated and recorded as the data sensitivity.
[0023] The risk degree of the affected test data is obtained by combining the data security interference degree, the device trust level and the data sensitivity, and is recorded as the basic risk degree; the basic risk degrees of all affected test data are superimposed to obtain the safe risk degree of the power grid test data.
[0024] Optionally, the step of obtaining the interference degree of the environment to the affected test data according to the standard safe state and the real-time safe state and recording it as the data security interference degree is specifically:
[0025] The deviation values of different security parameters in the standard safe state and the real-time safe state are calculated and recorded as the security deviation values, wherein the security parameters include data integrity, transmission confidentiality and access controllability.
[0026] According to the type of the affected test data, the sensitivity coefficient of the data to different security parameters is obtained.
[0027] The parameter interference degree is obtained by multiplying the security deviation value and the corresponding sensitivity coefficient; the parameter interference degrees of all security parameters are superimposed and summed to obtain the data security interference degree of the affected test data.
[0028] Optionally, the step of extracting the device trust level of the relay protection tester according to the hardware root of trust information is specifically:
[0029] It is judged whether the relay protection tester is a trusted device authenticated by the power Hongmeng system, if it is an authenticated trusted device, the authentication level of the hardware root of trust is obtained.
[0030] According to the preset authentication level-device trust level mapping table, the corresponding device trust level is found.
[0031] If the device is not authenticated, it is determined whether the device has a history of security violations;
[0032] If the device has a history of security violations, the initial trust level is reduced according to the number of violations and the severity; if the device does not have a history of security violations, the device trust level is set to the basic trust level.
[0033] Optionally, the step of evaluating the sensitivity of the affected test data in the power grid safety test and recording it as the data sensitivity, specifically:
[0034] It is determined whether the affected test data is classified as confidential test data, and if so, the data confidentiality level is obtained;
[0035] The corresponding basic sensitivity coefficient is obtained according to a preset confidentiality level-sensitivity coefficient lookup table;
[0036] If the test data is not classified as confidential, it is determined whether the data involves key parameters of the power grid, wherein the key parameters of the power grid include relay protection settings, power grid topology, and device operating thresholds;
[0037] If the key parameters are involved, the basic sensitivity coefficient is superimposed with a key parameter weighting value; if the key parameters are not involved, the basic sensitivity coefficient is used as the data sensitivity.
[0038] Optionally, the step of obtaining the risk level of the affected test data by combining the data security interference degree, the device trust level, and the data sensitivity and recording it as the basic risk level, specifically:
[0039] The importance weight of the affected test data in the power grid test process is obtained and recorded as the data importance, wherein the importance of key test items is higher than that of regular test items;
[0040] The attack threat level is obtained according to the threat type detected by the built-in security mechanism of the power Hongmeng system;
[0041] The risk weight coefficients of the data security interference degree, the device trust level, the data sensitivity, the data importance, and the attack threat level are set; the parameters are multiplied by the corresponding weight coefficients and summed to obtain the basic risk level of the affected test data.
[0042] Optionally, the key test items include relay protection action characteristic test data, and the threat types include data tampering, man-in-the-middle attacks, and unauthorized access.
[0043] Optionally, the step of extracting risk factors affecting the security of the test data according to the security risk level, obtaining historical protection data of the risk factors, and generating a protection scheme according to the historical protection data, specifically:
[0044] screening a dominant risk factor from the risk factors according to the security risk degree;
[0045] extracting a historical protection case matched with the dominant risk factor from historical protection data, obtaining protection measures and implementation effect scores in the case, and selecting a protection measure combination with the highest score according to weighted sorting of the implementation effect scores according to the security risk degree level;
[0046] combining a built-in security mechanism of the power Hongmeng system and a hardware root of trust of the relay protection tester, and generating a protection scheme adapted to the current test scene based on the protection measure combination with the highest score.
[0047] Optionally, the dominant risk factor includes device authentication failure, transmission encryption vulnerability and access permission anomaly, the built-in security mechanism includes secure boot, data encryption and access control, and the hardware root of trust includes device identity authentication and firmware integrity verification.
[0048] In the relay protection tester security system based on the power Hongmeng system, by fusing the endogenous security mechanism of the power Hongmeng system and the hardware root of trust of the relay protection tester, a full-chain security protection system from device identity authentication, data integrity verification to dynamic risk assessment and intelligent protection response is constructed; the test data is trusted and controllable in the whole process of collection, verification and storage, and the data tamper-proof, leakage-proof and attack-resistant capabilities are significantly improved; the security risk is accurately quantified by the risk assessment module, the historical protection strategy is intelligently matched by the scheme generation module, the information push module timely alarms, and the active defense capability and operation and maintenance response efficiency of the system are effectively enhanced; at the same time, the system has a clear modular design structure, and has safety, intelligence and scalability, and is suitable for complex and variable power grid test scenes, and provides high-trust security protection for the relay protection test of the power system. BRIEF DESCRIPTION OF DRAWINGS
[0049] Figure 1 is a structural schematic diagram of the first embodiment of the relay protection tester security system based on the power Hongmeng system of the present application;
[0050] Figure 2 is a specific step flowchart of judging whether the power grid test data is safe in the relay protection tester security system based on the power Hongmeng system of the present application.
[0051] The implementation of the object, functional characteristics and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0052] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those ordinarily skilled in the art without creative work fall within the scope of the present application.
[0053] In one embodiment, as shown in Figure 1 A power-horizon-system-based relay protection tester security system is provided, which includes a data extraction module, a data verification module, a risk assessment module, a scheme generation module, an information pushing module and a secure storage module.
[0054] The data extraction module is configured to determine a power grid test scenario and record it as a test scenario to be tested, extract power grid basic information data of the test scenario to be tested from a power-horizon system, and extract device identity authentication information from a hardware root of trust of a relay protection tester.
[0055] The power-horizon system can be a power-specific operating system based on a microkernel architecture, having a distributed security mechanism and a trusted execution environment, and can be used to provide endogenous security capabilities for the relay protection tester, including process isolation, secure communication, permission control and trusted execution environment support. In this embodiment, the power-horizon system can achieve resource minimization exposure through a system-level microkernel, and use distributed identity authentication and end-to-end encryption to ensure cross-device interaction security. Further, the power-horizon system can include one or more of a microkernel security subsystem, a distributed device authentication module, a trusted execution environment (TEE) manager, etc. The hardware root of trust of the relay protection tester can be a tamper-proof security element integrated in the tester hardware, which can be used to provide device unique identity and firmware integrity verification capabilities. For example, the hardware root of trust of the relay protection tester can use a physically unclonable function (PUF) or a secure chip to implement key generation and storage, support secure boot and remote attestation. In one exemplary embodiment, the hardware root of trust of the relay protection tester can include, but is not limited to, a secure boot controller, a device identity key storage unit, a firmware integrity measurement engine, etc.
[0056] The data extraction module can be a logical functional unit for synchronously obtaining test scene context and device identity information from the power cyber system and the hardware root of trust, which can be used to ensure that subsequent security verification is based on real and trusted input sources, and to establish an initial trust anchor for data processing. In one specific embodiment, the data extraction module can provide grid basic information data and device identity authentication information to the data verification module. The grid test scene can be the specific power system operating environment and test task context in which the relay protection tester is located, which can be used as the basis for environmental determination of test data collection and security policy formulation. Further, the grid test scene can include, but is not limited to, a substation local test scene, a power transmission line remote test scene, a distributed energy access test scene, etc. The test scene to be tested can be the grid test scene instance currently selected for performing relay protection testing, which can be used as the target object for data extraction and verification operations. In one exemplary embodiment, the test scene to be tested can be determined by the data extraction module according to the current test task.
[0057] The grid basic information data can be a set of metadata describing the topology, device parameters and operating state of the test scene to be tested, which can be used to verify whether the test data conforms to the physical and logical constraints of the scene. For example, the grid basic information data can be extracted from the device management or SCADA interface of the power cyber system. The device identity authentication information can be a device unique identifier and authentication credential generated and signed by the hardware root of trust, which can be used to verify the authenticity of the tester and prevent device forgery. In one specific embodiment, the device identity authentication information can be read through the secure interface of the hardware root of trust, which usually includes a public key certificate or a device ID signature.
[0058] Determining the grid test scene and recording it as the test scene to be tested can be to select a specific grid test scene as the processing object according to the current test task. Further, determining the grid test scene and recording it as the test scene to be tested can be achieved by manually selecting a test site through a user interface or automatically issuing a test task identifier by a dispatching system, so as to clearly define the context boundary of the security processing. Extracting the grid basic information data of the test scene to be tested from the power cyber system can be to call the data interface of the power cyber system to obtain the topology and parameter information related to the test scene. For example, extracting the grid basic information data of the test scene to be tested from the power cyber system can be achieved by subscribing to SCADA real-time data through the system service bus or querying from a locally cached grid model, so as to provide a scene consistency benchmark for data verification.
[0059] The device identity authentication information is extracted from the hardware root of trust of the relay protection tester, which can be reading the device identity credential stored in the hardware root of trust through a secure channel. In a specific embodiment, the device identity authentication information extracted from the hardware root of trust of the relay protection tester can be achieved by calling the read instruction of the TPM / SE chip or triggering the PUF circuit to generate a dynamic identity identifier, thereby establishing a device identity credibility basis.
[0060] The data verification module is configured to collect power grid test data of a test scene to be tested, and determine whether the test data is safe in combination with power grid basic information data and a hardware root of trust verification result.
[0061] The data verification module can be a functional module for dual verification of the legality of the source and the integrity of the content of the collected power grid test data, and can be used to determine in real time whether the test data is tampered with or comes from an unauthorized device, and to block abnormal data from entering the subsequent process. In an exemplary embodiment, the data verification module can receive the output of the data extraction module, and jointly determine according to the hardware root of trust verification result and the power grid basic information data; if it is not safe, the risk assessment module is triggered. The power grid test data can be the protection performance indicators such as current, voltage, and action time collected by the relay protection tester in the test scene to be tested, and can be used to reflect the actual response characteristics of the measured relay protection device, which is the core object of security protection. Further, the power grid test data can include, but is not limited to, analog sampling data, switch action record, fault recording fragment, etc. The hardware root of trust verification result can be a true / false or credibility score result output after verifying the device identity authentication information, which can be used as one of the bases for the data verification module to determine the legality of the data source. Exemplarily, the hardware root of trust verification result can be obtained by the data verification module calling the verification interface of the hardware root of trust.
[0062] The power grid test data of the test scene to be tested can be obtained by the analog / switch input channel of the tester to obtain the response signal of the relay protection device. In a specific embodiment, the power grid test data of the test scene to be tested can be achieved by synchronously sampling multiple channels of electrical quantities or triggering fault simulation and recording action timing, thereby obtaining the original test result to be verified. The determination of whether the test data is safe in combination with the power grid basic information data and the hardware root of trust verification result can be comparing the test data with the expected range of the scene, and verifying whether the device identity is legal. Further, the determination of whether the test data is safe in combination with the power grid basic information data and the hardware root of trust verification result can be achieved by rule engine matching + digital signature verification or machine learning anomaly detection + remote proof verification, thereby achieving dual credible determination of the source and the content.
[0063] a risk assessment module configured to extract security risk data from the power grid basic information data and the hardware root of trust information, assess a security risk level of the test data according to the security risk data, and record the security risk level as a security risk degree if the test data is unsafe;
[0064] The risk assessment module can be a functional module configured to structurally extract risk features from multi-source security information and quantify a security threat level, and can be configured to convert an abstract security threat into a measurable security risk degree to provide a basis for strategy matching. In an exemplary embodiment, the risk assessment module can rely on the abnormality determination result of the data verification module and output the security risk degree to the scheme generation module. The security risk data can be a set of structured features related to security threats extracted from the power grid basic information data and the hardware root of trust information, and can be used to support quantitative assessment of the security risk level. For example, the security risk data can include, but is not limited to, device identity abnormality features, data deviation from normal range features, communication link abnormality features, etc. The security risk degree can be a quantitative characterization value or a level identifier of the security risk of the test data, and can be used as an input parameter for matching a protection strategy. In a specific embodiment, the security risk degree can be calculated by the risk assessment module based on the security risk data.
[0065] The security risk data extracted from the power grid basic information data and the hardware root of trust information can be a structured analysis of abnormal data and authentication failure reasons to extract risk features. Further, the security risk data extracted from the power grid basic information data and the hardware root of trust information can be achieved by extracting fields based on a preset risk template or identifying associated abnormalities using a graph neural network, so that the security event can be converted into a processable risk element. The security risk level of the test data can be assessed according to the security risk data and recorded as a security risk degree, which can be a weighted or classified calculation of the security risk data to output the risk level. For example, the security risk level of the test data can be assessed according to the security risk data and recorded as a security risk degree by grading based on expert rules or using a trained risk assessment model to predict the level, so that the quantitative expression of the security threat can be achieved.
[0066] The scheme generation module is configured to extract a risk factor affecting the security of the test data according to the security risk degree, obtain historical protection data of the risk factor, and generate a protection scheme according to the historical protection data;
[0067] The scheme generation module can be a functional module that intelligently matches a current risk response strategy based on historical protection experience, and can be used to realize evolution from passive response to active intelligent protection, and improve the adaptability and effectiveness of the protection strategy. In one specific embodiment, the scheme generation module can receive a security risk degree, call historical protection data to generate a protection scheme, and deliver the protection scheme to the information pushing module. The risk factor can be a specific factor or variable that affects the security of the test data, and can be used to locate the root cause of the security problem and guide the strategy generation. Further, the risk factor can include, but is not limited to, device identity failure, data integrity destruction, scene context mismatch, etc. The historical protection data can be effective protection measures and their effect records that the system has adopted for similar risk factors in the past, and can be used to provide a basis for matching the current risk strategy. Illustratively, the historical protection data can be retrieved from a local or cloud security knowledge base. The protection scheme can be a specific set of security response measures matched and generated for the current security risk degree, and can be used to guide the operation and maintenance or the system to automatically execute the protection action. In one exemplary embodiment, the protection scheme can include, but is not limited to, isolating the test channel, resetting the device identity binding, enabling enhanced encryption mode, etc.
[0068] According to the security risk degree, the risk factor affecting the security of the test data can be extracted, which can be to analyze the dominant risk cause corresponding to the security risk degree. Further, according to the security risk degree, the risk factor affecting the security of the test data can be extracted by mapping the risk level to the factor set through a table or by backtracking the key features through a decision tree, so as to locate the specific security weak point. The historical protection data of the risk factor can be retrieved from the security knowledge base, which can be to retrieve the historical response records matching the current risk factor. Illustratively, the historical protection data of the risk factor can be retrieved by retrieving the strategy library based on the vector similarity or indexing the historical cases according to the risk factor label, so as to reuse the effective protection experience. According to the historical protection data, the protection scheme can be matched and generated, which can be to adapt the historical effective strategy to the current context to form an executable scheme. In one specific embodiment, according to the historical protection data, the protection scheme can be matched and generated by generating a new scheme through strategy template parameter filling or generating a composite response through multi-strategy fusion, so as to realize intelligent and adaptive protection response.
[0069] The information pushing module is configured to send the security risk degree and the corresponding protection scheme to an operation and maintenance terminal, and remind an operation and maintenance personnel to protect the power grid test data security.
[0070] The information pushing module can be a communication function unit responsible for transmitting the security risk information and the corresponding protection measures to the operation and maintenance terminal in real time, and can be used to shorten the security event response time and improve the intervention efficiency of the operation and maintenance personnel. In an exemplary embodiment, the information pushing module can receive the output of the scheme generation module and send the alarm and policy information to the operation and maintenance terminal. The operation and maintenance terminal can be a human-computer interaction device for the operation and maintenance personnel to receive alarm information and perform intervention operations, and can be used to realize a human-computer collaborative security response closed loop. Further, the operation and maintenance terminal can include but is not limited to a mobile inspection terminal, a main control room monitoring workstation, a remote operation and maintenance tablet, etc.
[0071] The security risk degree and the corresponding protection scheme are sent to the operation and maintenance terminal, which can be achieved by pushing the alarm and policy information to the designated terminal through a secure communication channel. Exemplarily, the security risk degree and the corresponding protection scheme sent to the operation and maintenance terminal can be achieved by MQTT secure message pushing or power special APN channel short message alarm, so as to realize human-computer collaborative response. The operation and maintenance personnel are reminded to protect the power grid test data security, which can be achieved by displaying or broadcasting the security alarm information on the operation and maintenance terminal. In a specific embodiment, the operation and maintenance personnel are reminded to protect the power grid test data security, which can be achieved by pop-up prompt + sound alarm or automatically generated disposal tasks in the work order system, so as to promote the timely intervention of manual intervention.
[0072] The security storage module is used for encrypting and storing the power grid test data if the test data security, and continuously monitoring and updating the power grid test data.
[0073] The security storage module can be a storage management unit that only performs encrypted storage and continuous monitoring of the state of the power grid test data that passes the verification, and can be used to protect the confidentiality and integrity of the test data in the static storage stage, and prevent leakage and subsequent tampering. In an exemplary embodiment, the security storage module can receive the security determination result of the data verification module and only perform encrypted storage and state monitoring on the legal data. The encrypted storage of the power grid test data can be a copy of the power grid test data protected by an encryption algorithm after security verification, which can be used to ensure the confidentiality and tamper resistance of the data in the storage stage. Exemplarily, the encrypted storage of the power grid test data can be completed by the security storage module calling the encryption service interface of the power Hongmeng system.
[0074] The power grid test data is encrypted and stored, which can be test data that passes the verification being written into a storage medium after an encryption algorithm is applied. In one specific embodiment, the power grid test data is encrypted and stored using a hardware root of trust derived key for AES encryption or calling an encryption service implementation in the power Hongmeng TEE, so that the static data security can be guaranteed. The power grid test data is continuously monitored and updated, which can be the stored test data being regularly checked for integrity and changes being recorded. Further, the power grid test data is continuously monitored and updated by periodically calculating a hash value and comparing it with the original value or enabling file system level integrity monitoring, so that the data can be prevented from being tampered with or damaged after storage.
[0075] Taking substation relay protection setting value verification test as an example, the power Hongmeng system-based relay protection tester security system of the embodiment can be that when a line protection device setting value verification task is carried out in a certain 220 kV substation, the data extraction module determines that the current test scene is a line differential protection test scene, and obtains basic information such as the line CT transformation ratio and protection setting value from the power Hongmeng system, and reads the tester device certificate from the hardware root of trust; after the tester collects the differential current data, the data verification module compares whether the measured value is within the setting value allowable range, and verifies the validity of the device certificate; if it is found that the test data exceeds the threshold and the device certificate is invalid, the risk assessment module extracts two types of risk factors of device identity abnormality and data overrun, and evaluates as a high risk level; the scheme generation module retrieves the strategy of terminating the test and locking the device that was once adopted in a similar situation in the history, and generates the same protection scheme; the information push module immediately sends the high-risk alarm and disposal suggestion to the substation main control room operation and maintenance terminal; if the data verification passes, the secure storage module uses the hardware derived key to encrypt and archive the test oscillogram data, and checks the file integrity every day.
[0076] In one of the embodiments, the steps of collecting power grid test data of a test scene to be tested, and judging whether the test data is safe in combination with power grid basic information data and hardware root of trust verification results are as follows:
[0077] According to the power grid basic information data, a standard test data feature of the test scene to be tested is extracted and recorded as a standard data feature; a hash similarity of the power grid test data and the standard data feature is calculated to obtain a data integrity similarity;
[0078] The standard test data features can be a set of typical patterns or statistical characteristics of the relay protection test data under the to-be-tested test scenario derived based on the power grid basic information data, and can be used as a complete integrity benchmark for judging whether the actual collected data is tampered with or abnormal. In the embodiment, the standard test data features can be generated by a rule engine or a simulation model based on the power grid basic information data (such as protection setting value, CT transformation ratio, system impedance, etc.). Further, the standard test data features can include, but are not limited to, one or more of the following: electrical quantity amplitude distribution characteristics, action timing logic characteristics, fault response phase relationship characteristics, etc. The standard data features can be a short form of the standard test data features, and are the same object as the standard test data features, and can be used for similarity comparison with the measured data. In an exemplary embodiment, the standard data features are obtained in the same way as the standard test data features.
[0079] The hash similarity can be a measure value of the similarity degree of two groups of data in the feature space after being mapped by a hash algorithm, and can be used to quantify the closeness of the power grid test data and the standard data features in structure or content. For example, the hash similarity can be obtained by calculating the Hamming distance or cosine similarity after perceptual hashing or local sensitive hashing is performed on the two groups of data. In a specific embodiment, the hash similarity can include, but is not limited to, one or more of the following: perceptual hash similarity, MinHash similarity, SimHash similarity, etc. The data integrity similarity can be a specific numerical result obtained by calculating the hash similarity between the power grid test data and the standard data features, and can be used as a core basis for judging whether the test data is tampered with. In the embodiment, the data integrity similarity is directly output by the hash similarity calculation operation. The data integrity standard threshold can be a preset similarity critical value for determining whether the data integrity is acceptable, and can be used to provide a decision boundary for integrity verification. Further, the data integrity standard threshold can be set according to the similarity distribution statistics of historical normal test data, or configured by a security policy.
[0080] The standard test data features of the to-be-tested test scene are extracted according to the power grid basic information data and are recorded as standard data features. The standard data features can be generated by analyzing the topology and parameters in the power grid basic information data to generate a theoretical or expected test data mode under the scene. Further, the operation can be implemented by generating a feature template based on the rules of protection setting values and system parameters, or calling a digital twin simulation engine to generate a typical response curve, so as to establish an objective benchmark for data integrity verification. The hash similarity of the power grid test data and the standard data features is calculated to obtain the data integrity similarity. The data integrity similarity can be calculated by hashing the measured data and the standard features respectively. Further, the operation can be implemented by using perceptual hashing to generate fingerprints of waveform data and comparing them, or projecting a multi-dimensional test vector into an LSH space to calculate an approximate similarity, so that automatic identification of data tampering or abnormal collection can be realized.
[0081] A data integrity standard threshold is set, and it is judged whether the data integrity similarity reaches the data integrity standard threshold. If it reaches, the device identity is verified through the hardware root of trust of the relay protection tester, and it is judged whether it is a trusted test device.
[0082] The data integrity standard threshold can be a lower limit of similarity configured for judging whether the data integrity is qualified. Further, the operation can be implemented by dynamically setting based on the 95% quantile of historical normal data, or issuing a fixed threshold by a security policy center, so that a quantitative decision basis for integrity verification can be provided. It is judged whether the data integrity similarity reaches the data integrity standard threshold, which can be a comparison of the size of the data integrity similarity and the preset threshold. Further, the operation can be implemented by a real-time threshold comparison trigger Boolean decision or a fuzzy matching tolerance interval decision, so that the data that may be tampered can be preliminarily screened. The trusted test device can be a relay protection tester that is verified by the hardware root of trust and has not been revoked or tampered, which can be used to ensure that the test data source device is real and legal. In the embodiment, the state of the device corresponding to the true result of the hardware root of trust verification is determined.
[0083] The device identity is verified through the hardware root of trust of the relay protection tester, which can be signature verification or remote attestation of the device identity certificate by calling the hardware root of trust interface. Further, the operation can be implemented by verifying the validity of the device certificate chain or performing a challenge-response protocol to complete device liveness detection, so that the physical authenticity of the test device can be confirmed. It is judged whether it is a trusted test device, which can be a Boolean decision output according to the hardware root of trust verification result. Further, the operation can be implemented by directly mapping the verification result to a trusted / untrusted state, or by comprehensive judgment combined with the device life cycle state, so that the data generated by fake or cloned devices can be filtered.
[0084] If the test device is trusted, the access control log is extracted according to the built-in security mechanism of the power-horizon system, and it is detected whether there is an unauthorized access record; if there is no unauthorized access record, it is detected whether the test data transmission process uses the encrypted transmission protocol of the power-horizon system; if the encrypted transmission protocol is used, it is judged that the test data is safe;
[0085] If the data integrity similarity does not reach the data integrity standard threshold, or the device identity is untrusted, or there is an unauthorized access record, or the encrypted transmission protocol is not used, it is judged that the test data is not safe.
[0086] The access control log can be a collection of information recorded by the power-horizon system about the access subject, time, permission and operation type of the test data related resources, which can be used to trace and detect whether there is an unauthorized or illegal access behavior. In the embodiment, the access control log is automatically recorded by the security audit subsystem of the power-horizon system and stored in the protected log area. For example, the access control log can include one or more of file access log, process call log, network interface call log, etc. The unauthorized access record can be an operation entry in the access control log that is identified as exceeding the current subject's permission range, which can be used as an important negative condition for determining the safety of the test data. In the embodiment, the unauthorized access record is identified by comparing the access subject permission policy with the actual operation behavior.
[0087] Extracting the access control log according to the built-in security mechanism of the power-horizon system can be to call the power-horizon security audit interface to obtain the access record related to the test data. Further, the operation can be achieved by subscribing to the access log stream in the security event bus or batch pulling the protected log file according to the time window, so that the complete audit clues of data access behavior can be obtained. Detecting whether there is an unauthorized access record can be to analyze whether there is a permission violation entry in the access control log. Further, the operation can be achieved by matching the access subject and resource permission based on the RBAC policy, or using an anomaly detection model to identify irregular access patterns, so that potential data leakage or injection risks can be identified.
[0088] The encrypted transmission protocol can be a secure communication protocol built in the power horcrux system to protect the confidentiality and integrity of data during network transmission, which can be used to prevent test data from being illegally obtained, tampered with or replayed during transmission. In this embodiment, the encrypted transmission protocol is based on the SM4 algorithm or TLS1.3+, and is integrated into the distributed soft bus security layer of the power horcrux. For example, the encrypted transmission protocol can include one or more of a point-to-point encryption channel based on SM4, a secure multicast protocol based on DTLS, a RPC security protocol based on certificate two-way authentication, etc. Detecting whether the test data transmission process uses the encrypted transmission protocol of the power horcrux system can be checking whether the system-level encryption channel is enabled for the data transmission session. Further, this operation can be achieved by parsing the network packet header to identify the protocol identifier, or verifying whether the session key is derived by the power horcrux security service, so as to ensure that the transmission link is safe and compliant.
[0089] Judging the safety of test data can be outputting a safe determination when all four checks of data integrity, device identity, access compliance, and transmission encryption pass. Further, this operation can be achieved by a four-way conditional logical AND gate determination, or a threshold determination after stage-by-stage confidence accumulation, so as to confirm the full-link trustworthiness of the test data. Judging the test data as unsafe can be outputting an unsafe determination when any check fails. Further, this operation can be achieved by short-circuit logic, where the first item fails, the determination is unsafe, or all failed items are recorded for risk factor extraction, so as to trigger the subsequent risk assessment process.
[0090] Taking transmission line distance protection testing as an example, the power horcrux system-based relay protection tester security system of the present embodiment can extract the line impedance, CT / PT transformation ratio and protection setting value from the power grid basic information data when testing the distance II segment protection of a certain 500kV line, and generate standard test data features, such as the fault current phase angle should be between-85° and-95°. After the tester collects the actual fault recording, the hash similarity between it and the standard features is calculated to be 0.92, which is higher than the preset threshold 0.85. Then, the hardware root of trust verifies that the device certificate is valid, confirming that it is a trusted test device. Next, the access control log is extracted from the power horcrux system, and no unauthorized process is found to read the test cache. Then, it is detected that the encrypted transmission protocol based on SM4 is used during data uploading. All four checks pass, and the test data is determined to be safe, entering the encrypted storage process. If any of the steps fails, such as a similarity of only 0.7, an expired device certificate, a log showing unauthorized access by a debugging tool, or the use of plain HTTP transmission, the system immediately determines that it is unsafe and starts the risk assessment.
[0091] In one of the embodiments, if the test data is not secure, the security risk data is extracted from the power grid basic information data and the hardware root of trust information, the security risk level of the test data is evaluated according to the security risk data, and the step of recording the security risk level is recorded as the security risk degree, which is specifically:
[0092] According to the security risk data, the affected test data in the power grid test environment is extracted, and the standard security state of the affected test data is obtained;
[0093] Among them, the affected test data can be a subset of power grid test data identified as being affected by security threats after security verification fails, and can be used as a specific object for risk assessment, avoiding indiscriminate assessment of all test data. In one exemplary embodiment, the affected test data can locate the corresponding test data entry through the abnormal field or timestamp associated in the security risk data. Further, the affected test data can include, but is not limited to, one or more of abnormal amplitude electrical quantity data, recorded wave data during identity verification failure, switch quantity action record without encrypted transmission, etc. The standard security state can be the ideal operating state of the affected test data under the conditions of no interference, device trust, and compliant access, which can be used as a benchmark to measure the degree of deviation of actual data. In one specific embodiment, the standard security state can be generated through a power system simulation model or protection logic rules, which is related to the standard test data characteristics but focuses on security properties. For example, the standard security state can include a theoretical fault response phase angle range, an expected action timing window, a compliant access permission set, etc.
[0094] According to the power grid test data, the real-time security state is extracted, and the interference degree of the environment to the affected test data is obtained according to the standard security state and the real-time security state, and is recorded as the data security interference degree;
[0095] Among them, the real-time security state can be the current security-related state feature extracted from the actually collected power grid test data, which can be used to reflect the security performance of the test data in the real environment. In this embodiment, the real-time security state can be obtained by analyzing the security context field (such as timestamp, source identification, integrity verification flag, etc.) in the power grid test data. Further, the real-time security state can include measured phase angle deviation value, device identity verification result flag, transmission protocol type identification, etc. The data security interference degree can be a difference degree quantization value between the standard security state and the real-time security state, representing the interference intensity of the external environment to the test data, which can be used to measure the degree of influence of the test data affected by tampering, forgery or environmental anomalies. In one specific embodiment, the data security interference degree can be calculated by state vector distance, rule violation count or probability distribution KL divergence, etc. For example, the data security interference degree can include state deviation index, rule violation degree, distribution offset degree, etc.
[0096] The operation of extracting the real-time security state according to the power grid test data can be to parse the security-related attributes (such as source, integrity flag, transmission mode, etc.) from the actually collected power grid test data. Further, the operation can be to realize the real-time security context by parsing the security label in the test data metadata or combining the log context, so that the security performance characteristics in the real environment can be obtained. The operation of obtaining the interference degree of the environment on the affected test data according to the standard security state and the real-time security state and recording the data security interference degree can be to calculate the difference measure between the standard and the real-time security state. Further, the operation can be to realize by calculating the Euclidean distance of the multi-dimensional state vector or the number of statistical rule violations and normalization, so that the influence of external interference on the data credibility can be quantified.
[0097] Extracting the device trust level of the relay protection tester according to the hardware trust root information;
[0098] The device trust level of the relay protection tester can be a hierarchical representation of the overall trust level of the device evaluated based on the hardware trust root information, and can be used to reflect the contribution weight of the anti-counterfeiting and anti-tampering ability of the device itself to the test data credibility. In this embodiment, the device trust level of the relay protection tester can be comprehensively evaluated according to the integrity verification result of the hardware trust root, the certificate validity period, whether it is listed in the revocation list, etc. For example, the device trust level of the relay protection tester can include high trust level (complete start-up chain + valid certificate), medium trust level (partially passed verification), low trust level (verification failed or unknown device), etc.
[0099] The operation of extracting the device trust level of the relay protection tester according to the hardware trust root information can be to analyze the verification result, certificate status and integrity measure value of the hardware trust root, and map it to the trust level. Further, the operation can be realized by mapping based on the preset rules (such as verification passed = high trust) or using a trust evaluation model to output a continuous trust score, so that the physical trustworthiness of the device can be converted into a numerical value that can be used for risk calculation.
[0100] Evaluating the sensitivity degree of the affected test data in the power grid security test and recording the data sensitivity degree;
[0101] The data sensitivity degree can be a criticality degree of the affected test data in the relay protection logic for the power grid safety decision, and can be used to reflect the system-level hazard size that can be caused by tampering or leakage of the data. In an exemplary embodiment, the data sensitivity degree can be semantically evaluated according to the power business rules (such as whether it involves primary protection or whether it triggers the circuit breaker trip). Further, the data sensitivity degree can include primary protection action criterion data, backup protection setting value related data, non-critical monitoring auxiliary data, and the like. The operation of evaluating the sensitivity degree of the affected test data in the power grid safety test and recording as the data sensitivity degree can be to judge the criticality of the data to the system safety according to the power protection business logic. Further, the operation can be achieved by table lookup matching the data type and the sensitivity level or based on the protection logic graph analysis data influence path, so that the business semantics can be introduced to improve the relevance of risk assessment.
[0102] The risk degree of the affected test data is obtained in combination of the data security interference degree, the device trust level and the data sensitivity degree and recorded as the basic risk degree;
[0103] The basic risk degree can be a local risk quantitative value calculated by fusing the data security interference degree, the device trust level and the data sensitivity degree for a single affected test data, and can be used as a basic unit for global risk aggregation. In the present embodiment, the basic risk degree can fuse the three-dimensional indicators through a weighted function (such as product, weighted sum or fuzzy reasoning). Exemplarily, the basic risk degree can include a high basic risk degree (high interference + low trust + high sensitivity), a medium basic risk degree (any one of the medium items), a low basic risk degree (all three items are low), and the like. The operation of obtaining the risk degree of the affected test data in combination of the data security interference degree, the device trust level and the data sensitivity degree and recording as the basic risk degree can be to calculate the local risk value through a fusion function of the three-dimensional indicators. Further, the operation can fuse the three inputs through a weighted product (interference degree x (1-trust level) x sensitivity degree) or a fuzzy reasoning system, so that the multi-factor coordinated risk characterization can be achieved.
[0104] The basic risk degrees of all the affected test data are superimposed to obtain the safety risk degree of the power grid test data.
[0105] The safety risk degree of the power grid test data can be the overall risk quantitative result after superimposition of the basic risk degrees of all the affected test data, and can be used as the input of the scheme generation module for matching the protection strategy. In a specific embodiment, the safety risk degree of the power grid test data can perform aggregation operations such as summation, weighted average or maximum value selection on all the basic risk degrees. Exemplarily, the safety risk degree of the power grid test data can include the cumulative risk total, the weighted aggregated risk index, the peak basic risk degree, and the like.
[0106] The operation of superimposing all the basic risk degrees of the affected test data to obtain the security risk degree of the power grid test data can be to perform an aggregation operation on all the basic risk degrees. Further, the operation can be implemented by linearly summing all the basic risk degrees or taking the maximum basic risk degree as a representative value, so as to generate a globally unified risk output to support policy matching.
[0107] Taking the data transmission exception encountered in the main transformer differential protection test as an example, the power Hongmeng system-based relay protection tester security system of the embodiment can be that in a certain 220 kV main transformer test, the data verification module finds that part of the differential current data is not transmitted using an encrypted transmission protocol, and determines that it is unsafe. The risk assessment module extracts the affected test data as the high-voltage side A-phase current sampling value from the security risk data. The system generates its standard security state according to the power grid basic information (CT transformation ratio, rated current): the amplitude should be in the range of 0.95-1.05 p.u., the phase angle is -30°±2°, and it must come from a trusted device and be transmitted in an encrypted manner. The real-time security state display: the amplitude is normal, but the phase angle is -45°, and the source device has a valid identity but the transmission is not encrypted. The data security interference degree is calculated to be 0.6; the device trust level is medium (downgraded due to transmission violation); the data belongs to the core criterion of the main protection, and the sensitivity is high. The three are fused to obtain a basic risk degree of 0.72. Since only this item is affected, the global security risk degree is 0.72, and the trigger scheme generation module matches the high-risk-main protection data exception strategy.
[0108] In one of the embodiments, the step of obtaining the interference degree of the environment on the affected test data according to the standard security state and the real-time security state and recording it as the data security interference degree is specifically:
[0109] The deviation values of different security parameters in the standard security state and the real-time security state are calculated and recorded as security deviation values, wherein the security parameters include data integrity, transmission confidentiality, and access controllability;
[0110] The sensitivity coefficients of the data on different security parameters are obtained according to the type of the affected test data;
[0111] The parameter interference degrees are obtained by multiplying the security deviation values and the corresponding sensitivity coefficients; the data security interference degree of the affected test data is obtained by superimposing and summing all the parameter interference degrees of the security parameters.
[0112] The security parameter can be a quantifiable index used to represent the compliance state of the test data in a specific security dimension, and can be used as a basic dimension to measure the difference between the standard security state and the real-time security state. In this embodiment, the security parameter can include, but is not limited to, one or more of data integrity, transmission confidentiality, and access controllability. The data integrity can be an attribute that the test data is not tampered with or damaged during collection, storage, or transmission, and can be used to reflect the anti-tampering capability, which is one of the security parameters. Further, the data integrity can be verified by a hash check, a digital signature, or an integrity measurement mechanism in a trusted execution environment (TEE). The transmission confidentiality can be the ability of the test data to prevent eavesdropping or leakage during communication, and can be used to reflect the anti-leakage capability, which is one of the security parameters. In an exemplary embodiment, the transmission confidentiality is determined by whether an encryption transmission protocol of a special power operating system is used and the validity of a key. The access controllability can be an attribute that the reading, modifying, or deleting operation of the test data is strictly limited to authorized subjects, and can be used to reflect the anti-unauthorized access capability, which is one of the security parameters. For example, the access controllability is determined based on an access control policy and an audit log of a special power operating system.
[0113] The security deviation value can be the numerical difference between the standard security state and the real-time security state in a certain security parameter, and can be used to quantify the degree of abnormality in this security dimension. In a specific embodiment, the security deviation value is calculated by state comparison, such as converting a Boolean difference to 0 / 1, or taking an absolute difference for a continuous value. Further, the security deviation value can include, but is not limited to, an integrity deviation value (e.g., hash mismatch = 1), a confidentiality deviation value (e.g., plaintext transmission = 1), and a controllability deviation value (e.g., existence of unauthorized access = 1). The type of affected test data can be a functional classification of the affected test data according to the relay protection business semantics, and can be used to determine the sensitivity coefficient of each security parameter. In this embodiment, the type of affected test data can include, but is not limited to, one or more of a fixed value check type data, a fault recording type data, and a GOOSE / SV communication message type data.
[0114] The sensitivity coefficient can be a weight factor reflecting the importance of a specific type of test data to a certain security parameter, and can be used to implement business semantics driven risk weighting. Further, the sensitivity coefficient is derived from a preset rule base or business knowledge graph, and is determined together with the data type and the security parameter. For example, the sensitivity coefficient can include, but is not limited to, a high sensitivity coefficient (such as primary protection recording for integrity), a medium sensitivity coefficient (such as backup setting for confidentiality), a low sensitivity coefficient (such as auxiliary monitoring for access controllability), and the like. The parameter interference degree can be the product of the deviation value of a certain security parameter and its corresponding sensitivity coefficient, and can be used to reflect the actual contribution of the security dimension to the overall interference degree. In one specific embodiment, the parameter interference degree is obtained by calculating the security deviation value x the sensitivity coefficient item by item. Further, the parameter interference degree can include, but is not limited to, an integrity interference degree, a confidentiality interference degree, a controllability interference degree, and the like. The data security interference degree can be the sum of the parameter interference degrees of all security parameters, representing the comprehensive interference intensity of the environment on a single affected test data, and can be used as a key input for the calculation of the basic risk degree. In this embodiment, the data security interference degree is obtained by linearly superimposing and summing the parameter interference degrees.
[0115] The deviation values of different security parameters in the standard security state and the real-time security state are calculated and recorded as security deviation values, which can be for data integrity, transmission confidentiality, and access controllability. The deviation values are compared with the standard and real-time states, and the deviation degrees are output. Further, this operation can be implemented by a Boolean parameter: the deviation value is 1 if the deviation is inconsistent, otherwise it is 0; or a continuous parameter: the absolute difference value is taken, so that the multi-dimensional security state difference can be structured into a calculable numerical value. The sensitivity coefficients of different security parameters for the affected test data are obtained according to the type of the data, which can be querying a preset mapping table or a rule engine, and outputting the sensitivity coefficients of the three security parameters according to the data type. For example, this operation can be implemented by loading a type-parameter sensitivity matrix from a configuration file or calling a power business knowledge graph to infer the sensitivity weight, so that business semantics can be introduced to make the risk assessment meet the actual protection logic requirements.
[0116] The parameter interference degree is obtained by multiplying the security deviation value by the corresponding sensitivity coefficient, which can be for each security parameter. In one exemplary embodiment, this operation can be implemented by direct scalar multiplication or introducing a nonlinear function (such as exponential weighting) to enhance the influence of high sensitivity items, so that the abnormal influence of key security dimensions can be amplified and non-key dimension noise can be suppressed. The data security interference degree of the affected test data is obtained by superimposing and summing the parameter interference degrees of all security parameters, which can be the sum of the integrity, confidentiality, and controllability parameter interference degrees. Further, this operation can be implemented by simple arithmetic summation or weighted summation (if more parameters are extended in the future), so that a single comprehensive interference index can be generated to support subsequent risk fusion calculation.
[0117] Taking the unauthorized access encountered in the GOOSE trip command test as an example, the security system of the relay protection tester based on the power horcrux system in this embodiment can be: when testing the GOOSE trip function of the main transformer protection in a certain intelligent substation, the data verification module finds that there is an unauthorized process reading the test cache. The type of affected test data is GOOSE communication message data. The system defines the sensitivity coefficients of the three types of security parameters as follows: data integrity 0.8, transmission confidentiality 0.6, and access controllability 0.95 (because GOOSE involves tripping, access control is extremely critical). The standard security state requirements are: integrity check passed (value 1), encrypted transmission (value 1), and no unauthorized access (value 1); the real-time state is: integrity passed (1), encrypted transmission (1), but there is unauthorized access (0). The calculated security deviation value is: integrity 0, confidentiality 0, and controllability 1. The parameter interference degrees are: 0x0.8=0, 0x0.6=0, and 1x0.95=0.95. The data security interference degree = 0+0+0.95=0.95, which is significantly higher than other scenarios, triggering a high-risk response strategy.
[0118] In one of the embodiments, the step of extracting the device trust level of the relay protection tester according to the hardware trust root information is specifically:
[0119] determining whether the relay protection tester is a trusted device authenticated by the power horcrux system.
[0120] The trusted device authenticated by the power horcrux system can be a relay protection tester that has passed the verification of the power horcrux system device access mechanism and is included in the trusted device directory, which can be used as a prerequisite for determining a high trust level device and enjoys trust assignment based on the hardware authentication level. In this embodiment, the trusted device authenticated by the power horcrux system can complete identity binding and certificate issuance by the distributed device authentication service of the power horcrux system. Determining whether the relay protection tester is a trusted device authenticated by the power horcrux system can be querying the trusted device registry of the power horcrux system or verifying the validity of the device certificate chain. Further, this determination can be achieved by verifying whether the device digital certificate is issued by the power horcrux CA or checking whether the device ID exists in the local trusted device white list, so as to distinguish whether the device has an authoritative authentication identity and determine the subsequent trust evaluation path.
[0121] If it is an authenticated trusted device, the authentication level of the hardware trust root is obtained.
[0122] The authentication level of the hardware root of trust can be a security level identifier that the hardware root of trust is endowed with according to its security capability (such as chip type, key protection strength, remote attestation support), which can be used to reflect the strength of the underlying security capability of the device and serve as an input basis for trust level mapping. In an exemplary embodiment, the authentication level of the hardware root of trust can be written and signed by the hardware root of trust or the power hub system at the time of device registration. For example, the authentication level of the hardware root of trust can include one or more of a high security level (supporting PUF + secure boot + remote attestation), a medium security level (having SE but no remote attestation), a basic security level (only software simulation of the root of trust), and the like. Obtaining the authentication level of the hardware root of trust can be reading the authentication level field from the secure storage area of the hardware root of trust or the power hub device metadata. Further, this operation can be achieved by calling the attribute reading instruction of the TPM / SE chip or parsing the authentication declaration uploaded at the time of device registration, so that the quantitative identifier of the underlying security capability of the device can be obtained.
[0123] According to the preset authentication level-device trust level mapping table, the corresponding device trust level is found.
[0124] The authentication level-device trust level mapping table can be a preset rule reference table for converting the authentication level of the hardware root of trust into a numerical or hierarchical device trust level, which can be used to achieve standardized mapping of hardware security capability to business understandable trust values. In a specific embodiment, the authentication level-device trust level mapping table can be configured by the system security policy center and fixed in the secure storage area, supporting dynamic updating. For example, the authentication level-device trust level mapping table can include one or more of a linear mapping table (such as high -> 0.9, medium -> 0.6, and basic -> 0.3), a non-linear decay mapping table, and a multi-dimensional conditional mapping table (combining device model and authentication level). According to the preset authentication level-device trust level mapping table, the corresponding device trust level can be found by taking the authentication level as the key and searching for the corresponding trust level value in the mapping table. Further, this operation can be achieved by table lookup direct mapping or interpolation calculation (if the authentication level is a continuous value), so that the hardware security capability can be converted into a trust factor available for risk assessment.
[0125] If the device is not an authentication trusted device, it is determined whether the device has a historical security violation record.
[0126] The historical security violation record can be a set of security event logs recorded by the relay protection tester in past operation, and can be used to evaluate the dynamic behavior credibility of the unauthenticated device. In this embodiment, the historical security violation record can be continuously collected by a security audit module of the power Hongmeng system and stored in a protected database. For example, the historical security violation record can include one or more of a data leakage event record, an unauthorized access attempt record, a firmware abnormal update record, and the like. Determining whether the device has a historical security violation record can be querying the violation event log associated with the device ID in the security audit database. Further, the operation can be achieved by indexing the log library according to the device unique identifier or calling a security information and event management (SIEM) interface for querying, so as to identify the historical risk behavior of the unauthenticated device.
[0127] If there is a historical security violation record, the initial trust level is reduced according to the number of violations and the severity.
[0128] The number of violations can be the occurrence frequency of the same type or all events in the historical security violation record, and can be used to reflect the stability of the device security behavior as one of the quantitative factors for trust degradation. In an exemplary embodiment, the number of violations can be obtained by counting the historical security violation record according to a time window or an event type. The severity can be the potential harm level of a single security violation event to the system security, and can be used to reflect the violation quality rather than only the quantity, and affect the trust degradation range. In this embodiment, the severity can be preset according to the event type (such as data tampering > configuration overreach > log anomaly). For example, the severity can include one or more of high risk (leading to protection misoperation / refusal), medium risk (sensitive data leakage), and low risk (debug interface abnormal opening). The initial trust level can be a default trust starting value of the unauthenticated device in the absence of historical violations, and can be used as a benchmark for degradation calculation when there is a violation. In a specific embodiment, the initial trust level can be preset by a system security policy, and is usually slightly higher than the basic trust level to reserve an observation space. Reducing the initial trust level according to the number of violations and the severity can be down-regulating the initial trust level based on a preset attenuation function (such as linear deduction, exponential attenuation). Further, the operation can be achieved by deducting 0.3 for each high-risk event, 0.15 for each medium-risk event, and accumulating no more than a threshold, or using a credit scoring model to dynamically calculate the remaining trust value, so as to realize dynamic negative adjustment of trust and reflect behavior accountability.
[0129] If there is no historical security violation record, the device trust level is set to the basic trust level.
[0130] The basic trust level can be a conservative trust value given to a device that has not passed the power Hongmeng authentication and has no historical violation record, and can be used to prevent excessive trust in unknown devices, embodying the principle of least privilege. In the present embodiment, the basic trust level can be uniformly set by a security policy, and is usually a low value (such as 0.2-0.3). Setting the device trust level to the basic trust level can be directly assigning a preset basic trust level to a device that has not been authenticated and has no violation record. Further, this operation can be implemented by directly assigning a fixed numerical value or fine-tuning the basic value according to the device type, so as to provide a conservative default value and avoid trust vacuum.
[0131] For example, in the scenario of a third-party tester accessing the main station test platform, the relay protection tester security system based on the power Hongmeng system in the present embodiment can be that a new type of handheld relay protection tester accesses a 220 kV substation test platform for the first time. The system first determines that it is not in the power Hongmeng trusted device directory. Then, it is found that the device had a medium-risk violation of unencrypted transmission of fixed value data in the past 6 months. The system sets the initial trust level to 0.5, and according to the strategy: medium-risk events are deducted by 0.15 each time, so the final device trust level = 0.5-0.15 = 0.35. If the device has no violation, it is directly set to the basic trust level of 0.3. If it has passed the power Hongmeng authentication and the hardware trust root is high security level, it directly obtains a trust level of 0.9 through the mapping table, without the need for behavior backtracking.
[0132] In one of the embodiments, the step of evaluating the sensitivity of the affected test data in the power grid safety test and recording it as the data sensitivity is specifically:
[0133] determining whether the affected test data is classified information test data, and if so, obtaining a data classified information level;
[0134] obtaining a corresponding basic sensitivity coefficient according to a preset classified information level-sensitivity coefficient correspondence table;
[0135] if not, determining whether the data involves power grid key parameters, wherein the power grid key parameters include relay protection fixed values, power grid topology structures, and device operation thresholds;
[0136] if so, superimposing a key parameter weighting value on the basic sensitivity coefficient; and if not, taking the basic sensitivity coefficient as the data sensitivity.
[0137] The confidential test data can be test data identified as containing sensitive or confidential information according to national or industry power data classification and grading standards, and can be used as a primary determination condition for high sensitivity evaluation, triggering the assignment of a sensitivity coefficient based on the statutory sensitivity level. In an exemplary embodiment, the confidential test data can be identified by data meta-labels, file attributes, or content keyword matching. Further, the confidential test data can include, but is not limited to, one or more of the value setting report containing the main network topology, the recorded wave data related to the core substation configuration, the test log containing the dispatch communication key, etc. The data confidentiality level can be the confidentiality level of the confidential test data defined by the power industry data security specification, and can be used to determine the initial value of the basic sensitivity coefficient. In a specific embodiment, the data confidentiality level can be extracted from the data metadata or the security management platform. For example, the data confidentiality level can include, but is not limited to, one or more of the sensitive level, the high sensitive level, the extremely high sensitive level, etc.
[0138] The confidential level-sensitivity coefficient table can be a preset rule table that maps the data confidentiality level to a numerical basic sensitivity coefficient, and can be used to automatically convert compliance requirements to risk model parameters. In this embodiment, the confidential level-sensitivity coefficient table is configured and fixed by the security policy center according to industry standards. Further, the confidential level-sensitivity coefficient table can use a linear mapping table (secret→0.5, confidential→0.7, top secret→0.9), a non-linear enhancement table (extremely high sensitive level index amplification), etc. The basic sensitivity coefficient can be an initial sensitivity reference value determined by the confidentiality level or the default rule, and can be used as a starting point for whether to superimpose a key parameter weighting value. In an exemplary embodiment, if it is confidential data, the table is obtained; if it is not confidential, it is set to a default low value (such as 0.3). The power grid key parameter can be a set of core technical parameters that directly affect the relay protection logic, system stability, or safe operation of equipment, and can be used to identify non-confidential but high business value data. For example, the power grid key parameter can include, but is not limited to, one or more of the relay protection setting value, the power grid topology structure, the equipment operation threshold, etc.
[0139] The relay protection setting value can be a setting value of an action criterion of a relay protection device, such as a current starting value, a time delay, etc., and can be used to directly determine whether the protection is correctly acted, and is a key parameter. In a specific embodiment, the relay protection setting value can be extracted from a protection device configuration file or a test task parameter. The power grid topology can be a network model describing electrical elements such as substations, lines, buses, etc., and can be used to affect fault location and protection cooperation, and is a key parameter. Further, the power grid topology can be obtained from a SCADA or a power grid model database. The equipment operation threshold can be a boundary parameter for safe operation of equipment, such as an overcurrent limit, a temperature rise upper limit, etc., and can be used to exceed the equipment damage or system instability, and is a key parameter. In an exemplary embodiment, the equipment operation threshold can be extracted from the equipment nameplate parameter or the operation procedure. The key parameter weighting value can be an additional sensitivity increment due to the data containing the key parameters of the power grid, and can be used to increase the weight of the key business data in the risk assessment. In this embodiment, the key parameter weighting value is a fixed value preset by a security policy or is accumulated according to the number of key parameters. For example, the key parameter weighting value can be weighted by 0.2 for a single key parameter, superimposed to a maximum of 0.4 for multiple key parameters, and dynamically weighted (according to the complexity of parameter combination).
[0140] The judgment of whether the affected test data is classified data can be checking whether the data is labeled with a sensitive label or matching a sensitive keyword library. Further, the judgment of whether the affected test data is classified data can be achieved by analyzing the security mark in the data file header or calling the data classification engine to scan the content, so as to distinguish whether the legal sensitive level evaluation path is applicable. The acquisition of the classified level of the data can be reading the security level of the classified test data from the metadata or a security management interface. Further, the acquisition of the classified level of the data can be achieved by reading the XML / JSON metadata field or querying the classification information in the unified data asset directory, so as to provide compliance basis for the assignment of the sensitive coefficient. The corresponding basic sensitive coefficient can be obtained according to the preset classified level-sensitivity coefficient table, which can be used as a key to search for the corresponding sensitive coefficient value in the table. In a specific embodiment, the corresponding basic sensitive coefficient can be obtained according to the preset classified level-sensitivity coefficient table by direct table mapping or interpolation calculation (if the level is a continuous score), so as to convert the legal compliance requirements into a calculable parameter of the risk model.
[0141] The judgment of whether the data relates to the grid key parameter can be an analysis of whether the content or field of the affected test data contains a relay protection setting value, a grid topology, or a device operation threshold. Further, the judgment of whether the data relates to the grid key parameter can be achieved by matching the field name with the key parameter keyword and identifying the parameter type by semantic analysis of the data content, so as to identify non-secret data with high business value. The superposition of the key parameter weighting value on the basis sensitive coefficient can be the addition of the basis sensitive coefficient and the preset key parameter weighting value. In an exemplary embodiment, the superposition of the key parameter weighting value on the basis sensitive coefficient can be achieved by fixed weighting (each type of key parameter + 0.15) and dynamic weighting (linearly increasing according to the number of parameter combinations), so as to increase the risk weight of the key business data and reflect its system-level impact. The basis sensitive coefficient as the data sensitive degree can be directly using the basis sensitive coefficient as the final sensitive degree for data that is neither secret nor related to key parameters. Further, the basis sensitive coefficient as the data sensitive degree can be achieved by directly assigning a default basis value (such as 0.3) and adjusting the basis value according to the data type, so as to provide a conservative default value and avoid over-assignment.
[0142] Taking the regional protection setting value verification test as an example, the relay protection tester security system based on the power Hongmeng system in this embodiment can be: in a certain 500kV line protection test, the affected test data is distance II section impedance setting value = 12.5Ω. The system first judges that the data is not marked as secret, so it enters the key parameter judgment process. It is identified that it belongs to the relay protection setting value, which is a grid key parameter. The system sets the basis sensitive coefficient to 0.3 (non-secret default value), the key parameter weighting value to 0.25, and the final data sensitive degree = 0.3 + 0.25 = 0.55. If the data contains the topology of the station and the opposite station, multiple key parameter weightings may be superimposed, and the sensitive degree is above 0.7. If it is a marked secret station setting table, the basis sensitive coefficient is directly obtained by table lookup, which is 0.7. If it also contains topology, it is further superimposed to 0.95.
[0143] In one of the embodiments, the risk degree of the affected test data is obtained in combination with the data security interference degree, the device trust level, and the data sensitive degree, and is recorded as the basis risk degree. Specifically:
[0144] The importance weight of the affected test data in the grid test process is obtained and recorded as data importance, wherein the importance of the key test item is higher than that of the regular test item;
[0145] The attack threat degree is obtained according to the threat type detected by the built-in security mechanism of the power Hongmeng system;
[0146] The risk weight coefficients of data security interference degree, device trust level, data sensitivity, data importance, and attack threat degree are set; and the base risk degree of the affected test data is obtained by multiplying each parameter by the corresponding weight coefficient and summing.
[0147] The data importance can be a weight value reflecting the structural importance of the affected test data in the power grid test process, and can be used to reflect the difference in the influence of key test items and regular test items on system security. In an exemplary embodiment, the data importance can be obtained from a preset policy library according to the test task type or test item classification. Further, the data importance can include, but is not limited to, one or more of key test item importance (such as main protection action verification), regular test item importance (such as auxiliary signal calibration), and non-core monitoring item importance. The key test item can be a core test content that directly affects the correct action of the relay protection or the fault isolation capability of the power grid, and can be used as a basis for determining high data importance. Exemplarily, the key test item can include differential protection action logic verification, distance protection setting value verification, circuit breaker trip time test, etc. The regular test item can be a non-core test content for auxiliary verification or performance evaluation, and can be used to assign a lower data importance. In a specific embodiment, the regular test item can include analog quantity accuracy calibration, communication interface connectivity test, human-machine interface response test, etc.
[0148] The threat type can be a specific attack category of the current security event identified by the built-in security mechanism of the power Hongmeng system, and can be used to map the attack threat degree and enhance the confrontation perception ability of the risk assessment. In this embodiment, the threat type can be output by the intrusion detection, log audit, or TEE anomaly monitoring module of the power Hongmeng system. Further, the threat type can include, but is not limited to, one or more of man-in-the-middle attack, firmware rollback attack, unauthorized access attempt, replay attack, etc. The attack threat degree can be a potential harm level of the current attack behavior to the system security based on the threat type, and can be used as a dynamic context factor for the base risk degree calculation. In an exemplary embodiment, the attack threat degree can be generated through a mapping rule or a scoring model from the threat type to the threat degree. Exemplarily, the attack threat degree can include high threat (which can cause misoperation / refusal to operate), medium threat (which can cause data leakage), low threat (which is only a probing behavior), etc. The risk weight coefficient can be a preset or adaptive parameter for adjusting the relative contribution of each risk factor in the base risk degree calculation, and can be used to realize the weighted fusion of multi-dimensional risk factors and support policy optimization. In this embodiment, the risk weight coefficient can be configured by the security policy center and can be dynamically adjusted based on historical protection effect feedback. Further, the risk weight coefficient can include a static weight (fixed configuration), a scene adaptive weight (adjusted according to the test type), a learning weight (optimized based on reinforcement learning), etc.
[0149] The importance weight of the affected test data in the power grid test process is obtained and recorded as data importance, which can be a preset importance weight according to the test item type (key / regular) to which the affected test data belongs. Further, the operation can be realized by looking up the table after extracting the test item classification from the test task metadata, or automatically deriving the test item criticality based on the protection logic atlas, so that the business process structure can be embedded in the risk assessment, and the engineering rationality of the risk ranking can be improved. The attack threat degree can be obtained according to the threat type detected by the built-in security mechanism of the power Hongmeng system, which can be the threat alarm type parsed from the output of the power Hongmeng security subsystem, and is mapped to the quantitative threat degree. Further, the operation can be directly converted by using a predefined threat-degree mapping table, or a lightweight threat scoring model is called to output a continuous value, so that the real-time confrontation context can be introduced, and the risk assessment can have dynamic response capability.
[0150] The risk weight coefficients of the data security interference degree, the device trust level, the data sensitivity degree, the data importance and the attack threat degree can be respectively assigned weight coefficients to form a weighted vector. Further, the operation can be realized by loading a static weight set from a policy configuration file, or dynamically selecting a weight template according to the current test, so that the flexible adjustment of the risk focus in different scenarios can be supported. The sum of the product of each parameter and the corresponding weight coefficient is obtained, and the basic risk degree of the affected test data is obtained, which can be a linear weighted sum operation, that is, each risk factor is multiplied by its corresponding weight coefficient and then accumulated. Further, the operation can be realized by using standard weighted sum or normalized weighted sum (to ensure that the result is in the [0, 1] interval), so that a unified and comparable local risk quantitative value can be generated.
[0151] Taking the intermediate attack encountered in the differential protection test of the main transformer as an example, the security system of the relay protection tester based on the power Hongmeng system in this embodiment can be: in a certain 500kV main transformer test, the affected test data is the high-voltage side differential current sampling value, which belongs to the key test item, and the data importance is 0.9. The power Hongmeng system detects the threat type of the man-in-the-middle attack, and maps the attack threat degree to 0.85. The previous steps have obtained: the data security interference degree is 0.7 (due to phase anomaly), the device trust level is 0.6 (the device is authenticated but the transmission is not encrypted), and the data sensitivity degree is 0.8 (related to the main protection and containing the setting value). The system configuration risk weight coefficients are: interference degree 0.3, trust level-0.2 (negative), sensitivity 0.25, importance 0.2, and threat degree 0.25. The basic risk degree is calculated as 0.7*0.3+0.6*(-0.2)+0.8*0.25+0.9*0.2+0.85*0.25=0.21-0.12+0.20+0.18+0.2125=0.6825, triggering the high-risk response strategy.
[0152] In one embodiment, the key test items include relay protection action characteristic test data, and the threat types include data tampering, man-in-the-middle attack, and unauthorized access.
[0153] The relay protection action characteristic test data can be core test data reflecting the action behavior of the relay protection device under simulated fault conditions, and can be used as a typical representative of the key test items, and is given high importance and high sensitivity in risk assessment because it directly affects the correctness of the protection. In an exemplary embodiment, the relay protection action characteristic test data can include, but is not limited to, one or more of differential protection action time data, distance protection impedance characteristic curve, overcurrent protection return coefficient test results, etc.
[0154] Data tampering can be an unauthorized modification of test data by an attacker during collection, transmission or storage, and can be used as one of the threat types to trigger integrity check failure and map to a high attack threat level. For example, data tampering can include, but is not limited to, one or more of sample value forgery, fixed value parameter replacement, and wave recording file injection. The man-in-the-middle attack can be a network layer attack by an attacker to intercept and possibly tamper with communication data between the test instrument and the master station, and can be used as one of the threat types to destroy the transmission confidentiality and integrity, and be identified by the power Hongmeng encryption channel anomaly detection. Further, the man-in-the-middle attack can include, but is not limited to, one or more of TLS session hijacking, GOOSE message replay, and unauthorized proxy forwarding. Unauthorized access can be an action of an unauthorized subject to read, write or control the test data or device interface, and can be used as one of the threat types to violate the access controllability, and be detected by the power Hongmeng access control log. In a specific embodiment, unauthorized access can include, but is not limited to, one or more of illegal call of a debugging interface, reading of test cache by a non-operation and maintenance account, and unauthorized call of a security service by a third party application.
[0155] For example, in the case of data tampering encountered in line pilot protection testing, the relay protection tester security system based on the power Hongmeng system of the present embodiment can be: in the testing of 220 kV line pilot protection, the affected test data is the phase differential action criterion of the current on both sides, which belongs to the relay protection action characteristic test data and is identified by the system as a key test item. At the same time, the power Hongmeng system detects that the data hash value does not match the standard feature and has no legal signature, and determines that the threat type is data tampering. The system gives high data importance (0.9) and high attack threat level (0.8) accordingly, and calculates the basic risk degree 0.78 combined with other factors, triggering the high-priority protection strategy of immediately terminating the test, locking the device, and alarming the master station.
[0156] In one of the embodiments, according to the security risk degree, risk factors affecting the security of test data are extracted, historical protection data of the risk factors is obtained, and according to the historical protection data, a protection scheme is generated. The steps of matching are specifically as follows:
[0157] According to the security risk degree, the dominant risk factor is screened out from the risk factors;
[0158] The historical protection case matched with the dominant risk factor is extracted from the historical protection data, the protection measures and the implementation effect score in the case are obtained, the implementation effect score is weighted and sorted according to the security risk degree, and the protection measure combination with the highest score is selected;
[0159] The protection scheme adapted to the current test scene is generated based on the protection measure combination with the highest score in combination with the built-in security mechanism of the power Hongmeng system and the hardware root of trust of the relay protection tester.
[0160] Among them, the dominant risk factor can be a single or a few risk causes that contribute most to the current security risk degree and play a decisive role among multiple risk factors, which can be used as a key index for searching historical protection cases and focusing on core threats. In an exemplary embodiment, the dominant risk factor can be obtained based on the contribution degree of each risk factor to the basic risk degree or threshold screening. Further, the dominant risk factor can include but is not limited to one or more of device identity forgery, transmission without encryption, and key parameter tampering. The historical protection case can be a complete protection event entry implemented and recorded by the system against a specific risk factor, containing measures and effect evaluation, which can be used to provide verified strategy reference for the current risk. For example, the historical protection case can be obtained by searching according to the dominant risk factor label in the structured historical protection data. In a specific embodiment, the historical protection case can include but is not limited to high-risk device impersonation handling case, man-in-the-middle attack blocking case, sensitive data leakage emergency response case, etc.
[0161] The protective measure can be a specific safety operation or a set of configuration instructions adopted in historical protection cases, and can be used to constitute a reusable protection action unit. In the embodiment, the protective measure can be extracted by operation and maintenance log or automatic execution record analysis. Further, the protective measure can include but is not limited to isolating a test channel, resetting a device binding relationship, enabling encryption processing in TEE, and forcing firmware version upgrade. The implementation effect score can be a quantitative evaluation of the comprehensive effect of the historical protection measure in actual application, and can be used for strategy optimization sorting. For example, the implementation effect score can be calculated based on multi-dimensional indicators (such as blocking success rate, performance impact, and operation and maintenance cost). In one specific embodiment, the implementation effect score can include but is not limited to high effectiveness and low overhead score, medium effectiveness and high reliability score, and emergency disposal but high resource consumption score. The security risk degree level can be a classification result of dividing continuous security risk degree values into discrete levels (such as low, medium, high, and extremely high), and can be used to guide the weighting strategy of the implementation effect score. In the embodiment, the security risk degree level can be mapped to the risk degree value through a preset threshold interval. Further, the security risk degree level can include but is not limited to low risk (0.0-0.3), medium risk (0.3-0.6), high risk (0.6-0.85), and extremely high risk (0.85-1.0). The protective measure combination can be a set of multiple coordinated protective measures included in a historical protection case, and can be used as a basic template for generating a new protection scheme. For example, the protective measure combination can be extracted from the historical protection case as a whole.
[0162] According to the security risk degree, the dominant risk factor can be selected from the risk factors by analyzing the contribution weight of each risk factor to the security risk degree, and selecting the highest or exceeding the threshold. Further, the operation can be realized by ordering each factor product item size in the basic risk degree decomposition or using SHAP and other explainable AI methods to identify the dominant feature, so as to focus on the core threat and avoid strategy generalization. The historical protection case matched with the dominant risk factor can be extracted from the historical protection data, which can be used as a key to search for related cases in the historical protection database. Further, the operation can be realized by exact label matching or semantic similarity retrieval (supporting approximate risk scene), so as to reuse the effective strategy verified in actual combat.
[0163] The protective measures and implementation effect score in the case can be parsed from the matched historical protection case structured field. Further, the operation can obtain the measure-effect association by directly reading the JSON / YAML format case record or calling the knowledge graph API, so as to obtain the executable action and its historical performance. The implementation effect score is weighted and sorted according to the security risk level, which can be to adjust the score weight according to the risk level (such as paying more attention to effectiveness when the risk is high, and considering efficiency when the risk is low). Further, the operation can be realized by high risk: effectiveness weight x 1.5; low risk: overhead weight x 0.8, or using a multi-objective optimization model to reorder, so as to realize risk-strategy dynamic adaptation. Selecting the protective measure combination with the highest score can be selecting the first ranked measure combination as the candidate after weighted sorting. Further, the operation can be realized by single best selection or Top-K candidate for manual confirmation, so as to ensure the optimality of the strategy. Based on the protective measure combination with the highest score, a protective scheme suitable for the current test scene is generated in combination with the built-in security mechanism of the power Hongmeng system and the hardware trust root of the relay protection tester, which can be instantiating the general measure combination into a specific instruction sequence that can call the power Hongmeng security service and the hardware trust root interface. Further, the operation can be realized by calling the power Hongmeng security service API to generate an execution script or generate a key binding or remote proof instruction that requires the participation of the hardware trust root, so as to ensure that the scheme is executable, verifiable and environment adapted.
[0164] Taking the case of on-site test encountering high-risk device impersonation as an example, the relay protection tester security system based on the power Hongmeng system of the embodiment can be: in the test of a certain substation, the security risk degree is 0.82 (high risk level), and the dominant risk factor is device identity forgery. The system retrieves 3 matching cases from the historical protection data, one of which is an original implementation effect score of 0.88 for the combination of isolation + re-binding + firmware verification. Because the current risk is high, the system weights the effectiveness dimension by 1.4, and the adjusted score is 0.92, ranking first. The scheme generation module initiates the test channel isolation by calling the device management interface of the power Hongmeng system, triggers the device identity re-binding process through the hardware trust root, and requires the firmware integrity remote proof, finally generates a protective scheme suitable for the current 500kV main transformer test scene and pushes it to the operation and maintenance terminal.
[0165] In one of the embodiments, the dominant risk factor includes device authentication failure, transmission encryption vulnerability, and access permission anomaly, the built-in security mechanism includes secure boot, data encryption, and access control, and the hardware trust root includes device identity authentication and firmware integrity verification.
[0166] In one embodiment, device authentication failure can be a failure of the relay protection tester to pass a verification of its identity legitimacy by a hardware root of trust or a power-horizon system, and can be used as one of the leading risk factors to represent a device identity forgery or impersonation threat. In one exemplary embodiment, the device authentication failure can include, but is not limited to, one or more of a certificate expiration, a device ID unregistration, a remote attestation failure, and the like. Transmission encryption vulnerability can be a failure of the test data to use or incorrectly use an encryption mechanism during transmission, resulting in a risk of data interception or tampering, and can be used as one of the leading risk factors to reflect a lack of anti-leakage capability. Further, the transmission encryption vulnerability can include, but is not limited to, one or more of a plaintext transmission, a weak encryption algorithm usage, a key agreement failure, and the like. Access permission anomaly can be an access behavior to the test data or system resources that exceeds the authorized subject's permission range, and can be used as one of the leading risk factors to represent an unauthorized access threat. Exemplary, the access permission anomaly can include, but is not limited to, one or more of an unauthorized read configuration, an illegal opening of a debugging interface, an unauthorized process access to sensitive memory, and the like.
[0167] Secure boot can be a boot process of the power-horizon system to verify firmware and key component integrity when the device is powered on, and can be used as one of the built-in security mechanisms to prevent malicious firmware loading. In one specific embodiment, the secure boot can include, but is not limited to, one or more of a BootROM level verification, a kernel image signature check, a driver module integrity measurement, and the like. Data encryption can be a security service provided by the power-horizon system to implement encryption and decryption of static or dynamic test data, and can be used as one of the built-in security mechanisms to protect data confidentiality and integrity. In this embodiment, the data encryption can include, but is not limited to, one or more of a storage encryption (TDE), a transport layer encryption (TLS / SM protocol), a TEE internal memory encryption, and the like. Access control can be a mechanism for the power-horizon system to make authorization decisions on resource access requests based on subject identity and policy, and can be used as one of the built-in security mechanisms to prevent unauthorized operations. Further, the access control can include, but is not limited to, one or more of a role-based access control (RBAC), an attribute-based access control (ABAC), a microkernel-level capability token, and the like.
[0168] The device identity authentication can be a device identity proof capability based on a unique unclonable identification provided by the hardware root of trust, which can be used as one of the core functions of the hardware root of trust to support device authenticity identification. For example, the device identity authentication can include one or more of PUF derived ID authentication, secure chip binding certificate, remote device attestation, etc. The firmware integrity verification can be a capability of the hardware root of trust to verify the firmware code hash value at startup or runtime, which can be used as one of the core functions of the hardware root of trust to prevent firmware tampering. In one specific embodiment, the firmware integrity verification can include one or more of startup chain level-by-level measurement, runtime firmware snapshot comparison, integrity monitoring in the secure world, etc.
[0169] Mapping the dominant risk factors to the built-in security mechanisms and the hardware root of trust to support the generation of protection schemes can be to establish a structured mapping relationship of the dominant risk factors to the corresponding security capabilities, which is used to automatically call the adapted protection means. Further, mapping the dominant risk factors to the built-in security mechanisms and the hardware root of trust to support the generation of protection schemes can be achieved by constructing a risk-capability mapping table or reasoning and matching the optimal security capability combination based on a knowledge graph, so as to realize the precise alignment of threat identification and protection capabilities and improve the response pertinence and execution efficiency.
[0170] The above is only the preferred embodiment of the present application, and does not limit the patent scope of the present application, and any equivalent structure or equivalent process transformation using the content of the specification and drawings, or direct or indirect application in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A power-hongmeng system-based relay protection tester security system, characterized in that, The system comprises a data extraction module, a data verification module, a risk assessment module, a scheme generation module, an information pushing module and a secure storage module; The data extraction module is configured to determine a power grid test scene and record it as a test scene to be tested, extract power grid basic information data of the test scene to be tested from a power Hongmeng system, and extract device identity authentication information from a hardware root of trust of a relay protection tester; The data verification module is configured to collect power grid test data of the test scene to be tested, and determine whether the power grid test data is safe in combination with the power grid basic information data and a hardware root of trust verification result; The risk assessment module is configured to extract security risk data from the power grid basic information data and the hardware root of trust information if the test data is not safe, and assess a security risk level of the test data according to the security risk data and record it as a security risk degree; The scheme generation module is configured to extract a risk factor affecting security of the test data according to the security risk degree, acquire historical protection data of the risk factor, and generate a protection scheme according to the historical protection data; The information pushing module is configured to send the security risk degree and the corresponding protection scheme to an operation and maintenance terminal, and remind an operation and maintenance personnel to protect the power grid test data; The secure storage module is configured to encrypt and store the power grid test data if the test data is safe, and continuously monitor and update the power grid test data; The step of collecting the power grid test data of the test scene to be tested, and determining whether the power grid test data is safe in combination with the power grid basic information data and the hardware root of trust verification result, specifically comprises: extracting standard test data features of the test scene to be tested according to the power grid basic information data and recording them as standard data features, calculating a hash similarity of the power grid test data and the standard data features to obtain a data integrity similarity, and setting a data integrity standard threshold to determine whether the data integrity similarity reaches the data integrity standard threshold; if the data integrity similarity reaches the data integrity standard threshold, verifying the device identity through the hardware root of trust of the relay protection tester to determine whether it is a trusted test device; if it is a trusted test device, extracting an access control log according to a built-in security mechanism of the power Hongmeng system to detect whether there is an unauthorized access record, and detecting whether an encrypted transmission protocol of the power Hongmeng system is used in a test data transmission process if there is no unauthorized access record; if the data integrity similarity does not reach the data integrity standard threshold, the device identity is not trusted, there is an unauthorized access record, or the encrypted transmission protocol is not used, the test data is determined to be not safe; The step of extracting security risk data from the power grid basic information data and the hardware root of trust information if the test data is not safe, and assessing a security risk level of the test data according to the security risk data and recording it as a security risk degree, specifically comprises: extracting affected test data in the power grid test environment according to the security risk data, and acquiring a standard security state of the affected test data; extracting a real-time security state according to the power grid test data, and obtaining an interference degree of the environment on the affected test data according to the standard security state and the real-time security state and recording it as a data security interference degree; According to the hardware root of trust information extraction of the relay protection tester device trust level; The affected test data in the power grid safety test is evaluated and recorded as the data sensitivity; The affected test data risk degree is obtained by combining the data security interference degree, the device trust level and the data sensitivity, and recorded as the basic risk degree; The safety risk degree of the power grid test data is obtained by superimposing the basic risk degrees of all affected test data.
2. The power-horizon system based protective relay testing system security system as claimed in claim 1, wherein, The step of obtaining the environmental interference degree of the affected test data according to the standard safety state and the real-time safety state and recording it as the data security interference degree is specifically: Calculate the deviation value of different safety parameters in the standard safety state and the real-time safety state, and record it as the safety deviation value, wherein the safety parameters include data integrity, transmission confidentiality and access controllability; According to the type of the affected test data, the sensitivity coefficient of the data to different safety parameters is obtained; The parameter interference degree is obtained by multiplying the safety deviation value and the corresponding sensitivity coefficient; the data security interference degree of the affected test data is obtained by superimposing and summing the parameter interference degrees of all safety parameters.
3. The power-horizon system based protective relay testing system security system as claimed in claim 2, wherein, The step of obtaining the device trust level of the relay protection tester according to the hardware root of trust information extraction is specifically: Determine whether the relay protection tester is a trusted device authenticated by the power Hongmeng system, if it is an authenticated trusted device, obtain the authentication level of the hardware root of trust; According to the preset authentication level-device trust level mapping table, the corresponding device trust level is found; If it is not an authenticated trusted device, determine whether the device has a historical security violation record; If there is a historical security violation record, the initial trust level is reduced according to the number of violations and the severity; If there is no historical security violation record, the device trust level is set as the basic trust level.
4. The power-horizon system based protective relay testing system security system of claim 3, wherein, The step of evaluating the sensitivity of the affected test data in the power grid safety test and recording it as the data sensitivity is specifically: Determine whether the affected test data is classified as secret test data, if it is classified as secret test data, obtain the data secret level; According to the preset secret level-sensitivity coefficient table, the corresponding basic sensitivity coefficient is found; If it is not classified as secret test data, determine whether the data involves key parameters of the power grid, wherein the key parameters of the power grid include relay protection setting value, power grid topology structure and device operation threshold value; If it involves key parameters, superimpose the key parameter weighting value on the basic sensitivity coefficient; if it does not involve key parameters, the basic sensitivity coefficient is taken as the data sensitivity.
5. The power-horizon system based protective relay testing system security system of claim 4, wherein, The step of obtaining the risk degree of the affected test data by combining the data security interference degree, the device trust level and the data sensitivity and recording it as the basic risk degree is specifically: Obtain the importance weight of the affected test data in the power grid test process and record it as the data importance, wherein the importance of the key test item is higher than that of the regular test item; According to the threat type detected by the built-in security mechanism of the power Hongmeng system, the attack threat degree is obtained; Set the risk weight coefficients of the data security interference degree, the device trust level, the data sensitivity, the data importance and the attack threat degree; sum the products of each parameter and the corresponding weight coefficient to obtain the basic risk degree of the affected test data.
6. The power-horizon system based protective relay testing system security system as claimed in claim 5, wherein, The key test items include relay protection action characteristic test data, and the threat types include data tampering, man-in-the-middle attack and unauthorized access.
7. The power-horizon system based protective relay testing system security system as claimed in claim 5, wherein, The step of extracting the risk factors affecting the security of the test data according to the security risk degree, obtaining historical protection data of the risk factors, and generating a protection scheme according to the historical protection data is specifically: Screening a dominant risk factor from the risk factors according to the security risk degree; Extracting historical protection cases matched with the dominant risk factor from the historical protection data, and obtaining protection measures and implementation effect scores in the cases; According to the security risk degree, the implementation effect scores are weighted and sorted, and the protection measure combination with the highest score is selected; Combined with the built-in security mechanism of the power Hongmeng system and the hardware root of trust of the relay protection tester, a protection scheme suitable for the current test scene is generated based on the protection measure combination with the highest score.
8. The power-horizon system based protective relay testing system security system of claim 7, wherein, The dominant risk factor includes device authentication failure, transmission encryption vulnerability and access permission anomaly, the built-in security mechanism includes secure boot, data encryption and access control, and the hardware root of trust includes device identity authentication and firmware integrity verification.
Citation Information
Patent Citations
Method and device for optimizing electric power near-field operation and maintenance based on open source gap, and medium
CN119444170A
Portable operation and maintenance gateway management and control method and system based on dynamic monitoring feedback
CN121000556A