Method and system for dynamically checking safety performance and information integrity of transformer substation monitoring host

By combining hard-trusted modules and national cryptographic algorithms, dynamic verification of the substation monitoring host is achieved, which solves the passive response problem of information integrity verification in the existing technology, realizes real-time security status perception and active protection, and improves the system's protection capabilities.

CN121502782APending Publication Date: 2026-02-10NARI NANJING CONTROL SYSTEM CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511538485.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-27
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

The information integrity verification of existing substation monitoring hosts relies on periodic CRC or MD5 fixed checks, which lacks vertical tracking and horizontal comparison. The security status assessment has not established a dynamic assessment model, resulting in passive response to potential threats. Furthermore, the verification mechanism is disconnected from security protection and cannot provide real-time feedback to access control.

Method used

It employs a hard-trusted module for static and dynamic measurement, combines national cryptographic algorithms for encryption protection and signature verification, generates security hardening strategies through trusted measurement data, forms a dynamic verification closed-loop control, and integrates trusted measurement, encryption protection and policy management.

Benefits of technology

It enables real-time perception and monitoring of host security status changes, prediction of risk trends, proactive hardening, dynamic optimization of protection strategies, improvement of protection strength and reduction of operation and maintenance costs, forming a system-level linkage security hardening.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121502782A_ABST
    Figure CN121502782A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for dynamically checking safety performance and information integrity of a substation monitoring host. The method comprises the following steps: performing static / dynamic measurement on monitoring host firmware, an operating system, a key process and configuration through a hardware trusted module to generate trusted data; executing access control, encrypting the key process and the configuration by adopting a national cryptographic algorithm, and generating an abstract and a signature; auditing logs are collected, and encrypted storage and signature verification are carried out by using a national cryptographic algorithm; the credible data, the signature and the log verification result are integrated, a fault mode is recognized and the influence level is evaluated by combining an original transformer substation model; dynamically evaluating a security situation and generating a reinforcement strategy based on multi-dimensional indexes such as a fault mode, a CPU, a check rate and response time delay; the strategy is fed back to access control, encryption protection and auditing verification links, configuration is optimized, and a dynamic check closed loop is formed. According to the invention, the safety operation and maintenance complexity is reduced, and the efficient balance of protection strength improvement and operation cost reduction is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electrical information technology, and more specifically, to a method and system for dynamic verification of the safety performance and information integrity of a substation monitoring host. Background Technology

[0002] As the nerve center of power grid dispatching and field control, the information integrity and security performance of substation monitoring hosts directly determine the continuity and reliability of power grid operation. However, existing systems generally remain at a rudimentary level of "single-point protection and static verification": on the one hand, data integrity verification relies solely on periodic CRC or MD5 checksums, lacking both longitudinal tracking of the historical security baseline of the same host and horizontal comparison across multiple hosts, making it difficult for operators to detect gradual tampering traces; on the other hand, security status assessment still adopts a crude "threshold + log" model, setting static alarm thresholds based solely on single indicators such as CPU utilization and network traffic, without establishing a dynamic assessment model based on multiple dimensions such as root of trust measurement, behavioral baseline, protocol integrity, and data signature, and lacking the ability to predict host status degradation trends, resulting in reactive responses to potential threats only after a failure has occurred. More critically, existing verification mechanisms and security protection systems operate in isolation, and integrity verification results cannot provide real-time feedback to access control and anomaly isolation strategies, leaving operational decisions still highly dependent on human experience. With the rapid increase in the proportion of ultra-high voltage and new energy, the data throughput and protocol complexity of substation monitoring hosts are growing exponentially. The traditional "post-audit and manual handling" approach can no longer meet the stringent requirements of modern power grids for real-time and reliable host information integrity. There is an urgent need to build a dynamic verification method and system for the security performance and information integrity of substation monitoring hosts that integrates reliability measurement, dynamic verification, trend prediction, and joint defense. Summary of the Invention

[0003] Purpose of the invention: The present invention aims to solve the above-mentioned problems existing in the prior art and provide a method and system for dynamic verification of the security performance and information integrity of a substation monitoring host. With autonomous and controllable intrinsic security as the core, it achieves efficient collaboration of trust measurement, encryption protection and policy control.

[0004] Technical solution: To achieve the above-mentioned objectives, the present invention adopts the following technical solution:

[0005] A first aspect is a method for dynamically verifying the security performance and information integrity of a substation monitoring host, the method comprising the following steps:

[0006] The hardware trust module performs static and dynamic measurements on the firmware, operating system, key processes, and configuration files of the monitored host to generate trust measurement data.

[0007] Based on the trusted state represented by the trusted measurement data, an access control policy is executed, and the key processes and configuration files are encrypted and protected using national cryptographic algorithms to generate corresponding data digests and digital signatures.

[0008] Collect key operation audit logs of the monitoring host, and use the national cryptographic algorithm to encrypt, store, and sign the audit logs;

[0009] Based on the trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit logs, a comprehensive analysis is conducted in conjunction with the original substation model to identify potential failure modes of the system and assess their impact level.

[0010] Based on the identified fault modes and their impact levels, and combined with system CPU utilization, security verification coverage, and key operation response latency indicators, the host security posture is dynamically assessed, a security hardening strategy is generated, and the security hardening strategy is fed back to the access control, encryption protection, and audit log verification links to optimize the corresponding strategy configuration and form a closed-loop control for dynamic verification.

[0011] Furthermore, static and dynamic measurements are performed through a hard-trusted module, including:

[0012] During the startup phase of the monitoring host, the firmware and operating system are statically measured and verified through the hard trusted module.

[0013] During the host operation phase, the memory behavior and resource calls of the core processes are dynamically measured and monitored through the hard trusted module.

[0014] Furthermore, national cryptographic algorithms are used to encrypt and protect critical processes and configuration files, including:

[0015] The SM4 algorithm is used to encrypt the binary files of critical processes and important configuration files;

[0016] The data digest of the file was generated using the SM3 algorithm.

[0017] The data digest is digitally signed using the SM9 algorithm.

[0018] Furthermore, based on the trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit logs, a comprehensive analysis is conducted using the original substation model to identify potential system failure modes and assess their impact level, including:

[0019] The trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit log are used as inputs to the rule reasoning engine;

[0020] The rule-based reasoning engine matches and compares the input real-time data with a pre-defined three-dimensional fault mode library of "architecture-component-data", and identifies specific security risks through matching logic.

[0021] Based on the comparison and location results, the influence radius of the safety hazard is determined by combining the business topology relationship of the original substation model, and the repair priority is determined according to the predefined business influence weight in the fault mode library.

[0022] By combining the radius of impact and the repair priority, a quantified level of fault impact is output.

[0023] Furthermore, based on the identified fault modes and their impact levels, and in conjunction with system CPU utilization, security check coverage, and critical operation response latency indicators, the host security posture is dynamically assessed, including:

[0024] An assessment model is constructed to calculate the host security index, and the security index is used as the result of the host security posture assessment.

[0025] The evaluation model is as follows:

[0026] Safety Index = α * (1 – CPU Failure Rate) + β * Verification Coverage + γ * (1 - Response Latency Failure Rate) - δ * Σ (Fault Impact Level)

[0027] Wherein, α, β, γ are weighting coefficients, which are preset according to the substation business scenario and satisfy α + β + γ = 1; CPU anomaly rate and response delay anomaly rate are obtained by comparing with historical baselines, and Σ(fault impact level) is a weighted sum of the impact levels of all identified fault modes, and the negative impact of confirmed faults on the overall situation is amplified by the penalty coefficient δ.

[0028] Furthermore, a security hardening strategy is generated and a closed-loop control system with dynamic verification is formed, including:

[0029] The host security posture assessment results and the fault mode library are input into the rule reasoning engine to intelligently match the optimal security hardening strategy.

[0030] The optimal security hardening strategy is automatically distributed to the access control policy library, the national cryptographic algorithm key management module, and the audit log policy configuration module.

[0031] The parameters and frequency of the verification mechanism are dynamically adjusted based on changes in system metrics after the strategy is implemented.

[0032] Secondly, a dynamic verification system for the security performance and information integrity of a substation monitoring host includes:

[0033] The Trusted Measurement Module is used to perform static and dynamic measurements on the firmware, operating system, critical processes, and configuration files of the monitored host through the Hard Trusted Module, and generate trusted measurement data.

[0034] The integrity protection module, connected to the trust measurement module, is used to execute access control policies based on the trust status represented by the trust measurement data, and to encrypt and protect the key processes and configuration files using national cryptographic algorithms, generating corresponding data digests and digital signatures.

[0035] An immune enhancement module, connected to the integrity protection module, is used to collect key operation audit logs of the monitoring host and call the national cryptographic algorithm capability of the integrity protection module to encrypt, store and sign the audit logs.

[0036] The security verification module is connected to the trust measurement module, integrity protection module and immune enhancement module respectively. It is used to perform a comprehensive analysis based on the trust measurement data, digital signature and audit log verification results, combined with the original substation model, to identify potential failure modes of the system and assess their impact level.

[0037] The intelligent analysis module, connected to the security verification module, is used to dynamically assess the host security posture based on the identified fault modes and their impact levels, combined with system CPU utilization, security verification coverage, and key operation response latency indicators. It generates security hardening strategies and feeds these strategies back to the access control, encryption protection, and immune enhancement modules of the integrity protection module for audit log verification, so as to optimize the corresponding strategy configuration and form a closed-loop control for dynamic verification.

[0038] Furthermore, the trust measurement module is specifically used for:

[0039] During the startup phase of the monitoring host, the firmware and operating system are statically measured and verified through the hard trusted module.

[0040] During the host operation phase, the memory behavior and resource calls of the core processes are dynamically measured and monitored through the hard trusted module.

[0041] Furthermore, the integrity protection module includes:

[0042] The encryption unit is used to encrypt critical process binary files and important configuration files using the SM4 algorithm;

[0043] A digest unit is used to generate a data digest of the file using the SM3 algorithm;

[0044] Signature unit, used to digitally sign data digests using the SM9 algorithm;

[0045] The immune enhancement module calls the encryption unit, digest unit, and signature unit to process the audit logs.

[0046] Furthermore, the security verification module includes:

[0047] Fault mode library, used to store preset three-dimensional fault modes of "architecture-component-data";

[0048] The analysis and positioning unit is used to match and compare the received trusted measurement data, digital signature verification results and audit log verification results with the fault mode library, and locate specific security risks through matching logic;

[0049] The result output unit is used to determine the impact radius of the safety hazard based on the comparison and positioning results and the business topology relationship of the original substation model. At the same time, it determines the repair priority according to the predefined business impact weight in the fault mode library. Combining the impact radius and the repair priority, it outputs the quantified fault impact level.

[0050] Furthermore, the intelligent analysis module includes:

[0051] The situation assessment unit is used to construct a quantitative assessment model of host security situation based on system operation indicators and the output of the security verification module, and obtain the host security situation assessment result; the assessment model is as follows:

[0052] Safety Index = α * (1 – CPU Failure Rate) + β * Verification Coverage + γ * (1 - Response Latency Failure Rate) - δ * Σ (Fault Impact Level)

[0053] Wherein, α, β, γ are weighting coefficients, which are preset according to the substation business scenario and satisfy α + β + γ = 1; CPU anomaly rate and response delay anomaly rate are obtained by comparing with historical baselines, and Σ(fault impact level) is a weighted sum of the impact levels of all identified fault modes, and the negative impact of confirmed faults on the overall situation is amplified by the penalty coefficient δ.

[0054] The hardening strategy generation unit is used to input the host security posture assessment results and the fault mode library into the rule reasoning engine to intelligently match the optimal security hardening strategy;

[0055] The closed-loop control unit is used to send the optimal security hardening strategy to the integrity protection module and the immune enhancement module, and dynamically adjust the parameters and frequency of the verification mechanism according to the changes in system indicators after the strategy is executed.

[0056] Thirdly, an electronic device comprising: one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, wherein when the programs are executed by the processors, they implement the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described in the first aspect.

[0057] Fourthly, a computer-readable storage medium storing a computer program thereon, characterized in that, when the computer program is executed by a processor, it implements the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described in the first aspect.

[0058] Fifthly, a computer program product includes a computer program that, when executed by a processor, implements the steps of the dynamic verification method for the security performance and information integrity of a substation monitoring host as described in the first aspect.

[0059] Sixthly, a method for constructing a dynamic verification system for the security performance and information integrity of a substation monitoring host includes the following steps:

[0060] Build an independent and controllable security foundation platform and establish a hard and reliable module technology framework adapted to substation scenarios to achieve reliable static measurement, dynamic measurement and dynamic management of key resources, processes and configuration files of monitoring hosts and access control policies.

[0061] An information integrity protection system based on Chinese cryptographic algorithms is constructed and integrated on the security base platform. The system uses Chinese cryptographic algorithms to encrypt and protect the binary files of key processes and important configuration files of the monitoring host. It also combines data digest algorithms, digital signature technology and database key information verification technology to ensure the integrity of host information.

[0062] Construct an immune enhancement system based on an autonomous and controllable strategy, integrating the encryption verification capabilities, key management mechanism, and audit log security management module of the information integrity protection system to form a system-level security hardening strategy and standardized configuration management scheme;

[0063] A safety performance verification system based on the original substation model is constructed, which connects the safety base platform, information integrity protection system and immune enhancement system. It is used to identify potential failure modes of the system and their impact level on overall safety, and to locate safety hazards based on key failure modes and access control rules.

[0064] An intelligent analysis module is constructed and connected to the security performance verification system. It is used to dynamically evaluate the host security status based on system CPU utilization, verification rate, and response time indicators, and generate reinforcement strategies in combination with the fault mode library to continuously optimize the verification mechanism. The optimization strategies are then fed back to the information integrity protection system and the immune enhancement system.

[0065] Furthermore, the construction of the autonomous and controllable security base platform includes:

[0066] Integrate a hard trust module as the root of trust to build a unified framework covering static measurement, dynamic measurement, and access control policy management;

[0067] It synchronously integrates an independent and controllable hardware platform, a secure operating system, a reliable database, and encryption middleware to form a security-hardened foundation environment covering the entire system stack.

[0068] Furthermore, the construction of the information integrity protection system based on national cryptographic algorithms includes:

[0069] Deploy national cryptographic algorithm encryption units, data digest units, and digital signature units;

[0070] Establish a full lifecycle security management mechanism covering key generation, storage, updating and destruction.

[0071] Furthermore, the construction of the immune enhancement system includes:

[0072] Deploy an audit log security management module to encrypt and verify the signatures of audit logs for critical operations;

[0073] The configuration policy collaboration module is used to deeply integrate information integrity protection, key management, and audit log security.

[0074] Beneficial effects:

[0075] (1) This invention, through a dynamic closed-loop defense system covering the entire lifecycle of "measurement-encryption-verification-evaluation-optimization," changes the traditional passive mode that relies on fixed thresholds and periodic verification. It can perceive and monitor changes in the security status of the host in real time, predict risk trends, and proactively implement reinforcement before potential risks emerge, achieving true intrinsic security and enhanced immunity. Furthermore, the dynamic closed-loop verification mechanism can continuously optimize the protection strategy, enabling the system's defense capabilities to continuously strengthen themselves over time, thereby achieving an exponential increase in protection strength. At the same time, the implementation of automation and intelligence significantly reduces manual intervention, lowers the risk of misoperation and long-term operation and maintenance costs, and achieves a balance between high-strength protection and low-cost operation.

[0076] (2) This invention organically integrates technologies such as trusted computing, national cryptographic encryption, integrity verification, audit trail, and intelligent analysis to form a multi-layered collaborative defense system of "encryption verification - immune enhancement - verification diagnosis - decision optimization." Data exchange and policy linkage between modules prevent security vulnerabilities and breakpoints, achieving system-level security hardening. Furthermore, with an independently controllable security foundation at its core, and employing national cryptographic algorithms, the autonomy, security, and controllability of the technology base are ensured. This provides a solid and reliable security hub for critical power facilities such as substations. Attached Figure Description

[0077] Figure 1 This is a diagram of the full-stack trusted base architecture of the substation monitoring host provided in an embodiment of the present invention.

[0078] Figure 2 This is a schematic diagram of the immune enhancement system provided in an embodiment of the present invention.

[0079] Figure 3 This is a framework diagram of the substation monitoring host safety performance verification system provided in an embodiment of the present invention.

[0080] Figure 4 This is a flowchart illustrating the intelligent generation process of reinforcement strategies provided in this embodiment of the invention.

[0081] Figure 5 This is a diagram of the dynamic verification system architecture for the security performance and information integrity of the substation monitoring host provided in this embodiment of the invention.

[0082] Figure 6 This is a flowchart of the dynamic verification method for the security performance and information integrity of the substation monitoring host provided in this embodiment of the invention. Detailed Implementation

[0083] The technical solution of the present invention will be further described below with reference to the accompanying drawings.

[0084] This invention aims to construct a data-enabled dynamic verification system for the security performance and information integrity of substation monitoring hosts, and to implement dynamic verification of the security performance and information integrity of substation monitoring hosts based on this system. The construction method of the system is described first, followed by an explanation of its working process.

[0085] In terms of system construction, this invention takes independent and controllable security as its core, constructing a standardized security foundation platform to achieve efficient collaboration between trusted measurement, encryption protection, and policy control. Based on this, a national-level integrity protection system is built, employing a triple composite verification mechanism of "SM3 digest + SM4 encryption + SM9 signature." A four-dimensional verification chain of firmware-process-configuration-data is established through a hardware trusted root (TPCM) to block tampering in real time. An intelligent immune enhancement system is built, generating a security index map based on a multi-dimensional dynamic evaluation model (CPU trust value / protocol compliance / memory anomaly rate, etc.), and combining it with a fault mode library to achieve precise risk location and second-level optimization of defense strategies. Through the multi-dimensional collaboration of the trusted foundation, verification engine, policy hub, and immune mechanism, the full-link protection efficiency of the monitoring host ("measurement-encryption-verification-evaluation-optimization") is comprehensively improved, constructing a millisecond-level response, intrinsically immune security hub for new power systems.

[0086] The build process includes the following steps:

[0087] S101. Construct an independent and controllable security foundation platform, establish a hard-trusted module technology framework adapted to substation scenarios, and realize dynamic management of trusted static measurement, dynamic measurement, and access control policies. For example... Figure 1 As shown, the independent and controllable security base platform takes "intrinsic trust and full-stack protection" as its main theme. It focuses on the construction of the hardware root of trust of the substation monitoring host and the full-link security management and control. It deeply integrates hard trust verification, domestic component collaboration and dynamic protection capabilities to form a unified trust base framework.

[0088] S102. Construct an information integrity protection system based on national cryptographic algorithms to achieve coordinated encryption and verification. Using national cryptographic algorithms as the core technology, implement encryption protection for the binary files of critical processes and important configuration files of the monitoring host, strengthening the information anti-tampering defense. Establish a three-in-one information integrity protection system covering "file encryption - digest verification - signature verification". Synchronously integrate data digest algorithms, digital signature technology, and database key information verification technology. Through coordinated encryption and verification, achieve integrity verification at every stage from file storage and transmission to database information retrieval, forming a full-link protection environment covering files, data, and databases, providing traceable and tamper-proof integrity assurance for the information security of the monitoring host.

[0089] S103. Construct an immune enhancement system based on an autonomous and controllable strategy, integrating information integrity protection, key management, and audit log encryption verification mechanisms to form a system-level security hardening strategy and standardized configuration management scheme. For example... Figure 2As shown, the immune enhancement system based on the autonomous and controllable strategy is guided by the principle of "intrinsic trust and proactive defense." It deeply integrates three core capabilities—information integrity protection, key management, and configuration baseline—around the encrypted storage, signature verification, and full lifecycle management of audit logs for critical operations on monitoring hosts, forming a unified security hardening strategy and continuous immunity framework. This system mainly includes three functional modules: audit log security management, security hardening strategy collaboration, and immune enhancement mechanism.

[0090] 1) Audit Log Security Management. Based on the national cryptographic standard SM4 encryption and SM9 signature, a closed-loop control system is implemented for every privileged operation, process loading, and configuration change of the monitoring host, ensuring that the audit logs are "encrypted upon generation, signed upon storage, verified upon viewing, and shredded upon destruction." At the same time, a hierarchical authorization viewing mechanism, timestamp-based replay prevention, and chain hash-based tamper prevention mechanism are established to ensure that the logs are complete, reliable, and traceable, providing an irrefutable chain of evidence for post-event tracing and compliance auditing.

[0091] 2) Collaborative security hardening strategies. The platform has a built-in standardized policy library covering system hardening, process whitelisting, access control, and data protection. It supports one-click push of differentiated hardening templates based on host roles and business scenarios. The hardening process is linked in real time with information integrity verification, key rotation, and audit logs. Any operation that deviates from the baseline will trigger an alarm and automatically roll back, realizing full-process digital and refined management of "policy issuance - compliance verification - effect evaluation - closed-loop correction".

[0092] 3) Immune Enhancement Mechanism. Integrating core functions such as policy optimization, vulnerability patching, and anomaly response, it relies on intelligent algorithms to continuously assess the effectiveness of security hardening and the system's operational status, accurately identifying potential security risks. Vulnerability patches, configuration corrections, and key updates can be implemented in a phased, phased manner, ensuring zero business interruption. Through a closed-loop operation of policy self-optimization, vulnerability self-healing, and anomaly self-response, it continuously amplifies the inherent immune capabilities of the monitored host, achieving a shift from passive hardening to proactive immunity.

[0093] S104. Construct a safety performance verification system based on the original substation model to achieve dynamic detection and hazard location. Identify potential system failure modes and their impact level on overall safety. Specifically, by analyzing the security architecture, hardened components, and data interaction security control of the monitoring host system, identify potential system failure modes and their impact level on overall safety; based on key failure modes and general access control rules, construct dynamic verification software for safety performance and information integrity to achieve accurate location of safety hazards. Figure 3As shown, by deeply analyzing the security architecture, hardening components, and data interaction links, a three-dimensional fault mode library of "architecture-component-data" is established, automatically quantifying the impact level of each potential fault on integrity, availability, and confidentiality. Based on critical fault modes and the general rules of least privilege control, dynamic verification software for security performance and information integrity is developed, achieving integrated "fault location-impact scoring-strategy recommendation": once an anomaly is detected, the system outputs the fault point coordinates, impact radius, and repair priority within seconds, and pushes precise handling solutions in conjunction with the hardening strategy library. Through real-time linkage with the trusted base, information integrity protection, and immune enhancement system, a panoramic verification capability covering the design, operation, and maintenance states is formed, providing millisecond-level accurate location of potential vulnerabilities and continuous security verification for the monitoring host.

[0094] S105. Utilizing intelligent analysis technology, dynamic security status assessment and strategy optimization are achieved. Host security status is dynamically evaluated based on multi-dimensional indicators. Combined with a fault mode library, the optimal hardening strategy is intelligently recommended, and the verification mechanism is continuously optimized to enhance host security protection capabilities.

[0095] 1) Situational Awareness. Based on multi-dimensional indicators such as real-time system CPU load rate, security verification coverage, and critical operation response latency, a quantitative assessment model of host security status is constructed. Intelligent analysis technology is used to accurately assess the host security status, providing a scientific basis for subsequent security protection and optimization.

[0096] 2) Intelligent generation and optimization of hardening strategies. For example... Figure 4 As shown, based on the host security posture assessment results, a rule-based reasoning engine deeply integrated with a fault mode library intelligently matches and dynamically generates the optimal security hardening strategy. Simultaneously, an adaptive dynamic verification mechanism is established to form an iterative optimization loop, continuously improving the inherent security protection capabilities and information integrity assurance strength of the monitored hosts, and driving the evolution of host security management towards lean and intelligent approaches.

[0097] Figure 5 The hierarchical architecture design of the dynamic verification system for the security performance and information integrity of the substation monitoring host is shown, from bottom to top as follows:

[0098] The foundation layer, serving as the underlying support of the system, constructs an independent and controllable security foundation platform. This platform uses the Trusted Module (TPCM) as the core root of trust, integrating domestically produced hardware (CPU), a secure operating system, a trusted database (DM), and national cryptographic middleware to form a full-stack trusted security foundation environment covering hardware, system, and applications.

[0099] The verification layer, located above the base layer, comprises three major systems that perform core security verification functions: a security performance verification system, responsible for the dynamic detection and analysis of system performance and security status; an information integrity protection system, ensuring the integrity and immutability of critical data, files, and configurations; and an immune enhancement system, providing continuous proactive defense and self-repair capabilities.

[0100] The analysis layer, with its core being the intelligent analysis engine, possesses the following analytical capabilities: multi-dimensional indicator collection and analysis, gathering and processing various runtime indicators; fault mode library matching analysis, performing fault diagnosis and hidden danger identification based on the knowledge base; and a rule-based reasoning engine, performing logical reasoning and decision-making based on preset rules.

[0101] The application layer, serving as the top-level interactive interface, provides users with specific functional modules: a security posture assessment module, which provides a visual assessment and display of the overall security status of the host; a policy management and control module, used for the configuration, distribution, and management of security policies; and a verification result display module, which presents the final results of various verifications, analyses, and tests.

[0102] This invention establishes an independent and controllable security foundation platform, integrating core modules such as the Trusted Driven Engine (TPCM), national cryptographic encryption verification, and multi-dimensional evaluation models. This forms a proactive defense system encompassing full-stack trusted verification, full-chain dynamic verification, full-dimensional risk perception, comprehensive intelligent linkage, and enhanced immunity across all states. With host-native security as its core objective, it establishes a full lifecycle management paradigm of static measurement, dynamic analysis, intelligent decision-making, and closed-loop hardening. This comprehensively achieves the dual goals of significantly improved security protection strength and greatly enhanced operational response efficiency, realizing end-to-end, integrated dynamic verification and security protection from the underlying root of trust to top-level intelligent applications.

[0103] As can be seen from the above layered architecture design, the core functions for dynamically verifying the security performance and information integrity of substation monitoring hosts lie in the verification layer and the analysis layer. Combining the functions of the verification layer and the analysis layer, this invention provides a method for dynamically verifying the security performance and information integrity of substation monitoring hosts, referring to... Figure 6 The method specifically includes the following steps:

[0104] S201, based on the hard trusted module, performs static and dynamic measurements on the firmware, operating system, key processes and configuration files of the monitoring host, and generates trusted measurement data;

[0105] S202, based on the trusted state represented by the trusted measurement data, execute the access control policy, and use the national cryptographic algorithm to encrypt and protect the key processes and configuration files, and generate the corresponding data digest and digital signature.

[0106] S203, Collect key operation audit logs of the monitoring host, and use the national cryptographic algorithm to encrypt, store and sign the audit logs;

[0107] S204. Based on the trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit log, a comprehensive analysis is conducted in conjunction with the original substation model to identify potential failure modes of the system and assess their impact level.

[0108] S205, based on the identified fault modes and their impact levels, and combined with system CPU utilization, security verification coverage and key operation response latency indicators, dynamically assesses the host security posture, generates security hardening strategies, and feeds these security hardening strategies back to the access control, encryption protection and audit log verification links to optimize the corresponding strategy configuration and form a closed-loop control for dynamic verification.

[0109] According to an embodiment of the present invention, in step S201, static and dynamic measurements are performed based on the Hard Trusted Module (TPCM), including:

[0110] During the host startup phase, static measurement and verification of the firmware and operating system are performed through a hardware trusted module. The TPCM calculates SM3 hash values ​​for the binary files of the BIOS, bootloader, operating system kernel, critical drivers, and applications, forming a baseline digital fingerprint for the startup trust chain. As an example, the static measurement method is as follows: Using the national cryptographic SM3 algorithm as the technical foundation, during the host power-on startup phase, following the trust chain sequence of "BIOS → bootloader → operating system kernel → drivers → applications," the binary files of each stage are read through the hardware bus interface between the TPCM and the CPU. A hash value of a specified length (e.g., 256 bits) is calculated in real time and compared with the baseline hash value in the pre-stored, non-erasable memory area of ​​the TPCM. If a deviation is detected, startup interception is immediately triggered, and an exception code is simultaneously output via serial port and recorded in the TPCM's local anti-tamper log, ensuring the integrity and trustworthiness of the system startup chain.

[0111] During the host operation monitoring phase, the memory behavior and resource calls of core processes are dynamically measured and monitored through a hard trusted module. TPCM, via a secure operating system kernel interface, periodically performs SM3 hash calculations on the memory images of the core process's code and data segments, comparing them with the initial baseline value at load time to generate evidence of process behavior integrity. As an example, the dynamic measurement method is as follows: A TPCM call interface is embedded in the secure operating system kernel, a core process monitoring list is configured, and TPCM reads the memory images of the monitored process's code and data segments using the process PID at a specified reading period (e.g., 500ms), calculates the real-time hash value, and compares it with the initial baseline value at process load time. Once tampering is detected, an interrupt signal is sent to the CPU to freeze the process within a specified time (e.g., 10ms), and the abnormal information is synchronized to the trusted database, achieving continuous trusted monitoring of the running core processes.

[0112] The measurement context data includes the measurement timestamp, the identifier of the measured object (such as file path, process PID), the measurement result (pass / fail), and the associated TPCM digital signature, ensuring the authenticity and non-repudiation of the measurement data itself.

[0113] According to an embodiment of the present invention, in step S202, based on the trusted state represented by the trusted measurement data, an access control policy is executed. In the access control policy library, high-privilege operations (such as modifying protection settings, starting or stopping critical processes) are bound to the subject's trusted state conditions. For example, a rule can be defined as: process A is allowed to write configuration file B, only if its dynamic measurement state is healthy and the operating system's static measurement passes. When the policy rule requires checking the trusted state, the access control engine initiates a real-time query to the security base platform. The engine obtains a trusted state report endorsed by TPCM, verifies its signature authenticity, and reads the final state conclusion ("healthy" or "unhealthy"). The access control engine matches the parsed state conclusion with the policy requirements: if the trusted state of process A and its runtime environment are both "healthy," then the write operation is allowed. If the query finds that the dynamic trusted state of process A is "unhealthy" (e.g., its memory image has been tampered with), then even if its identity and permissions are sufficient, access will be forcibly denied, and an alarm will be triggered immediately.

[0114] In steps S202 and S203, national cryptographic algorithms are used to encrypt and protect key processes and configuration files, and to encrypt, store, and sign audit logs to achieve information integrity protection. Specifically, this includes: encrypting the binary files of key processes and important configuration files using the SM4 algorithm; generating data digests of the files using the SM3 algorithm; digitally signing the data digests using the SM9 algorithm; and processing the audit logs using the same national cryptographic algorithm system.

[0115] Taking the encryption storage and verification of critical files as an example, the audit log process is the same. The specific process of encryption and verification collaboration includes: (1) File writing encryption: When the system needs to store critical process binary files or important configuration files, the integrity protection engine calls the national cryptographic SM4 encryption algorithm before writing the file to the disk, uses the key protected by TPCM to encrypt the file data, and then persists the ciphertext after it is generated. (2) Integrity verification value generation: After encryption is completed, the engine immediately calculates the SM3 hash value of the ciphertext of the file, and signs the hash value using the private key of the national cryptographic SM9 digital signature algorithm, forming a complete storage structure of "ciphertext file-SM3 hash-SM9 signature". (3) Verification before loading the file: When the system requests to load the protected file, the protection engine first reads the stored ciphertext, hash value and signature, and performs SM9 signature verification and SM3 hash comparison in sequence; only when both levels of verification are passed will the corresponding key be used to decrypt the file and load it into memory for operation.

[0116] The integrity protection of data transmission mainly includes: (1) Communication data signature: For critical data transmission between internal modules of the monitoring host or with external systems, the sender calculates the SM3 hash value of the transmitted data and performs SM9 signature before sending the data, and sends the "data-signature" as a whole. (2) Real-time verification at the receiving end: After the receiver obtains the data, it first verifies the validity of the signature, and recalculates the data hash value and compares it with the hash value in the signature to ensure that the data has not been tampered with during transmission.

[0117] According to an embodiment of the present invention, in step S204, identifying potential failure modes of the system and assessing their impact level specifically includes: matching and comparing the trust measurement data, digital signature verification results, and audit log verification results with a preset three-dimensional failure mode library of "architecture-component-data"; based on the comparison results, locating security risks and outputting their impact radius and repair priority.

[0118] The "Architecture-Component-Data" three-dimensional fault mode library defines potential fault models and their relationships across three dimensions: system architecture, hardware and software components, and critical data. The architecture dimension defines system-level faults, such as security policy failures; the component dimension defines specific module faults, such as process tampering or abnormal configuration files; and the data dimension defines data flow faults, such as communication data tampering or missing log records. The security performance verification engine receives trusted measurement data from the trusted base, verification results from the information integrity protection system, and audit and status information from the immune enhancement system. Trusted measurement data reflects component integrity, digital signature verification results reflect the authenticity of data and files, and audit log verification results reflect the compliance of operational behaviors. This multi-source data is synchronously input into the security performance verification system. The verification system quickly matches the above data with rules in the fault mode library, outputting diagnostic results within seconds. This includes accurately locating the physical device or software component where the potential problem lies (i.e., the coordinates of the fault point); assessing the impact range of the fault on related systems and business functions (i.e., the radius of influence); and determining the order of handling (i.e., the repair priority) based on the severity of the fault and its business impact. The treatment plan is pushed to the immune enhancement system and information integrity protection system for execution. The execution effect is fed back to the verification engine and strategy engine through the feedback optimization channel to achieve continuous self-optimization of the strategy.

[0119] According to an embodiment of the present invention, in step S205, based on the identified fault modes and their impact levels, and in conjunction with system CPU utilization, security verification coverage, and critical operation response latency indicators, a quantitative assessment of the security situation is achieved through an evaluation model. As an example, the evaluation model is as follows:

[0120] Safety Index = α * (1 – CPU Failure Rate) + β * Verification Coverage + γ * (1 - Response Latency Failure Rate) - δ * Σ (Fault Impact Level)

[0121] Where α, β, γ, and δ are weighting coefficients, preset according to the substation business scenario; CPU anomaly rate and response latency anomaly rate are obtained by comparing with historical baselines. For example, CPU anomaly rate = (current CPU utilization rate - historical CPU utilization rate baseline) / historical CPU utilization rate baseline, measuring whether computing resources are maliciously occupied. Response latency anomaly rate = (current average response latency of critical operations - historical response latency baseline) / historical response latency baseline. This value measures whether system performance has deteriorated. Verification coverage can be determined by the proportion of the number of critical processes and files that have been verified to the total number of critical processes and files that should be verified. This value measures the comprehensiveness of protective measures. Σ(fault impact level) is a weighted sum of the impact levels of all identified fault modes (e.g., defined as: low = 1, medium = 3, high = 5, urgent = 10), amplifying the negative impact of confirmed faults on the overall situation. δ is the fault impact penalty coefficient, a constant greater than 0 (e.g., δ = 0.2), used to control the amplification effect of faults on the total index. α, β, and γ are the weights of CPU, verification coverage, and response latency, respectively, and α + β + γ = 1. For example, in scenarios with high real-time requirements, γ can be relatively larger.

[0122] The system intelligently generates hardening strategies based on security indices and relevant context. Security indices, specific fault modes and their impact levels, and multi-dimensional indicators are input into the rule inference engine. The engine performs logical reasoning and intelligently matches and combines the optimal hardening strategy from the policy library based on pre-defined rules. For example, if a "process tampering" fault is detected and CPU usage spikes, the generated strategy is: "Isolate suspicious processes -> Restore process files from trusted backups -> Tighten process dynamic measurement frequency."

[0123] Finally, the hardening strategy is automatically distributed to the access control policy library, the national cryptographic algorithm key management module, and the audit log policy configuration module. Based on the changes in system indicators after the strategy is executed, the parameters and frequency of the verification mechanism are dynamically adjusted.

[0124] This invention, through a dynamic closed-loop defense system encompassing "measurement-encryption-verification-evaluation-optimization," transforms the traditional passive model reliant on fixed thresholds and periodic verification. It enables real-time perception and monitoring of host security status changes, predicts risk trends, and proactively implements hardening measures before vulnerabilities surface, achieving true intrinsic security and enhanced immunity. Furthermore, the dynamic closed-loop verification mechanism continuously optimizes protection strategies, allowing the system's defense capabilities to self-reinforce over time, resulting in an exponential increase in protection strength. Simultaneously, automation and intelligence significantly reduce manual intervention, lowering the risk of misoperation and long-term maintenance costs, achieving a balance between high-strength protection and low-cost operation.

[0125] The present invention also provides an electronic device, the device comprising: one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, wherein when the programs are executed by the processors, they implement the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described above.

[0126] The present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described above.

[0127] The present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described above.

[0128] Based on the same technical concept as the method embodiments, the present invention also provides a dynamic verification system for the security performance and information integrity of a substation monitoring host, comprising:

[0129] The Trusted Measurement Module 301 is used to perform static and dynamic measurements on the firmware, operating system, key processes and configuration files of the monitored host through the hard Trusted Module, and generate Trusted Measurement Data.

[0130] The integrity protection module 302 is connected to the trust measurement module and is used to execute access control policies based on the trust status represented by the trust measurement data, and to encrypt and protect the key processes and configuration files using national cryptographic algorithms, and generate corresponding data digests and digital signatures.

[0131] The immune enhancement module 303 is connected to the integrity protection module and is used to collect the key operation audit logs of the monitoring host, and call the national cryptographic algorithm capability of the integrity protection module to encrypt, store and sign the audit logs.

[0132] The security verification module 304 is connected to the trust measurement module, integrity protection module and immune enhancement module respectively. It is used to perform a comprehensive analysis based on the trust measurement data, digital signature and audit log verification results, combined with the original substation model, to identify potential failure modes of the system and assess their impact level.

[0133] The intelligent analysis module 305, connected to the security verification module, is used to dynamically assess the host security posture based on the identified fault modes and their impact levels, combined with system CPU utilization, security verification coverage, and key operation response latency indicators. It generates security hardening strategies and feeds these strategies back to the access control, encryption protection, and immune enhancement modules of the integrity protection module for audit log verification, so as to optimize the corresponding strategy configuration and form a closed-loop control for dynamic verification.

[0134] According to the present invention, the trust measurement module is used for:

[0135] During the startup phase of the monitoring host, the firmware and operating system are statically measured and verified through the hard trusted module.

[0136] During the host operation phase, the memory behavior and resource calls of the core processes are dynamically measured and monitored through the hard trusted module.

[0137] The integrity protection module specifically includes:

[0138] The encryption unit is used to encrypt critical process binary files and important configuration files using the SM4 algorithm;

[0139] A digest unit is used to generate a data digest of the file using the SM3 algorithm;

[0140] Signature unit, used to digitally sign data digests using the SM9 algorithm;

[0141] The immune enhancement module calls the encryption unit, digest unit, and signature unit to process the audit logs.

[0142] The security verification module includes:

[0143] Fault mode library, used to store preset three-dimensional fault modes of "architecture-component-data";

[0144] The analysis and positioning unit is used to match and compare the received trusted measurement data, digital signature verification results, and audit log verification results with the fault mode library, and output the fault location, impact radius, and repair priority.

[0145] The intelligent analysis module includes:

[0146] The situation assessment unit is used to construct a quantitative assessment model of host security situation based on system operation indicators and the output of the security verification module.

[0147] The strategy engine unit is used to generate the optimal hardening strategy through the rule reasoning engine;

[0148] The closed-loop control unit is used to send the hardening strategy to the integrity protection module and the immune enhancement module, and dynamically adjust the verification mechanism based on the feedback data.

[0149] It should be understood that the substation monitoring host security performance and information integrity dynamic verification system in this embodiment can realize all the technical solutions in the above method embodiments. The functions of each functional module can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can be referred to the relevant descriptions in the above method embodiments, which will not be repeated here.

[0150] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus (systems), electronic devices, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0151] This invention is described with reference to a flowchart of a method according to embodiments of the invention. It should be understood that each step in the flowchart and combinations of steps in the flowchart can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, generate instructions for implementing the process. Figure 1 A device for performing a specified function in one or more processes. The processor involved in each embodiment may be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a quantum computing-based data processing logic device, an artificial intelligence processor, etc., and is not limited thereto.

[0152] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 The function specified in one or more processes.

[0153] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 Steps of a specified function in one or more processes.

Claims

1. A method for dynamically verifying the security performance and information integrity of a substation monitoring host, characterized in that, The method includes the following steps: The hardware trust module performs static and dynamic measurements on the firmware, operating system, key processes, and configuration files of the monitored host to generate trust measurement data. Based on the trusted state represented by the trusted measurement data, an access control policy is executed, and the key processes and configuration files are encrypted and protected using national cryptographic algorithms to generate corresponding data digests and digital signatures. Collect key operation audit logs of the monitoring host, and use the national cryptographic algorithm to encrypt, store, and sign the audit logs; Based on the trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit logs, a comprehensive analysis is conducted in conjunction with the original substation model to identify potential failure modes of the system and assess their impact level. Based on the identified fault modes and their impact levels, and combined with system CPU utilization, security verification coverage, and key operation response latency indicators, the host security posture is dynamically assessed, a security hardening strategy is generated, and the security hardening strategy is fed back to the access control, encryption protection, and audit log verification links to optimize the corresponding strategy configuration and form a closed-loop control for dynamic verification.

2. The method according to claim 1, characterized in that, Static and dynamic measurements are performed using a hard-trusted module, including: During the startup phase of the monitoring host, the firmware and operating system are statically measured and verified through the hard trusted module. During the host operation phase, the memory behavior and resource calls of the core processes are dynamically measured and monitored through the hard trusted module.

3. The method according to claim 1, characterized in that, National cryptographic algorithms are used to encrypt and protect critical processes and configuration files, including: The SM4 algorithm is used to encrypt the binary files of critical processes and important configuration files; The data digest of the file was generated using the SM3 algorithm. The data digest is digitally signed using the SM9 algorithm.

4. The method according to claim 1, characterized in that, Based on the trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit logs, a comprehensive analysis is conducted using the original substation model to identify potential system failure modes and assess their impact level, including: The trusted measurement data, the digital signature generated by the encryption protection, and the verification results of the audit log are used as inputs to the rule reasoning engine; The rule-based reasoning engine matches and compares the input real-time data with a pre-defined three-dimensional fault mode library of "architecture-component-data", and locates specific security risks through matching logic; Based on the comparison and location results, the influence radius of the safety hazard is determined by combining the business topology relationship of the original substation model, and the repair priority is determined according to the predefined business influence weight in the fault mode library. By combining the radius of impact and the repair priority, a quantified level of fault impact is output.

5. The method according to claim 1, characterized in that, Based on the identified fault modes and their impact levels, and in conjunction with system CPU utilization, security check coverage, and critical operation response latency indicators, the host security posture is dynamically assessed, including: An assessment model is constructed to calculate the host security index, and the security index is used as the result of the host security posture assessment. The evaluation model is as follows: Safety Index = α * (1 – CPU Failure Rate) + β * Verification Coverage + γ * (1 - Response Latency Failure Rate) - δ * Σ (Fault Impact Level) Wherein, α, β, γ are weighting coefficients, which are preset according to the substation business scenario and satisfy α + β + γ = 1; CPU anomaly rate and response delay anomaly rate are obtained by comparing with historical baselines, and Σ(fault impact level) is a weighted sum of the impact levels of all identified fault modes, and the negative impact of confirmed faults on the overall situation is amplified by the penalty coefficient δ.

6. The method according to claim 1, characterized in that, Generate a security hardening strategy and form a closed-loop control system with dynamic verification, including: The host security posture assessment results and the fault mode library are input into the rule reasoning engine to intelligently match the optimal security hardening strategy. The optimal security hardening strategy is automatically distributed to the access control policy library, the national cryptographic algorithm key management module, and the audit log policy configuration module. The parameters and frequency of the verification mechanism are dynamically adjusted based on changes in system metrics after the strategy is implemented.

7. A dynamic verification system for the security performance and information integrity of a substation monitoring host, characterized in that, include: The Trusted Measurement Module is used to perform static and dynamic measurements on the firmware, operating system, critical processes, and configuration files of the monitored host through the Hard Trusted Module, and generate trusted measurement data. The integrity protection module, connected to the trust measurement module, is used to execute access control policies based on the trust status represented by the trust measurement data, and to encrypt and protect the key processes and configuration files using national cryptographic algorithms, generating corresponding data digests and digital signatures. An immune enhancement module, connected to the integrity protection module, is used to collect key operation audit logs of the monitoring host and call the national cryptographic algorithm capability of the integrity protection module to encrypt, store and sign the audit logs. The security verification module is connected to the trust measurement module, integrity protection module and immune enhancement module respectively. It is used to perform a comprehensive analysis based on the trust measurement data, digital signature and audit log verification results, combined with the original substation model, to identify potential failure modes of the system and assess their impact level. The intelligent analysis module, connected to the security verification module, is used to dynamically assess the host security posture based on the identified fault modes and their impact levels, combined with system CPU utilization, security verification coverage, and key operation response latency indicators. It generates security hardening strategies and feeds these strategies back to the access control, encryption protection, and immune enhancement modules of the integrity protection module for audit log verification, so as to optimize the corresponding strategy configuration and form a closed-loop control for dynamic verification.

8. The system according to claim 7, characterized in that, The trust measurement module is specifically used for: During the startup phase of the monitoring host, the firmware and operating system are statically measured and verified through the hard trusted module. During the host operation phase, the memory behavior and resource calls of the core processes are dynamically measured and monitored through the hard trusted module.

9. The system according to claim 7, characterized in that, The integrity protection module includes: The encryption unit is used to encrypt critical process binary files and important configuration files using the SM4 algorithm; A digest unit is used to generate a data digest of the file using the SM3 algorithm; Signature unit, used to digitally sign data digests using the SM9 algorithm; The immune enhancement module calls the encryption unit, digest unit, and signature unit to process the audit logs.

10. The system according to claim 7, characterized in that, The security verification module includes: Fault mode library, used to store preset three-dimensional fault modes of "architecture-component-data"; The analysis and positioning unit is used to match and compare the received trusted measurement data, digital signature verification results and audit log verification results with the fault mode library, and locate specific security risks through matching logic; The result output unit is used to determine the impact radius of the safety hazard based on the comparison and positioning results and the business topology relationship of the original substation model. At the same time, it determines the repair priority according to the predefined business impact weight in the fault mode library. Combining the impact radius and the repair priority, it outputs the quantified fault impact level.

11. The system according to claim 7, characterized in that, The intelligent analysis module includes: The situation assessment unit is used to construct a quantitative assessment model of host security situation based on system operation indicators and the output of the security verification module, and obtain the host security situation assessment result; the assessment model is as follows: Safety Index = α * (1 – CPU Failure Rate) + β * Verification Coverage + γ * (1 - Response Latency Failure Rate) - δ * Σ (Fault Impact Level) Wherein, α, β, γ are weighting coefficients, which are preset according to the substation business scenario and satisfy α + β + γ = 1; CPU anomaly rate and response delay anomaly rate are obtained by comparing with historical baselines, and Σ(fault impact level) is a weighted sum of the impact levels of all identified fault modes, and the negative impact of confirmed faults on the overall situation is amplified by the penalty coefficient δ. The hardening strategy generation unit is used to input the host security posture assessment results and the fault mode library into the rule reasoning engine to intelligently match the optimal security hardening strategy; The closed-loop control unit is used to send the optimal security hardening strategy to the integrity protection module and the immune enhancement module, and dynamically adjust the parameters and frequency of the verification mechanism according to the changes in system indicators after the strategy is executed.

12. An electronic device, characterized in that, The device includes: one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, wherein when the programs are executed by the processors, they implement the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described in any one of claims 1 to 6.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described in any one of claims 1 to 6.

14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the dynamic verification method for the security performance and information integrity of the substation monitoring host as described in any one of claims 1 to 6.

15. A method for constructing a dynamic verification system for the security performance and information integrity of a substation monitoring host, characterized in that, Includes the following steps: Build an independent and controllable security foundation platform and establish a hard and reliable module technology framework adapted to substation scenarios to achieve reliable static measurement, dynamic measurement and dynamic management of key resources, processes and configuration files of monitoring hosts and access control policies. An information integrity protection system based on Chinese cryptographic algorithms is constructed and integrated on the security base platform. The system uses Chinese cryptographic algorithms to encrypt and protect the binary files of key processes and important configuration files of the monitoring host. It also combines data digest algorithms, digital signature technology and database key information verification technology to ensure the integrity of host information. Construct an immune enhancement system based on an autonomous and controllable strategy, integrating the encryption verification capabilities, key management mechanism, and audit log security management module of the information integrity protection system to form a system-level security hardening strategy and standardized configuration management scheme; A safety performance verification system based on the original substation model is constructed, which connects the safety base platform, information integrity protection system and immune enhancement system. It is used to identify potential failure modes of the system and their impact level on overall safety, and to locate safety hazards based on key failure modes and access control rules. An intelligent analysis module is constructed and connected to the security performance verification system. It is used to dynamically evaluate the host security status based on system CPU utilization, verification rate, and response time indicators, and generate reinforcement strategies in combination with the fault mode library to continuously optimize the verification mechanism. The optimization strategies are then fed back to the information integrity protection system and the immune enhancement system.

Citation Information

Cited By

  • Ship navigation system fault injection hardware-in-the-loop test method, system and equipment

    CN122239686A