Commercial password application construction method and device for DCS (Distributed Control System) of thermal power plant
By constructing a multi-dimensional cryptographic requirement model and a five-layer defense-in-depth system for the DCS system of thermal power plants, the problem of insufficient dynamic risk assessment in existing technologies has been solved, enabling real-time key management and emergency response, and improving the system's security protection capabilities and response efficiency.
Patent Information
- Application Number
- CN202511756332.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-26
- Publication Date
- 2026-02-24
AI Technical Summary
The lack of dynamic risk assessment and multi-level emergency response mechanisms in the commercial cryptographic applications of existing thermal power plant DCS systems leads to delayed key updates, expanded protection blind spots, and an inability to respond to advanced persistent threats in a timely manner, thus affecting the system's real-time defense capabilities.
By collecting information on the physical environment, network topology, and equipment configuration of the DCS system, we can identify existing cryptographic application gaps, construct a multi-dimensional cryptographic requirement model, design a five-layer defense-in-depth system, configure cryptographic products that coordinate SM2/SM4 algorithms, calculate the comprehensive risk value in real time and trigger the key update process, establish a key hierarchy division mechanism, and realize dynamic risk assessment and emergency response.
It enhances the DCS system's real-time protection capabilities against key leakage and encryption failure, ensuring that the system can respond and recover quickly in the face of advanced persistent threats, meeting the requirements of GB/T39786-2021 Level 3 Security Protection, and reducing the impact of security incidents.
Smart Images

Figure CN121567408A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of control system technology, and in particular to a method and apparatus for constructing commercial cryptographic applications for DCS systems in thermal power plants. Background Technology
[0002] As a crucial component of the nation's critical information infrastructure, the DCS system of thermal power plants is widely used for real-time monitoring and automated control of the power production process. With increasing security requirements for industrial control systems, the application of commercial cryptography in the power industry has evolved from basic encryption functions to a multi-layered collaborative protection system. Specifically, existing technologies utilize the collaborative operation of physical access control, network communication encryption, and device authentication to construct a cryptographic application framework covering the DCS system's ring network unit server area, historical database area, and operating terminals. Based on the GB / T39786-2021 Level 3 security compliance requirements, related technologies cover the entire process from security baseline assessment to compliance verification, including key aspects such as vulnerability scanning, cryptographic product selection, and phased deployment. However, existing cryptographic application systems directly employ static key management and a single protection layer architecture, lacking a dynamic risk assessment and multi-level emergency response linkage mechanism. This may lead to delayed key updates, expanded protection blind spots, or the inability to promptly cut off risk sources when encountering abnormal logins, thus affecting the DCS system's real-time defense capabilities against advanced persistent threats.
[0003] Specifically, existing technologies typically employ fixed-cycle key update strategies, but lack real-time risk assessment models, making it impossible to trigger key updates based on dynamic indicators such as abnormal login frequency, device health, and network attack intensity. Furthermore, there are standard compatibility gaps in the collaborative protection between physical layer access control systems and network layer IPsec / SSL VPNs, and the two-factor authentication of device-layer smart cryptographic keys and bastion hosts lacks algorithmic compatibility with application-layer signature verification servers. While traditional protection solutions have made progress in compliance, they suffer from shortcomings such as reliance on manual judgment for security incident response, response times exceeding one hour for level four incidents, and a lack of quantitative verification for six key indicators, including key synchronization success rate. This makes it difficult for the system to complete risk containment and business recovery within 30 minutes in the event of key leakage or encryption failure, potentially leading to major security incidents with over 24 hours of business interruption in the DCS core control area. Summary of the Invention
[0004] The present invention aims to at least partially solve one of the technical problems in the related art.
[0005] Therefore, the first objective of this invention is to propose a method for constructing commercial cryptographic applications for DCS systems in thermal power plants.
[0006] The second objective of this invention is to provide a commercial cryptographic application construction device for DCS systems in thermal power plants.
[0007] The third objective of this invention is to provide an electronic device.
[0008] The fourth objective of this invention is to provide a computer-readable storage medium.
[0009] The fifth objective of this invention is to provide a computer program product.
[0010] To achieve the above objectives, a first aspect of the present invention proposes a method for constructing commercial cryptographic applications for DCS systems in thermal power plants, comprising: Step 1: Collect information on the physical environment, network topology, equipment configuration, and business data flow of the DCS system; identify existing cryptographic application gaps; and generate a risk assessment report. Step 2: Based on the risk assessment report, construct a multi-dimensional cryptographic requirement model for physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing, and output a structured requirement list; Step 3: Based on the requirements list, design a five-layer defense-in-depth system consisting of the physical layer, network layer, device layer, application layer, and data layer; configure cryptographic products that coordinate SM2 / SM4 algorithms; and establish a key level division mechanism. Step 4: By collecting data on abnormal login frequency, device health, and network attack intensity in real time, calculate the comprehensive risk value and trigger the key update process according to the preset threshold, while simultaneously executing the emergency response plan and log auditing.
[0011] Optionally, the collection of information on the physical environment, network topology, device configuration, and service data flow of the DCS system also includes: Step 11: Deploy vulnerability scanning equipment to collect network device configuration information, business data flow diagrams and device model parameters, and generate an assessment report containing 12 high-risk items and 18 medium-risk items according to the Level 3 requirements of GB / T39786-2021. Step 12 focuses on recording the current status of the physical computer room access control system and the network boundary firewall policy, and outputs the GM / T0036-2014 standard adaptation requirements for the access control system and suggestions for IPsec / SSL VPN deployment locations.
[0012] Optionally, the step of constructing a multi-dimensional cryptographic requirement model based on the risk assessment report further includes: Step 21: Calculate the implementation priority index P for each dimension of requirements using a dynamic weighted algorithm, as shown in the following formula:
[0013] in, It is a comprehensive weighting coefficient based on risk and business importance. It is a weighting coefficient for implementation costs. It is the attenuation coefficient due to time urgency. Indicates the level of safety risk. Indicates the influence range coefficient. Indicates implementation complexity. This underscores the urgency of compliance; Step 22: Link network communication encryption requirements with data storage protection requirements to ensure compatibility between transmission encryption and storage encryption algorithms.
[0014] Optionally, the five-layer defense-in-depth system design further includes: Step 31: Configure the server cryptographic machine to support SM2 / SM3 / SM4 algorithms and key generation rate. pairs / second; Step 32: Establish a two-factor authentication scheme for the smart password key and the bastion host. The smart password key must be certified by GM / T0027-2014 and support the USB interface.
[0015] Optionally, the calculation of the comprehensive risk value and triggering the key update process further includes: Step 41: Calculate the comprehensive risk value using the formula. The formula is as follows:
[0016] in, It is the weighting coefficient for the frequency of abnormal logins. It is a weighting coefficient for equipment health. It is a weighting coefficient for the intensity of network attacks. It is the attenuation coefficient. This indicates the number of abnormal logins within a unit of time. This indicates the device configuration hash deviation rate. Indicates the level of cyberattack threat. It is the time interval since the most recent risk event; Step 42: When an abnormal login event is detected, the server cryptographic machine is invoked to generate a new SM4 session key, which is synchronized to the historical database server and operator station through the SSLVPN encrypted channel. At the same time, the SM2 algorithm is used to digitally sign the key update record.
[0017] Optionally, the method further includes: Step 5, the phased deployment and implementation is divided into three phases: the core control area, the non-control area, and the management information area. After each phase of deployment, a 72-hour stability test is performed to verify the key synchronization success rate and key update response time. The operation of cryptographic devices is performed through a dedicated laptop, and audit logs are kept for key steps.
[0018] To achieve the above objectives, a second aspect of the present invention provides a commercial cryptographic application construction apparatus for a thermal power plant DCS system, comprising: The information collection and risk identification module is used to collect information on the physical environment, network topology, equipment configuration and business data flow of the DCS system, identify existing cryptographic application gaps and generate risk assessment reports. The multi-dimensional cryptographic requirement modeling module is used to construct a multi-dimensional cryptographic requirement model based on the risk assessment report, including physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing, and output a structured requirement list. The five-layer defense-in-depth system design module is used to design a five-layer defense-in-depth system consisting of the physical layer, network layer, device layer, application layer, and data layer in conjunction with the requirements list, configure cryptographic products that coordinate SM2 / SM4 algorithms, and establish a key level division mechanism. The risk calculation and key update triggering module is used to calculate a comprehensive risk value by collecting data on abnormal login frequency, device health and network attack intensity in real time, and trigger the key update process according to a preset threshold, while simultaneously executing emergency response plans and log auditing.
[0019] To achieve the above objectives, a third aspect of the present invention provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of the first aspects.
[0020] To achieve the above objectives, a fourth aspect of the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of the first aspects.
[0021] To achieve the above objectives, a fifth aspect of the present invention provides a computer program product that, when executed by a processor, implements the method described in any one of the first aspects.
[0022] This invention provides a method, apparatus, electronic device, and storage medium for constructing commercial cryptographic applications for DCS systems in thermal power plants. It enables the construction of multi-level commercial cryptographic applications for DCS systems in thermal power plants. Through dynamic risk assessment, it drives key management and hierarchical emergency response, effectively improving the system's real-time protection and handling capabilities against security threats such as key leakage and encryption failure, and ensuring compliance with the Level 3 Security Protection Requirements of GB / T39786-2021.
[0023] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description
[0024] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein: Figure 1 This is a flowchart illustrating a method for constructing commercial cryptographic applications for a DCS system in a thermal power plant, as provided in an embodiment of the present invention. Figure 2 This is a schematic diagram of the overall method flow provided in the embodiments of the present invention; Figure 3 This is a schematic diagram of the identity authentication process provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of a three-level key system provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of cryptographic application deployment provided in an embodiment of the present invention; Figure 6 This is a schematic diagram of the cryptographic security processing mechanism provided in an embodiment of the present invention; Figure 7 This is a schematic diagram of the password security emergency response process provided in an embodiment of the present invention; Figure 8 This is a schematic diagram of the emergency response process for security incidents provided in an embodiment of the present invention; Figure 9 This is a schematic diagram of a commercial cryptographic application construction device for a thermal power plant DCS system, provided in an embodiment of the present invention. Detailed Implementation
[0025] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.
[0026] Example 1 This invention provides a method for constructing commercial cryptographic applications for DCS systems in thermal power plants. Figure 1 This is a flowchart illustrating a method for constructing commercial cryptographic applications for a DCS system in a thermal power plant, as provided in an embodiment of the present invention. Figure 1 As shown, the method includes the following steps: Step 1: Collect information on the physical environment, network topology, equipment configuration, and business data flow of the DCS system, identify existing cryptographic application gaps, and generate a risk assessment report.
[0027] In one embodiment of the present invention, the system constructs a system security baseline by comprehensively collecting information on the physical environment, network topology, device configuration, and business data flow of the DCS system, providing data support for subsequent cryptographic application vulnerability identification and risk assessment. This step is technically implemented using a combination of automated scanning and manual verification. Vulnerability scanning equipment is deployed to conduct in-depth probing of key areas of the DCS system (such as the ring network server area, the AB network historical database area, and the engineer / operator area), collecting multi-dimensional data including network device configuration information, business data flow diagrams, and device model parameters. During the data collection process, the system must support recording the status of the physical data center access control system and extracting network boundary firewall policies to ensure comprehensive coverage of the existing security architecture.
[0028] Specifically, the system performs structured processing and risk identification on the collected data according to the Level 3 security requirements of GB / T39786-2021. The assessment results must clearly list 12 high-risk items and 18 medium-risk items, covering key areas such as physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing. Among these, the access control system must comply with the GM / T0036-2014 standard, and the network communication encryption must clearly specify the deployment location of IPsec / SSL VPN and the application scenarios of SM2 / SM4 algorithms. The assessment process also needs to output compatibility recommendations for device models and cryptographic products to ensure feasibility in the subsequent integration phase.
[0029] This step is applicable to the initial stage of security upgrades for DCS systems in thermal power plants, providing input for modeling cryptographic application requirements. By collecting and analyzing the actual operating status of the DCS system, gaps in existing cryptographic applications can be identified, such as the lack of two-factor authentication or the absence of integrity checks on sensitive data, thus providing data support for building a defense-in-depth system.
[0030] In one embodiment of the invention, this step ensures the accuracy and comprehensiveness of cryptographic application gap identification through systematic data collection and standardized evaluation. The evaluation results need to be verified through a 72-hour stability test to ensure their reliability in actual deployment. This step provides key input for subsequent cryptographic requirement modeling, scheme design, and deployment, and is a fundamental link in the entire commercial cryptographic application construction process, possessing significant practical value and technical support.
[0031] Further, step 1 includes: Step 11: Deploy vulnerability scanning equipment to collect network device configuration information, business data flow diagrams, and device model parameters. Generate an assessment report containing 12 high-risk items and 18 medium-risk items in accordance with the Level 3 requirements of GB / T39786-2021.
[0032] In one embodiment of the present invention, the system comprehensively collects the physical environment, network topology, equipment configuration, and business data flow of the DCS system of a thermal power plant by deploying vulnerability scanning equipment, in order to identify gaps in the application of commercial cryptography in the existing security architecture. The technical implementation of this step is based on the Level 3 security requirements in GB / T39786-2021 "Information Security Technology - General Technical Requirements for Commercial Cryptographic Applications", and performs in-depth scanning and analysis on key areas of the DCS system (such as the ring network unit server area, the AB network historical database area, and the engineer / operator area).
[0033] Specifically, vulnerability scanning devices collect network device configuration information (such as firewall policies, routing tables, and ACL rules), business data flow diagrams (including data sources, transmission paths, and storage nodes), and device model parameters (such as hardware version, firmware version, and interface type) through a combination of active probing and passive monitoring. The collected data is then input into an evaluation engine, which performs vulnerability identification and risk assessment of the system based on the compliance requirements for cryptographic applications in GB / T39786-2021. The evaluation results generate a structured evaluation report containing 12 high-risk items and 18 medium-risk items. High-risk items mainly involve issues such as unenabled cryptographic algorithms, missing authentication mechanisms, and non-standard key management, while medium-risk items include potential vulnerabilities such as incomplete configuration and unencrypted logs.
[0034] In this embodiment of the invention, the evaluation process should focus on recording the current status of the physical data center access control system, including whether it supports the GM / T0036-2021 standard "Information Security Technology - Technical Requirements for Cryptographic Applications in Electronic Access Control Systems", and whether the network boundary firewall policy has the conditions for IPsec / SSL VPN deployment. The evaluation report should also output the specific requirements for the access control system to adapt to the GM / T0036-2014 standard, as well as recommendations for the deployment location of the IPsec / SSL gateway, ensuring direct relevance to the five dimensions of requirements in the subsequent requirements analysis phase.
[0035] This step applies to the baseline assessment phase of a thermal power plant's DCS system before commercial cryptographic upgrades, providing data support for subsequent cryptographic product selection, deployment planning, and compliance verification. The assessment results must be verified through a 72-hour stability test to ensure the integrity and accuracy of the collected data, laying the foundation for building a defense-in-depth system.
[0036] The technical value of this step lies in systematically identifying the weaknesses of the DCS system in commercial cryptographic applications through a standardized vulnerability scanning and risk assessment process. This provides accurate input for subsequent cryptographic requirement modeling and protection scheme design, thereby improving the overall system's cryptographic application compliance and security.
[0037] Step 12 focuses on recording the current status of the physical computer room access control system and the network boundary firewall policy, and outputs the GM / T0036-2014 standard adaptation requirements for the access control system and suggestions for IPsec / SSL VPN deployment locations.
[0038] Specifically, in one embodiment of the present invention, the core task of the system security baseline assessment is to comprehensively collect information on the physical environment, network topology, equipment configuration, and business data flow of the DCS system in a thermal power plant, identify cryptographic application vulnerabilities in the existing security architecture, and output the GM / T0036-2014 standard adaptation requirements for the access control system and recommendations for IPsec / SSL VPN deployment locations. The technical implementation of this step is based on structured scanning and analysis of key areas of the DCS system, including the ring network unit server area, the AB network historical database area, and the engineer / operator area. By deploying vulnerability scanning equipment, the system can automatically collect network device configuration information, business data flow diagrams, and device model parameters, generating an assessment report that meets the Level 3 requirements of GB / T39786-2021, which includes 12 high-risk items and 18 medium-risk items.
[0039] In terms of physical access control, the current configuration of the data center access control system should be recorded, including the access controller model, card reader type, and permission management mechanism. It should be assessed whether the system meets the requirements of the GM / T0036-2014 standard regarding authentication, access control, logging, and auditing. If any non-compliance is found, adaptation recommendations should be provided, such as upgrading to a national cryptographic access control system that supports SM2 digital certificate authentication, to ensure the immutability and traceability of access control records.
[0040] In terms of network communication encryption, detailed policy configurations for the A / B network boundary firewalls need to be recorded, including inbound / outbound rules, IP address whitelists, and port opening status. Based on the data transmission requirements between the DCS system's control and non-control zones, the confidentiality and integrity protection gaps in the communication links are analyzed to determine the deployment location of the IPsec / SSL VPN. For example, an IPsec integrated security gateway can be deployed at the boundary between the control and non-control zones, using the SM2 algorithm for authentication and the SM4 algorithm for data encryption, ensuring communication latency is controlled within 50ms to meet the performance requirements of real-time control services.
[0041] The output of this step will serve as the input for the subsequent requirements analysis phase. The accuracy and completeness of the evaluation data will be verified through a 72-hour stability test to ensure that the design of the subsequent protection scheme has a sufficient realistic basis and compliance orientation.
[0042] Step 2: Based on the risk assessment report, construct a multi-dimensional cryptographic requirement model for physical access control, network communication encryption, device identity authentication, data storage protection, and operation and maintenance auditing, and output a structured requirement list.
[0043] In one embodiment of the present invention, a multi-dimensional cryptographic requirement model for the DCS system of thermal power plants is constructed based on the output risk assessment report. The model aims to systematically identify cryptographic application requirements from five dimensions: physical access control, network communication encryption, equipment authentication, data storage protection, and operation and maintenance auditing. It also outputs a structured list of requirements to provide accurate input for the design of subsequent protection schemes.
[0044] Specifically, this modeling process employs a layered, structured modeling approach, combining the physical deployment, network architecture, device types, and business processes of the DCS system to analyze cryptographic application gaps across various dimensions. For example, the physical access control dimension requires clarifying whether the access control system complies with the GM / T0036-2014 standard; the network communication encryption dimension requires assessing the confidentiality requirements of data transmission between the controlled and non-controlled areas based on the AB network topology, determining the deployment location of IPsec / SSL VPN, and the application scenarios of SM2 / SM3 algorithms. The device authentication dimension, combined with the access methods of maintenance terminals, proposes a two-factor authentication scheme of "smart cryptographic key + bastion host," directly related to USBKey selection. The data storage protection dimension, targeting sensitive fields in historical databases, clarifies the technical indicators for SM4 encryption and SM3 integrity verification, and synchronizes relevant policies to the lifecycle policy library of the key management system. The maintenance operation audit dimension requires defining the log collection scope and integrity protection mechanism to ensure that audit data meets the real-time analysis requirements of the security operations center.
[0045] In this embodiment of the invention, a dynamic weighted algorithm is introduced into the demand model to prioritize the demands of each dimension. The formula is as follows:
[0046] in, This indicates the priority index for implementing requirements (range 0-10). Indicates the level of safety risk (levels 1-5). Indicates the influence range coefficient (levels 1-3, where 3 represents the core control area). Indicates the implementation complexity (levels 1-4). Indicates the urgency of compliance (measured in months remaining until the regulatory deadline). , , This algorithm achieves scientific prioritization of needs and rational allocation of resources by quantifying security risks, scope of impact, implementation difficulty, and compliance time pressure.
[0047] It is clear that this model is suitable for the early requirements analysis phase of building a commercial cryptographic system for DCS systems in thermal power plants, especially for complex industrial control systems involving multi-level protection, multi-algorithm collaboration, and multi-device integration. Through structured output, it can guide subsequent deployments of national cryptographic access control systems at the physical layer, configuration of IPsec / SSL gateways at the network layer, implementation of two-factor authentication at the device layer, deployment of SM4 encryption and SM3 verification at the data layer, and establishment of log integrity protection mechanisms at the operation and maintenance layer.
[0048] In this embodiment of the invention, this step significantly improves the accuracy of cryptographic requirement identification and the operability of implementation through systematic modeling and quantitative priority calculation, providing clear technical guidance for the subsequent design of a defense-in-depth system. At the same time, it ensures the compliance of each cryptographic application link with the GB / T39786-2021 Level 3 security standard, and enhances the cryptographic protection capability of the DCS system in the face of new attack methods.
[0049] Further, step 2 includes: Step 21: Calculate the implementation priority index P of each dimension of requirements using a dynamic weighted algorithm.
[0050] In one embodiment of the present invention, a dynamic weighted algorithm is used to prioritize the requirements across five dimensions: physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing. This results in a structured list of requirements to guide subsequent protection scheme design. The algorithm quantifies the security risk level, scope of impact, implementation complexity, and compliance urgency of each dimension to comprehensively calculate a requirement implementation priority index. Its formula is:
[0051] in, This represents the priority index for implementing requirements, with a value ranging from 0 to 10. The higher the value, the higher the priority for implementing requirements in that dimension. The value indicates the safety risk level, assessed according to the GB / T39786-2021 standard, with a range of 1-5, where 5 represents the highest risk. This represents the scope of influence coefficient, which is determined based on the number of DCS system components to be covered, and ranges from 1 to 3, with 3 indicating coverage of the core control area. The value represents the implementation complexity, taking into account both technical difficulty and resource investment. The value ranges from 1 to 4, with 4 being the highest complexity. Indicates the urgency of compliance, measured in months remaining until the regulatory deadline, with a value ranging from 0.5 to 3, where 3 represents the most urgent requirement. Adjustment coefficient. , , By calibrating with historical project data, we ensure the adaptability and accuracy of the algorithm in different scenarios.
[0052] Specifically, the system first obtains current status data for various dimensions based on the evaluation results, including the integrity of the physical access control system, the topology and algorithm compatibility of network communication encryption, the two-factor authentication requirements for device identification, the distribution of encrypted fields and integrity verification mechanisms for data storage protection, and the scope and verification cycle of log collection for operation and maintenance auditing. Then, this data is mapped to... , , , The specific values are substituted into the formula to calculate each dimension. This value allows for the quantitative ranking of demands.
[0053] This step plays a crucial role in the overall technical solution, bridging the gap between previous and subsequent steps. Its output directly influences the design direction of subsequent protection schemes, ensuring that resource investment matches security requirements. Through a dynamic weighting mechanism, the system can adjust priorities based on real-time risk changes, improving the scientific nature and response efficiency of cryptographic application deployment.
[0054] Step 22: Link network communication encryption requirements with data storage protection requirements to ensure compatibility between transmission encryption and storage encryption algorithms.
[0055] In one embodiment of the present invention, the coordinated design of network communication encryption requirements and data storage protection requirements is a key step in constructing a commercial cryptographic application system for a DCS system. This step systematically identifies and quantifies cryptographic application requirements from five aspects—physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing—through multi-dimensional cryptographic requirement modeling. Among these, the coordinated mechanism between network communication encryption and data storage protection is particularly crucial. In the network communication dimension, based on the AB network topology, the system assesses the confidentiality requirements of data transmission between the controlled and non-controlled areas, and specifies the deployment of an IPsec / SSL integrated security gateway at the AB network boundary. The SM2 algorithm is used for authentication, and the SM4 algorithm is used for data encryption, ensuring that communication latency is controlled within 50ms. In the data storage dimension, for authentication and audit data involved in the historical database, the system specifies the use of the SM4 algorithm for field-level encryption, combined with the SM3 algorithm for integrity verification, to prevent data tampering and leakage.
[0056] To ensure compatibility between transmission and storage encryption algorithms, the system incorporates an algorithm consistency verification mechanism during the requirements modeling phase. Specifically, the SM4 encryption algorithm used in the network communication layer must maintain consistency with the SM4 encryption algorithm in the data storage layer in terms of key format, encryption mode (e.g., CBC, ECB, CTR), and padding method (e.g., PKCS7) to ensure data decryptability and consistency during transmission and storage. Furthermore, the hash value generated by the SM3 integrity verification algorithm during the data storage phase must be verified using the same algorithm during the network communication phase to guarantee end-to-end data consistency.
[0057] Specifically, the system prioritizes the requirements across various dimensions using a dynamic weighted algorithm. The linked requirements for network communication encryption and data storage protection are given a higher weight in the impact range coefficient S, especially when it covers the core control area, where S is set to 3. This is combined with the security risk level R (levels 1-5) and implementation complexity C (levels 1-4) using the formula... Calculate the priority index P to ensure that high-risk, high-impact collaborative requirements are prioritized in the solution design. The structured requirements list output in this step will directly guide the construction of the defense-in-depth system, especially in the co-design of encryption algorithms at the network and data layers, providing clear technical input for subsequent selection and deployment of cryptographic devices.
[0058] Step 3: Based on the requirements list, design a five-layer defense-in-depth system consisting of the physical layer, network layer, device layer, application layer, and data layer; configure cryptographic products that use SM2 / SM4 algorithms in tandem; and establish a key hierarchy division mechanism.
[0059] Specifically, this invention constructs a five-layer defense-in-depth system for DCS systems in thermal power plants, encompassing "physical-network-equipment-application-data," and combines commercial cryptographic algorithms SM2 and SM4 to achieve cross-layer collaborative protection. The core of this step lies in enhancing the overall security capabilities of the system through layered deployment of cryptographic technologies, ensuring that security mechanisms such as identity authentication, data encryption, and integrity protection are present at different levels.
[0060] In this embodiment of the invention, the physical layer deploys a national cryptographic access control system and video surveillance equipment conforming to the GM / T0036-2014 standard to achieve physical access control of the computer room and prevent unauthorized personnel from accessing critical infrastructure. At the network layer, an IPsec / SSL integrated security gateway is deployed at the AB network boundary, using the SM2 algorithm for identity authentication and the SM4 algorithm for data encryption, ensuring communication latency is controlled within 50ms to meet the high real-time requirements of the DCS system. At the device layer, a national cryptographic bastion host enables two-factor authentication for maintenance personnel, where the smart password key must conform to the GM / T0027-2014 certification standard and support a USB interface to ensure the security and compliance of device access.
[0061] The application layer employs a signature verification server to digitally sign operation commands using SM2, preventing tampering or forgery and ensuring the integrity and non-repudiation of control commands. The data layer implements SM4 encryption and SM3 integrity verification on sensitive fields in the historical database, ensuring data confidentiality and tamper-proof capabilities during storage. The server's cryptographic machine must support SM2 / SM3 / SM4 algorithms, and its key generation rate must be no less than 100 pairs / second to meet the key management requirements of high-concurrency scenarios.
[0062] Furthermore, this step ensures the consistency and compatibility of communication encryption and command signing in key usage through a collaborative algorithm mechanism at the network and application layers. Simultaneously, the key hierarchy mechanism is closely integrated with the key management system, enabling centralized key management and dynamic updates. This step plays a crucial role in the overall technical solution, providing a structured and standardized protection foundation for subsequent deployment, key management, and emergency response, significantly enhancing the DCS system's defense depth and response efficiency against threats such as network attacks and unauthorized access.
[0063] Furthermore, step 3 includes: Step 31: Configure the server cryptographic machine to support SM2 / SM3 / SM4 algorithms and key generation rate. Pairs / second.
[0064] Specifically, the server cryptographic machine is configured to support SM2 / SM3 / SM4 algorithms and have a key generation rate of [missing information]. The speed per second is a crucial step in realizing commercial cryptographic applications in DCS systems. The technical implementation of this step is based on the certification requirements for commercial cryptographic devices stipulated in the national cryptographic standard GM / T0027-2014, ensuring that the selected server cryptographic machine possesses the algorithm support capabilities and performance indicators certified by the State Cryptography Administration.
[0065] In this embodiment of the invention, the server cryptographic machine needs to have hardware-level SM2, SM3, and SM4 algorithm acceleration modules to achieve efficient processing of asymmetric encryption, hash calculation, and symmetric encryption. The SM2 algorithm is used for digital signatures and identity authentication, SM3 for data integrity verification, and SM4 for data encryption. The server cryptographic machine accelerates the algorithms through a dedicated cryptographic coprocessor or FPGA, thereby maintaining stable performance even under high-concurrency scenarios. Key generation rate Pairs / second refers to the number of SM2 key pairs (including public and private keys) that the server's cryptographic machine can generate and output within a unit of time. This metric directly affects the system's response efficiency in scenarios such as key updates and identity authentication.
[0066] Optionally, the integration process of the server cryptographic machine needs to be adapted to the physical architecture, network topology, and business processes of the DCS system. Before deployment, compatibility testing must be conducted to verify that the communication latency between the device and the DCS system is less than 50ms, ensuring real-time requirements. Furthermore, the integration process requires completion of hardware wiring, driver installation, interface development, and key synchronization mechanism configuration to achieve seamless integration with the key management platform.
[0067] Furthermore, this step plays a crucial role in the overall technical solution. On one hand, its output provides the hardware foundation for the deployment and implementation phase, ensuring that cryptographic devices have sufficient processing power; on the other hand, its performance indicators directly affect the real-time monitoring capabilities of the security operations center and the dynamic response efficiency of the key management system. By meeting... With a key generation rate of / second, the system can quickly generate new keys in the face of sudden security events, thereby effectively reducing the security risks caused by key leakage and improving the overall cryptographic application performance and security of the DCS system.
[0068] Step 32: Establish a two-factor authentication scheme for the smart password key and the bastion host. The smart password key must be certified by GM / T0027-2014 and support the USB interface.
[0069] Specifically, constructing a two-factor authentication scheme of "smart cryptographic key + bastion host" is a crucial step in achieving identity verification for DCS system operations and maintenance. This scheme authenticates the smart cryptographic key based on the national cryptographic standard GM / T0027-2014, ensuring it possesses the hardware security module (HSM) functionality compliant with national commercial cryptography standards. This includes, but is not limited to, support for the SM2 asymmetric encryption algorithm, implementation of the SM3 hash algorithm, execution capability of the SM4 symmetric encryption algorithm, and physical connection and driver compatibility of the USB interface. The bastion host, as the unified entry point for operations and maintenance, needs to integrate the smart cryptographic key's authentication interface to achieve hardware token-based identity verification and operation authorization.
[0070] In this embodiment of the invention, the smart password key is physically connected to the bastion host via a USB interface. Upon receiving a user login request, the bastion host first verifies the user's local password, then invokes the SM2 algorithm module within the smart password key to complete digital signature and identity authentication. During authentication, the bastion host sends a random challenge code to the smart password key. The smart password key signs the challenge code using a pre-set SM2 private key and returns the signature result to the bastion host for SM2 public key verification. If the verification passes, the user is allowed access to the system interface; otherwise, access is denied and a failure log is recorded.
[0071] Furthermore, the smart key must support a key generation rate of at least 100 pairs / second. The latency should be controlled within 50ms (pairs / second) to meet the performance requirements of high-concurrency operation and maintenance scenarios. This ensures the real-time nature of the authentication process and a good user experience. Furthermore, the smart key's storage module must support the SM4 encryption algorithm to protect user private keys and sensitive configuration information, while also supporting SM3 integrity verification to prevent device firmware tampering.
[0072] It is clear that this two-factor authentication mechanism is deployed at the engineer and operator stations of the DCS system as a mandatory authentication method for maintenance personnel to access the core control area. The bastion host, as the unified maintenance entry point, achieves strong identity binding and behavior auditing for all maintenance operations through an authentication interface integrated with smart password keys. This mechanism effectively prevents unauthorized users from bypassing authentication through weak passwords or network sniffing, thereby enhancing the access control strength of the DCS system at both the physical and logical levels.
[0073] This step plays a crucial role in the overall technical solution, directly supporting the identity binding and operation auditing functions in key management, while providing the security operations center with a trusted source of user identities. By introducing smart cryptographic keys compliant with national cryptographic standards, the system upgrades from traditional password authentication to hardware + password two-factor authentication, significantly enhancing the security protection capabilities of the DCS system at the operation and maintenance level, and meeting the mandatory requirements for identity authentication in GB / T39786-2021 Level 3 security requirements.
[0074] Step 4: By collecting data on abnormal login frequency, device health, and network attack intensity in real time, calculate the comprehensive risk value and trigger the key update process according to the preset threshold, while simultaneously executing the emergency response plan and log auditing.
[0075] In one embodiment of the present invention, the system integrates a log auditing system and a key management platform to construct an emergency response mechanism based on the classification of cryptographic security events, thereby achieving real-time monitoring and automated handling of the commercial cryptographic application status of the DCS system. The technical implementation of this step is based on a multi-source data collection and risk assessment model, specifically including the real-time collection and fusion analysis of three key indicators: abnormal login frequency, device health, and network attack intensity.
[0076] Specifically, the system first collects abnormal login events through the bastion host logs, including unauthorized IP access, login behavior deviating from the baseline, and abnormal smart password key certificates. Abnormal login frequency. The time window is 5 minutes, with values ranging from 0 to 5. Values exceeding 5 are uniformly counted as 5. Device health status. The configuration hash value of the cryptographic device is compared with a preset baseline value using the SM3 algorithm to calculate the deviation rate, which ranges from 0 to 1, where 0 indicates no deviation and 1 indicates a severe anomaly. (Network attack strength) Threats reported by the Intrusion Detection System (IDS) are categorized into levels 1 to 5, with level 5 being the highest threat. The three types of data are weighted and fused using an algorithm to calculate a comprehensive risk value. Its formula is:
[0077] in, , , These are the weighting coefficients for each indicator. The time decay coefficient, This represents the time interval (in hours) since the most recent risk event. This model dynamically reflects the current security status of the system, ensuring the timeliness and accuracy of risk assessments.
[0078] It is clear that when This means that the overall risk value reaches a preset threshold. Upon activation, the system automatically triggers a key update process, calling the key management platform to generate a new SM4 session key and synchronizing it to relevant devices via an SSL VPN encrypted channel. Simultaneously, the system activates the corresponding emergency plan according to the cryptographic security incident classification standards (Levels 1 to 4), ensuring that response time and handling efficiency meet the Level 3 requirements of GB / T39786-2021. All operation logs during the handling process are digitally signed using the SM2 algorithm to ensure the integrity and immutability of audit data, and are pushed to the key status dashboard of the situational awareness platform in real time, providing data support for subsequent optimization and compliance verification. This step plays a crucial role in the overall solution for real-time risk awareness, emergency response coordination, and closed-loop security management, significantly improving the DCS system's response efficiency and handling capabilities in the face of cryptographic security threats.
[0079] Furthermore, step 4 includes: Step 41, using the formula Calculate the overall risk value R, where =0.4, =0.3, =0.3, =0.2, This indicates the number of abnormal login attempts (0-5 times) within a unit of time (5 minutes). This indicates the device configuration hash deviation rate (0-1). Indicates the level of network attack threat (1-5).
[0080] Specifically, the system uses formulas This system enables real-time risk assessment of cryptographic application status. The formula, based on the fusion of multi-source heterogeneous data, quantifies the level of cryptographic security threats currently facing the system, thus providing a basis for decision-making in subsequent emergency response mechanisms.
[0081] In this embodiment of the invention, the formula uses a weighted fusion method to calculate the frequency of abnormal logins. Device configuration hash deviation rate and the level of cyberattack threat Three key indicators were comprehensively evaluated. Among them, This represents the number of abnormal logins that occur within a unit of time (5 minutes), with a value ranging from 0 to 5. If the number exceeds 5, it will be uniformly calculated as 5 to avoid extreme values causing nonlinear disturbances to the evaluation results. This represents the deviation rate between the cryptographic device configuration hash value and the baseline value, with a value range of 0 to 1, where 0 indicates no deviation and 1 indicates a serious configuration anomaly. This indicates the network attack threat level, reported by the Intrusion Detection System (IDS), and ranges from 1 to 5, with 5 representing the highest threat level. Time decay factor. Used to exponentially decay the impact of historical attack events, where Indicates the time interval since the most recent attack (in hours). This reduces the impact of the attack two hours ago on the current risk value to 13.5% of the initial value.
[0082] What is clear is the weighting coefficient. , , These correspond to risk sensitivities across three dimensions: abnormal logins, device malfunctions, and network attacks. This setting is based on statistical analysis of historical security incidents to ensure that each risk factor contributes a reasonable proportion to the overall assessment. Overall Risk Value The value range is from 0 to 10, when When this happens, the system will automatically trigger the key update process.
[0083] In practical applications, this step is deployed in the Security Operations Center (SOC). Through the integration of the log auditing system and the key management platform, it collects security event data from key nodes such as bastion hosts, cryptographic devices, and network boundaries in real time. The system calculates a risk value every 5 minutes to ensure rapid response to abnormal behavior. In the DCS system of thermal power plants, this mechanism can effectively identify risk events such as unauthorized IP access, login behavior deviating from the baseline, and abnormal smart key certificates, providing quantitative basis for subsequent emergency response.
[0084] In this embodiment of the invention, the formula enables dynamic and quantitative evaluation of the cryptographic application status, improving the system's ability to perceive and respond to security threats. By introducing a time decay factor, the system can distinguish the impact weight of current and historical attack events, avoiding interference from old events in current judgments. Simultaneously, the formula forms a closed-loop linkage with the key management platform, situational awareness platform, and compliance verification module, ensuring that key updates or revocation operations can be quickly executed after a risk threshold is triggered, and that complete audit logs are recorded, thereby enhancing the overall security resilience and compliance of the system.
[0085] Step 42: When an abnormal login event is detected, the server cryptographic machine is invoked to generate a new SM4 session key, which is synchronized to the historical database server and operator station through the SSLVPN encrypted channel. At the same time, the SM2 algorithm is used to digitally sign the key update record.
[0086] Specifically, when an abnormal login event is detected, the system will automatically call the server's cryptographic machine to generate a new SM4 session key and synchronize it to the historical database server and operator station via an SSL VPN encrypted channel. Simultaneously, the key update record will be digitally signed using the SM2 algorithm. This step is a crucial link in the linkage between dynamic key lifecycle management and the security operations center in this invention, aiming to achieve real-time key updates and traceability of the operation process.
[0087] In this embodiment of the invention, the server cryptographic machine, as a cryptographic hardware device conforming to national cryptographic standards, supports commercial cryptographic algorithms such as SM2, SM3, and SM4. Its key generation rate is no less than 100 pairs / second, ensuring rapid generation of new SM4 session keys even under high concurrency or emergency conditions. The generated keys are transmitted through an SSL VPN encrypted channel. This channel, built on IPsec or SSL protocols and deployed at the AB network boundary, ensures a communication latency of less than 50ms, meeting the real-time and reliability requirements of the DCS system. During synchronization, the system employs a key distribution protocol (such as KDP) to ensure secure key transmission and consistency verification between the historical database server and the operator station.
[0088] It is clear that key update operations must meet the following requirements: a key synchronization success rate of over 99.5%, a key update response time controlled within 10 seconds, and the digital signature process must use the SM2 algorithm with a signature verification success rate of no less than 99.9%. The digital signature operation takes key update records (including the old key revocation time, the new key activation time, operator certificate information, etc.) as input to generate tamper-proof signature data, ensuring the integrity and reliability of the audit log.
[0089] This step is typically triggered by the security operations center after detecting abnormal login behavior (such as unauthorized IP access, login behavior deviating from the baseline, abnormal smart password key certificates, etc.). The system calculates a comprehensive risk value based on a real-time risk assessment model. ,when Upon such an event, the key update process is immediately initiated. This mechanism is widely used in DCS system operation and maintenance auditing, identity authentication, and data protection scenarios, playing a particularly important role in boundary protection between the core control area and the non-control area.
[0090] The technical benefits of this step are that, through automatic key updates and digital signature mechanisms, it effectively curbs security risks caused by key leaks or identity forgery, enhancing the system's resistance to attacks and compliance. Simultaneously, the signature and audit logs of key update records are synchronized to the situational awareness platform, providing reliable data support for subsequent cryptographic application performance evaluation and compliance verification, thus achieving closed-loop management and dynamic response for cryptographic applications.
[0091] Step 5, the phased deployment and implementation is divided into three phases: core control area, non-control area, and management information area. After each phase of deployment, a 72-hour stability test is performed to verify six indicators, including key synchronization success rate and key update response time. The operation of cryptographic devices is performed through a dedicated laptop (with a high-complexity password and no irrelevant software is allowed to be installed), and audit logs are kept for key steps.
[0092] In one embodiment of the present invention, a three-phase deployment strategy of "core control area - non-control area - management information area" is adopted to ensure the gradual coverage and stable operation of commercial cryptography applications in the DCS system of thermal power plants. This deployment method follows the principle of defense in depth and, combined with the business partitioning characteristics of the DCS system, achieves the orderly integration of cryptographic devices and the gradual implementation of security policies.
[0093] Specifically, the first phase involves deploying key cryptographic equipment in the core control area, including four server cryptographic machines and two national cryptographic access control systems. The server cryptographic machines must support SM2 / SM3 / SM4 algorithms and have a key generation rate of no less than 100 pairs / second to meet real-time encryption and signature requirements. The national cryptographic access control systems must comply with the GM / T0036-2014 standard to achieve strong authentication and operation auditing for physical access. The second phase involves deploying two SSL VPN gateways and four signature verification servers in the non-control area. The SSL gateways must be configured with SM2 authentication and SM4 data encryption, ensuring communication latency of less than 50ms to guarantee the real-time performance of control commands. The signature verification servers should have a signature verification capability of 200 times per second to meet performance requirements under high-concurrency operation scenarios. The third phase involves distributing 200 smart cryptographic keys to the management information area. These smart cryptographic keys must be certified by GM / T 0027-2014 and support a USB interface to ensure the authentication and data encryption capabilities of terminal devices.
[0094] In this embodiment of the invention, a 72-hour stability test is required after each deployment phase to verify six key indicators, including key synchronization success rate and key update response time. Specifically, the key synchronization success rate should reach above 99.5%, and the key update response time should be controlled within 5 seconds to ensure the continuity and availability of the cryptographic service. Furthermore, cryptographic device operations must be performed through a dedicated laptop. This laptop must have a highly complex password (containing at least uppercase and lowercase letters, numbers, and special characters), and software unrelated to cryptographic operations must be prohibited from installation to prevent potential malware interference or key leakage.
[0095] In one embodiment of the present invention, this deployment strategy is applicable to commercial cryptographic transformation projects of DCS systems in thermal power plants, and is particularly suitable for scenarios involving critical control logic, historical data storage, and remote operation and maintenance access. Phased deployment effectively reduces the risk of business interruption during system transformation, while facilitating layer-by-layer verification of the compatibility and stability of cryptographic devices with the existing system.
[0096] The technical benefits of this step lie in ensuring the reliable integration and long-term stable operation of commercial cryptographic devices within the DCS system through structured deployment and rigorous stability testing mechanisms. Simultaneously, the introduction of dedicated operating terminals and a dual-person oversight mechanism enhances the security and auditability of cryptographic operations, providing a solid foundation for subsequent key management, risk assessment, and emergency response.
[0097] Example 2 This invention relates to another method for constructing commercial cryptographic applications for DCS systems in thermal power plants, such as... Figure 2 As shown, in addition, embodiments of the present invention also propose an identity authentication process, such as... Figure 3 As shown; this embodiment of the invention also proposes a three-level key system, such as Figure 4 As shown; embodiments of the present invention also propose cryptographic application deployment, such as Figure 5 As shown; embodiments of the present invention also propose a cryptographic security processing mechanism, such as Figure 6 As shown; this embodiment of the invention also proposes a cryptographic security emergency response procedure, such as Figure 7 As shown; this embodiment of the invention also proposes a security incident emergency response process, such as Figure 8 As shown.
[0098] Specifically, this method for constructing commercial cryptographic applications for DCS systems in thermal power plants includes the following steps: S1: Comprehensively collect information on the physical environment, network topology, equipment configuration, and business data flow of the DCS system to identify cryptographic application gaps in the existing security architecture. The evaluation results will serve as the input for the S2 requirements analysis.
[0099] S2: Based on the evaluation results of S1, a requirement model is constructed from five dimensions: physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing. The output requirement list will guide the design direction of S3.
[0100] S3: Based on the requirements model of S2, design a defense-in-depth system covering "physical-network-device-application-data", focusing on planning the linkage mechanism between network layer VPN encryption and application layer data encryption. The solution must simultaneously meet the technical adaptation requirements of S6 key management.
[0101] S4: Based on the technical specifications of S3, select core products such as server cryptographic machines and signature verification servers that have passed national cryptographic certification, conduct compatibility testing with the DCS system, and the integration results must pass the pre-verification of S5 deployment and implementation.
[0102] S5: Deployed in three phases in the order of "core control area - non-control area - management information area". After each phase of deployment is completed, the equipment operation status data must be synchronized to the S7 security operation center to ensure seamless connection with subsequent security monitoring.
[0103] S6: Based on the cryptographic devices deployed on S5, a key management system integrating real-time risk assessment is built. When S7 detects an abnormal login, it automatically triggers the key update process and synchronizes the key status log to the S8 situational awareness platform.
[0104] S7: Integrates the log auditing system deployed in S5 with the key management platform in S6 to establish a 24 / 7 monitoring mechanism and analyze the status of cryptographic applications in real time. When an abnormal event is detected, it automatically activates an emergency response mechanism based on the cryptographic security event classification (level 1 to 4), triggers the corresponding level of emergency plan according to the preset emergency handling process, calls the S6 key management platform to perform emergency key update or revocation operations, synchronizes the handling process log to the S8 situational awareness platform, and pushes an emergency event handling report to the S9 compliance verification module.
[0105] S8: Utilize the operational data collected by S7 to conduct a cryptographic application effectiveness assessment every quarter, update the protection scheme of S3 in light of newly emerging attack methods, and synchronize the optimization results to the key policy library of S6.
[0106] S9: Based on the optimization results of S8, organize a security assessment of cryptographic applications, verify the compliance of each step from S1 to S8, and form complete acceptance materials including technical documents, test reports, and rectification records.
[0107] In step S1, the system security baseline assessment must cover the DCS system ring network server area, the AB network historical database area, and the engineer / operator area. Vulnerability scanning equipment should be deployed to collect network device configuration information, business data flow diagrams, and device model parameters. An assessment report containing 12 high-risk items and 18 medium-risk items should be generated based on the Level 3 requirements of GB / T39786-2021. The assessment process should focus on recording the current status of the physical data center access control system and network boundary firewall policies. The report should output the GM / T0036-2014 standard adaptation requirements for the access control system and recommendations for IPsec / SSL VPN deployment locations, ensuring direct relevance to the five dimensions of requirements in the S2 requirements analysis phase. The assessment results, as input for subsequent solution design, must be verified through a 72-hour stability test.
[0108] In step S2, the multi-dimensional cryptographic requirements modeling unfolds across five dimensions: physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing. The physical dimension specifies that the electronic access control system must comply with the GM / T0036-2014 standard. The network dimension determines that an IPsec / SSL VPN integrated security gateway must be deployed at the AB network boundary and configured with SM2 authentication and SM4 data encryption. The device dimension proposes a two-factor authentication scheme of "smart cryptographic key + bastion host." The data dimension stipulates that sensitive fields in the historical database use SM4 encryption and SM3 integrity verification. The operation and maintenance dimension defines the scope of log collection and the integrity protection mechanism verification every six months. The requirements for each dimension are calculated using a dynamic weighted algorithm to determine a priority index. Security risk levels are divided into 1-5 levels, with an impact scope coefficient of 3 when covering the core control area. Implementation complexity is divided into 1-4 levels based on technical difficulty, and compliance urgency is measured by the number of months remaining until the regulatory deadline. First, obtain current status data for each dimension through the S1 system security baseline assessment. The physical access control dimension focuses on analyzing the integrity of data center access records and the protection requirements for video surveillance data. The network communication encryption dimension, based on the AB network topology, assesses the confidentiality requirements of data transmission between the controlled and non-controlled areas, determining the deployment location of IPsec / SSL VPN and the application scenarios for SM2 / SM3 algorithms. The device authentication dimension, combined with the access method of the maintenance terminal, directly relates to the USB key selection during the S4 cryptographic product adaptation and integration phase through two-factor authentication requirements. The data storage protection dimension clarifies the technical indicators of SM4 encryption and SM3 integrity verification for authentication and audit data in the historical database, and synchronizes them to the lifecycle strategy of S6 key management. The maintenance operation audit dimension needs to define the log collection scope and integrity protection mechanism to ensure that audit data meets the real-time analysis requirements of the S7 security operations center. The output of these five dimensions will form a structured requirement list, serving as the input basis for the design of the S3 cross-layer collaborative protection solution. Among these, the network communication encryption requirement needs to be linked with the data storage protection requirement to ensure the compatibility of transmission encryption and storage encryption algorithms.
[0109] In the requirement prioritization stage, the formula for calculating the implementation priority index P of each dimension of requirement using a dynamic weighted algorithm is as follows: ; In the formula: This indicates the priority index for implementing requirements (value range 0-10, the higher the value, the higher the priority). Indicates the safety risk level (assessed based on GB / T39786-2021, with a value of 1-5, where 5 is the highest risk); This represents the influence range coefficient (the number of DCS system components covered, with a value of 1-3, where 3 represents the core control area). This indicates the implementation complexity (technical difficulty and resource input, with a value of 1-4, where 4 is the highest complexity). Indicates the urgency of compliance (the number of months remaining until the regulatory deadline, ranging from 0.5 to 3, with 3 indicating the most urgent requirement); , , These represent adjustment coefficients (1.2, 0.8, and 0.15, respectively, calibrated using historical project data).
[0110] In step S3, the cross-layer collaborative protection scheme constructs a five-layer defense system encompassing physical, network, device, application, and data layers. The physical layer deploys a national cryptographic access control and video surveillance system compliant with GM / T0036-2014. The network layer deploys an IPsec / SSL VPN integrated security gateway at the AB network boundary, configuring SM2 authentication and SM4 data encryption to ensure communication latency <50ms. The device layer uses a national cryptographic bastion host to enable authentication of maintenance personnel based on smart cryptographic keys. The application layer uses a signature verification server to perform SM2 digital signatures on operation commands. The data layer implements SM4 encryption and SM3 integrity protection for sensitive fields in the historical database. The scheme must ensure that the network layer VPN encryption and application layer signature verification algorithms are coordinated, synchronously meeting the hierarchical division requirements of S6 key management. Specifically, the server cryptographic machine must support SM2 / SM3 / SM4 algorithms and have a key generation rate ≥100 pairs / second.
[0111] In step S4, the compliant cryptographic product adaptation and integration phase selects devices with commercial cryptographic product model certificates. The server cryptographic machine must support SM2 / SM3 / SM4 algorithms and have a key generation rate ≥100 pairs / second. The signature verification server should meet the performance requirement of 200 signature verifications per second. The smart cryptographic key must be certified by GM / T0027-2014 and support a USB interface. Compatibility testing with the DCS system is conducted, focusing on verifying that the communication latency between devices is <50ms. This includes completing device mounting, hardware wiring, driver installation, and interface development. The integration results must pass pre-deployment functional verification testing, where all six indicators, including key synchronization success rate and key update response time, must meet the standards. Cryptographic device operation must be supervised by two or more people.
[0112] Step S5 involves a phased deployment implemented in three phases. The first phase deploys four server cryptographic machines and two national cryptographic access control systems in the core control area. The second phase deploys two SSL VPN gateways and four signature verification servers in the non-control area. The third phase distributes 200 smart cryptographic keys to the management information area. Each phase requires a 72-hour stability test, verified by six indicators including key synchronization success rate and key update response time. During deployment, real-time device operation status data is pushed to the S7 security operations center to ensure seamless integration with the security monitoring system. Dedicated laptops for operating cryptographic devices must have highly complex passwords and are prohibited from installing any software unrelated to operation.
[0113] In step S6, dynamic key lifecycle management is based on a three-tier key system. The management key is centrally stored in a KMS system, the user key is stored in a smart password key with a validity period of one year, and the session key is automatically updated every 24 hours. Real-time data on abnormal login frequency, device health, and network attack intensity are collected. A comprehensive risk value R is calculated using a risk assessment formula. When R ≥ 8.5, the key update process is immediately triggered. The new key is synchronized to relevant devices via an SSL VPN encrypted channel. The update process generates an audit log containing the old key revocation time, the new key effective time, and the operator's certificate information. The key update record is digitally signed using the SM2 algorithm and pushed to the key status dashboard of the S8 situational awareness platform in real time.
[0114] In step S7, when S7 detects abnormal login events (such as unauthorized IP access, login behavior deviating from the baseline, abnormal smart key certificates, etc.) through the bastion host logs, the system automatically initiates a real-time risk assessment process. First, three types of real-time data are collected: abnormal login frequency N (the number of failed login attempts triggered per unit time), device health D (the deviation rate between the cryptographic device configuration hash value calculated using the SM3 algorithm and the baseline value), and network attack strength A (the attack threat level reported by the intrusion detection system, level 1-5). A weighted fusion algorithm is then used to calculate the comprehensive risk value R, as shown in the following formula: ; In the formula: This represents the overall risk assessment value (range 0-10, the higher the value, the more severe the risk). This represents the weighting coefficient (corresponding to abnormal login, device malfunction, and network attack, with values of 0.4, 0.3, and 0.3 respectively). This indicates the number of abnormal login attempts within a unit of time (5 minutes) (values range from 0 to 5, with more than 5 attempts counted as 5). This indicates the device configuration hash deviation rate (value 0-1, where 0 indicates no deviation and 1 indicates severe tampering). Indicates the level of network attack threat (values range from 1 to 5, with 5 being the highest level). This represents the time decay factor (with a value of 0.2, which reduces the impact of an attack event from 2 hours ago to 13.5% of its initial value). Indicates the time interval since the most recent risk event (unit: hours); This represents the risk threshold (a fixed value of 8.5, the critical value that triggers a key update).
[0115] Trigger the corresponding level of emergency response plan according to the preset emergency response procedure, call the S6 key management platform to perform emergency key update or revocation operation, synchronize the process log to the S8 situation awareness platform, and push the emergency event handling report to the S9 compliance verification module.
[0116] The emergency response plan specifically includes: Password security incident classification: Based on the importance of the network system, the system loss, and the social impact, cryptographic security incidents are classified into three levels: extremely serious security incidents (Level 1), serious security incidents (Level 2), relatively serious security incidents (Level 3), and general security incidents (Level 4).
[0117] (a) Particularly serious cryptographic security incidents (Level 1) A particularly serious security incident refers to a network and cryptographic security incident that can cause catastrophic damage or impact, posing a disastrous threat to social stability and national security, including the following situations: 1. All user and password-related services are paralyzed and unusable; 2. The cryptographic service module is not working properly, and the key and core security configuration are invalid. 3. The password encryption function failed, and classified information was widely disseminated; 4. Password-related terminals and application services have been interrupted for more than 24 hours.
[0118] (II) Major Cryptographic Security Incidents (Level 2) Major security incidents refer to network and cryptographic security incidents that can cause serious impact or damage, posing a serious threat to social stability and the interests of an organization, including the following situations: 1. A large number of user and password-related services were affected; 2. Most cryptographic service modules are not working properly; 3. Password-related functional modules contain high-risk security vulnerabilities; 4. Password-related terminals and application services have been interrupted for more than 24 hours.
[0119] (III) Major cryptographic security incidents (Level 3) A major cryptographic security incident refers to a network and cryptographic security incident that can cause serious impact or damage, posing a certain threat to social stability and the interests of an organization, including the following situations: 1. Some user and password-related services have been affected.
[0120] 2. Some cryptographic service modules are not working; 3. Password-related terminals and application services are interrupted for more than 2 hours but less than 12 hours.
[0121] (iv) General cryptographic security incidents (level 4) General cryptographic security incidents refer to network and cryptographic security incidents with relatively low impact, posing little or no harm to social stability and organizational interests, including the following situations: 1. Some users and users associated with their passwords were affected; 2. A single cryptographic service module malfunctioned; 3. Password-related terminals and application services are interrupted for less than 2 hours.
[0122] Emergency response organization: The emergency response leading group, composed of relevant leaders and key personnel from the project construction party, is responsible for coordinating and planning the emergency response mechanism for cryptographic security incidents, and has the following duties: (i) To guide the prevention and emergency response to system password security incidents; (ii) Promote the establishment and implementation of the system's emergency response mechanism for cryptographic security incidents.
[0123] The Emergency Response Leadership Project Coordination Group, composed of unit / department leaders and key personnel, guides and coordinates the implementation of the cryptographic security emergency response project and has the following responsibilities: (a) Review and update the password security incident management specifications; (ii) Coordinate and supervise the implementation of measures for handling, correcting, and preventing cryptographic security incidents; (iii) Organize investigations into cryptographic security incidents and cooperate with relevant departments in the investigation and evidence collection of network and cryptographic security cases; (iv) Report to the cryptographic security handling leading group and propose handling opinions.
[0124] The Emergency Response Leadership Project Implementation Team, composed of relevant technical service providers and implementation personnel, is responsible for the implementation of the cryptographic security emergency response project and has the following duties: (i) The domestic hardware equipment provider shall be responsible for providing technical support and emergency technical services for the hardware equipment it provides; (ii) The network operation and maintenance support service provider shall be responsible for the technical support and implementation of security protection and emergency response for the physical environment of the server, network communication lines and network boundaries of the network where the system is located; (iii) The system integration service provider shall be responsible for providing technical support for the overall system architecture, deployment, operation and functional response, and coordinating with relevant technical service providers to implement emergency response work.
[0125] (iv) The application system developer shall be responsible for providing technical support and implementation for the actual emergency response work of the relevant system.
[0126] Emergency response mechanism: Upon discovering a network or password security incident, the user unit or personnel should promptly report it to the emergency response team. The emergency coordination team should promptly organize the emergency implementation team to investigate the cause of the fault and make a preliminary judgment based on the fault situation and repair time within half an hour to determine the fault level. If it is a major (Level 3 or above) incident, it should be reported to the emergency response leadership team.
[0127] After an emergency occurs, depending on the severity of the emergency, the leader shall report to the superior authority and the relevant cryptography administration bureau, and designate a specific team or personnel to promptly release information about the failure to the public.
[0128] (i) When a network and password security incident occurs, the reporting role and handling procedure shall be followed according to the type of incident and the extent of its impact.
[0129] 1. When internal personnel discover suspected network and password security incidents or receive external reports of information security incidents, the discoverer should simultaneously inform the network and information security specialist of the department that issued the notification, the emergency coordination and implementation team, and inform all relevant departments and business leaders. 2. In the event of a network and cryptography security incident, the network and information security specialists of each department shall immediately report to the network and cryptography security emergency response team.
[0130] (ii) The content of information security incident reports should, as far as possible, cover the facts of the incident, the scope of potential impact, loss assessment, support needed, and countermeasures taken.
[0131] (iii) Upon receiving a report, the Network and Cryptography Coordination Group shall assess and analyze the incident: 1. If the incident is determined to be not a network or password security incident, the result will be sent back to the person who discovered it.
[0132] 2. If the incident is determined to be a network and password security incident, further analysis of its impact will be conducted, and it will be handled according to relevant procedures and protocols. (1) When a general security incident occurs, the Network and Cryptography Coordination and Implementation Team shall handle it and take relevant corrective and preventive measures to prevent similar incidents from occurring.
[0133] (2) When a major or serious safety incident occurs, it should be reported to the emergency response leading group, and the emergency coordination and implementation group should handle the incident according to the decision of the leading group.
[0134] (3) If the impact is found to be greater than the original judgment during the processing, the event analysis should be re-executed.
[0135] (iv) When handling network and cryptographic security incidents, if internal resources are needed, the emergency response coordination team shall coordinate the work; if external resources are needed, the emergency response leadership team shall coordinate the work. When a major security incident occurs and needs to be explained to the public, the unit's unified external communication window shall explain the situation and handling methods to the public, and report to the superior competent department and cryptographic management department at the same time.
[0136] (v) Establish corresponding mechanisms to monitor and record security incidents, and to compile statistics on their types, numbers, and the costs of the losses they cause.
[0137] (vi) When a security incident involves civil or criminal proceedings and requires judicial evidence collection, the following should be noted: 1. The sealing process requires the presence of the parties involved, investigators, and judicial appraisal departments, and the sealing site must bear the signatures of all parties. 2. The process of data preservation and evidence discovery must be conducted with the presence of a forensic expert to ensure the integrity and reliability of the data; 3. Forensic appraisal institutions are required to issue forensic appraisal reports on the process of obtaining evidence.
[0138] (vii) Report major security incidents and security incidents that cannot be handled to the public security department and the cryptography management department.
[0139] (viii) The processing time for information security incidents is shown in Table 1: Table 1
[0140] Emergency response procedures Emergency response to network and cryptography security incidents involves incident procedure assessment and development, as well as the immediate implementation of emergency measures to restore affected system services to normal as quickly as possible. The procedures can be broadly divided into five phases: identification, escalation, containment, prevention, and recovery. Understanding the specific tasks at each phase is crucial for a rapid response in the event of a security incident.
[0141] Emergency Announcement Process Based on the interruption time caused to the application system's cryptographic application, the emergency level is divided into general (level 3), major (level 2), and serious (level 1).
[0142] After a security incident occurs: The emergency response team should take effective measures to handle the situation as soon as possible, minimize the damage and impact, and determine the level of the emergency. If it is a major (Level II) or higher level, it is necessary to immediately report verbally to the superior authority.
[0143] The report includes: (1) Time and place; (2) A brief account of the process; (3) Event types and classifications; (4) Scope of impact; (5) Degree of harm; (6) Preliminary cause analysis; (7) Emergency measures already taken.
[0144] The procedure for higher-level authorities to issue instructions to various emergency response teams (such as loss assessment teams, network recovery teams, and data backup and recovery teams) is as follows: the loss assessment team is responsible for assessing the damage; the network recovery team is responsible for quickly restoring the network; the data backup and recovery team is responsible for backing up the data; communication between all emergency response personnel is ensured, and emergency contacts are designated. Incidents involving deliberate sabotage should also be reported to the local public security bureau.
[0145] In-process reporting and handling: (a) An incident report shall be submitted in writing within 2 hours of the discovery of the security incident.
[0146] (ii) The emergency response team shall prepare the in-process report, which shall be reviewed by the application leadership group and then submitted to the superior competent authority. After the incident was handled: (i) The post-incident rectification report shall be submitted in writing within 5 working days after the safety incident has been handled; (ii) The emergency response team shall prepare the in-process situation report, which shall be reviewed by the emergency leadership group and then submitted to the superior competent department and the cryptography administration bureau.
[0147] Loss Assessment Loss assessment should be the responsibility of a dedicated loss assessment team. Following a safety incident, the loss assessment team should be the first to be instructed to arrive at the scene and conduct the loss assessment.
[0148] The loss assessment team, accompanied by the emergency coordination team and the emergency implementation team, enters the computer room to inspect and assess the equipment, and records the loss situation to form a report. The loss report should include the specific details of the incident, an analysis of the cause of the incident, physical property loss, business loss, loss of credibility, risk improvement plans, and other aspects, which are used as the conditions for activating the emergency plan.
[0149] Timely follow-up actions include assessing the damage caused by the incident, improving systems to prevent recurrence, updating security policies and procedures, and conducting case investigations for future prosecution.
[0150] Contingency Plan Activation Conditions Based on different security incident classification levels, corresponding measures will be taken for emergency handling of cryptographic applications. During the incident handling process, the emergency implementation team will adjust the incident level in a timely manner as needed, and the emergency loss assessment team will assess the incident loss.
[0151] General (Level 3): The emergency response team organizes and carries out system emergency response work. Significant (Level 2) and above: The emergency implementation team reports the incident level and situation to the emergency coordination team, which in turn reports the incident level and situation to the emergency leadership team and activates the corresponding emergency response plan.
[0152] When R ≥ threshold T (preset to 8.5 according to the DCS system security level), the S6 key management system immediately triggers the update process: it calls the server cryptographic machine to generate a new SM4 session key, synchronizes it to the historical database server and operator station through the SSL VPN encrypted channel, and uses the SM2 algorithm to digitally sign the key update record, generating an audit log containing the old key revocation time, the new key effective time, and the operator's certificate information, which is pushed to the key status dashboard of the S8 situation awareness platform in real time.
[0153] In step S8, continuous optimization and situational awareness involve quarterly cryptographic application performance assessments, collecting data such as key update success rate and risk event response time from the S7 security operations center, and identifying potential optimization points through trend analysis. For VPN encryption pass rates below 99.5% at the network layer, encryption algorithm parameters are adjusted or network topology is optimized, and optimization suggestions are compiled into a revised solution and synchronized to the S3 solution design stage. Annually, a cryptographic testing organization is commissioned to conduct a cryptographic application security assessment. Non-compliant items are rectified and retested to ensure compliance with GB / T39786-2021 Level 3 requirements. The assessment results serve as the basis for formulating optimization strategies for the following year.
[0154] In step S9, the full-process compliance verification, based on the optimization results of S8, is commissioned to a cryptographic testing organization for evaluation. The evaluation scope covers all output documents from S1 to S8, focusing on verifying the integrity of physical layer access control records, network layer data encryption strength, and device layer identity authentication effectiveness. It tests 12 technical indicators, including SM2 signature verification success rate and SM4 encryption / decryption accuracy rate. Non-compliant items are rectified and retested, resulting in acceptance materials including technical documents, test reports, and rectification records, ensuring compliance with GB / T39786-2021 Level 3 requirements. After acceptance, the system is put into formal operation. During operation, a centralized inspection of cryptographic devices is conducted every six months, and key personnel are rotated every two years, adhering to declassification period management requirements.
[0155] From the above, we can conclude that: This invention integrates a log auditing system with a key management platform to establish a 24 / 7 monitoring mechanism. This mechanism analyzes the status of cryptographic applications in real time, and abnormal events are automatically pushed to the optimization module, improving the efficiency of real-time detection and response to security incidents. When an anomaly is detected, an emergency response mechanism based on cryptographic security incident classification is automatically activated. Following a preset process, the corresponding level of emergency plan is triggered, and the key management platform is invoked to perform emergency key updates or revocation operations. This strengthens the ability to handle sudden security incidents and ensures that the system can react quickly and take effective measures when facing security threats.
[0156] This invention achieves dynamic management of the entire key lifecycle. It calculates a comprehensive risk value using a risk assessment formula, and immediately triggers a key update process when the risk value reaches a threshold, thus improving the security and flexibility of key management. By synchronizing the handling process logs to the situational awareness platform and pushing emergency incident handling reports to the compliance verification module, it strengthens the supervision and auditing of the entire cryptographic application process, ensuring that system operations comply with relevant standards and specifications, and reducing security risks caused by human error or malicious attacks.
[0157] This invention establishes a three-tiered response structure consisting of an emergency response leadership team, a coordination team, and an implementation team. This ensures that the level of the incident is determined and the corresponding contingency plan is activated within half an hour of its occurrence. The mechanism stipulates that the response time for a Level 4 incident should not exceed one hour, and the fault handling time should be 2-8 hours. For Level 1 incidents, a response should be initiated within 30 minutes and the situation resolved within 1-2 hours. Simultaneously, it requires dual-person supervision during incident handling and the retention of audit logs for key steps. This tiered response and clearly defined responsibility emergency system improves the efficiency of rapid identification and handling of security incidents, strengthens the closed-loop management of the entire process from incident discovery, reporting, analysis to recovery, and ensures that in extreme situations such as key leakage or encryption failure, the source of risk can be quickly cut off and system functionality restored, minimizing the impact on core DCS business operations.
[0158] Example 3 To achieve the above embodiments, the present invention also proposes a commercial cryptographic application construction device for DCS systems in thermal power plants. Figure 9 This is a schematic diagram of a commercial cryptographic application construction device for a thermal power plant DCS system, provided as an embodiment of the present invention. Figure 9 As shown, the device includes: The information collection and risk identification module 100 is used to collect information on the physical environment, network topology, equipment configuration and business data flow of the DCS system, identify existing cryptographic application gaps and generate risk assessment reports. The multi-dimensional cryptographic requirement modeling module 200 is used to construct a multi-dimensional cryptographic requirement model based on the risk assessment report, including physical access control, network communication encryption, device identity authentication, data storage protection, and operation and maintenance auditing, and output a structured requirement list. The five-layer defense-in-depth system design module 300 is used to design a five-layer defense-in-depth system consisting of the physical layer, network layer, device layer, application layer, and data layer in conjunction with the requirements list, configure cryptographic products that coordinate SM2 / SM4 algorithms, and establish a key level division mechanism. The risk calculation and key update triggering module 400 is used to calculate a comprehensive risk value by collecting data on abnormal login frequency, device health and network attack intensity in real time, and trigger the key update process according to a preset threshold, while simultaneously executing emergency response plans and log auditing.
[0159] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0160] Example 4 To implement the above embodiments, the present invention also proposes an electronic device, comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method provided in the foregoing embodiments.
[0161] Example 5 To implement the above embodiments, the present invention also proposes a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods provided in the foregoing embodiments.
[0162] Example 6 To implement the above embodiments, the present invention also proposes a computer program product, including a computer program that, when executed by a processor, implements the methods provided in the foregoing embodiments.
[0163] In the foregoing descriptions of the embodiments, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0164] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0165] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of the invention pertain.
Claims
1. A method for constructing commercial cryptographic applications for DCS systems in thermal power plants, characterized in that, Includes the following steps: Step 1: Collect information on the physical environment, network topology, equipment configuration, and business data flow of the DCS system; identify existing cryptographic application gaps; and generate a risk assessment report. Step 2: Based on the risk assessment report, construct a multi-dimensional cryptographic requirement model for physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing, and output a structured requirement list; Step 3: Based on the requirements list, design a five-layer defense-in-depth system consisting of the physical layer, network layer, device layer, application layer, and data layer; configure cryptographic products that coordinate SM2 / SM4 algorithms; and establish a key level division mechanism. Step 4: By collecting data on abnormal login frequency, device health, and network attack intensity in real time, calculate the comprehensive risk value and trigger the key update process according to the preset threshold, while simultaneously executing the emergency response plan and log auditing.
2. The method according to claim 1, characterized in that, The collection of information on the physical environment, network topology, device configuration, and service data flow of the DCS system also includes: Step 11: Deploy vulnerability scanning equipment to collect network device configuration information, business data flow diagrams and device model parameters, and generate an assessment report containing 12 high-risk items and 18 medium-risk items according to the Level 3 requirements of GB / T39786-2021. Step 12 focuses on recording the current status of the physical computer room access control system and the network boundary firewall policy, and outputs the GM / T0036-2014 standard adaptation requirements for the access control system and suggestions for IPsec / SSL VPN deployment locations.
3. The method according to claim 1, characterized in that, The multi-dimensional cryptographic requirements model constructed based on the aforementioned risk assessment report also includes: Step 21: Calculate the implementation priority index P for each dimension of requirements using a dynamic weighted algorithm, as shown in the following formula: in, It is a comprehensive weighting coefficient based on risk and business importance. It is a weighting coefficient for implementation costs. It is the attenuation coefficient due to time urgency. Indicates the level of safety risk. Indicates the influence range coefficient. Indicates implementation complexity. This underscores the urgency of compliance; Step 22: Link network communication encryption requirements with data storage protection requirements to ensure compatibility between transmission encryption and storage encryption algorithms.
4. The method according to claim 1, characterized in that, The design of a five-layered defense system also includes: Step 31: Configure the server cryptographic machine to support SM2 / SM3 / SM4 algorithms and key generation rate. pairs / second; Step 32: Establish a two-factor authentication scheme for the smart password key and the bastion host. The smart password key must be certified by GM / T0027-2014 and support the USB interface.
5. The method according to claim 1, characterized in that, Calculating the overall risk value and triggering the key update process also includes: Step 41: Calculate the comprehensive risk value using the formula. The formula is as follows: in It is the weighting coefficient for the frequency of abnormal logins. It is a weighting coefficient for equipment health. It is a weighting coefficient for the intensity of network attacks. It is the attenuation coefficient. This indicates the number of abnormal logins per unit of time. This indicates the device configuration hash deviation rate. Indicates the level of cyberattack threat. It is the time interval since the most recent risk event; Step 42: When an abnormal login event is detected, the server cryptographic machine is invoked to generate a new SM4 session key, which is synchronized to the historical database server and operator station through the SSLVPN encrypted channel. At the same time, the SM2 algorithm is used to digitally sign the key update record.
6. The method according to claim 1, characterized in that, Also includes: Step 5, the phased deployment and implementation is divided into three phases: the core control area, the non-control area, and the management information area. After each phase of deployment, a 72-hour stability test is performed to verify the key synchronization success rate and key update response time. The operation of cryptographic devices is performed through a dedicated laptop, and audit logs are kept for key steps.
7. A commercial cryptographic application construction device for DCS systems in thermal power plants, characterized in that, include: The information collection and risk identification module is used to collect information on the physical environment, network topology, equipment configuration and business data flow of the DCS system, identify existing cryptographic application gaps and generate risk assessment reports. The multi-dimensional cryptographic requirement modeling module is used to construct a multi-dimensional cryptographic requirement model based on the risk assessment report, including physical access control, network communication encryption, device authentication, data storage protection, and operation and maintenance auditing, and output a structured requirement list. The five-layer defense-in-depth system design module is used to design a five-layer defense-in-depth system consisting of the physical layer, network layer, device layer, application layer, and data layer in conjunction with the requirements list, configure cryptographic products that coordinate SM2 / SM4 algorithms, and establish a key level division mechanism. The risk calculation and key update triggering module is used to calculate a comprehensive risk value by collecting data on abnormal login frequency, device health and network attack intensity in real time, and trigger the key update process according to a preset threshold, while simultaneously executing emergency response plans and log auditing.
8. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-6.