Unified digital treatment method for network security equipment based on SCCD-plus model
By constructing SCCD model files and configuring translation and conversion tools, the challenge of unified digital governance of network security devices was solved, enabling automated configuration and policy consistency for all network security devices across the site, thereby improving operational efficiency and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-10
- Publication Date
- 2026-03-10
AI Technical Summary
When applying the SCCD-plus model to the daily operation and configuration management of network security devices within a site, existing technologies suffer from non-standardized and fragmented configuration interfaces due to the mixed deployment of new and existing devices. This makes it difficult to transition from unified modeling to unified management and control, resulting in operational difficulties and challenges in ensuring policy consistency.
Construct SCCD model files, including asset ledgers, network topology, and security configuration information, and describe them uniformly according to the IEC 61850 system standard. Use configuration translation and conversion tools to perform protocol conversion on existing devices that do not support IEC 61850MMS services to achieve automated configuration.
It has achieved unified digital governance of all network security equipment on the site, reduced the error rate of human configuration, improved the accuracy and auditability of security policy deployment, and opened up a closed-loop link for the collection, modeling and configuration of incremental and existing equipment.
Smart Images

Figure CN121644303A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security operation and maintenance technology, specifically to a unified digital governance method for network security devices based on the SCCD-plus model. Background Technology
[0002] In the current process of building digital power plants, to improve the completeness and accuracy of equipment information management, the industry has built the SCCD-plus unified data model by extending the IEC 61850 standard. This model successfully realizes the structured information representation of network security devices, hosts, and other objects throughout the plant, and completes configuration collection and model consistency verification before equipment is connected to the network, forming a reliable digital model benchmark.
[0003] However, existing technologies have encountered bottlenecks when applying this structured model to the daily operation and configuration management of network security devices within an site, failing to achieve an effective transition from unified modeling to unified management. The core challenge lies in the common mixed deployment of newly added devices and a large number of existing devices in field network environments. For the diverse types and interfaces of existing network security devices, due to the general lack of native support for the IEC 61850 standard, their configuration interfaces and communication protocols exhibit non-standardized and fragmented characteristics, such as reliance on multiple protocols like SSH and SNMP. This makes it impossible to directly map their actual configurations to a unified model for centralized management, requiring maintenance personnel to perform a significant amount of manual configuration and verification, making it difficult to guarantee policy consistency and auditability.
[0004] Meanwhile, even new devices supporting the IEC 61850 standard often face a governance dilemma: data collection is easy, but configuration distribution is difficult, due to inconsistent standard implementations by different manufacturers and incomplete configuration distribution pathways. This prevents the formation of an effective closed-loop management system for data collection, modeling, and configuration. Therefore, current technology urgently needs a mechanism that is compatible with heterogeneous devices and establishes bidirectional configuration pathways to solve the problem of the disconnect between models and actual control, and to achieve truly integrated and automated governance of all network security devices across the entire site. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a unified digital governance method for cybersecurity devices based on the SCCD-plus model, which solves the problems of existing technologies, such as reliance on manual configuration, inconsistent standards, susceptibility to errors, and difficulty in unified digital management of cybersecurity devices.
[0006] To achieve the above objectives, the present invention provides the following technical solution:
[0007] The unified digital governance method for cybersecurity devices based on the SCCD-plus model includes the following steps:
[0008] S1. Construct SCCD model file: The SCCD model file follows the IEC 61850 system standard and includes newly added asset ledger, network topology, security configuration information, as well as redefined network security equipment model and station control layer host model;
[0009] S2. Collect the actual operating configuration values of network security equipment and station control layer host, verify and merge the collected actual operating configuration values with the configuration baseline defined in the SCCD model file, and generate SCCD-plus archive file;
[0010] S3. Based on the SCCD-plus archive file, instantiate the model of the target device and generate a CID-plus file containing the target device configuration information;
[0011] S4. Use the CID-plus file to complete the automated configuration of the target device.
[0012] Preferably, in step S1, the process of creating the SCCD model file further includes:
[0013] The IED model has been expanded, and new logical devices and logical nodes have been added to support the unified modeling of security policies and topology interconnection information.
[0014] Preferably, the security configuration information includes VLAN configuration, routing configuration, access control policy configuration, tunnel configuration, and network address translation configuration.
[0015] Preferably, in step S2, the actual operating configuration values collected include:
[0016] The actual configuration information of cybersecurity equipment security policies, actual physical network topology information, and security configuration information required for the practical application of situational awareness.
[0017] Preferably, the actual physical network topology information includes online device status, address resolution protocol status table, and media access control status table.
[0018] Preferably, the security configuration information required for the practical application of situational awareness includes port mirroring configuration, Simple Network Management Protocol (Trap) configuration, and system log configuration.
[0019] Preferably, the data acquisition step S2 specifically includes:
[0020] When the network security equipment and the station control layer host are incremental devices that support IEC 61850MMS services, the master station system obtains and parses the original configuration information of the incremental devices through IEC 61850MMS services.
[0021] When the network security equipment and the station control layer host are existing devices that do not support the IEC 61850MMS service, the configuration translation and conversion tool obtains and parses the original configuration information of the existing devices through SSH, SNMP and API protocols.
[0022] Preferably, in step S3, the process of generating the CID-plus file specifically includes:
[0023] Load the SCCD-plus archive file in the configuration tool;
[0024] Based on the loaded SCCD-plus archive file, select the target device and instantiate the logical device and logical node of the target device to form an independent configuration view;
[0025] Populate runtime parameters, interface parameters, and security policies in the standalone configuration view;
[0026] Export the populated configuration as a CID-plus file.
[0027] Preferably, when the target device is an incremental device supporting IEC 61850 MMS services, step S4 specifically includes:
[0028] The incremental device directly parses the CID-plus file to complete the automatic configuration.
[0029] Preferably, when the target device is an existing device that does not support IEC 61850MMS service, step S4 specifically includes:
[0030] The configuration translation and conversion tool parses the CID-plus file, converts the parsed configuration information into protocol commands supported by existing devices, and then sends the protocol commands to the existing devices to execute and apply the configuration information, thus completing the automated configuration.
[0031] This invention provides a unified digital governance method for cybersecurity devices based on the SCCD-plus model. It has the following beneficial effects:
[0032] 1. This invention constructs a unified SCCD model file containing asset ledgers, network topology, and security configuration information as the configuration baseline for the entire site, and uses this to drive subsequent configuration generation and verification, thereby ensuring the uniformity of configuration baselines and the consistency of policies for heterogeneous network security devices.
[0033] 2. This invention replaces the traditional manual configuration method by executing automated collection, verification, model instantiation and configuration application processes, thereby reducing the configuration error rate caused by human factors and improving the accuracy and auditability of security policy deployment.
[0034] 3. This invention introduces a configuration translation and conversion tool to perform protocol conversion and information adaptation for existing devices that do not support IEC 61850MMS services, thus establishing a digital closed-loop link covering the entire scenario of data collection, modeling, and configuration for both incremental and existing devices. This provides a unified and scalable technical path for the digital governance of the entire lifecycle of network security devices. Attached Figure Description
[0035] Figure 1 A schematic diagram illustrating the closed-loop application of the unified digital governance method for cybersecurity devices based on the SCCD-plus model provided in this embodiment of the invention;
[0036] Figure 2 This is a schematic diagram illustrating the configuration distribution path of the master station system for different types of devices provided in this embodiment of the invention;
[0037] Figure 3 This is a schematic diagram of the process for generating SCCD-plus archive files provided in an embodiment of the present invention;
[0038] Figure 4 This is a schematic diagram of the automatic download process of SCCD-plus model file fixed values provided in an embodiment of the present invention;
[0039] Figure 5 A schematic diagram illustrating the initialization and uplink data acquisition functions of the configuration translation conversion tool provided in this embodiment of the invention;
[0040] Figure 6 A schematic diagram illustrating the real-time data monitoring function of the configuration translation conversion tool provided in an embodiment of the present invention;
[0041] Figure 7 A schematic diagram illustrating the periodic data inspection function of the configuration translation conversion tool provided in this embodiment of the invention;
[0042] Figure 8 This is a schematic diagram illustrating the downlink configuration data distribution function of the configuration translation and conversion tool provided in this embodiment of the invention. Detailed Implementation
[0043] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0044] See attached document Figure 1 Appendix Figure 4This invention mainly consists of data files and functional entities. The data files include the Standard Digital Model File (SCCD), SCCD-plus archive files, and device configuration description files (CID-plus). The functional entities include a configuration translation and conversion tool. This method applies to two types of target devices: incremental devices and existing devices.
[0045] The Standard Digital Model File (SCCD) is a template file that defines the baseline configuration of all equipment in the station. Constructed in accordance with the IEC 61850 standard, its internal data structure includes information on newly added assets, network topology relationships, and security configurations, and redefines the network security equipment model and the station control layer host model. This file serves as the technical starting point and standard benchmark for the entire methodology.
[0046] The SCCD-plus archive file is generated by verifying and merging the actual operating configuration values collected from field equipment with the overall digital standard model file (SCCD). This file contains both the configuration baseline standard and the actual operating status of the equipment, forming a unified configuration data source that reflects the current situation across the entire site.
[0047] The Device Configuration Description File (CID-plus) is a standalone configuration file generated for a single target device. It is produced by instantiating the model of the specified target device from the SCCD-plus archive file and contains complete, directly applicable configuration information for the target device to drive subsequent automated configuration processes.
[0048] Reference Appendix Figure 2 , Figure 2 This diagram illustrates the configuration distribution path for different types of devices provided by the master station system in this embodiment of the invention. The configuration translation and conversion tool is a functional entity used to enable information exchange between this method and existing devices that do not support the IEC 61850MMS service. During data acquisition in the master station system, the configuration translation and conversion tool connects to existing devices via protocols such as SSH, SNMP, and API to obtain and parse the raw configuration information, outputting unified structured data. In downlink configuration applications, this tool parses the configuration items in the device configuration description file (CID-plus), converts them into protocol commands or interface calls supported by the existing devices, and distributes them to the existing devices for configuration execution.
[0049] Incremental devices refer to network security devices or site control layer hosts that natively support IEC 61850MMS services and have the ability to directly parse CID-plus and complete their own configuration without the need for configuration translation tools as an intermediary.
[0050] Existing equipment refers to network security devices or station control layer hosts that do not support IEC 61850MMS services. They need to be integrated into the governance process of this method by configuring translation and conversion tools to complete protocol translation and data adaptation.
[0051] The overall workflow of this method constitutes a closed-loop data link of acquisition, modeling, and configuration. The starting point is the pre-built full-site digital standard model file (SCCD), which serves as the configuration baseline and defines the standardized configuration that all devices should follow.
[0052] The first step in the data flow is configuration acquisition and merging. The system collects the actual operating configuration values of on-site network security equipment and station control layer hosts, and verifies and merges these values with the configuration baseline defined in the Station Digital Standard Model (SCCD) file, ultimately generating an SCCD-plus archive file. This SCCD-plus archive file includes both the baseline standard and the real-time operating status of the equipment, forming a unified set of configuration data that reflects the current actual situation of the power station.
[0053] The second step in the data flow is configuration instantiation. This step takes the SCCD-plus archive file as input. When configuring a target device, the target device is selected from the SCCD-plus archive file and its device model, including logical devices and logical nodes, is instantiated. In the instantiated independent configuration view, specific runtime settings, interface parameters, and security policies are filled in, and then an independent CID-plus containing complete configuration information for the target device is exported.
[0054] The third stage of the data flow is automated configuration application. The generated CID-plus is sent to the corresponding target device to perform automated configuration. This stage has two execution paths depending on the type of target device. For incremental devices, the CID-plus file is directly received and parsed to complete its own configuration update. For existing devices, a configuration translation and conversion tool receives the CID-plus file, parses its contents, and translates the structured configuration information into protocols such as SSH, SNMP, or API supported by the existing device. The commands are then sent to the device for execution via the corresponding protocol.
[0055] The above three steps constitute a complete configuration management closed loop. After the target device completes an automated configuration, its operating status changes. In the next data collection cycle, this changed status will be re-collected as the new actual operating configuration value and checked against the SCCD baseline, thereby achieving continuous tracking and verification of the device configuration status and ensuring the continuous consistency of the device configuration with the station-wide standards.
[0056] Step S1 of the method of this invention is to construct a site-wide digital standard model file (SCCD). The purpose of this step is to create a unified, machine-readable configuration baseline that covers all network security devices and site control layer hosts. The SCCD model file strictly follows the IEC 61850 standard, uses the System Configuration Description Language (SCL) as its carrier, and is specifically extended based on the standard model.
[0057] To provide a comprehensive description of network security, the SCCD model file in this embodiment adds data dimensions such as asset ledger, network topology, and security configuration information to the existing System Configuration Description Language (SCL) file structure. The asset ledger information is added by expanding the definition of data objects describing the physical attributes of devices in the IED model's data type template, such as device manufacturer, model, serial number, firmware version, and physical installation location. Network topology modeling is achieved by defining the physical and logical connections between devices, specifically including defining each device's network interface, IP address, subnet mask, as well as the connection relationships between interfaces and their associated Virtual Local Area Network (VLAN) information.
[0058] To address the diverse functionalities of network security devices, this embodiment redefines and expands the standard IED model to accurately describe their unique security functions. This process specifically includes adding new Logical Device (LD) and Logical Node (LN) types dedicated to modeling network security devices. For example, a logical device named "Security Device" is defined, and several function-specific logical nodes are added under it: a "Security Policy" logical node to carry access control policies; a "Route" logical node to carry routing table information; and a "Virtual Private Network" logical node to carry tunnel configuration information. This expansion allows models originally designed for power automation to accurately map the functions of network security devices.
[0059] Within the extended model framework described above, this embodiment provides a structured definition of specific security configuration information. Access control policy configuration is modeled as an ordered set of rules within the security policy logical node, where each rule consists of a series of data objects, including source address, destination address, service port, protocol type, and action (allow or deny). Routing configuration is modeled as a routing table within the routing logical node, where each routing entry contains data objects such as destination network segment, subnet mask, next-hop address, and priority. Tunnel configuration is modeled as a set of data objects within the virtual private network logical node, defining parameters such as tunnel type, endpoint address, encryption algorithm, and authentication method. Network Address Translation (NAT) configuration is modeled as an independent set of rules, with each rule explicitly defining the mapping relationship between internal and external addresses. In this way, all critical security configuration information is transformed into a unified, standardized data structure, solidified in the SCCD model file, laying the data foundation for subsequent automated collection, verification, and configuration.
[0060] Step S2 of the method of this invention involves collecting the actual operating configuration values of the network security equipment and the station control layer host, verifying and merging them with the configuration baseline defined in the full-site digital standard model file (SCCD), and finally generating an SCCD-plus archive file. The core of this step is to obtain a configuration snapshot of the equipment in the real operating environment and compare and merge it with a preset ideal standard.
[0061] The data acquisition process employs two different technical paths depending on the device type. For incremental devices supporting the IEC 61850 Manufacturing Message Specification (MMS) service, the system directly accesses predefined logical nodes and data objects in the device model through the MMS read service to obtain their current configuration values. For existing devices that do not support this service, the data acquisition is performed by a configuration translation and conversion tool. This tool first establishes a communication session with the target device using protocols such as SSH, SNMP, or API, based on the preset device address and credentials. Subsequently, the tool executes a predefined set of instructions for the device model, such as sending command lines like `showrunning-config` via SSH, or sending a Get request to a specific Object Identifier (OID) in the Management Information Base (MIB) via SNMP, to obtain the text stream or data of its raw configuration information. After obtaining the raw configuration information, the tool applies parsing rules matching the device model, using regular expression matching, keyword extraction, and other methods to convert the unstructured raw configuration information into structured data consistent with the data structure of the full-site digital standard model file.
[0062] The collected actual operational configuration values cover three aspects. The first aspect is the actual configuration information of the network security device's security policies, including currently active firewall access control lists, network address translation rules, and tunnel configuration parameters. The second aspect is the actual physical network topology information, including the device online status obtained through periodic probing, the dynamic mapping relationship between Internet Protocol (IP) addresses and Media Access Control (MAC) addresses obtained by reading the device's Address Resolution Protocol (ARP) cache table, and the mapping relationship between switch network ports and MAC addresses obtained by reading the device's MAC address table. The third aspect is the security configuration information required for practical application of situational awareness, specifically including port mirroring configuration for traffic monitoring, the target address and community word for Simple Network Management Protocol Trap (SNMPTrap) configuration for alarm uploading, and the server address and transport protocol for System Log (Syslog) configuration for logging.
[0063] After collecting and structuring all actual operational configuration values for all devices, the system performs verification and information merging operations. This operation relies on a professional, visual SCCD editing tool. Engineers use this tool to load the collected structured configuration values and compare them item by item with the configuration baseline values contained in the predefined SCCD model file to identify differences. Simultaneously, engineers use the SCCD model file as a template to perform merging, creating a new archive file and filling the corresponding data objects in the new file with the collected actual operational configuration values. Differences identified during the verification process are specifically marked. Finally, this archive file, integrating baseline standards, actual configuration status, and difference markers, is the SCCD-plus archive file.
[0064] Reference Appendix Figure 3 , Figure 3 This is a schematic diagram illustrating the process of generating an SCCD-plus archive file according to an embodiment of the present invention. Step S3 of the method of the present invention involves instantiating the model of the target device based on the SCCD-plus archive file and generating a CID-plus file containing the configuration information of the target device. This step is a key link connecting the configuration data of the entire site with the configuration task of a single device, and its purpose is to generate an independent, self-contained, and directly executable configuration file for a specific device.
[0065] This step is performed in a configuration tool software called SCCD editing tool. Its primary operation is to load the SCCD-plus archive file generated in step S2. This archive file contains the model definitions, baseline configurations, and actual operating configuration values of all network security devices and site control layer hosts across the entire site, and is the complete set of data for generating individual device configurations.
[0066] After the SCCD-plus archive is fully loaded, the system provides a list of target devices to select. The operator or automation script selects the target device from this list. Once the target device is selected, the configuration tool performs an instantiation operation. This operation extracts all model definitions and data values related to the selected target device from the SCCD-plus archive's dataset, including specific logical devices and logical nodes, and builds a separate configuration view in memory containing only that device's information.
[0067] In the independent configuration view, the system populates specific configuration parameters into the corresponding model data objects. These parameters include setpoints for device operation, interface parameters defining network connections, and security policies specifying behavioral guidelines. These parameter values to be populated are derived from baseline values or actual operating values already merged in the SCCD-plus archive files, and final modifications or confirmations can be made at this stage.
[0068] Once all configuration items in the independent configuration view are populated and confirmed, the SCCD editing tool executes the export function. This function encapsulates all data in the current independent configuration view according to the IEC 61850 CID file format standard, generating an independent, self-contained device configuration description file, namely the CID-plus file. This file is structurally compatible with the standard CID file, but its content has been extended using the method of this invention, containing all the information required for complete configuration of the target device, and can be directly used for the next step of automated configuration application.
[0069] Step S4 of the method of this invention involves applying the CID-plus file to complete the automated configuration of the target device. This step is the end point of the entire closed-loop chain, aiming to accurately convert the standardized configuration file generated in step S3 into the actual operating configuration of the target device. The execution path of this step is divided into two cases depending on the protocol support capabilities of the target device.
[0070] In the first scenario, when the target device is an incremental device supporting IEC 61850MMS services, the automated configuration process is executed directly by the device itself. In this process, the generated CID-plus file is transmitted to the target device. The configuration service or agent integrated within the device receives this file and calls its built-in System Configuration Description Language (SCL) parsing engine to parse the file content. The parsing engine extracts the device model, logical nodes, and configuration values of each data object defined in the CID-plus file and converts them into internal configuration instructions recognizable by the device's operating system. Subsequently, the device automatically executes these internal instructions, updating network interfaces, routing tables, access control policies, and other configuration items to its runtime configuration, thereby completing the automated configuration.
[0071] In the second scenario, when the target device is an existing device that does not support IEC 61850MMS services, the automated configuration process is executed by a configuration translation and conversion tool. In this process, the CID-plus file is sent to the tool. The tool first extracts the structured configuration information from the CID-plus file using its SCL parsing engine. Then, based on the target device's model and manufacturer information, the tool matches the corresponding instruction template in its internal translation rule base. This instruction template defines how to convert standard, structured configuration items (such as an access control rule) into unstructured command-line statements, specific object identifiers and values for SNMPSet requests, or specific data formats for API calls supported by that specific device model. After translation, the tool establishes a connection with the target device through the corresponding protocol and sends a series of converted protocol commands to the device for execution in a predetermined order, thereby indirectly completing the automated configuration of the existing device.
[0072] The configuration translation and conversion tool is a functional entity that enables information exchange between the method of this invention and existing devices that do not support the IEC 61850MMS service. Internally, it mainly consists of an IEC 61850MMS server module, a model parsing engine module, a multi-protocol client module (including sub-modules such as SSH, SNMP, and API), and a data parsing and translation module. The main functions of this configuration translation and conversion tool include initialization and uplink data acquisition, real-time data monitoring, periodic data inspection, and downlink configuration data distribution.
[0073] See attached document Figure 5 The diagram illustrates the tool's initialization and uplink data acquisition functions. Initialization and uplink data acquisition begin with the tool importing a CID-plus file. Subsequently, the tool's internal model parsing engine module analyzes the CID-plus file and stores the data model in the database. Based on this, the tool starts the IEC 61850 MMS server, providing standard MMS services to the master station based on the parsed data model. The tool's multi-protocol client module establishes connections with the target network security device via SSH, SNMP, and API protocols based on the connection information in the model, and executes commands to read all data, updating the collected device configuration information to the database. Finally, this information can be accessed by the master station through the started MMS service.
[0074] See attached document Figure 6The diagram illustrates the tool's real-time data monitoring function. This function involves the master station subscribing to reports from the tool to receive real-time updates on the status of specific devices. Upon receiving a subscription request, the tool's real-time monitoring module is activated. This module continuously monitors the operational status and resources of network security devices via its internal SSH, SNMP, and API clients. When the client obtains status changes or alarm data from the device, it forwards the data to the tool for processing. After determining that the data meets the reporting criteria, the tool executes a data publishing operation, proactively uploading the generated report to the subscribed master station via the MMS service.
[0075] See attached document Figure 7 The diagram illustrates the tool's periodic data inspection function. This function has two triggering methods. The first method involves the master station actively issuing an inspection command. Upon receiving this command, the tool's IEC 61850 server immediately drives the SSH, SNMP, and API clients to perform a one-time data inspection of the network security equipment. The second method involves the master station issuing an inspection cycle configuration, or maintenance personnel directly configuring a periodic inspection cycle on the tool. Both configuration methods affect the tool's automatic periodic inspection module, causing it to automatically trigger inspections at preset time intervals. Regardless of the triggering method, once the SSH, SNMP, and API clients obtain data from the network security equipment, they will return the data to the IEC 61850 server, which ultimately provides the inspection results to the master station.
[0076] See attached document Figure 8 This diagram illustrates the tool's downlink configuration data distribution function. The downlink configuration data distribution function begins with the master station initiating a write data request to the tool's IEC 61850 server. Upon receiving the request, the server forwards the command to the SSH, SNMP, and API clients via its internal forwarding mechanism. The client, upon receiving the command, converts it into a native device command and executes the write data operation on the network security device. After completing the configuration, the network security device returns the execution result to the SSH, SNMP, and API clients. Upon receiving the result, the client also forwards it to the IEC 61850 server via the forwarding mechanism. Finally, the server encapsulates this execution result into a standard MMS write service response and returns it to the master station, thus completing a closed-loop configuration distribution operation.
Claims
1. A method for unified digital management of network security devices based on a SCCD-plus model, characterized in that, The method comprises the following steps: S1, constructing an SCCD model file: the SCCD model file complies with the IEC 61850 system standard, and contains newly added asset account, network topology, security configuration information, and redefined network security device model and station control layer host model; S2, collecting actual operation configuration values of the network security device and the station control layer host, checking and merging the collected actual operation configuration values with the configuration value baseline defined in the SCCD model file, and generating an SCCD-plus archive file; S3, instantiating the model of the target device based on the SCCD-plus archive file, and generating a CID-plus file containing configuration information of the target device; S4, applying the CID-plus file to complete the automatic configuration of the target device.
2. The SCCD-plus model-based network security device unified digital governance method according to claim 1, characterized in that, In the S1 step, the establishment of the SCCD model file further comprises: Extending the IED model, and newly adding logical devices and logical nodes for supporting unified modeling of security policies and topology interconnection information.
3. The SCCD-plus model-based network security device unified digital governance method according to claim 1, characterized in that, The actual operation configuration values collected in the S2 step include: Actual configuration information of the security policy of the network security device, actual physical network topology relationship information, and security configuration information required for situational awareness.
4. The SCCD-plus model-based network security device unified digital governance method according to claim 1, characterized in that, The process of generating the CID-plus file in the S3 step specifically comprises: Loading the SCCD-plus archive file in the configuration tool; Selecting the target device and instantiating the logical devices and logical nodes of the target device based on the loaded SCCD-plus archive file, to form an independent configuration view; Filling in the operation value, interface parameter and security policy in the independent configuration view; Exporting the filled configuration as a CID-plus file.
5. The SCCD-plus model-based network security device unified digital governance method according to claim 1, characterized in that, The collection step of S2 specifically comprises: When the network security device and the station control layer host are incremental devices supporting the IEC 61850 MMS service, the master station system obtains and parses the original configuration information of the incremental device through the IEC 61850 MMS service; When the network security device and the station control layer host are stock devices that do not support the IEC 61850 MMS service, the configuration translation conversion tool obtains and parses the original configuration information of the stock device through SSH, SNMP and API protocols.
6. The SCCD-plus model based cyber security device unified digital governance method according to claim 1, characterized in that, When the target device is an incremental device supporting the IEC 61850 MMS service, the S4 step specifically comprises: The incremental device directly parses the CID-plus file to complete the automatic configuration.
7. The method of claim 1, wherein the method is based on the SCCD-plus model, and the method is characterized by, When the target device is a stock device that does not support the IEC 61850 MMS service, the S4 step specifically comprises: The configuration translation conversion tool parses the CID-plus file, converts the parsed configuration information into a protocol command supported by the stock device, and then issues the protocol command to the stock device to execute and apply the configuration information, thereby completing the automatic configuration.
8. The SCCD-plus model based cyber security device unified digital governance method according to claim 1, characterized in that, The security configuration information includes VLAN configuration, routing configuration, access control policy configuration, tunnel configuration and network address translation configuration.
9. The method of claim 3, wherein the SCCD-plus model-based unified digital governance of cyber security devices is characterized by, The actual physical network topology relationship information includes online device state, address resolution protocol state table and media access control state table.
10. The method of claim 3, wherein the SCCD-plus model-based unified digital governance of cyber security devices is characterized by, Security configuration information required by situational awareness utility includes port mirroring configuration, simple network management protocol Trap configuration, and system log configuration.