Remote operation and maintenance method, device and system based on relay protection
By introducing trusted hardware modules and operating systems into smart grid relay protection equipment, combined with two-factor authentication and tamper-proof audit logs, the security issues in remote operation and maintenance modes are resolved, achieving inherent security of the equipment and traceability of operations.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING CREDIBLE HUATAI TECHNICAL SERVICE CO LTD
- Filing Date
- 2025-12-25
- Publication Date
- 2026-04-28
AI Technical Summary
The remote operation and maintenance mode of smart grid relay protection equipment has low security issues, especially in terms of the lack of effective solutions for the plaintext transmission of sensitive information and user authentication.
A remote operation and maintenance system based on trusted hardware modules and a trusted operating system is adopted. Through two-factor authentication, encryption, anti-replay, and digital signature technologies, an audit log that is tamper-proof throughout the entire process is constructed to ensure the security of operation and maintenance operations.
It achieves inherent safety for smart grid relay protection equipment, ensures the safety and traceability of remote operation and maintenance processes, and meets the safety audit compliance requirements of the power industry.
Smart Images

Figure CN121940429A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of smart grids, and more specifically, to a remote operation and maintenance method, device, and system based on relay protection. Background Technology
[0002] This section is intended to provide background or context for the content set forth in the claims or specification, and the content described herein is not acknowledged as prior art simply because it is included in this section.
[0003] With the rapid development of smart grid relay protection technology and the continuous improvement of refined management requirements, the number of devices is increasing and new technologies are constantly being introduced. Traditional operation and maintenance models are labor-intensive and inefficient. Therefore, remote operation and maintenance of relay protection equipment is widely used. However, the security issues such as plaintext transmission of sensitive information and inability to verify user identity also need to be addressed.
[0004] There is currently no effective solution to the above problems. Summary of the Invention
[0005] This application provides a remote operation and maintenance method, device, and system based on relay protection, to at least solve the technical problem of low security of relay protection in smart grids.
[0006] According to one aspect of the embodiments of this application, a remote operation and maintenance system based on relay protection is provided, comprising: a remote operation and maintenance master station deployed in an operation and maintenance center, the remote operation and maintenance master station employing a first trusted hardware module, the first trusted hardware module running a first trusted operating system, the first trusted operating system running a data analysis and processing platform, the data analysis and processing platform being used to encapsulate trusted remote operation and maintenance operation instructions into secure operation and maintenance files and record the operation process to a first audit log, wherein the first audit log is an immutable log; and an intelligent waveform recorder deployed at a substation site, interacting with the remote operation and maintenance master station via files and interacting with protection devices using a secure and controllable protocol, the intelligent waveform recorder employing a second trusted hardware module, the second trusted hardware module running a second trusted operating system, the second trusted operating system running a business processing module, the business processing module being used to parse trusted remote operation and maintenance operation instructions from secure operation and maintenance files, control protection devices according to trusted remote operation and maintenance operation instructions, and record the operation process to a second audit log, wherein the second audit log is an immutable log.
[0007] According to another aspect of the embodiments of this application, a remote operation and maintenance method based on relay protection is also provided, applied to a remote operation and maintenance master station, comprising: upon obtaining a remote operation and maintenance operation instruction from a trusted user, encapsulating the remote operation and maintenance operation instruction into a secure operation and maintenance file, wherein the remote operation and maintenance master station employs a first trusted hardware module, the first trusted hardware module runs a first trusted operating system, the first trusted operating system runs a data analysis and processing platform, the data analysis and processing platform is used to record the operation process to a first audit log, the first audit log being an immutable log; sending the operation and maintenance file to an intelligent waveform recorder via a file, wherein the intelligent waveform recorder interacts with the protection device using a secure and controllable protocol, the intelligent waveform recorder employs a second trusted hardware module, the second trusted hardware module runs a second trusted operating system, the second trusted operating system runs a business processing module, the business processing module is used to parse trusted remote operation and maintenance operation instructions from the secure operation and maintenance file, control the protection device according to the trusted remote operation and maintenance operation instructions, and record the operation process to a second audit log, the second audit log being an immutable log.
[0008] Optionally, a two-factor authentication method is used to determine whether the current user is a trusted user: A login request from the current user is received; if the username and password in the login request do not match the pre-stored credentials, the current user is determined to be an untrusted user; if the username and password in the login request match the pre-stored credentials, the signature information of the current user is obtained, wherein the signature information of a trusted user is obtained by signing using its national cryptographic digital certificate; if the signature information verification of the current user fails, the current user is determined to be an untrusted user; if the signature information verification of the current user passes, the current user is determined to be a trusted user.
[0009] Optionally, the remote operation and maintenance instructions are packaged into a secure operation and maintenance file, including: adding a timestamp, digital signature and encryption to the remote operation and maintenance instructions to form the operation and maintenance file.
[0010] Optionally, the maintenance files can be sent to the intelligent waveform recorder via a file, including: calling the IEC 61850 file service to distribute the maintenance files to the intelligent waveform recorder.
[0011] According to another aspect of the embodiments of this application, a remote operation and maintenance method based on relay protection is also provided, applied to an intelligent waveform recorder, comprising: receiving an operation and maintenance file sent by a remote operation and maintenance master station via a file, wherein the remote operation and maintenance master station is used to encapsulate remote operation and maintenance operation instructions from a trusted user into a trusted operation and maintenance file, the remote operation and maintenance master station employs a first trusted hardware module, the first trusted hardware module runs a first trusted operating system, the first trusted operating system runs a data analysis and processing platform, the data analysis and processing platform is used to record the operation process to a first audit log, the first audit log being an immutable log; parsing trusted remote operation and maintenance operation instructions from the secure operation and maintenance file, controlling the protection device according to the trusted remote operation and maintenance operation instructions, and recording the operation process to a second audit log, wherein the intelligent waveform recorder interacts with the protection device using a secure and controllable protocol, the intelligent waveform recorder employs a second trusted hardware module, the second trusted hardware module runs a second trusted operating system, the second trusted operating system runs a business processing module, and the second audit log is an immutable log.
[0012] Optionally, parsing trusted remote operation instructions from secure operation and maintenance files includes: extracting embedded timestamps from the received operation and maintenance files and calculating the time deviation between the timestamps and the local time; if the absolute value of the time deviation exceeds a target threshold, determining that the operation and maintenance file is expired or is a replay attack; if the absolute value of the time deviation does not exceed the target threshold, performing signature verification on the operation and maintenance file; if the signature verification of the operation and maintenance file passes, performing national cryptographic decryption on the operation and maintenance file; if the decryption is successful, determining that the operation and maintenance file is secure and obtaining trusted remote operation and maintenance instructions.
[0013] According to another aspect of the embodiments of this application, a remote operation and maintenance device based on relay protection is also provided, applied to a remote operation and maintenance master station, comprising: an encapsulation unit, used to encapsulate the remote operation and maintenance operation instructions of a trusted user into a secure operation and maintenance file, wherein the remote operation and maintenance master station adopts a first trusted hardware module, the first trusted hardware module runs a first trusted operating system, the first trusted operating system runs a data analysis and processing platform, the data analysis and processing platform is used to record the operation process to a first audit log, the first audit log being an immutable log; and a sending unit, used to send the operation and maintenance file to an intelligent waveform recorder via a file, wherein the intelligent waveform recorder interacts with the protection device using a secure and controllable protocol, the intelligent waveform recorder adopts a second trusted hardware module, the second trusted hardware module runs a second trusted operating system, the second trusted operating system runs a business processing module, the business processing module is used to parse trusted remote operation and maintenance instructions from the secure operation and maintenance file, control the protection device according to the trusted remote operation and maintenance operation instructions, and record the operation process to a second audit log, the second audit log being an immutable log.
[0014] According to another aspect of the embodiments of this application, a remote operation and maintenance device based on relay protection is also provided, applied to an intelligent waveform recorder, comprising: a receiving unit, configured to receive operation and maintenance files sent by a remote operation and maintenance master station via a file, wherein the remote operation and maintenance master station is configured to encapsulate remote operation and maintenance operation instructions from a trusted user into a trusted operation and maintenance file, the remote operation and maintenance master station employs a first trusted hardware module, the first trusted hardware module runs a first trusted operating system, the first trusted operating system runs a data analysis and processing platform, the data analysis and processing platform is configured to record the operation process to a first audit log, the first audit log being an immutable log; and a control unit, configured to parse trusted remote operation and maintenance operation instructions from the secure operation and maintenance file, control the protection device according to the trusted remote operation and maintenance operation instructions, and record the operation process to a second audit log, wherein the intelligent waveform recorder interacts with the protection device using a secure and controllable protocol, the intelligent waveform recorder employs a second trusted hardware module, the second trusted hardware module runs a second trusted operating system, the second trusted operating system runs a business processing module, and the second audit log is an immutable log.
[0015] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the storage medium including a stored program that executes the above-described method when the program is run.
[0016] According to another aspect of the embodiments of this application, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor performs the above-described method through the computer program.
[0017] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps of any of the embodiments of the methods described above.
[0018] In this embodiment, upon obtaining remote operation and maintenance instructions from a trusted user, the remote operation and maintenance instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station employs a first trusted hardware module, on which runs a first trusted operating system. Within the first trusted operating system, a data analysis and processing platform is run. This platform records the operation process to a first audit log, which is an immutable log. The operation and maintenance file is sent to an intelligent waveform recorder via file. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. Within this second trusted operating system, a business processing module is run. This business processing module parses the trusted remote operation and maintenance instructions from the secure operation and maintenance file, controls the protection device according to the trusted instructions, and records the operation process to a second audit log, which is also an immutable log. By using trusted technologies to ensure the inherent security of equipment, and employing encryption, anti-replay, and digital signature technologies during remote operation and maintenance of inspection models and incremental configurations, the security of remote operation and maintenance is effectively guaranteed, which can solve the technical problem of low security in smart grid relay protection. Attached Figure Description
[0019] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a schematic diagram of an optional remote operation and maintenance system based on relay protection according to an embodiment of this application; Figure 2 This is a flowchart of an optional remote operation and maintenance method based on relay protection according to an embodiment of this application; Figure 3 This is a flowchart of an optional remote operation and maintenance method based on relay protection according to an embodiment of this application; Figure 4 This is a schematic diagram of an optional remote operation and maintenance scheme based on relay protection according to an embodiment of this application; Figure 5 This is a schematic diagram of an optional remote operation and maintenance device based on relay protection according to an embodiment of this application; Figure 6 This is a schematic diagram of an optional remote operation and maintenance device based on relay protection according to an embodiment of this application; Figure 7 This is a structural block diagram of a terminal according to an embodiment of this application. Detailed Implementation
[0020] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0021] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0022] To address the issue of insufficient security measures during remote operation and maintenance of relay protection equipment, this application provides a method embodiment for remote operation and maintenance based on relay protection. This method constructs an overall security architecture for remote operation and maintenance, and designs technologies such as remote secure communication based on national cryptographic algorithms and non-repudiation of critical operations to ensure the security of the entire operation and maintenance process. In this embodiment, the aforementioned remote operation and maintenance method based on relay protection can be applied to applications such as... Figure 1 The remote operation and maintenance system based on relay protection shown below: The remote operation and maintenance master station is deployed in the operation and maintenance center. The remote operation and maintenance master station adopts a first trusted hardware module. The first trusted hardware module runs a first trusted operating system. The first trusted operating system runs a data analysis and processing platform. The data analysis and processing platform is used to encapsulate trusted remote operation and maintenance instructions into secure operation and maintenance files and record the operation process to a first audit log. The first audit log is an unalterable log. The intelligent waveform recorder, deployed at the substation site, interacts with the remote operation and maintenance master station via files and uses a secure and controllable protocol to interact with the protection device. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. Within the second trusted operating system, a business processing module is run. This business processing module is used to parse trusted remote operation and maintenance instructions from secure operation and maintenance files, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process in a second audit log, which is an immutable log.
[0023] In the technical solution of this application, the overall architecture of trusted and secure remote operation and maintenance for relay protection mainly consists of a remote operation and maintenance master station for relay protection, an intelligent waveform recorder, and relay protection devices. This solution constructs a remote operation and maintenance master station for relay protection to achieve remote operation and maintenance of the intelligent waveform recorder. The relay protection operation and maintenance master station adopts underlying hardware and operating system based on trusted technology, and builds a data analysis and processing platform to realize functions such as user management, command control, configuration updates, remote upgrades, and log auditing. The intelligent waveform recorder also adopts underlying hardware and operating system based on trusted technology, realizing the remote operation and maintenance business functions issued by the master station and forwarding the commands to the protection device. The master station and the intelligent waveform recorder communicate using the existing IEC 61850 communication mode, using file-based remote operation and maintenance command interaction. Simultaneously, the operation and maintenance files are encrypted, protected against replay, and digitally signed to ensure the security and reliability of the operation and maintenance process.
[0024] Figure 2 This is a flowchart of an optional remote operation and maintenance method based on relay protection according to an embodiment of this application, applied to a remote operation and maintenance master station, such as... Figure 2 As shown, the method may include the following steps: Step S202: Upon obtaining the remote operation and maintenance instructions from a trusted user, the remote operation and maintenance instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station adopts a first trusted hardware module, on which a first trusted operating system runs. A data analysis and processing platform runs in the first trusted operating system. The data analysis and processing platform is used to record the operation process to a first audit log, which is an unalterable log.
[0025] In the above scheme, two-factor authentication can be used to determine whether the current user is a trusted user: The login request from the current user is received; if the username and password in the login request do not match the pre-stored credentials, the current user is determined to be an untrusted user; if the username and password in the login request match the pre-stored credentials, the signature information of the current user is obtained, which is obtained by calling their national cryptographic digital certificate; if the signature information verification of the current user fails, the current user is determined to be an untrusted user; if the signature information verification of the current user passes, the current user is determined to be a trusted user.
[0026] When encapsulating remote operation and maintenance instructions into secure operation and maintenance files, timestamps, digital signatures, and encryption can be added to the remote operation and maintenance instructions to form the operation and maintenance files.
[0027] Step S204: The operation and maintenance file is sent to the intelligent waveform recorder via file. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder adopts a second trusted hardware module, on which a second trusted operating system runs. The second trusted operating system contains a business processing module. The business processing module is used to parse trusted remote operation and maintenance instructions from the secure operation and maintenance file, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process to the second audit log. The second audit log is an unalterable log.
[0028] In the above solution, the IEC 61850 document service can be invoked to send the operation and maintenance documents to the intelligent waveform recorder.
[0029] Through the above steps, upon obtaining remote operation and maintenance instructions from a trusted user, these instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station employs a first trusted hardware module, on which runs a first trusted operating system. Within this first trusted operating system, a data analysis and processing platform is run. This platform records the operation process to a first audit log, which is immutable. The operation and maintenance file is then sent to an intelligent waveform recorder. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. Within this second trusted operating system, a business processing module is run. This business processing module parses the trusted remote operation and maintenance instructions from the secure file, controls the protection device according to these instructions, and records the operation process to a second audit log, which is also immutable. By using trusted technologies to ensure the inherent security of equipment, and employing encryption, anti-replay, and digital signature technologies during remote operation and maintenance of inspection models and incremental configurations, the security of remote operation and maintenance is effectively guaranteed, thus solving the technical problem of low security in smart grid relay protection.
[0030] Figure 3 This is a flowchart of an optional remote operation and maintenance method based on relay protection according to an embodiment of this application, applied to an intelligent waveform recorder, such as... Figure 3 As shown, the method may include the following steps: Step S302: Receive maintenance files sent by the remote maintenance master station via file. The remote maintenance master station encapsulates the remote maintenance operation instructions of trusted users into trusted maintenance files. The remote maintenance master station uses a first trusted hardware module, on which a first trusted operating system runs. A data analysis and processing platform runs within the first trusted operating system. The data analysis and processing platform records the operation process to a first audit log, which is an immutable log.
[0031] Step S304: Parse the trusted remote operation and maintenance instructions from the secure operation and maintenance files, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process to the second audit log. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder adopts a second trusted hardware module, on which a second trusted operating system runs. A business processing module runs in the second trusted operating system. The second audit log is an immutable log.
[0032] When parsing trusted remote operation instructions from secure operation and maintenance files, the embedded timestamp can be extracted from the received operation and maintenance file, and the time deviation between the timestamp and the local time can be calculated. If the absolute value of the time deviation exceeds the target threshold, the operation and maintenance file is determined to be expired or a replay attack. If the absolute value of the time deviation does not exceed the target threshold, the operation and maintenance file is signed and verified. If the signature verification of the operation and maintenance file passes, the operation and maintenance file is decrypted using national cryptographic standards. If the decryption is successful, the operation and maintenance file is confirmed to be secure, and trusted remote operation and maintenance instructions are obtained.
[0033] As an optional embodiment, the following is combined with Figure 4 Further details of the technical solution of this application: In substation renovation, expansion, or new construction scenarios, after the user provides a new SCD file, service personnel complete offline configuration through the remote operation and maintenance master station, generate encrypted incremental configuration files, and distribute them remotely. After receiving the files, the intelligent waveform recorder automatically completes security verification (decryption, signature verification, and anti-replay), configuration parsing, and database solidification, without requiring on-site personnel involvement throughout the entire process.
[0034] The execution of remote operation and maintenance (O&M) services primarily involves user login and two-factor authentication (F2A) and user permission verification at the remote O&M master station. Upon successful verification, a timestamp, digital certificate signature, and encryption based on national cryptographic algorithms are added to the operation to create an O&M file. This file is sent to the intelligent waveform recorder via the IEC61850 file service. The intelligent waveform recorder receives the file, decrypts it, verifies the digital certificate signature, and performs anti-replay verification. After successful verification, it parses the file's content and executes the corresponding commands, then returns the result. The entire process requires audit log recording to ensure traceability. A typical system business process is as follows: Figure 4 As shown.
[0035] Anti-replay and anti-tampering protection: 1) Anti-replay attack: Precise timestamps are embedded in the operation and maintenance files. After receiving the file, the intelligent waveform recorder verifies the validity of the timestamps (default allowance ±30s deviation, configurable). If an expired or duplicate timestamp is detected, the operation is rejected. 2) Anti-tampering guarantee: The operation and maintenance file digest is calculated using the SM3 hash algorithm, combined with the SM2 digital signature. After receiving the file, the intelligent waveform recorder recalculates the digest and compares it with the digest after decryption. If the file content is tampered with, the digest will change, and the verification will fail directly, ensuring the integrity of the operation and maintenance commands. The tampering detection success rate reaches 100%.
[0036] The system enables full-process log auditing of operation and maintenance, recording key information such as "user identity, operation time, operation content, execution result, and digital signature". The logs are immutable and traceable. When abnormal operations occur, the responsible person and operation trajectory can be quickly located through the logs. The time spent on tracing is reduced from one week of traditional manual investigation to 10 minutes, meeting the safety audit compliance requirements of the power industry.
[0037] The innovative aspects of the technical solution in this application are as follows: 1) Architecture Level: Deep Integration and Innovation of Trusted Technology and Power Operation and Maintenance Scenarios Breaking through the limitations of traditional remote operation and maintenance architectures that prioritize functionality over intrinsic security, this invention deeply embeds trusted technologies (trusted hardware + trusted operating system) into the entire relay protection remote operation and maintenance chain, constructing a three-tiered trusted protection system of "master station - intelligent waveform recorder - protection device". Unlike conventional operation and maintenance systems that only add encryption at the communication layer, this invention introduces trusted technologies at the underlying hardware and operating system levels of the master station and intelligent waveform recorder: the master station relies on trusted hardware to build a data analysis and processing platform, enabling trusted execution of functions such as user management and command control; the intelligent waveform recorder ensures the security of master station command reception, parsing, and forwarding through a trusted carrier, eliminating risks such as malicious code injection and hardware tampering from the device's root cause, forming a full-stack protection of "hardware trust - system trust - operation trust", solving the core problem of insufficient intrinsic security of devices under traditional architectures.
[0038] 2) Operational Control: Closed-Loop Innovation of Two-Factor Authentication and Full-Process Traceability This system establishes a closed-loop operation control mechanism encompassing identity verification, operation signature, and log storage, overcoming the bottlenecks of traditional operations and maintenance systems where identity verification and operation traceability are difficult. On one hand, it innovatively adopts a two-factor authentication mechanism of "account password + national cryptographic digital certificate." Users must pass dual verification to log in to the main station. When performing critical operations such as modifying settings or remote restarts, an additional SM2 digital signature is generated to ensure the uniqueness and legitimacy of the operating entity. On the other hand, it designs an immutable, full-process audit log that records complete information such as user identity, operation time, operation content, execution result, and digital signature. The log is linked to the operation process in real time. When abnormal operations occur, the operating entity can be traced through the digital signature, and the problematic link can be located through the timestamp and operation content. The tracing time is reduced from one week of traditional manual investigation to 10 minutes, achieving traceable operations and identifiable responsibility, meeting the stringent safety audit compliance requirements of the power industry.
[0039] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0040] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0041] According to another aspect of the embodiments of this application, a relay-based remote operation and maintenance device for implementing the above-described relay-based remote operation and maintenance method is also provided. Figure 5 This is a schematic diagram of an optional remote operation and maintenance device based on relay protection according to an embodiment of this application, applied to a remote operation and maintenance master station, such as... Figure 5 As shown, the device may include: The encapsulation unit 501 is used to encapsulate the remote operation and maintenance operation instructions into a secure operation and maintenance file when a trusted user's remote operation and maintenance operation instructions are obtained. The remote operation and maintenance master station adopts a first trusted hardware module, the first trusted hardware module runs a first trusted operating system, the first trusted operating system runs a data analysis and processing platform, and the data analysis and processing platform is used to record the operation process to a first audit log, the first audit log being an unalterable log.
[0042] In the above scheme, two-factor authentication can be used to determine whether the current user is a trusted user: The login request from the current user is received; if the username and password in the login request do not match the pre-stored credentials, the current user is determined to be an untrusted user; if the username and password in the login request match the pre-stored credentials, the signature information of the current user is obtained, where the signature information of a trusted user is obtained by signing using their national cryptographic digital certificate; if the signature information verification of the current user fails, the current user is determined to be an untrusted user; if the signature information verification of the current user passes, the current user is determined to be a trusted user.
[0043] When encapsulating the remote operation and maintenance instructions into a secure operation and maintenance file, a timestamp, digital signature, and encryption can be added to the remote operation and maintenance instructions to form the operation and maintenance file.
[0044] The sending unit 503 is used to send the operation and maintenance file to the intelligent waveform recorder via a file. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder adopts a second trusted hardware module, on which a second trusted operating system runs. The second trusted operating system has a business processing module running. The business processing module is used to parse trusted remote operation and maintenance instructions from the secure operation and maintenance file, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process to a second audit log. The second audit log is an unalterable log.
[0045] In the above solution, the IEC 61850 file service can be invoked to send the maintenance files to the intelligent waveform recorder.
[0046] According to another aspect of the embodiments of this application, a relay-based remote operation and maintenance device for implementing the above-described relay-based remote operation and maintenance method is also provided. Figure 6 This is a schematic diagram of an optional remote operation and maintenance device based on relay protection according to an embodiment of this application, applied to an intelligent waveform recorder, such as... Figure 6 As shown, the device may include: The receiving unit 601 is used to receive maintenance files sent by the remote maintenance master station via a file. The remote maintenance master station is used to encapsulate the remote maintenance operation instructions of trusted users into trusted maintenance files. The remote maintenance master station adopts a first trusted hardware module, on which a first trusted operating system runs. The first trusted operating system runs a data analysis and processing platform, which is used to record the operation process to a first audit log. The first audit log is an immutable log.
[0047] The control unit 603 is used to parse trusted remote operation and maintenance instructions from secure operation and maintenance files, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process to the second audit log. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder adopts a second trusted hardware module, on which a second trusted operating system runs. A business processing module runs in the second trusted operating system. The second audit log is an immutable log.
[0048] When parsing trusted remote operation instructions from secure operation and maintenance files, the embedded timestamp can be extracted from the received operation and maintenance file, and the time deviation between the timestamp and the local time can be calculated. If the absolute value of the time deviation exceeds a target threshold, the operation and maintenance file is determined to be expired or a replay attack. If the absolute value of the time deviation does not exceed the target threshold, the operation and maintenance file is signed and verified. If the signature verification of the operation and maintenance file passes, the operation and maintenance file is decrypted using national cryptographic standards. If the decryption is successful, the operation and maintenance file is confirmed to be secure, and trusted remote operation and maintenance instructions are obtained.
[0049] Through the aforementioned modules, upon obtaining remote operation and maintenance instructions from a trusted user, these instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station employs a first trusted hardware module, on which runs a first trusted operating system. Within this first trusted operating system, a data analysis and processing platform is run. This platform records the operation process to a first audit log, which is an immutable log. The operation and maintenance file is then sent to an intelligent waveform recorder. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. Within this second trusted operating system, a business processing module is run. This business processing module parses trusted remote operation and maintenance instructions from the secure operation and maintenance file, controls the protection device according to these instructions, and records the operation process to a second audit log, which is also an immutable log. By using trusted technologies to ensure the inherent security of equipment, and employing encryption, anti-replay, and digital signature technologies during remote operation and maintenance of inspection models and incremental configurations, the security of remote operation and maintenance is effectively guaranteed, thus solving the technical problem of low security in smart grid relay protection.
[0050] It should be noted that the examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the content disclosed in the above embodiments. It should also be noted that the above modules, as part of the device, can run in a corresponding hardware environment, and can be implemented through software or hardware, wherein the hardware environment includes a network environment.
[0051] According to another aspect of the embodiments of this application, a server or terminal for implementing the above-described remote operation and maintenance method based on relay protection is also provided.
[0052] Figure 7 This is a structural block diagram of a terminal according to an embodiment of this application, such as... Figure 7 As shown, the terminal may include: one or more (only one is shown in the figure) processors 701, memory 703, and transmission devices 705, such as... Figure 7 As shown, the terminal may also include input / output devices 707.
[0053] The memory 703 can be used to store software programs and modules, such as the program instructions / modules corresponding to the remote operation and maintenance method and device based on relay protection in this embodiment. The processor 701 executes various functional applications and data processing by running the software programs and modules stored in the memory 703, thereby realizing the aforementioned remote operation and maintenance method based on relay protection. The memory 703 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 703 may further include memory remotely located relative to the processor 701, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0054] The aforementioned transmission device 705 is used to receive or send data via a network, and can also be used for data transfer between the processor and memory. Specific examples of the network described above may include wired networks and wireless networks. In one example, the transmission device 705 includes a Network Interface Controller (NIC), which can be connected to other network devices and a router via a network cable to communicate with the Internet or a local area network. In another example, the transmission device 705 is a radio frequency (RF) module used for wireless communication with the Internet.
[0055] Specifically, memory 703 is used to store application programs.
[0056] The processor 701 can invoke the application program stored in the memory 703 via the transmission device 705 to perform the following steps: Upon obtaining remote operation and maintenance instructions from a trusted user, these instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station employs a first trusted hardware module, which runs a first trusted operating system. Within this first trusted operating system, a data analysis and processing platform is run. This platform records the operation process to a first audit log, which is immutable. The operation and maintenance file is then sent to an intelligent waveform recorder. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, which runs a second trusted operating system. Within this second trusted operating system, a business processing module is run. This business processing module parses trusted remote operation and maintenance instructions from the secure operation and maintenance file, controls the protection device according to these instructions, and records the operation process to a second audit log, which is also immutable.
[0057] Processor 701 is also used to perform the following steps: The system receives maintenance files sent by a remote maintenance master station via file transfer. The remote maintenance master station encapsulates remote maintenance operation instructions from trusted users into trusted maintenance files. The remote maintenance master station employs a first trusted hardware module, on which runs a first trusted operating system. Within the first trusted operating system, a data analysis and processing platform runs, recording the operation process in a first audit log, which is tamper-proof. Trusted remote maintenance operation instructions are parsed from the secure maintenance files, and the protection device is controlled according to these instructions. The operation process is then recorded in a second audit log. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. Within the second trusted operating system, a business processing module runs, and the second audit log is also tamper-proof.
[0058] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be repeated here.
[0059] Those skilled in the art will understand that Figure 7The structure shown is for illustrative purposes only. The terminal can be a smartphone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile internet device (MID), a PAD, or other terminal devices. Figure 7 This does not limit the structure of the aforementioned electronic device. For example, the terminal may also include components that are more... Figure 7 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 7 The different configurations shown.
[0060] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0061] Embodiments of this application also provide a storage medium. Optionally, in this embodiment, the storage medium can be used to execute program code for a remote operation and maintenance method based on relay protection.
[0062] Optionally, in this embodiment, the storage medium may be located on at least one of the network devices in the network shown in the above embodiment.
[0063] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: Upon obtaining remote operation and maintenance instructions from a trusted user, these instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station employs a first trusted hardware module, which runs a first trusted operating system. Within this first trusted operating system, a data analysis and processing platform is run. This platform records the operation process to a first audit log, which is immutable. The operation and maintenance file is then sent to an intelligent waveform recorder. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, which runs a second trusted operating system. Within this second trusted operating system, a business processing module is run. This business processing module parses trusted remote operation and maintenance instructions from the secure operation and maintenance file, controls the protection device according to these instructions, and records the operation process to a second audit log, which is also immutable.
[0064] Optionally, the storage medium is also configured to store program code for performing the following steps: The system receives maintenance files sent by a remote maintenance master station via file transfer. The remote maintenance master station encapsulates remote maintenance operation instructions from trusted users into trusted maintenance files. The remote maintenance master station employs a first trusted hardware module, on which runs a first trusted operating system. Within the first trusted operating system, a data analysis and processing platform runs, recording the operation process in a first audit log, which is tamper-proof. Trusted remote maintenance operation instructions are parsed from the secure maintenance files, and the protection device is controlled according to these instructions. The operation process is then recorded in a second audit log. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. Within the second trusted operating system, a business processing module runs, and the second audit log is also tamper-proof.
[0065] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be repeated here.
[0066] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0067] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0068] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0069] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0070] In the several embodiments provided in this application, it should be understood that the disclosed client can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between units or modules, and may be electrical or other forms.
[0071] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0072] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0073] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A remote operation and maintenance system based on relay protection, characterized in that, include: The remote operation and maintenance master station is deployed in the operation and maintenance center. The remote operation and maintenance master station adopts a first trusted hardware module. The first trusted hardware module runs a first trusted operating system. The first trusted operating system runs a data analysis and processing platform. The data analysis and processing platform is used to encapsulate trusted remote operation and maintenance instructions into secure operation and maintenance files and record the operation process to a first audit log. The first audit log is an unalterable log. The intelligent waveform recorder, deployed at the substation site, interacts with the remote operation and maintenance master station via files and uses a secure and controllable protocol to interact with the protection device. The intelligent waveform recorder employs a second trusted hardware module, on which a second trusted operating system runs. Within the second trusted operating system, a service processing module is executed. This service processing module parses trusted remote operation and maintenance instructions from secure operation and maintenance files, controls the protection device according to these instructions, and records the operation process in a second audit log, which is an immutable log.
2. A remote operation and maintenance method based on relay protection, characterized in that, Applied to remote operation and maintenance master stations, including: Upon obtaining remote operation and maintenance instructions from a trusted user, the remote operation and maintenance instructions are encapsulated into a secure operation and maintenance file. The remote operation and maintenance master station adopts a first trusted hardware module, on which a first trusted operating system runs. A data analysis and processing platform runs in the first trusted operating system. The data analysis and processing platform is used to record the operation process to a first audit log, which is an unalterable log. The maintenance file is sent to the intelligent waveform recorder via a file. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which runs a second trusted operating system. The second trusted operating system contains a business processing module. The business processing module is used to parse trusted remote maintenance operation instructions from the secure maintenance file, control the protection device according to the trusted remote maintenance operation instructions, and record the operation process to a second audit log, which is an immutable log.
3. The method according to claim 2, characterized in that, The method also includes determining whether the current user is a trusted user through two-factor authentication: Receive the login request from the current user; If the username and password in the login request do not match the pre-stored credentials, the current user is determined to be an untrusted user. If the username and password in the login request match the pre-stored credentials, the signature information of the current user is obtained, wherein the signature information of the trusted user is obtained by calling its national cryptographic digital certificate to sign; If the signature information verification of the current user fails, the current user is determined to be an untrusted user; If the signature information of the current user is verified, the current user is determined to be a trusted user.
4. The method according to claim 2, characterized in that, The remote operation and maintenance instructions are encapsulated into a secure operation and maintenance file, including: The remote operation and maintenance instructions are timestamped, digitally signed, and encrypted to form the operation and maintenance file.
5. The method according to claim 2, characterized in that, Send the maintenance files to the intelligent waveform recorder via file, including: The IEC 61850 file service is invoked to send the maintenance file to the intelligent waveform recorder.
6. A remote operation and maintenance method based on relay protection, characterized in that, Applications in intelligent waveform recorders include: The system receives maintenance files sent by a remote maintenance master station via file transfer. The remote maintenance master station encapsulates remote maintenance operation instructions from trusted users into trusted maintenance files. The remote maintenance master station employs a first trusted hardware module, on which a first trusted operating system runs. A data analysis and processing platform runs within the first trusted operating system. The data analysis and processing platform records the operation process to a first audit log, which is an immutable log. The system extracts trusted remote operation and maintenance instructions from secure operation and maintenance files, controls the protection device according to these instructions, and records the operation process in a second audit log. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which a second trusted operating system runs. The second trusted operating system contains a business processing module. The second audit log is an immutable log.
7. The method according to claim 6, characterized in that, Extract trusted remote operation instructions from secure operation and maintenance files, including: Extract the embedded timestamp from the received operation and maintenance file, and calculate the time deviation between the timestamp and the local time; If the absolute value of the time deviation exceeds the target threshold, it is determined that the operation and maintenance file is expired or that a replay attack has occurred. If the absolute value of the time deviation does not exceed the target threshold, the operation and maintenance documents are signed and verified. If the signature verification of the operation and maintenance file is successful, the operation and maintenance file is decrypted using national cryptographic standards. If the decryption is successful, the security of the operation and maintenance file is confirmed, and trusted remote operation and maintenance instructions are obtained.
8. A remote operation and maintenance device based on relay protection, characterized in that, Applied to remote operation and maintenance master stations, including: The encapsulation unit is used to encapsulate the remote operation and maintenance operation instructions into a secure operation and maintenance file when a trusted user's remote operation and maintenance operation instructions are obtained. The remote operation and maintenance master station adopts a first trusted hardware module, on which a first trusted operating system runs. A data analysis and processing platform runs in the first trusted operating system. The data analysis and processing platform is used to record the operation process to a first audit log, which is an unalterable log. The sending unit is used to send the operation and maintenance file to the intelligent waveform recorder via a file. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder employs a second trusted hardware module, on which a second trusted operating system runs. The second trusted operating system contains a business processing module. The business processing module is used to parse trusted remote operation and maintenance instructions from the secure operation and maintenance file, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process to a second audit log, which is an immutable log.
9. A remote operation and maintenance device based on relay protection, characterized in that, Applications in intelligent waveform recorders include: The receiving unit is used to receive maintenance files sent by the remote maintenance master station via a file. The remote maintenance master station is used to encapsulate the remote maintenance operation instructions of trusted users into trusted maintenance files. The remote maintenance master station adopts a first trusted hardware module, on which a first trusted operating system runs. A data analysis and processing platform runs in the first trusted operating system. The data analysis and processing platform is used to record the operation process to a first audit log, which is an unalterable log. The control unit is used to parse trusted remote operation and maintenance instructions from secure operation and maintenance files, control the protection device according to the trusted remote operation and maintenance instructions, and record the operation process to the second audit log. The intelligent waveform recorder interacts with the protection device using a secure and controllable protocol. The intelligent waveform recorder adopts a second trusted hardware module, on which a second trusted operating system runs. A business processing module runs in the second trusted operating system. The second audit log is an immutable log.
10. A computer-readable storage medium, characterized in that, The storage medium includes a stored program, wherein the program executes the method described in any one of claims 2 to 7 when it is run.