Identity authentication system of industrial control system based on domestic commercial cryptographic algorithm
The multi-level encrypted transmission and dual-certificate authentication system built with domestically developed commercial cryptographic algorithms and the Ukey smart cryptographic key solves the security problems of identity authentication and data transmission in industrial control systems, achieves efficient and reliable identity verification and data protection, adapts to complex network security environments, and enhances the system's autonomy and controllability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUANENG LANCANG RIVER HYDROPOWER CO LTD
- Filing Date
- 2026-02-03
- Publication Date
- 2026-05-01
AI Technical Summary
Existing industrial control systems suffer from several problems in identity authentication, including susceptibility to cracking single authentication factors, difficulties in certificate management, vulnerability to eavesdropping and tampering in network communications, outdated encryption technologies, inadequate data backup, and security vulnerabilities in foreign cryptographic algorithms. These issues make it difficult to meet the increasingly severe cybersecurity threats and interoperability requirements.
By adopting domestically developed commercial cryptographic algorithms, combined with the national cryptographic certificate system and the smart cryptographic key Ukey, an identity authentication module, a network and communication data security module, and an application and data transmission security module are constructed for special scenarios. This enables multi-level encrypted transmission and dual certificate authentication, ensuring the identity verification and data transmission security of users and devices.
It improves the reliability of identity authentication and the security of data transmission in industrial control systems, reduces the risk of illegal intrusion, ensures the stability and reliability of the system, reduces production interruptions caused by security incidents, complies with national cryptography management policies, and enhances independent controllability.
Smart Images

Figure CN121967030A_ABST
Abstract
Description
Identity Authentication System for Industrial Control Systems Based on Domestically Developed Commercial Cryptographic Algorithms Technical Field
[0001] This invention relates to the field of industrial control system security technology, and more specifically, to an identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms. Background Technology
[0002] Industrial control systems are widely used in critical sectors such as power, petroleum, and chemical industries, and their security is directly related to national economic security and social stability. With the rapid development of information technology, industrial control systems are increasingly connected to the internet, facing increasingly severe cybersecurity threats. Identity authentication, as the first line of defense for the security of industrial control systems, can effectively prevent unauthorized users and devices from accessing the system, ensuring its secure operation.
[0003] To implement the requirements of the Cryptography Law of the People's Republic of China regarding the application of cryptography in information systems, this paper analyzes the current status and cryptographic application needs of the Ruiwo HNICS-H316 domestically produced hydropower plant computer monitoring system. Based on the "Information Security Technology: Basic Requirements for Cryptographic Applications in Information Systems" (GB / T 39786-2021, hereinafter referred to as "Basic Requirements for Cryptographic Applications in Information Systems"), this paper designs and carries out the construction of commercial cryptographic applications for the computer monitoring system from four levels: physical and environmental security, network and communication security, equipment and computing security, and application and data security, as well as key management and security management. This provides a basis for the subsequent construction of cryptographic applications in domestically produced hydropower plant computer monitoring systems.
[0004] China's commercial cryptography application technologies and products have formed a mature system. Domestically designed commercial cryptographic algorithms ZUC, SM2, SM3, SM4, and SM9 have become international standards. Compared to foreign cryptographic algorithms, Chinese cryptographic algorithms are more secure and controllable. However, there are no mature application cases of commercial cryptography technologies in domestic hydropower computer monitoring systems. To ensure the high stability and real-time availability of production data, and to protect the confidentiality and integrity of important data storage, difficulties exist in application and data encryption / decryption integration between the underlying engineer workstations and operator terminals. The main reason is that the business systems involve application vendors and developers, resulting in a large amount of secondary development work. Traditional industrial control system authentication technologies mainly use usernames and passwords, which are simple and easy to implement but have many security vulnerabilities. With the continuous development of network attack techniques, some advanced authentication technologies are gradually being applied to industrial control systems, such as digital certificate authentication and biometric technology. However, these technologies still have some shortcomings in practical applications.
[0005] Traditional username and password authentication is the most common method in industrial control systems. However, users often set simple, easy-to-guess passwords, such as birthdays or phone numbers, for ease of remembering. Attackers can obtain user passwords through brute-force attacks, dictionary attacks, and other methods, thereby illegally logging into the system. Furthermore, passwords are also vulnerable to theft during transmission and storage, such as through network sniffing and man-in-the-middle attacks, leading to the leakage of user account information.
[0006] While digital certificate authentication technology has improved the security of identity verification to some extent, several problems remain in practical applications. Some industrial control systems may use digital certificates issued by non-authoritative certificate authorities, resulting in lower credibility. Furthermore, the management and maintenance of digital certificates present challenges, such as untimely updates and insufficient security measures during storage and use, all of which can lead to certificate forgery or tampering, thus affecting the accuracy of identity verification.
[0007] Most existing identity authentication technologies employ a single authentication factor, such as relying solely on a password or digital certificate for identity verification. This approach is vulnerable to attack because once any authentication factor is compromised, an attacker can easily log into the system. Multi-factor authentication mechanisms, on the other hand, combine multiple authentication factors, such as passwords, digital certificates, and biometrics, significantly improving the security of identity authentication. However, the application of multi-factor authentication technology in industrial control systems is currently not widespread.
[0008] Data in industrial control systems is vulnerable to eavesdropping and tampering during network transmission. Some industrial control systems employ network communication protocols that may have security vulnerabilities. Attackers can use network sniffing tools to obtain transmitted data or tamper with data content through man-in-the-middle attacks. For example, in power systems, attackers can tamper with grid dispatch instructions, leading to abnormal grid operation or even power outages.
[0009] During network access, existing industrial control systems lack rigorous authentication for both devices and users. Some devices may connect to the network without proper authentication, providing opportunities for attackers. Attackers can impersonate legitimate devices to access the network and launch attacks. Furthermore, authentication mechanisms for remote users are weak and easily bypassed by unauthorized users.
[0010] Some industrial control systems use outdated encryption technologies that cannot meet the growing security demands. Some systems may use symmetric encryption algorithms, which present difficulties in key management and distribution, making them susceptible to key leaks. Furthermore, symmetric encryption algorithms are inefficient when dealing with large-scale data encryption, impacting system performance.
[0011] Industrial control systems may contain various security vulnerabilities, such as buffer overflows, SQL injection, and cross-site scripting (XSS) attacks. Attackers can exploit these vulnerabilities to gain system privileges, tamper with data, or execute malicious code. Due to the special nature of industrial control systems, some application systems are not updated and maintained in a timely manner, allowing these security vulnerabilities to persist for a long time, posing a serious threat to system security.
[0012] Data backup and recovery are crucial measures for ensuring the data security of industrial control systems. However, some industrial control systems have inadequate data backup and recovery mechanisms, leading to security vulnerabilities in the storage and management of backup data. For example, backup data may not be stored encrypted, making it vulnerable to theft or tampering. Furthermore, the lack of effective verification mechanisms during data recovery may result in inaccurate or maliciously altered recovered data.
[0013] Existing identity authentication technologies and security mechanisms may not be adequate for the needs of these emerging technologies. For example, in the Industrial Internet of Things (IIoT) environment, a large number of devices and sensors need to be connected to the network, and traditional identity authentication methods are insufficient to meet the authentication requirements of large-scale devices.
[0014] Currently, the cryptographic algorithms used in industrial control systems are mainly from abroad, such as RSA and DES. These algorithms may contain backdoors or security vulnerabilities, which could be exploited by foreign forces for intelligence gathering or attacks. Moreover, given the increasingly complex international situation, reliance on foreign cryptographic algorithms may pose supply chain security risks. If foreign suppliers cease operations or are sanctioned, the security of industrial control systems will be severely threatened.
[0015] The security needs and application scenarios of my country's industrial control systems have their own characteristics, requiring cryptographic application standards and technologies that conform to national conditions. However, the lack of unified standards and specifications for cryptographic applications in existing industrial control systems leads to differences in cryptographic applications between different systems, making interconnection and interoperability difficult. This also hinders the security supervision and management of industrial control systems. Therefore, we propose an identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms to address this issue. Summary of the Invention
[0016] The purpose of this invention is to address the problems identified in the existing background technology. To achieve the above-mentioned objective, this invention provides the following technical solution: an identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms. This system includes a special scenario identity authentication module, a network and communication data security module, and an application and data transmission security module. The special scenario identity authentication module uses a national cryptographic certificate system combined with a smart cryptographic key (Ukey) to achieve user identity authentication and secure login at the application layer. The network and communication data security module constructs a dual-certificate authentication system, working with a gateway client and a smart cryptographic key to achieve network-level identity verification. The application and data transmission security module establishes a multi-level encrypted transmission system to ensure data confidentiality and integrity.
[0017] As a preferred technical solution of the present invention, in the identity authentication module under special scenarios, the modified system calls the smart password key interface through a browser control, and calls the private key in the smart password key to perform SM2 signature to achieve compliant identity authentication; the browser control adopts the development technology that conforms to the HTML5 standard to ensure stable operation in mainstream browsers such as Chrome, Firefox, IE11 and above, and the response time of calling the smart password key interface does not exceed 1 second.
[0018] As a preferred technical solution of the present invention, the smart password key is issued to the user and has a built-in SM2 private key and digital certificate. When the user logs into the system, he / she enters the smart password key PIN code, calls the built-in SM2 private key to sign the random challenge code initiated by the server, and sends the signature value and digital certificate to the server for identity authentication. The PIN code is 6-8 digits long, the random challenge code is 32 bytes long, and the signature value adopts DER encoding format.
[0019] As a preferred technical solution of the present invention, after the server receives the client's signature value and the user's digital certificate, it first verifies the validity of the client's user certificate. After the verification is successful, the server uses the user certificate to verify the validity of the signature value based on a random challenge code. Only users who pass the verification can log in to the system to complete identity authentication. The server's verification time for the validity of the user certificate does not exceed 2 seconds, and the verification time for the validity of the signature value does not exceed 3 seconds.
[0020] As a preferred technical solution of the present invention, the network and communication data security module is accessed through an SSL VPN security gateway using a user password and a smart password key. The smart password key stores the national cryptographic digital certificate issued by the CA to the individual user. The SSL VPN security gateway supports SSL / TLS 1.2 and above protocols, and the user password is no less than 8 characters long and contains at least two of the following: letters, numbers, and special characters.
[0021] As a preferred technical solution of the present invention, the dual certificate authentication system, together with the gateway client and the smart password key, ensures the authenticity of the network identity of devices and terminals in the access system and the establishment of the national cryptographic network security channel; the dual certificates are a device certificate and a user certificate, the device certificate is valid for 3 years, the user certificate is valid for 1 year, and the data transmission rate of the national cryptographic network security channel is not less than 10Mbps.
[0022] As a preferred technical solution of the present invention, the application and data transmission security module uses an SSL VPN gateway device to implement a GMTLS secure tunnel between the client and the server, so as to access the business system without being noticed; the establishment time of the GMTLS secure tunnel does not exceed 5 seconds.
[0023] As a preferred technical solution of the present invention, the system communicates with the dispatching network vertically through dedicated power lines and dispatching data networks, and establishes an encrypted transmission channel IPSec VPN through a dedicated power vertical encryption authentication device; the dedicated power vertical encryption authentication device complies with DL / T 5480-2013 "Technical Conditions for Dedicated Power Vertical Encryption Authentication Device", and the bandwidth of the IPSec VPN encrypted transmission channel is not less than 100Mbps.
[0024] As a preferred technical solution of the present invention, the encrypted transmission channel IPSec VPN realizes the identity authentication of the two entities communicating with the scheduling and central control station, as well as the integrity and confidentiality of the data transmission process; the success rate of identity authentication of the two entities is not less than 99.9%.
[0025] As a preferred technical solution of the present invention, the domestic commercial cryptographic algorithm includes the SM2 algorithm, which is used for signing the private key in the smart cryptographic key and for the certificate verification process; the key length of the SM2 algorithm is 256 bits, and the hash algorithm used in the signature verification process is SM3, with a hash value length of 256 bits.
[0026] Compared with existing technologies, the advantages of this invention are as follows: Based on the national cryptographic certificate system and the special scenario identity authentication mechanism of the smart password key Ukey, this invention provides high-strength security for application-layer user login. When logging in, users need to insert the Ukey and enter the correct PIN code. The challenge code randomly generated by the server is signed using the SM2 signature algorithm. The use of random challenge codes avoids replay attacks; only users with a valid Ukey and correct PIN code can generate a valid signature. This greatly reduces the possibility of unauthorized users logging into the system by guessing passwords or other means, effectively preventing unauthorized intrusion and ensuring that only authorized users can access the industrial control system, protecting the system's core data and operational security.
[0027] This invention's server performs dual verification on the digital certificate and signature value sent by the client when verifying user identity. First, it verifies the validity of the digital certificate, including its expiration date and issuing authority. Then, it uses the public key in the certificate to verify the signature value based on a random challenge code. This rigorous verification mechanism ensures the authenticity and accuracy of user identity, effectively identifies attempts at impersonation, and further improves the reliability of identity authentication in industrial control systems.
[0028] This invention's dual-certificate authentication system, combined with a gateway client and a smart password key, provides strong support for network-level identity verification. The use of device certificates and user certificates ensures that both devices and users accessing the industrial control system undergo rigorous authentication. Only devices and users with valid certificates can access the network, effectively preventing unauthorized access and ensuring network security and reliability.
[0029] This invention establishes a national cryptographic network security channel through the cooperation of an SSL VPN security gateway and a smart cryptographic key. This channel uses domestically developed commercial cryptographic algorithms for encrypted communication, ensuring the confidentiality and integrity of network data transmission. Even if data is intercepted during transmission, attackers cannot obtain sensitive information, effectively preventing security threats such as network eavesdropping and data tampering, and ensuring the secure and stable network communication of industrial control systems.
[0030] The multi-level encrypted transmission system established in this invention provides comprehensive security protection for data transmission in industrial control systems. The GMTLS secure tunnel implemented by the SSL VPN gateway device ensures that data transmission between the client and server occurs in an encrypted environment, allowing users to access business systems seamlessly while guaranteeing data confidentiality. The IPSec VPN encrypted transmission channel established by the power-specific vertical encryption authentication device enables identity authentication and encrypted data transmission between the communicating entities in communication between the system and the dispatching and central control stations, effectively preventing data theft or tampering during transmission and ensuring data integrity and confidentiality.
[0031] The encrypted transmission mechanism of this invention complies with relevant industry standards. For example, the power-specific vertical encryption authentication device complies with DL / T 5480-2013 "Technical Conditions for Power-Specific Vertical Encryption Authentication Devices," and the SSL VPN gateway device supports GM / T0024-2014 "SSL VPN Technical Specifications." This compliance enables the system to meet the security requirements of industrial control systems in cryptographic applications, providing a solid guarantee for the stable operation of industrial production.
[0032] This invention's system is based on domestically developed commercial cryptographic algorithms, such as SM2, SM3, and SM4, and complies with the relevant standards and policy requirements of the State Cryptography Administration. Using domestically developed cryptographic algorithms helps safeguard national information security, reduces dependence on foreign technologies, and improves the independent controllability of my country's industrial control systems.
[0033] The application of this identity authentication system represents a positive exploration and practice of applying domestically developed commercial cryptographic algorithms in industrial control systems. By introducing advanced cryptographic technology into industrial control systems, it promotes the innovative development of cryptographic applications, provides valuable lessons and references for cryptographic applications in other industries, and facilitates the widespread application and promotion of cryptographic technology in various fields in my country.
[0034] The identity authentication system of this invention employs multiple security mechanisms, such as strict identity verification and encrypted transmission, which effectively reduce the risk of security attacks on industrial control systems. It reduces system failures and production interruptions caused by security incidents such as illegal intrusion and data breaches, improves system reliability and stability, and ensures the continuity and efficiency of industrial production.
[0035] The system of this invention fully considers performance factors during its design process. For example, the response time of browser controls calling the smart password key interface and the server-side verification time have been rigorously optimized. These optimizations ensure the high efficiency of identity authentication and data transmission, preventing the introduction of security mechanisms from significantly impacting system performance and enabling the industrial control system to maintain good operational status while ensuring security. Attached Figure Description
[0036] Figure 1 is a logic block diagram of the system modules provided by the present invention; Figure 2 is a parameter block diagram of the system modules provided by the present invention; Figure 3 is a schematic diagram of the system scenario provided by the present invention; Figure 4 is a schematic diagram of the system comparison provided by the present invention. Detailed Implementation
[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0038] Therefore, the following detailed description of the embodiments of the present invention is not intended to limit the scope of the claimed invention, but merely illustrates some embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention. It should be noted that, in the absence of conflict, the embodiments and features and technical solutions in the embodiments of the present invention can be combined with each other. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0039] Example 1: An identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms, including a special scenario identity authentication module, a network and communication data security module, and an application and data transmission security module. The special scenario identity authentication module uses a national cryptographic certificate system combined with a smart cryptographic key (Ukey) to achieve user authentication and secure login at the application layer. The network and communication data security module constructs a dual-certificate authentication system, working with the gateway client and the smart cryptographic key to achieve network-level identity verification. The application and data transmission security module establishes a multi-level encrypted transmission system to ensure data confidentiality and integrity. In the special scenario identity authentication module, the modified system calls the smart cryptographic key interface through a browser control, using the private key within the smart cryptographic key for SM2 signing to achieve compliant identity authentication. The browser control uses HTML5-compliant development technology to ensure stable operation in mainstream browsers such as Chrome, Firefox, IE11, and above, with a response time of no more than 1 second for calling the smart cryptographic key interface.
[0040] The smart password key is issued to the user and contains a built-in SM2 private key and digital certificate. When the user logs into the system, they enter the smart password key PIN code, call the built-in SM2 private key to sign the random challenge code initiated by the server, and send the signature value and digital certificate to the server for identity verification. The PIN code is 6-8 digits long, the random challenge code is 32 bytes long, and the signature value adopts DER encoding format.
[0041] After receiving the client's signature value and user digital certificate, the server first verifies the validity of the client's user certificate. If the verification is successful, the server uses the user certificate to verify the validity of the signature value based on a random challenge code. Only users who pass the verification can log in to the system to complete identity authentication. The server takes no more than 2 seconds to verify the validity of the user certificate and no more than 3 seconds to verify the validity of the signature value.
[0042] In the network and communication data security module, access is made via an SSL VPN security gateway using a user password and a smart password key. The smart password key stores the national cryptographic digital certificate issued by the CA to the individual user. The SSL VPN security gateway supports SSL / TLS 1.2 and above protocols, and the user password is at least 8 characters long and contains at least two of the following: letters, numbers, and special characters.
[0043] The dual-certificate authentication system, in conjunction with the gateway client and smart password key, ensures the authenticity of the network identity of devices and terminals in the access system and the establishment of a national cryptographic network security channel. The dual certificates are a device certificate and a user certificate. The device certificate is valid for 3 years, and the user certificate is valid for 1 year. The data transmission rate of the national cryptographic network security channel is no less than 10Mbps.
[0044] In the application and data transmission security module, an SSL VPN gateway device is used to implement a GMTLS secure tunnel between the client and the server, enabling seamless access to the business system; the establishment time of the GMTLS secure tunnel is no more than 5 seconds.
[0045] The system communicates with the dispatch center vertically via dedicated power lines and the dispatch data network, and establishes an encrypted transmission channel IPSec VPN through a dedicated power vertical encryption authentication device. The dedicated power vertical encryption authentication device complies with DL / T 5480-2013 "Technical Conditions for Dedicated Power Vertical Encryption Authentication Device", and the bandwidth of the IPSec VPN encrypted transmission channel is not less than 100Mbps.
[0046] The encrypted transmission channel IPSec VPN enables authentication of the entities communicating with the dispatch and central control station, as well as the integrity and confidentiality of data transmission; the success rate of authentication between the communicating entities is no less than 99.9%.
[0047] Domestic commercial cryptographic algorithms include the SM2 algorithm, which is used for signing private keys and verifying certificates in smart cryptographic keys. The key length of the SM2 algorithm is 256 bits, and the hash algorithm used in the signature verification process is SM3, with a hash value length of 256 bits.
[0048] The working principle of the identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms: The identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms mainly consists of a special scenario identity authentication module, a network and communication data security module, and an application and data transmission security module. This system utilizes technologies such as the national cryptographic certificate system, smart cryptographic keys (Ukey), dual-certificate authentication systems, and multi-level encrypted transmission to achieve identity authentication of users and devices in the industrial control system and secure data transmission, ensuring the security and reliability of the industrial control system.
[0049] Before being issued to users, the smart password key Ukey contains an SM2 private key and a digital certificate that conform to the relevant standards of the State Cryptography Administration. The SM2 private key is the critical data used for signing, while the digital certificate serves as legitimate proof of the user's identity, adhering to the national cryptographic certificate system specifications. Upon receiving the Ukey, users are required to set a 6-8 digit PIN code to protect the security of the private key within the Ukey.
[0050] When a user attempts to log in to the industrial control system, the client system prompts the user to insert a smart key and enter a PIN code. Simultaneously, upon receiving the login request, the server immediately generates a 32-byte random challenge code. This random challenge code is one-time use and is used to prevent replay attacks.
[0051] The client modifies a browser control within the system, employing HTML5-compliant development techniques to call the smart password key interface. After the user enters the correct PIN code, the smart password key uses its built-in SM2 private key to sign the random challenge code sent by the server. The signing process follows the SM2 algorithm specification, and the generated signature value is in DER encoding format. Once the signature is complete, the client sends the signature value and digital certificate to the server.
[0052] After receiving the signature value and digital certificate from the client, the server performs a two-step verification process. First, it verifies the validity of the client's user certificate, including checking the certificate's expiration date and issuing authority; this verification takes no more than 2 seconds. If the certificate verification passes, the server uses the public key from the user certificate to verify the validity of the signature value based on a random challenge code; this process takes no more than 3 seconds. Only when both certificate and signature verifications pass will the server consider the user's identity legitimate and allow them to log in to the system.
[0053] The system employs a dual-certificate authentication system, comprising device certificates and user certificates. Device certificates identify the devices accessing the system and are valid for 3 years; user certificates identify the users and are valid for 1 year. Both certificates are issued by authoritative Certificate Authorities (CAs) and comply with relevant national cryptographic standards.
[0054] When users access the industrial control system through the SSL VPN security gateway, authentication is performed using a combination of user password and smart key. The user password must be at least 8 characters long and contain at least two of the following: letters, numbers, and special characters, to enhance password security. The smart key stores the national cryptographic digital certificate issued by the CA to the individual user. The SSL VPN security gateway supports SSL / TLS 1.2 and above protocols. After the user enters the correct password and inserts a valid smart key, the gateway verifies the user certificate and checks the validity of the smart key, thereby achieving network-level authentication and ensuring the authenticity of the network identity of devices and terminals accessing the system.
[0055] After successful identity verification, the system establishes a national cryptographic network security channel based on a dual-certificate authentication system and a smart cryptographic key. This channel uses domestically developed commercial cryptographic algorithms for encrypted communication, ensuring the security of network and communication data. The data transmission rate in this channel is no less than 10Mbps, guaranteeing the high efficiency of network communication.
[0056] A GMTLS secure tunnel is established between the client and server via an SSL VPN gateway device. The SSL VPN gateway device supports the GM / T 0024-2014 SSL VPN technical specification. During tunnel establishment, both parties perform authentication and key negotiation, employing domestically developed commercial cryptographic algorithms to ensure tunnel security. Tunnel establishment time is no more than 5 seconds, enabling seamless access to the business system for users.
[0057] When industrial control systems communicate vertically with dispatching and centralized control stations via dedicated power lines and dispatching data networks, they primarily rely on a dedicated power-specific vertical encryption authentication device to establish an IPSec VPN encrypted transmission channel. This device complies with DL / T 5480-2013 "Technical Conditions for Dedicated Power-Specific Vertical Encryption Authentication Devices," with a channel bandwidth of no less than 100Mbps. Before data transmission, both communicating parties undergo entity authentication, with a success rate of no less than 99.9%, ensuring the legitimacy of both parties' identities. Simultaneously, encryption algorithms are used to encrypt the transmitted data, guaranteeing data integrity and confidentiality, with a data transmission error rate not exceeding 10%. -9 .
[0058] In special scenarios, the identity authentication module ensures legitimate login for application-layer users, providing an identity foundation for subsequent data interaction; the network and communication data security module guarantees identity verification and the establishment of secure channels at the network layer, preventing unauthorized devices and users from accessing the network; and the application and data transmission security module encrypts and protects the application and data transmission process, ensuring data security throughout the entire transmission process. These three modules collaborate and reinforce each other, forming a complete identity authentication and data security protection system for industrial control systems. Based on domestically developed commercial cryptographic algorithms, this system provides strong support for the safe and stable operation of industrial control systems.
[0059] The working process of the identity authentication system of the industrial control system based on domestic commercial cryptographic algorithms: System initialization: The smart cryptographic key Ukey is initialized. The cryptographic management department generates a 256-bit SM2 private key for the smart cryptographic key Ukey in accordance with the relevant standards of the State Cryptography Administration.
[0060] Authoritative Certificate Authorities (CAs) issue corresponding digital certificates for each Ukey in accordance with national cryptographic certificate system standards. These certificates contain user identity information, public keys, and other data. The generated SM2 private key and digital certificate are then written into the Ukey, which is then encapsulated and protected.
[0061] Distribute the Ukey to authorized users of the industrial control system. When a user uses it for the first time, they need to set a 6-8 digit PIN code for authentication when accessing the private key within the Ukey.
[0062] A dual-certificate authentication system is established: equipment certificates and user certificates are generated separately for devices connected to the industrial control system. The validity period for equipment certificates is set at 3 years, and the validity period for user certificates is set at 1 year.
[0063] The CA (Certificate Authority) verifies the identity information submitted by the device and the user, and issues the corresponding digital certificate upon successful verification. The device certificate is then installed on the corresponding device, while the user certificate is stored in the smart password key (Ukey).
[0064] Encrypted transmission device configuration: Configure the SSL VPN gateway device to support GM / T 0024-2014 "SSLVPN Technical Specification" and enable the GMTLS secure tunnel function.
[0065] Configure the parameters of the power-specific vertical encryption authentication device to comply with DL / T 5480-2013 "Technical Conditions for Power-Specific Vertical Encryption Authentication Device" to prepare for the establishment of an IPSec VPN encrypted transmission channel.
[0066] In a special scenario, the user authentication process involves the following steps: The user initiates the login request by opening the industrial control system client. The system prompts the user to insert a smart password key (Ukey). After inserting the Ukey, the user enters a PIN code on the client interface. The client then uses a browser control conforming to HTML5 standards to call the Ukey interface to verify the PIN code's correctness.
[0067] Server-side random challenge code generation: The client sends a login request to the server. Upon receiving the login request, the server immediately generates a 32-byte random challenge code and sends it to the client.
[0068] Client-side signing operation: After receiving the random challenge code, if the user's entered PIN code is verified, the Ukey uses the built-in SM2 private key to sign the random challenge code.
[0069] After signing is complete, the client will send the signature value in DER encoding format along with the digital certificate in the Ukey to the server.
[0070] Server-side verification process: After receiving the signature value and digital certificate from the client, the server first verifies the validity of the digital certificate, including checking information such as the certificate's validity period, issuing authority, and certificate chain. This verification process is completed within 2 seconds.
[0071] If the certificate verification passes, the server uses the public key from the digital certificate to verify the validity of the signature value based on a random challenge code. This verification process is completed within 3 seconds.
[0072] If both certificate verification and signature verification pass, the server determines that the user's identity is legitimate and allows the user to log in to the industrial control system; otherwise, the login request is rejected and a corresponding error message is given.
[0073] Network and communication data security process: Network access authentication: When a user accesses the industrial control system through the SSL VPN security gateway, they need to enter a user password that is no less than 8 characters long and contains at least two of the following: letters, numbers and special characters, and insert a smart password key Ukey.
[0074] The SSL VPN security gateway verifies the password entered by the user and reads the user certificate stored in the Ukey.
[0075] The gateway sends the user's certificate information to the CA authority for verification to confirm the legitimacy of the user's identity.
[0076] If the verification is successful, the gateway establishes a national cryptographic network security channel for the user based on a dual-certificate authentication system, and the data transmission rate of this channel is no less than 10Mbps.
[0077] Device authentication: When a device in an industrial control system connects to the network, the device sends an access request containing the device certificate to the authentication server in the network.
[0078] Upon receiving the request, the authentication server verifies the validity of the device certificate. If the certificate is valid, the device is allowed to access the network, and the appropriate network permissions are assigned to it.
[0079] Application and data transmission security process: GMTLS secure tunnel establishment. The client and server negotiate and establish a GMTLS secure tunnel through an SSLVPN gateway device. During tunnel establishment, both parties use the SM2 algorithm for authentication and key exchange. Specific steps include: the client and server exchanging certificates and verifying the validity of each other's certificates; then generating a session key based on the SM2 algorithm for subsequent encrypted data transmission. The entire GMTLS secure tunnel establishment process is completed within 5 seconds. After successful establishment, the client can seamlessly access the business systems of the industrial control system.
[0080] When the industrial control system communicates with the dispatch and central control station via dedicated power lines and dispatch data networks, the dedicated vertical encryption authentication device for power is activated.
[0081] The two communicating parties first perform entity identity authentication by exchanging and verifying device certificates to confirm the legitimacy of each other's identities, with an authentication success rate of no less than 99.9%.
[0082] After successful identity authentication, both parties use the pre-agreed SM4 encryption algorithm to encrypt the transmitted data, ensuring its integrity and confidentiality. Upon receiving the encrypted data, the receiver uses the corresponding decryption key to decrypt and restore the original data.
[0083] The system is equipped with a dedicated monitoring module to monitor the identity authentication process, network connection status, and data transmission in real time.
[0084] The monitoring module records all login attempts, certificate verification results, data transmission traffic, and other information, and stores them in a log file.
[0085] When the monitoring module detects abnormal situations, such as multiple failed login attempts, certificate verification failures, or excessively high data transmission error rates, the system will immediately issue an alarm and take corresponding measures, such as limiting the number of login attempts or disconnecting abnormal connections.
[0086] Regularly conduct security audits of the system, check log files, identify potential security threats, and address them promptly.
[0087] Regularly check the validity period of equipment certificates and user certificates, and remind users or equipment administrators to renew certificates before they expire.
[0088] Perform regular maintenance on the smart password key Ukey, such as checking the hardware status of the Ukey and updating the Ukey driver, to ensure that the Ukey can be used normally.
[0089] The above embodiments are only used to illustrate the present invention and are not intended to limit the technical solutions described herein. Although the present invention has been described in detail with reference to the above embodiments, the present invention is not limited to the specific embodiments described above. Therefore, any modifications or equivalent substitutions to the present invention, as well as all technical solutions and improvements that do not depart from the spirit and scope of the invention, are covered within the scope of the claims of the present invention.
Claims
1. An identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms, characterized in that, This includes modules for identity authentication in special scenarios, network and communication data security, and application and data transmission security. The identity authentication module in the special scenario adopts the national cryptographic certificate system combined with the smart password key Ukey to realize the identity authentication and secure login authentication of application layer users; The network and communication data security module constructs a dual certificate authentication system, which, together with the gateway client and smart password key, enables network-level identity verification. The application and data transmission security module establishes a multi-level encrypted transmission system to ensure data confidentiality and integrity.
2. The identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms according to claim 1, characterized in that, In the special scenario identity authentication module, the modified system calls the smart password key interface through a browser control, and uses the private key in the smart password key to perform SM2 signing to achieve compliant identity authentication; the browser control adopts HTML5 standard compliant development technology to ensure stable operation in mainstream browsers such as Chrome, Firefox, IE11 and above, and the response time of calling the smart password key interface does not exceed 1 second.
3. The identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms according to claim 2, characterized in that, The smart password key is issued to the user and contains a built-in SM2 private key and digital certificate. When logging into the system, the user enters the smart password key PIN code, calls the built-in SM2 private key to sign the random challenge code initiated by the server, and sends the signature value and digital certificate to the server for identity verification. The PIN code is 6-8 digits long, the random challenge code is 32 bytes long, and the signature value adopts DER encoding format.
4. The identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms according to claim 3, characterized in that, After receiving the client's signature value and user digital certificate, the server first verifies the validity of the client's user certificate. If the verification is successful, the server uses the user certificate to verify the validity of the signature value based on a random challenge code. Only users who pass the verification can log in to the system to complete identity authentication. The server takes no more than 2 seconds to verify the validity of the user certificate and no more than 3 seconds to verify the validity of the signature value.
5. The identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms according to claim 1, characterized in that, In the network and communication data security module, access is made via an SSL VPN security gateway using a user password and a smart password key. The smart password key stores the national cryptographic digital certificate issued by the CA to the individual user. The SSL VPN security gateway supports SSL / TLS 1.2 and above protocols, and the user password is at least 8 characters long and contains at least two of the following: letters, numbers, and special characters.
6. The identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms according to claim 5, characterized in that, The dual-certificate authentication system, in conjunction with the gateway client and smart password key, ensures the authenticity of the network identity of devices and terminals in the access system and the establishment of a national cryptographic network security channel. The dual certificates are a device certificate and a user certificate, with the device certificate valid for 3 years and the user certificate valid for 1 year. The data transmission rate of the national cryptographic network security channel is no less than 10Mbps.
7. The identity authentication system for industrial control systems based on domestically developed commercial cryptographic algorithms according to claim 1, characterized in that, In the application and data transmission security module, an SSL VPN gateway device is used to implement a GMTLS secure tunnel between the client and the server, enabling seamless access to the business system; The establishment time of a GMTLS secure tunnel is no more than 5 seconds.
8. The identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms according to claim 7, characterized in that, The system communicates with the dispatch center vertically through dedicated power lines and the dispatch data network, and establishes an encrypted transmission channel IPSec VPN through a dedicated power vertical encryption authentication device; the bandwidth of the IPSec VPN encrypted transmission channel is no less than 100Mbps.
9. The identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms according to claim 8, characterized in that, The encrypted transmission channel IPSec VPN enables identity authentication between the communicating entities and the scheduling and central control stations, as well as the integrity and confidentiality of data transmission; the success rate of identity authentication between the communicating entities is no less than 99.9%.
10. The identity authentication system for an industrial control system based on domestically developed commercial cryptographic algorithms according to any one of claims 1 to 9, characterized in that, The domestically developed commercial cryptographic algorithms include the SM2 algorithm, which is used for signing the private key in the smart cryptographic key and for the certificate verification process. The key length of the SM2 algorithm is 256 bits, and the hash algorithm used in the signature verification process is SM3, with a hash value length of 256 bits.