Fine-grained security auditing method and system for power system

By implementing a fine-grained security auditing method in the power system, and utilizing multi-dimensional feature capture, national cryptographic signature, and hash chain binding technology, the problems of easy tampering of power system audit records and difficulty in linking cross-domain trajectories have been solved, achieving high-precision security event analysis and cross-domain evidence continuity.

CN122137523APending Publication Date: 2026-06-02HUANENG LANCANG RIVER HYDROPOWER CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUANENG LANCANG RIVER HYDROPOWER CO LTD
Filing Date
2026-02-28
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing power system auditing technologies suffer from problems such as coarse recording granularity, lack of strong cryptographic protection for audit logs leading to easy tampering and repudiation risks, and difficulty in logically linking audit trajectories in cross-security domain scenarios.

Method used

By employing multi-dimensional feature capture, hardware-protected signatures, hash chain binding, and cross-domain fingerprint anchoring, a trusted audit chain covering the entire lifecycle of power business is constructed. The security context capture module extracts fine-grained security contexts, and combined with the national cryptographic signature module and hash chain management module, fine-grained audit records, non-repudiation, and cross-domain trajectory correlation are achieved.

Benefits of technology

It enables fine-grained and in-depth traceability of audit records, enhances the authenticity and completeness of audit evidence, ensures the logical connection and continuity of cross-domain business, and improves the accuracy of power system security event analysis and the ability to reconstruct the chain of evidence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137523A_ABST
    Figure CN122137523A_ABST
Patent Text Reader

Abstract

This invention relates to the field of information security technology and discloses a fine-grained security audit method and system for power systems. The method includes: intercepting messages at authentication and authorization decision points using a security context capture module to extract fine-grained security contexts characterizing multi-dimensional features of security events; concatenating and encapsulating the original logs, the context, and an authoritative timestamp using an audit log generation module, and executing a national cryptographic algorithm using a hardware-protected private key within a national cryptographic signature module to generate a signature audit entry with non-repudiation properties; performing sequential iterative hash calculations using a hash chain management module to chain-bind the current entry with the hash value generated at the previous moment to generate a real-time end hash value; monitoring cross-domain business signals, transmitting the end hash value as an anchor feature to the destination domain and embedding it into its iteration process to achieve cross-domain trajectory logical association. This invention improves the depth of audit tracing and ensures evidence non-repudiation, tamper-proof capabilities, and cross-domain collaboration levels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically to a fine-grained security audit method and system for power systems. Background Technology

[0002] In critical information infrastructure sectors such as power energy, industrial production, and government information, Authentication and Authorization as a Service (AAaaS), as a centralized security service model, has become a core infrastructure for ensuring the secure operation of businesses by providing unified and efficient user identity management and access control capabilities. To ensure security, autonomy, and controllability, this type of model requires the use of domestically developed commercial cryptographic algorithms. During the operation of AAaaS, auditing mechanisms are crucial for achieving security compliance, behavior tracing, and post-event accountability.

[0003] However, existing auditing technologies have revealed significant limitations in practical applications. Current audit logs suffer from coarse granularity; most systems only record the final result of authentication or authorization events, lacking the capture of multi-dimensional security context during the decision-making process. This makes it impossible to reconstruct the basis for decisions from audit logs, hindering in-depth security event analysis and behavior tracing. Regarding the credibility of evidence, traditional audit logs lack effective cryptographic protection measures, and are mostly stored in plaintext or simple text formats. The lack of hardware-isolated digital signature mechanisms makes audit logs vulnerable to tampering or deletion by internal personnel with high system privileges. This lack of protection makes it difficult to verify the authenticity of audit evidence, failing to meet the strong non-repudiation requirements of critical business scenarios.

[0004] Meanwhile, existing audit logs are structurally composed of isolated, discrete entries, lacking strong logical connections. Under this discrete storage model, any silent tampering of historical audit tracks is difficult to detect in real-time or dynamically. Especially in the complex cross-security domain business collaboration scenarios of power systems, the lack of logical locking and fingerprint anchoring mechanisms between audit tracks in different security domains leads to the risk of a broken chain of evidence for cross-domain business, making it impossible to form a continuous, closed-loop sequence of audit evidence covering the entire lifecycle. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a fine-grained security auditing method and system for power systems. It solves the problems of coarse recording granularity, lack of strong cryptographic protection for audit logs leading to easy tampering and repudiation risks, and difficulty in logically linking audit trajectories in cross-security domain scenarios.

[0006] To achieve the above objectives, the present invention provides the following technical solution:

[0007] The first aspect of this invention provides a fine-grained security auditing method for power systems. This method constructs a trusted auditing chain covering the entire lifecycle of power services through multi-dimensional feature capture, hardware-protected signatures, hash chain binding, and cross-domain fingerprint anchoring. The method includes the following steps: By using a security context capture module to intercept communication protocol messages in real time at the decision point of the power system's authentication and authorization service, fine-grained security contexts that characterize the multi-dimensional features of security events are extracted. These fine-grained security contexts, through deep packet inspection technology, simultaneously capture key factors reflecting the subject's identity, environmental status, and operational intent at the moment of dynamic decision-making for identity authentication or access authorization, providing original evidence with decision-making traceability capabilities for subsequent audits.

[0008] The audit log generation module concatenates and encapsulates the original log data, the fine-grained security context, and the authoritative timestamp according to a preset field order to form a data packet to be signed. Then, it calls the hardware-protected audit private key inside the national cryptographic signature module to execute the national cryptographic signature algorithm and generate an audit entry with a signature that has non-repudiation characteristics. This step ensures the immutability of the signing process by introducing a hardware-isolated private key computing environment and eliminates the ambiguity of the audit record in the time dimension by using the authoritative timestamp.

[0009] The audit entries of the signature are obtained using the hash chain management module. Sequential iterative hash calculation is performed using the national cryptographic digest algorithm. The audit entries of the signature at the current moment are chained together with the hash values ​​generated at the previous moment to generate a real-time end hash value that represents the integrity of the audit sequence in this domain. The sequential iterative hash calculation, through logical preorder association, ensures that any small change in a single entry in the audit sequence will cause the cascading failure of all subsequent hash values, thereby achieving strong integrity verification of the audit trajectory.

[0010] The hash chain management module monitors cross-security domain service trigger signals, obtains the real-time end hash value, and transmits the real-time end hash value as a cross-domain anchoring feature to the destination domain. By embedding the real-time end hash value into the current hash chain iteration process of the destination domain, the logical association of cross-security domain audit trajectories is realized. This step utilizes the irreversibility and uniqueness of hash values ​​to establish a logical transmission path of audit status between two physically isolated or logically independent security domains, ensuring the continuity of the cross-domain service evidence chain.

[0011] Based on the above scheme, the fine-grained security context is extracted according to the business stage. In the identity authentication stage, the focus is on extracting parameters such as request time, source Internet Protocol address, user digital certificate digest, and random challenge data in the authentication challenge response process, which are used to reconstruct the root of trust state at the time of authentication. In the access authorization stage, the focus is on extracting the unique identifier of the requesting subject, resource identifier, operation instruction type, and specific policy rule identifier of successful matching, which are used to characterize the compliance basis of the authorization decision.

[0012] During the execution of national cryptographic signature and hash calculation, the audit record generation module connects to the secondary clock node through the power dispatch data network and uses a precision time protocol for high-precision time synchronization, controlling the time synchronization error between audit nodes across the entire network to the millisecond level. The national cryptographic signature module uses hardware isolation technology to protect the audit-specific private key, performs digest processing on the sequence to be signed, and then performs SM2 signature calculation to generate a platform-level signature value.

[0013] Furthermore, the hash chain management module has an internal tampering detection function. It extracts historical signature audit entries stored in the database and recalculates them with previous hash values ​​to obtain the expected hash value. This expected hash value is then logically compared with the actual stored value in the database. If a discrepancy exists, an alarm for breach of audit trace integrity is triggered, enabling dynamic awareness of the security status of audit data on the storage side.

[0014] For cross-domain scenarios, after receiving the real-time end hash value transmitted from the source domain, the destination domain defines it as an external input feature that spans the operation sequence. When the destination domain generates subsequent authorized operation audit records, the hash chain management module performs concatenated digest calculations on the audit entries of the signature currently generated by the destination domain and the real-time end hash value to generate an anchor hash value, thereby transforming the audit endpoint of the source domain into a component of the audit starting point of the destination domain.

[0015] A second aspect of the present invention provides a fine-grained security audit system for power systems, the system being applied to the aforementioned fine-grained security audit method for power systems, comprising: The security context capture module is used to extract fine-grained security context in real time in the decision path of identity authentication or access authorization services in the power system; the module has protocol parsing capabilities and can parse power dispatch-specific protocols and extract metadata representing security features from them.

[0016] The audit log generation module is used to concatenate and encapsulate the raw log data, the fine-grained security context, and the authoritative timestamp to form a data packet to be signed; the module is responsible for maintaining the standard field format of the audit log to ensure the normalization of heterogeneous audit data.

[0017] The national cryptographic signature module is used to call a hardware-protected audit-specific private key to execute the national cryptographic signature algorithm on the data packet to be signed, generating an audit entry with a signature that has non-repudiation characteristics; the module is integrated into a physically protected hardware security module, and improves the signature calculation performance and key security through a hard-core encryption engine.

[0018] The hash chain management module is used to construct a hash chain using the national cryptographic digest algorithm and generate a real-time end hash value, and to perform hash fingerprint anchoring in cross-security domain scenarios by transmitting the real-time end hash value to the destination domain; the module is responsible for auditing the logical maintenance of the chain, integrity self-checking, and cross-domain state synchronization.

[0019] This invention provides a fine-grained security audit method and system for power systems. It offers the following advantages: 1. This invention enables fine-grained and in-depth tracing of audit records. By using a security context capture module to extract multi-dimensional features in real time at the authentication and authorization decision point, the audit dimension is expanded from a single result to causal logic, ensuring that each audit record contains an environmental snapshot at the time of decision, thereby improving the analysis accuracy and evidence chain reconstruction capability of power business security events.

[0020] 2. This invention provides strong non-repudiation characteristics based on national cryptographic algorithms. By calling the audit-specific private key protected by hardware isolation through the national cryptographic signature module, the encapsulated data is subjected to national cryptographic SM2 signature calculation to generate a signed audit entry, ensuring that the audit evidence has the authenticity and non-repudiation of the source, and solving the technical problem that internal audit records of the power system are easily denied or maliciously forged.

[0021] 3. This invention enhances the integrity protection and cross-domain collaboration of audit trails. By using the hash chain management module to perform sequential iterative hash calculation and fingerprint anchoring, discrete log entries are constructed into a logically strongly related chain structure. Any tampering with historical entries can be dynamically monitored through recalculation of the expected hash value, and the logical locking and continuity guarantee of audit evidence across security domains are achieved. Attached Figure Description

[0022] Figure 1 This is a structural block diagram of a fine-grained security audit system for power systems provided in an embodiment of the present invention. Figure 2 A flowchart illustrating the fine-grained security auditing method for power systems provided in this embodiment of the invention; Figure 3 This is a flowchart illustrating the fine-grained security context capture process in an embodiment of the present invention. Figure 4 This is a flowchart of the audit record encapsulation and national cryptographic signature process in an embodiment of the present invention; Figure 5This is a flowchart illustrating the logical process of sequential iterative hash calculation and internal tampering detection in an embodiment of the present invention. Figure 6 This is a comparison chart of the success rates of audit data integrity verification under different simulated tampering scales according to the present invention; Figure 7 This is a comparison chart of the average latency of a single audit record processing under different concurrent log generation rates according to the present invention.

[0023] Among them, 101 is the security context capture module; 102 is the audit log generation module; 103 is the national cryptographic signature module; and 104 is the hash chain management module. Detailed Implementation

[0024] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] See attached document Figure 1 The present invention provides a fine-grained security audit system for power systems, which may include: a security context capture module 101, an audit record generation module 102, a national cryptographic signature module 103, and a hash chain management module 104.

[0026] The security context capture module 101 is logically connected to the power system's authentication and authorization service to extract fine-grained security context in real time at the decision points of identity authentication or access authorization. The security context capture module 101 extracts multi-dimensional security feature parameters from system environment variables, request messages, and decision intermediate states based on the type of security event currently triggered.

[0027] The audit log generation module 102 is connected to the security context capture module 101, the national cryptographic signature module 103, and an external time synchronization source. The audit log generation module 102 is used to receive raw log data. The fine-grained security context output by the security context capture module 101 and authoritative timestamps The audit log generation module 102 concatenates and encapsulates the above three types of data according to a preset field order to form a data packet to be signed.

[0028] The national cryptographic signature module 103 is connected to the audit record generation module 102, and its internal components include a hardware-protected audit-specific private key. The national cryptographic signature module 103 is used to receive the data packet to be signed sent by the audit record generation module 102, and execute the national cryptographic SM2 signature algorithm to generate an audit entry with a signature that has non-repudiation characteristics. .

[0029] The hash chain management module 104 is connected to the audit record generation module 102 and is used to receive signed audit entries. The hash chain management module 104 uses the national cryptographic SM3 algorithm to perform iterative digest calculation, chaining the hash values ​​generated by the currently generated audit record with those generated by the previous audit record to generate a hash value representing the integrity of the audit sequence. Meanwhile, the hash chain management module 104 is responsible for hash fingerprint anchoring in cross-security domain scenarios.

[0030] See attached document Figure 2 This invention provides a fine-grained security audit method for power systems, executed by the aforementioned fine-grained security audit system for power systems, and may include: Step S1: Perform fine-grained security context capture through the security context capture module 101.

[0031] In the business access process of the power system, when the authentication and authorization service receives an access request, the security context capture module 101 intercepts and extracts the context information of the decision point in real time.

[0032] If the current event is an authentication event, the security context capture module 101 extracts the security context of the authentication phase. Specifically, this includes, but is not limited to: the IP address of the access source, the unique digest of the user's digital certificate, the random value in the authentication challenge response process, the SM2 signature value generated by the user, and the verification status returned by the authentication server.

[0033] If the current event is an access authorization event, the security context capture module 101 extracts the security context of the authorization phase. Specifically, this includes, but is not limited to: the identity of the subject, the identity of the accessed resource, the executed operation instructions, the triggered policy rule identifier, and the final authorization decision result.

[0034] Step S2: The audit record is encapsulated and signed by the audit record generation module 102 and the national cryptographic signature module 103.

[0035] The audit log generation module 102 will generate the fine-grained security context obtained in step S1. Raw log data generated by the power system Establish a correlation and incorporate an authoritative timestamp provided by the time synchronization source. The audit log generation module 102 will... , and Physical concatenation is performed according to a fixed format. Subsequently, the national cryptographic signature module 103 calls the internally stored audit-specific private key. The concatenated data packets are processed using the national cryptographic SM2 algorithm, and the generated signature value serves as the anti-counterfeiting credential for the audit record. This signature is then ultimately encapsulated into a signed audit entry. .

[0036] Step S3: Audit the construction of the hash chain through the hash chain management module 104.

[0037] Hash chain management module 104 obtains the audit entry of the signature generated in step S2. For the first audit record generated during the initial system operation, the hash chain management module 104 directly performs a national cryptographic SM3 digest operation on the entry to generate an initial hash value. For subsequent audit records, the hash chain management module 104 will record the audit entries with the current signatures. The hash value calculated from the previous audit record Cascade the hash, perform the SM3 digest operation again, and generate the hash value. The audit records are stored in the audit database, which enables cryptographic locking of the audit records on the timeline.

[0038] Step S4: Perform cross-security domain audit fingerprint anchoring through the hash chain management module 104.

[0039] In cross-domain business flows involving provincial and municipal dispatch centers, the hash chain management module 104 transmits the key audit hash fingerprint generated in the source domain to the destination domain. The hash chain management module 104 also transmits the hash value generated in the source domain... As one of the input parameters for subsequent calculations, it is introduced into the current hash chain iteration process of the destination domain. By embedding the cryptographic digest of the source domain into the audit sequence of the destination domain, end-to-end logical association and immutability of the audit trail across security domains are achieved.

[0040] Regarding the underlying mathematical implementation of the national cryptographic algorithms SM2 and SM3, and the authoritative timestamp involved in this invention... The time synchronization method and raw log data The specific data structure can be implemented by those skilled in the art based on existing communication protocols and national standards of power systems. It is a well-known technology in this field and will not be described in detail here.

[0041] See attached document Figure 3 In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S1 involves real-time extraction of the security context during the authentication phase, and its specific implementation is as follows: The security context capture module 101 is deployed in the decision path of the power system identity authentication service. When the identity authentication service receives an access request initiated by a user or terminal device, the security context capture module 101 intercepts communication protocol messages in real time. The security context capture module 101 extracts fine-grained features that characterize the legality and uniqueness of the authentication behavior by parsing transport layer or application layer protocol packets.

[0042] During the authentication process, the security context capture module 101 extracts the authentication phase security context. It includes technical parameters across multiple dimensions. First, the security context capture module 101 obtains the request time at the moment the request was initiated. and the source Internet Protocol address of the requesting party. Secondly, the security context capture module 101 extracts the certificate digest from the digital certificate submitted by the user. This digest is used to uniquely identify the digital identity of the requesting subject.

[0043] To ensure that the audit logs can reconstruct the dynamic interaction process of authentication, the security context capture module 101 further captures random challenge data during the authentication process. And the SM2 digital signature value generated by the user based on the challenge data. Meanwhile, the security context capture module 101 records the final authentication result of the identity authentication server after verifying the signature on the above data. .

[0044] In this embodiment, the security context during the authentication phase The structured expression formula is as follows: ; in: This represents the authentication phase security context generated during the authentication phase. Indicates the time when the authentication request was initiated by the user. Indicates the source Internet Protocol address of the requesting party; Represents the certificate digest of the user's digital certificate; This represents random challenge data generated by the system during the authentication process; This represents the SM2 digital signature value calculated by the user using their private key on the challenge data; This indicates the final authentication result returned by the authentication server, usually in the form of a binary status value; This represents the concatenation operator, used to concatenate the above parameters according to a preset sequence.

[0045] For digital certificate parsing methods, protocol message interception techniques, and The specific extraction process can be implemented by those skilled in the art using existing network packet capture and filtering tools or application layer protocol plugins, which are well-known technologies in the field and will not be elaborated here.

[0046] The security context of the authentication phase is extracted by the security context capture module 101. This allows audit logs to include not only static conclusions of certification success or failure, but also all procedural evidence supporting those conclusions. This fine-grained parameter capture provides a complete data foundation for the generation of subsequent audit entries.

[0047] In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S1 involves real-time extraction of the security context during the authorization phase, and its specific implementation is as follows: The security context capture module 101 is logically connected to the authorization decision point of the power system. When a subject in the power system (such as a dispatcher, automation equipment, or third-party application) initiates an operation request to a specific power resource, the authorization decision point makes a logical judgment based on a preset security policy. During this decision-making process, the security context capture module 101 extracts fine-grained environmental factors and decision data in real time to support the authorization decision behavior.

[0048] During the authorization process, the security context capture module 101 extracts the authorization phase security context. It includes technical parameters across multiple dimensions. First, the security context capture module 101 obtains the unique identifier of the request subject. and the resource identifier of the accessed resource In a power system environment, resource identification... This includes, but is not limited to, the communication address of the remote terminal unit, the equipment number at the substation level, or the specific table entry identifier of the dispatch database.

[0049] Secondly, the security context capture module 101 extracts the operation instruction type of the current request. For example, this includes instructions for switching on / off of power equipment, setting modification instructions, or sensitive data reading instructions. To enable traceability of the decision-making logic, the security context capture module 101 further obtains the specific policy rule identifiers triggered during the authorization decision-making process. This identifier corresponds to a specific entry in the power security authorization policy library. Finally, the security context capture module 101 records the final authorization result output by the authorization decision point. .

[0050] In this embodiment, the security context during the authorization phase The structured expression formula is as follows: ; in: This represents the authorization phase security context generated during the authorization phase. A unique identifier representing the user or device that initiated the access request; Indicates the identifier of the resource being requested to be accessed; Indicates the type of operation instruction currently requested to be executed; Indicates the specific strategy rule that was successfully matched during the authorization decision-making process; This indicates the final authorization result at the authorization decision point; This represents the concatenation operator, used to concatenate the above parameters according to a preset sequence.

[0051] The attribute parsing process of authorization decision points, the specific implementation of the strategy matching algorithm, and and The allocation mechanism can be implemented by those skilled in the art based on the XACML framework or power-specific access control protocols, which are well-known technologies in the field and will not be elaborated here.

[0052] The security context during the authorization phase is extracted by the security context capture module 101. This ensures that audit logs not only reflect whether an operation was permitted, but also precisely trace the specific equipment targeted, the content of the instructions, and the policy rules upon which the operation was based. This fine-grained capture method provides multi-dimensional technical parameters for subsequently generating audit entries with strong evidentiary value.

[0053] See attached document Figure 4 In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S2 involves the cascading construction and encapsulation of signature audit entries, the specific implementation of which is as follows: The audit log generation module 102, as the core unit for data aggregation and preprocessing, is responsible for integrating audit elements from different dimensions into a standardized data packet to be signed. This is done when the security context capture module 101 completes the fine-grained security context... After extraction, the audit record generation module 102 obtains the raw log data generated by the power system business layer in real time. And simultaneously obtain authoritative timestamps from authoritative time sources. .

[0054] In the model construction, the audit log generation module 102 first performs data normalization processing. (Original log data) Includes a basic description of the business behavior, such as the name of the operating entity, the event type identifier, and the target system identifier; fine-grained security context. The authentication phase security context is dynamically selected based on the event type. Or authorization phase security context Authoritative timestamp To provide a legally valid, microsecond-level precision reference time, in this embodiment, the audit record generation module 102 accesses a secondary clock node based on BeiDou or GPS timing through the power dispatch data network, and uses the Precise Time Protocol (PTP) for high-precision time synchronization to ensure that the time synchronization error between all audit nodes in the network is less than 1ms, which is used to determine the absolute spatiotemporal coordinates of the audit event.

[0055] The audit log generation module 102 will generate the above , and The data is concatenated according to a strict preset timing and logical topology. The concatenation process is not a simple data stacking, but rather the construction of an indivisible logical whole, serving as the input digest for the national cryptographic signature method. Subsequently, the audit record generation module 102 sends the concatenated data to the national cryptographic signature module 103, which then uses its internally protected, hardware-isolated audit-specific private key. Perform SM2 signature operation on the entire logic.

[0056] Finally, the audit record generation module 102 encapsulates the original elements and the signature result into a signed audit entry. .Should The formula for constructing the model is as follows: ; in: This represents the audit entry for the generated signature; This represents the raw log data; This represents the fine-grained security context extracted by the security context capture module 101; This indicates an authoritative timestamp added by an authoritative time source; This represents the audit-specific private key stored in the national cryptographic signature module 103; Indicates the use of private key For input messages The digital signature value calculated by executing the Chinese national cryptographic SM2 algorithm; The concatenation operator is used to connect data items into a continuous binary stream in a specific sequence.

[0057] For raw log data Generation mechanism, authoritative timestamp The specific process of calibration using a power grid synchronization protocol (such as the PTP protocol) can be implemented by those skilled in the art using existing system log collection tools and precision timing devices. This is a well-known technology in the field and will not be described in detail here.

[0058] Built by audit record generation module 102 The model ensures the integrity of audit records at the data structure level. Because the signature object encompasses the original log, fine-grained context, and authoritative time, any tampering with any field (such as modifying the operation time or replacing the IP address) will cause the subsequent signature verification process to fail, thus providing the power system with audit evidence that has strong anti-repudiation properties.

[0059] In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S2 involves the non-repudiation signature process executed by the national cryptographic signature module 103, and its specific implementation is as follows: Upon receiving the concatenated data packet from the audit record generation module 102, the national cryptographic signature module 103 initiates a digital signature process based on the national cryptographic SM2 algorithm. The national cryptographic signature module 103 internally stores a dedicated audit private key through a hardware security module or a protected execution environment. This private key is unique and is used to provide cryptographic endorsement of the authenticity of audit records on behalf of the cryptographic service platform.

[0060] In the specific non-repudiation signature process, the national cryptographic signature module 103 first performs digest processing on the data sequence to be signed. For different business scenarios in the power system, the audit entries encapsulated by the national cryptographic signature module 103 have specific structures. Taking an identity authentication event as an example, the national cryptographic signature module 103 acquires the raw log data generated during the authentication process. Security context during the authentication phase and authoritative timestamps Perform cascading and utilize the audit-specific private key. The entire cascade is digitally signed to generate a platform-level signature value. .

[0061] The structured expression for the certification event audit entries generated by the above process is as follows: ; in: This represents the audit entry for the signature generated in response to the authentication event; This represents the raw log data generated during the authentication process; This represents the authentication phase security context extracted by the security context capture module 101; This indicates an authoritative timestamp added by an authoritative timekeeper; This indicates that the signature module 103 uses the audit-specific private key. Regarding the message The platform-level signature value is generated by calculating using the SM2 algorithm.

[0062] To further enhance the non-repudiation of high-risk operations, the audit record generation module 102, when processing operation requests, first considers the operation instruction type. It is matched against a pre-defined high-risk instruction strategy library. If a match is successful (e.g., a match for critical instructions such as the opening and closing of power equipment or modification of protection settings), a dual signature process is triggered: the audit entry generated by the national cryptographic signature module 103. It contains dual credentials: a user signature and a platform signature. Through this policy-triggered signature enhancement process, the system ensures that even internal personnel with administrative privileges cannot forge or deny it.

[0063] The national cryptographic signature module 103 outputs audit entries for signatures. Previously, the integrity of the signature calculation was verified to ensure... It maintains a logical one-to-one correspondence with the original cascaded data. The generated... It is then sent to the hash chain management module 104 as an atomic data unit for subsequent chain-based evidence storage.

[0064] For the selection of elliptic curve parameters and hash values ​​in the national cryptographic SM2 algorithm For the calculation process and the specific mathematical implementation of point operations, those skilled in the art can refer to the SM2 elliptic curve public key cryptography algorithm (GM / T0003) issued by the State Cryptography Administration, which is a well-known technology in this field and will not be elaborated here.

[0065] Through the aforementioned non-repudiation signature technology based on the national cryptographic signature module 103, the system assigns a cryptographic identity to each fine-grained audit record. This is achieved using a dedicated audit private key. Controlled solely by the national cryptographic signature module 103 and not exportable, the risk of audit logs being maliciously forged is eliminated at the technical level, thus supporting the authority of power safety audits.

[0066] See attached document Figure 5 In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S3 involves a sequential iterative hash calculation model executed by the hash chain management module 104, the specific implementation of which is as follows: Hash chain management module 104 is connected to audit log generation module 102 and is used to receive the signed audit entries output by it. To achieve strong integrity protection of audit logs and prevent internal management personnel of the power system from maliciously tampering with or selectively deleting audit databases, the hash chain management module 104 constructs a hash chain with cryptographic temporal dependencies using the national cryptographic SM3 algorithm.

[0067] During the hash chain initialization phase, when the system generates the first audit record, the hash chain management module 104 directly performs a digest calculation on that entry. For the first audit record generated by the system, the hash chain management module 104 calculates its initial hash value. The calculation formula is as follows: ; in: This represents the initial hash value corresponding to the first audit record in the system. This indicates the first audit entry with a signature generated by the system; Indicates the input message The 256-bit hash value is calculated by executing the SM3 digest algorithm.

[0068] As the power business continues to operate, the hash chain management module 104 performs sequential iterative calculations on subsequently generated audit entries. For each subsequently generated audit entry... The hash chain management module 104 extracts the audit entries of the currently pending audit records. And retrieve the hash value of the previous moment stored in the audit database. The hash chain management module 104 will... and After data concatenation, SM3 calculation is performed again to generate the hash value at the current time. Its general iterative calculation formula is as follows: ; in: Indicates the first The hash value corresponding to each audit record; Indicates the immediately preceding (the first) The hash value corresponding to each audit record; Indicates the number of processes currently pending. Audit entries in the audit record; This represents the concatenation operator, used to concatenate the current audit entry with the previous hash value in a preset bit order.

[0069] As a specific application scenario of the above general model, when the system processes the enhanced authorization event in Embodiment 2, the hash chain management module 104 receives the audit entry of the signature corresponding to the authorization event. And retrieve the hash value generated by the preceding authentication event. At this point, the hash value corresponding to the authorization event... The calculation formula is as follows: ; in: This represents the hash value corresponding to the authorization event; This indicates an audit entry for the signature generated for this authorization action; This indicates the hash value generated by the authentication action that precedes this authorization action.

[0070] The hash chain management module 104, through the aforementioned iterative calculations, ensures that each record in the audit database contains the cryptographic fingerprints of all preceding records. Under this chain-dependent structure, if an attacker modifies the... The contents of the audit record (including) This will lead to... Start to All subsequent hash values ​​deviated. Auditors can accurately detect whether audit data has been tampered with by recalculating the full-chain hash and comparing it with the stored values.

[0071] For the padding and compression functions, message expansion logic, and iterative compression process within the SM3 cryptographic algorithm, those skilled in the art can refer to the SM3 cryptographic hash algorithm (GB / T 32905-2016) published by the State Cryptography Administration, which is a well-known technology in the field and will not be elaborated here.

[0072] By using the sequential iterative hash calculation model executed by the hash chain management module 104, this invention logically transforms isolated audit entries into a chain of evidence with strong causal relationships, ensuring the authenticity and irrevocability of the power system security audit trajectory.

[0073] In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S3 also involves internal tampering monitoring and audit trajectory protection performed by the hash chain management module 104, the specific implementation of which is as follows: The hash chain management module 104 maintains a cryptographic chain relationship between audit records to achieve dynamic verification of historical evidence data in the audit database. When an auditor or the system's automated inspection mechanism triggers an integrity verification command, the hash chain management module 104 sequentially reads the signed audit entries from the storage medium. Sequence and its corresponding hash value sequence.

[0074] During the monitoring process, the hash chain management module 104 executes recalculation verification logic. First, the hash chain management module 104 audits the first signature entry. Re-execute the national cryptographic SM3 algorithm to generate the expected initial hash value. and compare it with the initial hash value stored in the database. A comparison is performed. If the two do not match, it is determined that the first audit record has been altered or deleted.

[0075] Subsequently, the hash chain management module 104 performs iterative verification one by one according to the time sequence. For the first... The hash chain management module 104 reads the audit entry for the current signature. Compared with the hash value stored in the previous moment And calculate the expected hash value at the current moment according to the following verification formula. : ; in: Indicates the first The expected hash value obtained by recalculating the audit record; This indicates the number stored in the database. The hash value of each audit record; Indicates the number of reads. Audit entries in the audit record; Indicates the input message The 256-bit hash value obtained by executing the SM3 digest algorithm (Chinese national cryptographic standard); This indicates the cascading operator.

[0076] The hash chain management module 104 will calculate the expected hash value. Compared with the hash value actually stored in the database Perform a logical equivalence check. If the judgment condition is met... Then the hash chain management module 104 determines the audit trail at the 104th node. A data integrity breach occurred at the audit log entry. Due to the collision resistance and chain dependency properties of hash algorithms, any attack... Even minor changes to the content, or the illegal removal of historical entries, will cause the verification of all subsequent nodes to fail, thus achieving full lifecycle protection of the audit trail.

[0077] In addition, when the hash chain management module 104 detects an anomaly caused by tampering, it extracts the authoritative timestamp of the damaged record. With fine-grained security context This allows for precise location of the business logic where the tampering occurred. In this way, the hash chain management module 104 can effectively resist attempts by high-privilege administrators within the system to conceal sensitive operation records, ensuring the reliability of audit data evidence.

[0078] For database sequential read optimization techniques, verification result alarm reporting mechanisms, and parallel verification algorithms under large-scale logs, those skilled in the art can use existing index acceleration techniques and distributed computing frameworks to implement them. These are well-known technologies in the field and will not be elaborated here.

[0079] Through the internal tampering monitoring and audit trajectory protection implemented by the hash chain management module 104, this invention constructs a self-proving integrity verification system using cryptographic intrinsic logic without relying on external third-party audit sources, thus meeting the high-intensity anti-counterfeiting requirements of the power dispatching system for secure audit data.

[0080] In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S4 involves cross-security domain audit pointer coordination technology, the specific implementation of which is as follows: In multi-level dispatching scenarios at the provincial, municipal, and county levels within the power system, audit targets involve logical interactions across different security domains. The hash chain management module 104 establishes a cross-domain behavior association model to achieve full-path tracing of cross-domain business flows at the cryptographic level. This model divides the power system into a first security domain. (e.g., provincial-level dispatch domain) and second security domain (e.g., city-level dispatch domain).

[0081] When the user is in the first security domain After completing identity authentication and obtaining cross-domain access credentials, it enters the second security domain. Operational instructions executed for specific power resources and the first security domain The authentication processes have logical dependencies. The hash chain management module 104 monitors such cross-domain business trigger signals in real time and initiates the cross-domain association process.

[0082] During the association modeling process, the hash chain management module 104 first extracts the first security domain. The real-time end hash value corresponding to the authentication event (in This is the sequence number of the latest audit entry generated by the user within this security domain. (This is the real-time end-hash value.) Includes the first security domain Security context of all authentication phases of this user authentication behavior And the cryptographic digest of the original log information. The hash chain management module 104 will... As input parameters for cross-domain association, they are sent to the second security domain through the secure transmission channel of the power dispatch data network. The hash chain management module 104.

[0083] Second security domain The hash chain management module 104 in the middle receives Then, it is defined as the external input feature across the operation sequence. In the second security domain Generate subsequent authorization operation audit logs. At that time, the hash chain management module 104 no longer relies solely on the second security domain. Instead of using the internal preorder hash value, it forcibly introduces the hash value from the first security domain. Real-time end hash value .

[0084] This modeling approach allows the system to construct a logical chain of evidence that transcends physical boundaries. If the first security domain... The authentication record in the system has been tampered with; its actual end hash value is being altered. This will change, leading to a second security domain. The hash verification of all related operation records in the system fails. This cross-domain behavior association model eliminates the technical shortcomings of traditional auditing systems, such as isolated logs in different regions and the inability to achieve end-to-end traceability.

[0085] For the cross-domain communication protocol of the power dispatch data network, the data synchronization mechanism between different security domains, and the specific distribution process of cross-domain access credentials, those skilled in the art can use existing power system security protection schemes and vertical encryption authentication devices to implement them. These are well-known technologies in the field and will not be elaborated here.

[0086] Cross-domain behavior association modeling provides a logical framework for subsequent execution of specific hash pointer anchoring calculations, ensuring the rigor of cross-domain audit trajectories in terms of timing and logic, and supporting the power system's need for penetrating supervision of cross-regional operations.

[0087] In the fine-grained security auditing method for power systems provided in this embodiment of the invention, step S4 involves the specific calculation implementation of cross-domain hash fingerprint anchoring, and its specific implementation method is as follows: Hash chain management module 104 performs cross-domain hash fingerprint anchoring calculations, aiming to integrate the first security domain. The audit status is cryptographically linked to the second security domain. In the audit sequence. When the second security domain The audit log generation module 102 generates audit entries for signatures related to cross-domain business. At that time, the hash chain management module 104 does not directly use the second security domain. Instead of iterating over the internal preceding hash value, the first security domain is obtained by calling the cross-domain interface. The audit fingerprint anchor point transmitted to this domain.

[0088] During this anchoring calculation process, the hash chain management module 104 will allocate the first security domain Provided real-time end hash value As one of the input parameters. Represents the first security domain A summary of the integrity status at a specific point in time and within a specific business context. The hash chain management module 104 will then manage the second security domain. Audit entries for currently generated signatures With from the first security domain Real-time end hash value Binary streams are concatenated, and then the second security domain is calculated using the national cryptographic SM3 algorithm. anchor hash value .

[0089] In this embodiment, the formula for cross-domain hash fingerprint anchoring calculation is as follows: ; in: Indicates the second security domain The anchor hash value generated from the current audit record; Indicates the second security domain The audit entry for the currently generated signature; Indicates originating from the first security domain The existing real-time end hash value is used as a cross-domain anchor point; Indicates the input message The 256-bit hash value obtained by executing the SM3 digest algorithm (Chinese national cryptographic standard); This indicates the cascading operator.

[0090] The hash chain management module 104 implements the first security domain through the above calculation process. With the second security domain The strong coupling of audit evidence between them. Due to The calculation results depend directly on Any targeting the first security domain Modifications to the original audit entries will result in The value changes, thus affecting the second security domain. The recalculated expected hash value and the stored Inconsistency. This anchoring mechanism ensures the logical continuity of cross-domain audit trails.

[0091] In the specific implementation details, the hash chain management module 104 completes... After calculation, it is used as the second security domain. The foundational node for subsequent audit record iterations. This means that subsequent generated audit records... , The hash values ​​implicitly contain the first security field. The fingerprint characteristics. This technology can not only monitor data tampering within a single domain, but also detect missing or illegally inserted logs during cross-domain collaboration by verifying the consistency of cross-domain anchor points.

[0092] For the specific software or hardware implementation details of data transmission encryption protection across security domains, hash synchronization frequency control in a distributed environment, and the SM3 algorithm, those skilled in the art can configure them according to the vertical encryption specifications of the power dispatch data network and the computing performance of the server. These are well-known technologies in the field and will not be elaborated here.

[0093] By performing cross-domain hash fingerprint anchoring calculations through the hash chain management module 104, this invention technically constructs a cryptographic trust chain spanning different management authority regions, providing an immutable underlying data support for penetrating auditing of multi-level scheduling operations in the power system.

[0094] Specific application examples: Business Background: Assume a provincial dispatch center (first security domain) Dispatcher Zhang needs to manage a certain municipal-level dispatch center (second security domain). The 220kV substation switches under its jurisdiction are remotely closed.

[0095] Implementation process: Provincial certification stage: Zhang in the first security domain Login, security context capture module 101 captures its login information in real time. (10.1.1.5), Certificate Digest, SM2 Signature Value, and SM3 Challenge Random Number, encapsulated as .

[0096] Signature and Evidence Preservation: National Cryptographic Signature Module 103 Utilizes Audit-Specific Private Key right Perform signing and generate Hash chain management module 104 calculations Complete the first security domain Internal chain locking.

[0097] Cross-domain anchoring trigger: When Zhang initiates a cross-domain closing request, the first security domain... of Transmitted to the second security domain .

[0098] Municipal Authorization Phase: Second Security Domain The security context capture module 101 captures the closing command ( ), RTU device identification ( ) and matching five-defense strategies ( ), packaged as .

[0099] Federation Chain Construction: Second Security Domain generate Hash chain management module 104 performs anchoring calculations: .

[0100] This experiment simulates a provincial-level (first security domain) environment. ) and prefecture-level (second security domain) The system was tested in a scheduling environment. During the experiment, the original records in the audit database were randomly modified (including changing operation instructions, adjusting timestamps, or deleting intermediate entries) to test the system's detection performance.

[0101] Integrity verification success rate analysis: See attached document Figure 6 The study demonstrates a comparison of the success rates of audit systems in detecting data integrity breaches under different scales of tampering.

[0102] The coordinate axes are defined as follows: the X-axis represents the number of simulated tampered records (number of records), ranging from 10 to 100; the Y-axis represents the integrity verification success rate (%).

[0103] Data trends: Traditional system log auditing (dashed line): As the number of tampered entries increases, the success rate of detection shows a significant downward trend. When the number of tampered entries is 10, the success rate is approximately 65%; however, when the number of tampered entries increases to 100, the success rate drops sharply to approximately 38%. This indicates that traditional auditing lacks strong correlations between records and is prone to missing detections when large-scale tampering occurs.

[0104] This invention features fine-grained security auditing (solid line): regardless of the number of tampered records, its detection success rate remains consistently around 100%.

[0105] Technical Conclusion: Experiments have shown that this invention introduces a hash chain iteration model based on the national cryptographic standard SM3. Any slight change in data can trigger a chain reaction, ensuring the immutability of audit evidence.

[0106] System processing latency overhead analysis: See attached document Figure 7 This demonstrates the system's computational performance under different load conditions.

[0107] Coordinate axis definition: The X-axis represents the "concurrent log generation rate (logs / second)," covering high-concurrency scenarios of 100, 500, 1000, 2000, and 5000 logs / second; the Y-axis represents the "average processing latency per log (ms)."

[0108] Data Comparison: Traditional system audit latency (light gray bars): At a concurrent rate of 100 records / second, the latency is approximately 1.2ms; under extreme pressure of 5000 records / second, the latency increases to approximately 2.4ms.

[0109] Audit latency of this invention (dark gray bars): Due to the addition of fine-grained context capture and national cryptographic signature calculation, the latency has increased slightly. It is approximately 1.5ms at 100 records / second and approximately 3.1ms at 5000 records / second.

[0110] Experimental results show that although the present invention adds a security protection dimension, the overall latency increment is controlled within 1ms, which fully meets the stringent requirements of the power system production control area for the real-time performance of business operations.

Claims

1. A fine-grained security audit method for power systems, characterized in that: Includes the following steps: The security context capture module (101) is used to intercept communication protocol messages in real time at the decision point of the power system's authentication and authorization service, and extract fine-grained security contexts that characterize the multi-dimensional features of security events. The audit log generation module (102) concatenates and encapsulates the original log data, the fine-grained security context, and the authoritative timestamp according to the preset field order to form a data packet to be signed. The audit private key protected by hardware inside the national cryptographic signature module (103) is called to execute the national cryptographic signature algorithm and generate an audit entry with a signature that has non-repudiation characteristics. The audit entries of the signature are obtained by using the hash chain management module (104), and sequential iterative hash calculation is performed using the national cryptographic digest algorithm. The audit entries of the signature at the current moment are chained together with the hash values ​​generated at the previous moment to generate a real-time end hash value that represents the integrity of the audit sequence of this domain. The hash chain management module (104) is used to monitor cross-security domain service trigger signals, obtain the real-time end hash value, and transmit the real-time end hash value as a cross-domain anchoring feature to the destination domain. By embedding the real-time end hash value into the current hash chain iteration process of the destination domain, the logical association of cross-security domain audit trajectories is completed.

2. The fine-grained security audit method for power systems according to claim 1, characterized in that, The fine-grained security context includes the authentication phase security context; When the security context capture module (101) determines that the current event is an identity authentication event, it extracts the request time, the source Internet Protocol address of the requester, the certificate digest of the user's digital certificate, the random challenge data in the authentication challenge response process, the digital signature value generated by the user terminal, and the final authentication result fed back by the authentication server, and uses the extracted content as the security context of the authentication stage.

3. The fine-grained security audit method for power systems according to claim 1, characterized in that, The fine-grained security context includes the authorization phase security context; When the security context capture module (101) determines that the current event is an access authorization event, it extracts the unique identity of the requesting subject, the resource identifier of the accessed resource, the type of operation instruction executed, the identifier of the specific policy rule that was successfully matched in the authorization decision process, and the final authorization result, and uses the extracted content as the security context of the authorization stage.

4. The fine-grained security audit method for power systems according to claim 1, characterized in that, The authoritative timestamp is provided by an authoritative time source; The audit record generation module (102) accesses the secondary clock node through the power dispatch data network inside the power system, uses the secondary clock node as the authoritative time source, and uses a precision time protocol to synchronize with the authoritative time source to obtain the authoritative timestamp, ensuring that the time synchronization error between all audit nodes in the network is less than one millisecond.

5. The fine-grained security audit method for power systems according to claim 1, characterized in that, The specific steps for executing the national cryptographic signature algorithm include: The national cryptographic signature module (103) performs digest processing on the data packet to be signed, and calls the audit-specific private key protected by hardware isolation to perform national cryptographic SM2 signature calculation on the data packet to be signed, generating a platform-level signature value, and combining the platform-level signature value with the data packet to be signed to generate the audit entry for the signature.

6. The fine-grained security audit method for power systems according to claim 1, characterized in that, The sequential iterative hash calculation performed by the aforementioned national cryptographic digest algorithm includes an initialization phase, which specifically comprises: For the first audit record generated during the initial operation of the system, the hash chain management module directly performs the national cryptographic digest algorithm on the signed audit entry to generate an initial hash value.

7. The fine-grained security audit method for power systems according to claim 1, characterized in that, The specific steps for performing sequential iterative hash calculation using the national cryptographic digest algorithm include: The hash chain management module (104) extracts the audit entry of the signature corresponding to the audit record at the current moment, obtains the hash value of the previous moment stored in the audit database, concatenates the audit entry of the signature at the current moment with the hash value of the previous moment, and then executes the national cryptographic digest algorithm again to generate the real-time end hash value at the current moment.

8. The fine-grained security audit method for power systems according to claim 1, characterized in that, The fine-grained security auditing method also includes an internal tampering monitoring step: The hash chain management module (104) recalculates the audit entry of the signature stored in the database with the hash value of the previous moment to obtain the expected hash value, and performs a logical equivalence judgment between the expected hash value and the actual hash value stored in the database. If the two are inconsistent, it is determined that the audit trace has been corrupted.

9. The fine-grained security audit method for power systems according to claim 1, characterized in that, The specific process of embedding the real-time end hash value into the current hash chain iteration of the destination domain includes: After receiving the real-time terminal hash value, the destination domain defines the real-time terminal hash value as an external input feature across the operation sequence; When the destination domain generates subsequent authorized operation audit records, the hash chain management module (104) concatenates the audit entry of the signature generated at the current moment in the destination domain with the real-time end hash value and executes the national cryptographic digest algorithm to calculate and generate an anchor hash value.

10. A fine-grained security audit system for power systems, characterized in that: The fine-grained security audit method for power systems, applied to any one of claims 1-9, includes: The security context capture module (101) is used to extract fine-grained security contexts in real time in the decision path of identity authentication or access authorization services in the power system; The audit log generation module (102) is used to concatenate and encapsulate the raw log data, the fine-grained security context, and the authoritative timestamp to form a data packet to be signed; The national cryptographic signature module (103) is used to call the hardware-protected audit private key to execute the national cryptographic signature algorithm on the data packet to be signed, and generate an audit entry with a signature that has non-repudiation characteristics. The hash chain management module (104) is used to construct a hash chain using the national cryptographic digest algorithm and generate a real-time end hash value, and to perform hash fingerprint anchoring in cross-security domain scenarios by transmitting the real-time end hash value to the destination domain.